Skip to main content

Understanding hazards in data access requests

When applying to use data in the Thames Valley and Surrey Secure Data Environment, users are asked to consider whether their project includes any potential hazards. This does not mean the project is unsafe or unsuitable. It means there may be features of the project, data, methods or outputs that need to be understood carefully so that the right safeguards can be put in place.

What we mean by a hazard

A hazard is anything about the proposed work that could lead to harm, an unacceptable outcome, or a loss of trust if it is not properly understood and managed. In this context, hazards may relate to the data being requested, the people or groups included in the study, the way the data will be analysed, the people who will access it, or the outputs that may be produced.

Examples might include work involving a very small or specific group of patients, data that could be sensitive or potentially identifying, the use of artificial intelligence or other advanced analytical methods, or outputs that could accidentally reveal confidential information if not checked carefully.

Why this matters

Identifying hazards helps make sure that data is used safely, responsibly and in line with public expectations. It supports proportionate decision-making by helping the SDE understand where standard safeguards are likely to be enough, and where additional controls or advice may be needed.

This process helps protect patient confidentiality, reduce the risk of misuse or accidental disclosure, and maintain public trust in the use of health and care data for research and planning. It also helps applicants think through any issues early, before access is approved.

What to consider when completing the hazards section

Users should consider the project as a whole, rather than looking only at individual data items. This includes the population covered by the project, the level of detail in the data, whether data will be linked with other information, who will access the data, what methods will be used, and what outputs may be produced.

Users should also consider whether the work could have an unequal or negative impact on individuals or communities, whether findings could be misunderstood or misused, and whether there are any circumstances that could make identification more likely. This might include small numbers, rare conditions, detailed dates or locations, free text, images, or information already known to members of the project team.

If users are unsure whether something is a hazard, they should say so. Selecting “Unsure” is not a problem; it simply shows that further information, advice or review may be needed. The SDE will carry out its own assessment and may ask for more information or apply additional controls where appropriate.

Controls and Safeguards

TVS SDE applies standard safeguards to all approved projects, including access controls, user checks, secure workspaces, monitoring and output checking. You only need to describe additional controls where the nature of the project may require extra assurance.
 
This might include, for example, tighter access restrictions, additional review of outputs, independent review of methods, limits on data linkage, restrictions on importing external data, enhanced monitoring, or specific controls for AI models, small populations, sensitive data or potentially identifying outputs.
 
The TVS SDE team will review the risks as part of the access review process. Additional risks may be identified and further controls may be required before the project is approved.