Mandatory Data Protection Training · Alpha 1 · Pass mark 80%
0%
Training dashboard Log out
Mandatory learning

Vision Care Mandatory Data Protection Training

For people affected by homelessness: protect patient information, use Blink safely, and report concerns within 24 hours. The Microsoft Forms quiz is the formal assessment.

Vision Care clinician carrying out an eye-care consultation
Progress saves on this device All sections and checks required Formal assessment pass mark: 80%
Section 1

Welcome and why data protection matters

Vision Care volunteers handle information because patients trust us to protect privacy and dignity.

Information you may handle

  • Patient names, dates of birth and addresses
  • NHS eligibility, medical and eye-health information
  • Prescriptions and referral information
  • Volunteer and internal organisational information

Where data protection applies

  • Blink, Teams, Outlook and referral systems
  • Devices, screens and conversations
  • AI tools, translation tools and shared links
Why this matters: Patients trust Vision Care with sensitive information so they can receive safe eye care. Poor handling can cause distress, loss of privacy, and loss of trust.

Personal responsibility

Every volunteer is responsible for protecting the information they access during their role. Data protection is not only the responsibility of Tony Wing or Vision Care management.

Access only when needed

Only access patient information when it is necessary for the task you are carrying out.

Information can be exposed in different ways

A breach does not only mean hacking. Information can be exposed through:

  • An email
  • An unlocked screen
  • A conversation
  • A shared link
  • A screenshot
  • An unauthorised app
Knowledge check

Which item contains personal or confidential information?

Section 2

What information Vision Care holds

Vision Care holds both personal data and special category health data.

Health data needs extra protection: Health information is particularly sensitive and must be handled with additional care.
Key message: Outside Blink, volunteers should use Blink IDs only.
Blink IDs are still confidential: A Blink ID reduces identification risk, but it is still part of a confidential patient record and should only be used where necessary.

Examples of data held

  • Name, date of birth and address
  • NHS eligibility and medical history
  • Eye health, prescription and referral details

Why this matters

Removing only a name does not always make data anonymous. Other details can still identify someone.

Information does not need to contain a name to identify someone. Several small details can identify a person when combined.

True or false

Removing a patient's name always makes information anonymous.

Section 3

Using Blink safely

Volunteers must

  • Use Blink for patient-identifiable information
  • Access records only when needed for the task you are carrying out
  • Use only their own login and never share passwords
  • Check the previous user has logged out and never continue in another volunteer's session
  • Log out and fully close the browser after clinic
  • Report significant errors or wrong-patient entries

Volunteers must not

  • Download Blink reports or patient attachments
  • Take screenshots or photographs of Blink screens
  • Save patient information locally or in personal notes
Need-to-know access: Being able to open a record does not automatically mean you are authorised to view it.
Browser sign-out reminder: Closing a browser tab is not always the same as signing out. Always log out of Blink first, then fully close the browser.
If information is entered in the wrong patient record: Stop, do not try to hide it, and report it promptly.
Vision Care cannot remotely wipe patient information saved to personal devices.
Choose the permitted action
Section 4

Teams, Outlook and authorised referrals

Absolute Teams rule: Teams is not a patient record system. Never place patient-identifiable information in Teams.
Blink ID use: A Blink ID should only be used where there is a genuine need to discuss the patient.

Outlook and referrals

  • Use minimum necessary information
  • Before sending, stop and check recipient, subject line, body, attachment and sharing permissions
  • Avoid patient names in subject lines
  • Use only approved Vision Care accounts and authorised referral systems
  • Check the full email chain before forwarding or using Reply All
  • Do not use unrestricted "anyone with the link" sharing for personal or confidential files

An authorised referral system is one approved for that clinic area by Vision Care or the relevant NHS service.

If an email goes to the wrong person

  1. Ask the unintended recipient to delete it
  2. Report the incident to Tony Wing
  3. Attempt recall only for internal email
  4. Do not wait for deletion confirmation before reporting the breach
Knowledge check

You need to discuss a patient in Teams with another volunteer. What should you use?

Section 5

AI, translation tools and unauthorised apps

Absolute rule: do not enter any patient or clinical information into public AI tools.

AI tools

AI may be used only for generic admin wording with no personal or clinical information.

Translation support

Do not use personal translation apps or public translation sites for patient consultations. Use the local NHS-funded interpreting service or a patient-chosen interpreter.

Anonymised does not always mean safe: Removing a name does not remove all risk. Clinical details may still identify a patient or reveal confidential information.
Convenience is not approval: A tool being free, popular or already installed does not mean it is approved for patient information.
Stop and check: Before using any AI or translation tool, ask whether the content includes anything about a real patient. If it does, do not use the tool.

Patient-chosen interpreters

A patient may choose to bring someone they trust to interpret, but volunteers should remain mindful of privacy, consent, and whether the patient is comfortable discussing sensitive information in front of that person.

If NHS interpreting is unavailable

Do not switch to a public app. Do not send the patient away; make reasonable adjustments and document this on the patient record.

Unapproved tools and services

Do not paste, upload, record or dictate patient information into any unapproved app or online service.

  • Personal note-taking apps
  • WhatsApp or personal messaging apps
  • Personal cloud storage
  • Consumer transcription tools
  • Voice-recording apps
  • Browser extensions that process page content

Do not use voice assistants or dictation tools to process patient information unless they are specifically approved.

