NHS England Data Sharing Audit: University of Leeds
This report records the key findings of a remote data sharing audit of University of Leeds (UoL) between 8 – 12 June 2026.
Audit summary
Purpose
This report records the key findings of a remote data sharing audit of University of Leeds (UoL) between 8 – 12 June 2026. It provides an evaluation of how UoL and its Processors conform to the requirements of:
- the data sharing framework contract (DSFC) CON-315426-K3W7R-v2.03
- the data sharing agreement (DSA) DARS-NIC-11809-H1Y3W-v7.2
- the organisations’ own policies, processes and procedures
This DSA covers the provision of the following datasets:
| Dataset | Classification of data | Dataset period |
|---|---|---|
|
Cancer Registration Data |
Identifiable/ Sensitive |
Latest available 09/2026, One-off |
|
Emergency Care Data Set (ECDS) |
Identifiable / Sensitive |
2019/20 – 2022/23 M06, One-off |
|
HES-ID to MPSID HES Accident and Emergency |
Pseudo/Anonymised /Non-Sensitive |
Historic Held, Latest Available, One-off |
|
HES-ID to MPSID HES Admitted Patient Care |
Pseudo/Anonymised / Non-Sensitive |
Historic Held, Latest Available, One-off |
|
HES-ID to MPSID HES Outpatients |
Pseudo/Anonymised / Non-Sensitive |
Historic Held, Latest Available, One-off |
|
Hospital Episode Statistics Accident and Emergency (HES A and E) |
Identifiable / Non-Sensitive |
Historic Held, Latest Available, One-off |
|
HES-Admitted Patient Care (HES APC) |
Identifiable / Sensitive Consultant code, Referrer code |
Historic Held, Latest Available, One-off |
|
HES-Outpatients (HES OP) |
Identifiable / Sensitive Consultant code, Person referring patient |
Historic Held, Latest Available, One-off |
|
Mental Health and Learning Disabilities Data Set (MHLDDS) |
Identifiable / Sensitive All Sensitive Fields |
Historic Held, Latest Available, One-off |
|
Mental Health Minimum Data Set (MHMDS) |
Identifiable / Sensitive All Sensitive Fields |
Historic Held, Latest Available, One-off |
|
Mental Health Services Data Set (MHSDS) |
Identifiable / Sensitive All Sensitive Fields |
Historic Held, Latest Available, One-off |
|
NDRS Cancer Registrations |
Identifiable / Sensitive |
Latest Available, One-off |
|
NDRS National Radiotherapy Dataset (RTDS) |
Identifiable / Sensitive |
Latest Available, One-off |
|
NDRS Systemic Anti-Cancer Therapy Dataset (SACT) |
Identifiable / Sensitive |
Latest Available, One-off |
The Controller is UoL. The Processors are ARROW Business Communication Ltd (ARO) and Microsoft Limited.
UoL requires access to NHS England data for the purpose of the following research project:
Cancer registration data from The Yorkshire Specialist Register of Cancer in Children and Young People (YSRCCYP) is used to carry out a programme of epidemiological and applied health research as set out in the Yorkshire Register protocol.
The YSRCCYP was originally set up in collaboration with local clinicians to provide research information. Since 1994, the YSRCCYP database and research programme has been managed by UoL’s Division of Epidemiology and Biostatistics. UoL is the Sole Data Controller for the YSRCCYP with sole responsibility for determining the purposes for which and the manner in which any personal data are processed.
The interviews during the audit were conducted remotely through video conferencing.
This is an exception report based on the criteria expressed in the Data Sharing Audit Guide version 5.
Audit type and scope
|
Audit type |
Routine |
|---|---|
|
Scope areas |
Information Transfer Access Control Data Use and Benefits Risk Management Operational Management and Control Data Destruction |
|
Restrictions |
Access Control - limited visibility of physical controls |
Overall risk statement
Based on evidence presented during the audit and the type of data being shared the following risk has been assigned from the options of Critical - High - Medium - Low.
Current risk statement: Low
In deriving this risk, the Audit Team takes into account compliance, duty of care, confidentiality and integrity, as appropriate.
Data recipient’s acceptance statement
UoL has reviewed this report and confirmed that it is accurate.
Data recipient’s action plan
UoL will establish a corrective action plan to address each finding. The Audit Team will validate this plan and the resultant actions will be followed up with UoL by the IG Risk and Assurance team at NHS England to confirm the findings have been satisfactorily addressed.
