Order Management transparency notice
This transparency notice for the Genomics Order Management project explains:
- why we collect information about you (we call this 'personal data')
- what we do with it, including who we share it with
- how long we keep it for and where we store it
- our legal basis for using it
- what your data protection rights are
To read more about how NHS England uses personal data to improve health and care, see NHS England's privacy notice.
About the Order Management project
The National Genomics Order Management Interoperability Project is focused on allowing genomic tests to be ordered through a single electronic system nationally. Currently, each region within the Genomics Medicine Service has their own process for ordering tests which can vary depending on the region and organisations involved. To standardise the test requesting, it uses a standardised master data set, which provides all data fields required by both the requester of the test and the lab completing the test. This is used to accept and progress the genomic test request and support the report being provided back to the requestor.
Ultimately, the project is aiming to make the ordering and management of Genomic Test orders more simple, efficient and effective by allowing electronic ordering and communication across organisations to be smoother.
The key parts of the project include:
Central broker: to coordinate the electronic communication required between organisations and allow for genomic testing, genomic test reports and updates between given organisations and systems. This includes storage of data for these activities centrally.
Genomic Test Order portal: to provide a generic way for requestors to create and manage genomic test orders access the national order management system, where their local systems do not have capabilities or integration to the national broker is not available (for example, lab system isn’t able to communicate to the central broker).
Integrated Trust and Lab Genomic Test ordering: to enable the use of an existing system (electronic patient record systems (EPRs) and Laboratory Information Management Systems (LIMS)) to connect to the central broker and to allow for end-to-end communication of the test across organisations.
Introduction of the national Order Management infrastructure will drive the following key, fundamental benefits:
Data quality and consistency – Electronic ordering will improve the completeness and accuracy of information passed between the requestors of tests and laboratories fulfilling the order.
Time and resource savings – Electronic ordering will remove the need for manual transcription of current paper-based order forms.
Order and sample tracking – A way of providing and querying status updates for the order and the whereabouts of related samples will address the current lack of visibility for both clinicians and laboratory personnel.
Strategic alignment - to the 'Accelerating genomic medicine in the NHS' strategic ambitions within the NHS (for example, NHS Long Term Plan), to improve and align with NHS ambitions to improve interoperability and use of standardised data within the Genomic Medicines Service (GMS).
Equity of access –This work adds a scalable, interoperable capability to the GMS ecosystem. Once expanded, it will help ensure fair access to test ordering and improve communication of the tasks needed to complete an order.
Turnaround times for test – Faster communications and reduced manual tasks will improve how quickly a test can be turned around from request to a report being completed and received.
Process improvements and standardisation – Use of the solution will mean more specialities are working in the same way.
Scalability and integration opportunities – it is likely that there are further opportunities to collaborate and share data between systems or organisations will be realised in future. The Order Management infrastructure is the enabler for introduction of the Unified Genomic Record (UGR) and introduction of structured reporting data to standardise the way genomic test reports are shared.
Each of the above listed items can be considered as either directly or indirectly benefitting patients.
Our role
Under data protection law, NHS England is the 'controller' for the Order Management project. This means that we make decisions about what personal data we need to collect and how we will use your data to deliver the service.
What data we collect
The personal data to be processed within the scope of the Order Management project relates to both patients and NHS personnel. In addition to the areas mentioned below, a PDF of the test report will also be shared through the broker from the testing lab to the clinician.
To provide the Order Management Service we need to collect and process your:
Genomic test data [Category] – such as your:
- demographics information Name, date of birth, ethnicity and sex, gender identity, NHS number [data item]
- patient information: Personal and Personal-Sensitive (special category) information for patients (relatives of patient for certain test)
- test request data – Test ID, test type, clinical details, pregnancy status
- record of your consent choice in relation to research [data item]
- information in relation to your biopsy or specimen [data item]
- previous genomic reports
- patient clinical information (see table below)
- relevant previous non-genomic diagnostic reports (for example, pathology)
- healthcare professionals – names, contact details and organisations
Genomic test reports as an attached PDF file, including genomic test results, variants of interest, patient and clinician information.
In some circumstances we may perform diagnostic requests on groups rather than single individuals, such as testing a family (mother, father and child) or testing a pregnant mother and her feotus. In these events, we collect relevant Genomic test data and test reports for each individual. We also link these records so that the group can be reviewed together.