AI and translation guidance showing allowed generic admin use, prohibited patient data use in AI, and approved interpreting options
Mini-game: match the action
Section 6

Device, screen and physical security

Clinic devices

  • Vision Care laptops and tablets stay on clinic premises
  • USB drives are not permitted
  • Use only the host centre's authorised secure network or Vision Care-provided connectivity
  • Do not use open guest networks, public hotspots or unknown networks

Security routine

  • If stepping away briefly but remaining in the room, lock the screen
  • If the room will be unattended, lock the device away in the cabinet
  • Before using a shared device, confirm the previous volunteer has logged out of Blink and Microsoft
  • Position screens so patients, visitors and host-centre staff cannot casually view confidential information
  • Personal phones, tablets or laptops used for Vision Care systems must also be locked whenever unattended
  • Never leave passwords written beside a device or visible in the clinic room
  • Do not leave a device charging in an unlocked or unattended area
  • Report lost or stolen devices to Tony Wing within 24 hours
Personal device loss: If a personal device used to access Vision Care systems is lost or stolen, report it to Tony Wing within 24 hours, even if no information was downloaded.

End-of-clinic shutdown checklist

  1. Save authorised work in the approved system.
  2. Log out of Blink.
  3. Log out of Microsoft if required.
  4. Close the browser.
  5. Lock or shut down the device.
  6. Store the device in the lockable cabinet.
Device security steps: lock screen with Windows plus L, secure devices in a cabinet, avoid public Wi-Fi, and report incidents within 24 hours
Choose all that apply

Which actions are correct before leaving a clinic room unattended?

Section 7

Phishing, passwords and MFA

Phishing is one of the highest data breach risks.

Warning signs

  • Unexpected urgency or suspicious senders
  • Requests for passwords or patient information
  • Unexpected links, attachments or MFA prompts

Rules

  • Never share passwords
  • Never approve an MFA request you did not initiate
  • If a link is clicked by mistake, report immediately
If details are entered into a phishing page: Report it to Tony Wing immediately so the account can be blocked and the breach investigated. Once complete, a temporary password will be issued.
Phishing warning signs and an unexpected MFA approval prompt with Deny selected
Knowledge check

You receive an unexpected MFA request. What should you do?

Section 8

Information sharing and patient requests

Sharing rules

  • Share only with authorised recipients who need it
  • Before sharing, ask whether the recipient genuinely needs the information for their role
  • Even where sharing is authorised, share only the minimum information needed for the purpose
  • Use Blink IDs outside Blink where possible
  • Do not disclose information simply because someone says they are a support worker, relative or health professional
  • If someone phones asking for patient information, do not confirm anything until authority and reason are checked
  • Confirming clinic attendance is still a disclosure of personal information
  • If unsure, ask Tony Wing before sharing

Safeguarding

Confidentiality does not prevent necessary sharing where there is a serious safeguarding concern. Where there is serious risk, seek immediate guidance from Elaine Styles rather than withholding information because of confidentiality concerns.

If a patient asks to see, correct, delete, or receive their information, escalate the request to Tony Wing. Do not release information immediately.
Patient request response: Tell the patient their request will be passed to the appropriate person and that they will be contacted through the proper process.
Knowledge check

A patient asks verbally for a copy of everything Vision Care holds. What is the correct response?

Section 9

Data breaches, reporting and accountability

All suspected or confirmed breaches must be reported to Tony Wing within 24 hours.

Reportable incidents include

  • Wrong email recipient or data posted in Teams
  • Use of unauthorised apps or translation tools
  • Screenshots/downloads, phishing, lost devices
  • Unauthorised access or sharing with wrong person

Immediate action examples

  • Ask unintended recipients to delete information
  • Attempt internal recall when relevant
  • Lock or secure compromised devices
  • Take reasonable steps to reduce immediate risk, but do not delay reporting while trying to fix the problem
  • Even if unintended recipients confirm deletion, the incident must still be reported
When unsure: If you are unsure whether something is a breach, report it anyway.

What to include when reporting

  • What happened
  • When it happened
  • What information was involved
  • Who may have received or accessed it
  • What immediate action was taken
Prompt reporting helps Vision Care reduce risk and protect patients. Concealing or ignoring an incident may make the situation more serious.
Volunteers are not expected to decide whether the ICO must be notified, whether a patient must be contacted, or how serious the legal risk is. Tony Wing handles the next steps.
Choose all that apply

Which incidents should be reported to Tony Wing within 24 hours?

Section 10

Final checklist and formal assessment

Final checklist

  • Do I need this information and am I authorised?
  • Am I using Blink where required and Blink ID outside Blink?
  • Am I using approved systems only?
  • Have I avoided downloads, screenshots and unapproved apps?
  • Is the recipient correct and the device secure?
  • Do I need to report this to Tony Wing within 24 hours?

Awareness points

National Data Opt-Out

If asked detailed questions, refer to Tony Wing. Volunteers are not expected to provide legal advice.

Freedom of Information-style requests

Do not ignore or answer directly. Forward requests to Tony Wing for review.

Completing this learning page does not complete the mandatory training. You must also pass the Microsoft Forms assessment.

Three rules to remember

  • Keep patient information in Blink.
  • Use Blink IDs outside Blink.
  • Report concerns to Tony Wing within 24 hours.

Tony Wing

Data protection, incidents, requests, phishing, sharing, National Data Opt-Out and FOI-style queries.

Email: tony@visioncarecharity.org.uk

Elaine Styles

Internal Safeguarding Lead for uncertainty around serious safeguarding disclosure.

Email: elaine@visioncarecharity.org.uk

Stephen Pratt

Technical queries: access, browser issues, broken links, progress-saving faults.

Email: steve@visioncarecharity.org.uk

Start the formal assessment

The Microsoft Forms quiz is the official completion record. You must achieve at least 80%.

Locked until all required sections and knowledge checks are complete.

Version: Alpha 1 · Review date: 31/7/2027 · Content owner: Vision Care is content owner · Approved by: CDPO

Completion check

Final commitment