Skip to main content

NHS England Data Sharing Audit: University of Leeds

This report records the key findings of a remote data sharing audit of University of Leeds (UoL) between 8 – 12 June 2026.

Audit summary

Purpose

This report records the key findings of a remote data sharing audit of University of Leeds (UoL) between 8 – 12 June 2026. It provides an evaluation of how UoL and its Processors conform to the requirements of:

  • the data sharing framework contract (DSFC) CON-315426-K3W7R-v2.03
  • the data sharing agreement (DSA) DARS-NIC-11809-H1Y3W-v7.2
  • the organisations’ own policies, processes and procedures

This DSA covers the provision of the following datasets: 

Dataset Classification of data Dataset period

Cancer Registration Data

Identifiable/ Sensitive

Latest available 09/2026, One-off

Emergency Care Data Set (ECDS)

Identifiable / Sensitive

2019/20 – 2022/23 M06, One-off

HES-ID to MPSID

HES Accident and Emergency

Pseudo/Anonymised /Non-Sensitive

Historic Held, Latest Available, One-off

HES-ID to MPSID

HES Admitted Patient Care

Pseudo/Anonymised / Non-Sensitive

Historic Held, Latest Available, One-off

HES-ID to MPSID

HES Outpatients

Pseudo/Anonymised / Non-Sensitive

Historic Held, Latest Available, One-off

Hospital Episode Statistics

Accident and Emergency (HES A and E)

Identifiable / Non-Sensitive

Historic Held, Latest Available, One-off

HES-Admitted Patient Care (HES APC)

Identifiable / Sensitive

Consultant code, Referrer code

Historic Held, Latest Available, One-off

HES-Outpatients (HES OP)

Identifiable / Sensitive

Consultant code, Person referring patient

Historic Held, Latest Available, One-off

Mental Health and Learning

Disabilities Data Set (MHLDDS)

Identifiable / Sensitive

All Sensitive Fields

Historic Held, Latest Available, One-off

Mental Health Minimum Data

Set (MHMDS)

Identifiable / Sensitive

All Sensitive Fields

Historic Held, Latest Available, One-off

Mental Health Services Data Set (MHSDS)

Identifiable / Sensitive

All Sensitive Fields

Historic Held, Latest Available, One-off

NDRS Cancer Registrations

Identifiable / Sensitive

Latest Available, One-off

NDRS National Radiotherapy

Dataset (RTDS)

Identifiable / Sensitive

Latest Available, One-off

NDRS Systemic Anti-Cancer

Therapy Dataset (SACT)

Identifiable / Sensitive

Latest Available, One-off

The Controller is UoL. The Processors are ARROW Business Communication Ltd (ARO) and Microsoft Limited.

UoL requires access to NHS England data for the purpose of the following research project:

Cancer registration data from The Yorkshire Specialist Register of Cancer in Children and Young People (YSRCCYP) is used to carry out a programme of epidemiological and applied health research as set out in the Yorkshire Register protocol.

The YSRCCYP was originally set up in collaboration with local clinicians to provide research information. Since 1994, the YSRCCYP database and research programme has been managed by UoL’s Division of Epidemiology and Biostatistics. UoL is the Sole Data Controller for the YSRCCYP with sole responsibility for determining the purposes for which and the manner in which any personal data are processed.

The interviews during the audit were conducted remotely through video conferencing.

This is an exception report based on the criteria expressed in the Data Sharing Audit Guide version 5.

Audit type and scope

Audit type 

Routine

Scope areas 

Information Transfer

Access Control

Data Use and Benefits

Risk Management

Operational Management and Control

Data Destruction

Restrictions 

Access Control - limited visibility of physical controls  

Overall risk statement

Based on evidence presented during the audit and the type of data being shared the following risk has been assigned from the options of Critical - High - Medium - Low.

Current risk statement: Low

In deriving this risk, the Audit Team takes into account compliance, duty of care, confidentiality and integrity, as appropriate.


Data recipient’s acceptance statement

UoL has reviewed this report and confirmed that it is accurate.

Data recipient’s action plan

UoL will establish a corrective action plan to address each finding. The Audit Team will validate this plan and the resultant actions will be followed up with UoL by the IG Risk and Assurance team at NHS England to confirm the findings have been satisfactorily addressed.