The data being either used or generated has been documented formally within a Master Data Set (MDS), the data groups contained within this are found below:
MDS data groups
| Data group | Short description |
|---|---|
| Healthcare professional | Name, contact and organisational information |
| Patients |
Personal and Personal-Sensitive (special category) information for patients (patient and/or relatives of the patient). Broad examples range from name and other personal identifiers such as DOB, ethnicity, sex, gender identity. Foetus detail is recorded (identifier, sex, status at time of test, pregnancy ID) for relevant tests. |
| Record of Discussion (RoD) or (NGRL) Consent for Research | Incorporating clinical staff name and patient demographics (or patient representative) as relating to the consent. |
| Test request | Information associating test request to patient. |
| Primary sample (raw specimen or biopsy) | Information associating a specimen to patient or relatives' identifiers. |
| Other relevant clinical document (attachable file) | Comparable data to 'Patients' data group, (PDF), clinical personnel identifiers present in report files. |
| Patient clinical information | Personal and Personal-Sensitive data, for example, phenotypic information, and genomic ethnicity for the patient and various elements relating to specifics of the disease and subject of the testing. |
| Further supporting information | Information associating clinical encounter or speciality to patient |
Where we get your data from
Data will be collected about individual patients, from clinicians requesting a test and from related IT systems used at the requesting organisation – which will be a hospital or other care setting. For example, information relating to the test request, or to the patient themselves such as name, date of birth, ethnicity and gender. This will be provided by National NHS systems (Personal Demographics Service) that are already in place.
Data will in some circumstances be collected directly from the patient by the relevant treatment provider and it is expected that the patient will be registered locally with the patient electronic record prior to being referred for a genomic test.
Data will in some circumstances be entered manually by clinicians and health care professionals when dealing with patients or their family members as part of the test ordering consultation process. At the stage of test requesting, the following types of data may be collected:
Patient Demographics
Organisation or clinician Details
Reason for testing
Relevant clinical information to support testing
Record of Discussion (consent for WGS research)
Sample type information
Data held within the central broker will be managed through secure communication infrastructure standards (Application Programming Interfaces Management (APIM) and Apigee) to ensure appropriate levels of security and authenticated access.
How we use your data
Use and management of genomic test data
This section explains how data is used, transferred, and stored as part of the Genomics Order Management project, delivered under a Ministerial Direction. It outlines the key processes that support the ordering, fulfilment, and reporting of genomic tests across the NHS, and the measures in place to ensure data is managed securely, responsibly, and in accordance with national standards.
Overview of the genomic testing process
Data referenced within this notice supports a range of NHS systems and activities involved in the genomic testing pathway - from the initial test request through to sample processing, analysis, and the generation of a final report.
At a high level, the process includes:
- Test request: A hospital, laboratory, or healthcare organisation requests a specific genomic test.
- Sample processing: The request may involve preparing and sequencing a DNA sample, followed by analysis and interpretation of the results.
- Reporting: A final report is created and shared securely with the requesting organisation.
Data underpins each of these stages; for example, sample quality information supports laboratory preparation, and patient details are used by scientists to interpret results accurately.
Order Management and data exchange
The Genomics Order Management System enables secure, standardised communication between NHS organisations and Genomic Laboratory Hubs (GLHs). Its core features include:
Test status updates: Real-time notifications showing when a test request has been received, is in progress, or is awaiting a sample.
Sample tracking: Updates confirming when a sample has been sent or received, including transfers between organisations or GLHs.
Request processing: Validation of request details and matching to available samples, with routing to the appropriate testing location.
Result reporting: Creation and storage of final test reports in secure PDF format, accessible only to authorised users.
Data security and storage
All patient and test request information is transmitted and stored securely using modern encryption standards (HTTPS/AES-256). The Order Management solution, including the central broker and national genomics portal, is hosted in line with NHS England’s security and interoperability standards.
Access and authentication are managed through Apigee and API Management (APIM), ensuring that only authorised systems and users can exchange data.
Data such as test requests, sample updates, and reports may be held within a patient’s Electronic Patient Record (EPR) or within the National Genomics Portal, depending on the system used to place the request.
Organisations submitting electronic requests must comply with NHS and international standards - FHIR UK Core R4 and Open API (APIM) standards - to ensure secure interoperability. Where existing systems use a different standard, HL7 V2, NHS England provides guidance to support message transformation to the FHIR and Open API standards mentioned and support safe data exchange.
Further detail is available in the FHIR Genomics Implementation Guide, which outlines technical specifications for connecting local systems to the national broker.
Access and authentication
Access to the National Genomics Portal requires secure authentication, either through Care Identity Service 2 (CIS2) or locally managed multi-factor authentication within NHS organisations.
Where genomic test requests are submitted via an Electronic Patient Record, authentication follows NHS Smartcard processes and local governance policies to ensure appropriate access controls.
Hosting and cloud infrastructure
The programme follows a cloud-first approach, with data hosted securely within the UK using Amazon Web Services (AWS) and NHS England-approved services (for example, Patient Data Manager).
All data storage and processing comply with UK data protection legislation and NHS information governance standards, ensuring patient information is safeguarded throughout the testing process.
Our legal basis
Data protection law requires NHS England to have a legal basis before we can use your personal data.
