Effective date: June 2026
Introduction
Carnall Farrar (CF) is a healthcare management consultancy and data science company. We use data about NHS care in England to help the NHS and its partners understand where pressures and variation lie, plan services, and improve care. This notice explains what patient data we hold, where it comes from, what we do with it, what we do not do with it, and who to contact if you have questions.
The data we hold does not include your name, address, NHS number, date of birth or any other detail that identifies you. It has been pseudonymised by NHS England before it reaches us, and we do not hold the key that would reverse that. We cannot tell who any individual record belongs to, and we do not try to find out.
Who this notice applies to
This notice applies to you if you have received NHS-funded hospital, emergency, mental health, community or cancer care in England, or been prescribed medicines dispensed in primary care in England, at any point in roughly the last eight years. It also applies to information from death registrations in England and Wales.
It does not cover the personal data we hold about our own clients, staff, suppliers or website visitors. That is covered by our main Privacy Policy, available on our website.
Who is responsible for the data
Carnall Farrar Limited is the data controller for the NHS England data described in this notice. That means we decide what the data is used for and how it is processed, within the limits set by our agreement with NHS England. Carnall Farrar Limited is registered in England, company number 09264497, at 1 Lyric Square, Hammersmith, London W6 0NB, and is registered with the Information Commissioner’s Office under registration number ZA105315.
We receive the data from NHS England under a Data Sharing Agreement, reference DARS-NIC-243790-Y8K8C. NHS England reviews and approves what we may hold and what we may use it
What data we hold
We hold pseudonymised records from the following national datasets:
- Hospital Episode Statistics (HES): Admitted Patient Care, Outpatients, Critical Care, and Accident and Emergency. We hold historical Accident and Emergency data but no longer receive new releases of it.
- Emergency Care Data Set (ECDS)
- Diagnostic Imaging Data Set (DID)
- Mental Health Services Data Set (MHSDS)
- Community Services Data Set (CSDS)
- Civil Registrations of Death
- NDRS Cancer Consolidated Data Set
- Medicines Dispensed in Primary Care, supplied by the NHS Business Services Authority
The records describe episodes of care: for example the type of admission, the diagnoses and procedures recorded, the dates and length of stay, the treating organisation, and broad demographic details such as age band, sex, ethnicity and area of residence. We ask NHS England only for the fields we need for the analyses described below, and we hold up to eight years of history.
A small number of fields are treated as sensitive and we have justified each one to NHS England. From the death registration data we receive date of death, sex, place of death, and registration references used to match records accurately. We do not receive cause of death free text. From the emergency care data we receive attendance start and end times, needed to measure waiting and flow. From the medicines data we receive a pseudonymous professional code identifying the type of prescriber, used to look at variation in prescribing between organisations and professions, not to identify or profile individual prescribers.
The medicines data is used only to provide intelligence about the safety and effectiveness of medicines, as required by the NHS Business Services Authority Medicines Data Directions 2019.
We do not link this data to any other data at patient or record level. