SA国际传媒

Sunday 27 September 2026
Salisbury Foundation Trust

FOI_9575

Internal Reference Number: FOI_9575

Date Request Received: 27/07/2026 00:00:00

Date Request Replied To: 18/08/2026 00:00:00

This response was sent via: By Email

Request Summary: Breach of sharing opted out staff PID with external supplier

Request Category: Private Individuals

 
Question Number 1:
Under the provisions of the Freedom of Information Act 2000, I am writing to request the following information regarding the breach of personal identifiable information between the Trust and Bank Partners - the new supplier of Temporary staffing re 'opted out' staff please could the following questions be answered.

Had there been a data cleanse of staff that hadn鈥檛 had a job via their bank contract in the previous months/years before migration of data to Bank Partners?



 
Answer To Question 1:
The Trust would have routinely completed a data cleanse for bank worker contracts only. This would not have been extended to individuals who hold a substantive and bank contract.

 
Question Number 2:
If that was the case, were there staff still on the temporary staffing database that hadn鈥檛 been contracted to do a bank shift before the 6 month deadline?
 
Answer To Question 2:
Yes, there would have been individuals who hold a substantive and bank contract retained on the database
 
Question Number 3:
How did the breach between Temporary staffing at the Trust/s and Bank Partners occur?
 
Answer To Question 3:
The request not to have the information shared with Bank Partners had been recorded. However, during the preparation of the data file provided to Bank Partners, the details were not excluded as intended. As a result,the information was included in the dataset that was transferred.
 
Question Number 4:
How soon, after the information re opted out staff was incorrectly sent, was it noticed and by whom, Trust staff or Bank Partners?
 
Answer To Question 4:
The information was shared with Bank Partners on 22 June 2026. Upon becoming aware of the issue, we immediately instructed Bank Partners to delete the affected records. Final deletion of all affected data was confirmed on 8 July 2026
 
Question Number 5:
Please list all details of staff that was sent to Bank Partners that were being fast tracked - e.g Name/Date of Birth/Address/National Insurance number etc?
 
Answer To Question 5:
鈥� Name
鈥� Email address
鈥� National Insurance Number
鈥� Address
鈥� Date of birth
 
Question Number 6:
Have Bank Partners deleted the information that was incorrectly sent re opted out staff?
 
Answer To Question 6:
The Trust have received written confirmation via email from a senior representative of Bank Partners confirming that the affected data has been permanently deleted from their systems
 
Question Number 7:
If Bank Partners have deleted the incorrectly sent information how did Bank Partners notify the 3 Trusts (SFT, GWH, RUH) that they had. Was this a phone/teams call or by email? Who was actually notified?
 
Answer To Question 7:
The Trust have received written confirmation via email from a senior representative of Bank Partners confirming that the affected data has been permanently deleted from their systems. The Group Head of Resourcing was notified.
 
Question Number 8:
How were staff, that had opted out of their information being sent to Bank Partners, notified of the breach?
 
Answer To Question 8:
They were emailed.
 
Question Number 9:
If the notification of the breach was sent only by email to staffs鈥� NHS account, how were staff contacted if they no longer had access to their NHS account, e.g left the Trust/s?
 
Answer To Question 9:
They were contacted via the email address in which they had their bank agreement under, this could be personal or NHS.
 
Question Number 10:
How many emails 鈥榖ounced鈥� back saying either out of office/invalid etc and was this recorded either on a spreadsheet or other method?
 
Answer To Question 10:
One - recorded on a spreadsheet
 
Question Number 11:
Of those that were invalid or out office stating they had left the Trust/s, how many have been contacted in another way such as by letter?
 
Answer To Question 11:
Via personal email
 
Question Number 12:
If those that were invalid or out office stating they had left the Trust were not contacted in any other way other than by NHS mail why was this the case as this still a breach of their personal information?
 
Answer To Question 12:
N/A
 
Question Number 13:
Was a datix raised regarding the breach and were the ICO notified?
 
Answer To Question 13:
A Datix incident report was raised as soon as the breach was identified, and the matter was reviewed by the Trusts' Information Governance teams and Data Protection Officers.
The Data Protection Officer used the NHS Guide to the Notification of Data Security and Protection Incidents, it was determined that whilst this constituted a data protection incident, it did not meet the threshold for notification to the Information Commissioner's Office (ICO).
 
To return to the list of all the FOI requests please click here

Our staff at SA国际传媒 Hospital have long been well regarded for the quality of care and treatment they provide for our patients and for their innovation, commitment and professionalism. This has been recognised in a wide range of achievements and it is reflected in our award of NHS Foundation Trust status. This is afforded to hospitals that provide the highest standards of care.

Person Centred & Safe

Professional

Responsive

Friendly

Progressive

SA国际传媒, SA国际传媒 Hospital, Odstock Road, Salisbury, Wiltshire, SP2 8BJ
T: 01722 336262 E: sft.pals@nhs.net
© 2026 SA国际传媒
Trust Values