The Audit has identified 3 opportunities for improvement which are provided for reference only and will not be followed up.
Findings
The following table identifies the 1 agreement nonconformity, 1 organisation nonconformity and 2 points for follow-up raised as part of the audit.
| Ref | Finding | Link to area | Clause | Designation |
|---|---|---|---|---|
|
1 |
The Data Breach Management Process does not include a requirement to notify NHS England immediately upon identification of a data breach involving NHS England data. |
Operational Management |
DSFC, Part 2, Terms and Conditions, Clause 4.1.8 |
Agreement nonconformity |
| 2 |
Risks have not been consistently or accurately scored in line with the risk scoring matrix and a documented, team-specific risk management process is not in place, contrary to the organisation’s risk management requirements. |
Risk Management |
UoL risk management policy
|
Organisation nonconformity |
| 3 |
An updated DSA reflecting current processing arrangements was not available during the audit and will be reviewed during the post-audit review. Specifically, DARS-NIC-11809-H1Y3W-v7.2 (dated 22/05/2025) contains information that no longer reflects current practices, including references to the use of the LASER VRE, the inclusion of Microsoft Ltd as a data processor, and a restriction of the territory of use to England and Wales. UoL has advised that a revised DSA application is in progress to address these discrepancies, including aligning the agreement to the ARO Trusted Research Environment (TRE), updating processor details, and extending the approved territory of use to Europe. The updated agreement and supporting evidence will be reviewed post-audit to confirm that these amendments have been formally authorised and accurately implemented. Data is currently stored within data centres located in the approved territory of use, with both primary and backup data centres situated within England. At the time of the audit, no NHSE data had been downloaded to the ARO hosted TRE by UoL. |
Information Transfer |
|
Follow-up |
| 4 | A formal Patch Management Policy was not available during the audit and will be reviewed during the post-audit review. At the time of the audit, UoL had not yet ratified a Patch Management Policy; however, a draft version was under development and provided as audit evidence. The final, approved policy and supporting evidence of implementation will be reviewed post-audit review to confirm alignment with organisational requirements. | Access Control |
|
Follow-up |
Opportunities for improvement
The following table identifies 3 opportunities for improvement which could help an organisation improve its controls or processes.
|
Ref |
Opportunities for improvement |
Link to Area |
|---|---|---|
|
1. |
Risk reviews are currently undertaken on a six-monthly cycle. The organisation may wish to consider introducing monthly risk reviews via the Audit and Risk Committee, or an equivalent forum, to enhance oversight, improve accountability and support more proactive risk management. |
Risk Management |
| 2. |
Access to the Trusted Research Environment is currently managed through informal approval arrangements without a documented approval process. The organisation may wish to consider introducing a formal access approval mechanism to strengthen governance, accountability and auditability of user access decisions. |
Access Control |
| 3. |
Records of Processing Activities (RoPA) and Information Asset Register (IAR) information is currently maintained across multiple locations rather than a unified structure. The organisation may wish to consider consolidating this into a single, centralised record to enhance accessibility, support audit activities and align more closely with ICO expectations for transparency and accountability. |
Operational Management |
Use of Data
UoL confirmed that the datasets were only being processed and used for the purposes defined in the DSA and were not being linked with another dataset.
Data Location
UoL confirmed that processing and storage locations, including disaster recovery and backups, of the datasets were limited to the location shown in the following table. These locations conform with the territory of use defined in section 2c of the DSA.
| Organisation | Territory of Use |
|---|---|
|
UOL |
England / Wales |
Backup Retention
The duration for which data may be retained on backup media is:
| Organisation | Media Type | Period |
|---|---|---|
|
ARO |
Cloud |
Duration of the research programme |
Disclaimer
The audit was based upon a sample of the data recipient’s activities, as observed by the Audit Team. The findings detailed in this audit report may not include all possible nonconformities which may exist. In addition, as the audit interviews were conducted through a video conference platform, certain controls that would normally be assessed whilst onsite could not be witnessed.
NHS England has prepared this audit report for its own purposes. As a result, NHS England does not assume any liability to any person or organisation for any loss or damage suffered or costs incurred by it arising out of, or in connection with, this report, however such loss or damage is caused. NHS England does not assume liability for any loss occasioned to any person or organisation acting or refraining from acting as a result of any information contained in this report.
Last edited: 24 July 2026 2:48 pm