Our legal basis is:
Legal obligation - Article 6(1)(c) of UK GDPR. This is because the Secretary of State for Health and Social Care has issued us with a Direction to deliver this service. This Direction is called the NHS Genomics Medicine Services Directions.
We also need an additional legal basis in the UK GDPR and the Data Protection Act 2018 (DPA 2018) to use data which is extra sensitive. This is known as 'special categories of personal data'. Our legal basis to use data relating to your health, race, ethnicity, genetics is:
Health or social care – Article 9(2)(h) of UK GDPR, plus Schedule 1, Part 1, Paragraph 2 "Health or social care purposes" of DPA 2018.
Processors
We also share some data with our data processor Intersystems Healthcare Connect who provide a broker service which will deliver electronic communication required in order to process each test request under a contract. They can only use, store and keep the data in accordance with our instructions and cannot use the data for any other purposes.
How long we keep data for
NHS England shall retain data in line with The Records Management Code of Practice 2021 and organisational policy.
Data item or category
Records (as defined in the Genomics FHIR IG) covering orders, results, consent, clinical structured observations.
How long we keep it for
30 years.
Why
Records Management Code of Practice retention schedule and Royal College of Pathology and BSGM guidelines.
We keep your data in accordance with The Records Management Code of Practice 2021.
Where we store data
We securely store your data on our servers in the United Kingdom (UK), on NHS England AWS cloud infrastructure that is conformant to United Kingdom (UK) boundary needs for data capture.
All patient and test request information is transmitted and stored securely using modern encryption standards (HTTPS/AES-256). The Order Management solution, including the central broker and national genomics portal, is hosted in line with NHS England’s security and interoperability standards.
Access and authentication are managed through Apigee and API Management (APIM), ensuring that only authorised systems and users can exchange data.
Data such as test requests, sample updates, and reports may be held within a patient’s Electronic Patient Record (EPR) or within the National Genomics Portal, depending on the system used to place the request.
Organisations submitting electronic requests must comply with NHS and international standards - FHIR UK Core R4 and Open API (APIM) standards - to ensure secure interoperability. Where existing systems use a different standard, HL7 V2, NHS England provides guidance to support message transformation to the FHIR and Open API standards mentioned, and support safe data exchange.
Further detail is available in the FHIR Genomics Implementation Guide, which outlines technical specifications for connecting local systems to the national broker.
Your data protection rights
Under data protection law, you have the following rights over your data for this service:
Your right to be informed – You have the right to be told how and why we are using your personal data. We have published this transparency notice to provide you with this information.
Your right to get copies of your data – You have the right to ask us for copies of your personal data (right of access). For more information, see how to make a subject access request.
Your right to get your data corrected – You have the right to ask us to correct (rectify) your personal data if you think it is inaccurate or incomplete.
Your right to limit how we use your data – You have the right to ask us to limit the way we use your personal data (restrict processing) in certain circumstances.
To make a rights request, email us at [email protected].
Opt outs
National Data Opt-Out
When NHS England collects the Order Management data from healthcare providers
If you have registered a National Data Opt-Out, NHS England can still collect your data under the Genomics Services Directions. This is because the National Data Opt-Out does not apply where NHS England has a legal obligation to collect the data (see section 6.4 of the National Data Opt-Out Operational Policy Guidance for more information).
When NHS England shares Genomics Order Management data
For any data we share with other organisations through our Data Access Request Service, we will apply the national data opt-out in line with the National Data Opt-Out Operational Policy Guidance.
You can find out more about and register a national data opt-out or change your choice on the NHS.uk website.
Your right to complain
We take our responsibility to look after your data very seriously. If you have any questions or concerns about how NHS England uses your data, please contact our Data Protection Officer at: [email protected].
If you are not happy with our response, you have the right to make a complaint about how we are using your data to the Information Commissioner’s Office by calling 0303 123 1113 or through their website.
Changes to this notice
We may make changes to this notice. If we do, the 'last edited' date on this page will also change. Any changes to this notice will apply immediately from the date of any change.
Appendix A
| Right to be informed | Right to get copies (access) | Right to get data corrected (rectification) | Right to get data deleted (erasure) | Right to limit how data is used (restrict processing) | Right to object | Right to data portability | Right not to be subject to automated decision making | Right to withdraw consent | |
|---|---|---|---|---|---|---|---|---|---|
| Consent | Yes | Yes | Yes | Yes | Yes | No | Yes | No | Yes |
| Contract | Yes | Yes | Yes | Yes | Yes | No | Yes | No | No |
| Legal obligation | Yes | Yes | Yes | No | Yes | No | No | No | No |
| Vital interests | Yes | Yes | Yes | No | Yes | No | No | Yes | No |
| Public task | Yes | Yes | Yes | No | Yes | Yes | No | Yes | No |
| Legitimate interests | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No |
Last edited: 1 October 2026 11:09 am