The Audit has identified 3 opportunities for improvement which are provided for reference only and will not be followed up.


Findings

The following table identifies the 1 agreement nonconformity, 1 organisation nonconformity and 2 points for follow-up raised as part of the audit.

Ref Finding Link to area Clause Designation

1

The Data Breach Management Process does not include a requirement to notify NHS England immediately upon identification of a data breach involving NHS England data.

Operational Management

DSFC, Part 2, Terms and Conditions, Clause 4.1.8

Agreement nonconformity

2

Risks have not been consistently or accurately scored in line with the risk scoring matrix and a documented, team-specific risk management process is not in place, contrary to the organisation’s risk management requirements.

Risk Management

UoL risk management policy

 

Organisation nonconformity

3

An updated DSA reflecting current processing arrangements was not available during the audit and will be reviewed during the post-audit review. Specifically, DARS-NIC-11809-H1Y3W-v7.2 (dated 22/05/2025) contains information that no longer reflects current practices, including references to the use of the LASER VRE, the inclusion of Microsoft Ltd as a data processor, and a restriction of the territory of use to England and Wales.

UoL has advised that a revised DSA application is in progress to address these discrepancies, including aligning the agreement to the ARO Trusted Research Environment (TRE), updating processor details, and extending the approved territory of use to Europe. The updated agreement and supporting evidence will be reviewed post-audit to confirm that these amendments have been formally authorised and accurately implemented.

Data is currently stored within data centres located in the approved territory of use, with both primary and backup data centres situated within England.

At the time of the audit, no NHSE data had been downloaded to the ARO hosted TRE by UoL.

Information Transfer

 

Follow-up

4 A formal Patch Management Policy was not available during the audit and will be reviewed during the post-audit review. At the time of the audit, UoL had not yet ratified a Patch Management Policy; however, a draft version was under development and provided as audit evidence. The final, approved policy and supporting evidence of implementation will be reviewed post-audit review to confirm alignment with organisational requirements. Access Control

 

Follow-up

Opportunities for improvement

The following table identifies 3 opportunities for improvement which could help an organisation improve its controls or processes.

Ref

Opportunities for improvement

Link to Area 

1.

Risk reviews are currently undertaken on a six-monthly cycle. The organisation may wish to consider introducing monthly risk reviews via the Audit and Risk Committee, or an equivalent forum, to enhance oversight, improve accountability and support more proactive risk management.

Risk Management
2.

Access to the Trusted Research Environment is currently managed through informal approval arrangements without a documented approval process. The organisation may wish to consider introducing a formal access approval mechanism to strengthen governance, accountability and auditability of user access decisions.

Access Control
3.

Records of Processing Activities (RoPA) and Information Asset Register (IAR) information is currently maintained across multiple locations rather than a unified structure. The organisation may wish to consider consolidating this into a single, centralised record to enhance accessibility, support audit activities and align more closely with ICO expectations for transparency and accountability.

Operational Management

Use of Data

UoL confirmed that the datasets were only being processed and used for the purposes defined in the DSA and were not being linked with another dataset.

Data Location

UoL confirmed that processing and storage locations, including disaster recovery and backups, of the datasets were limited to the location shown in the following table. These locations conform with the territory of use defined in section 2c of the DSA.

Organisation Territory of Use

UOL

England / Wales

Backup Retention

The duration for which data may be retained on backup media is:

Organisation Media Type Period

ARO

Cloud

Duration of the research programme

 


Disclaimer

The audit was based upon a sample of the data recipient’s activities, as observed by the Audit Team. The findings detailed in this audit report may not include all possible nonconformities which may exist. In addition, as the audit interviews were conducted through a video conference platform, certain controls that would normally be assessed whilst onsite could not be witnessed.

NHS England has prepared this audit report for its own purposes. As a result, NHS England does not assume any liability to any person or organisation for any loss or damage suffered or costs incurred by it arising out of, or in connection with, this report, however such loss or damage is caused. NHS England does not assume liability for any loss occasioned to any person or organisation acting or refraining from acting as a result of any information contained in this report.

Last edited: 24 July 2026 2:48 pm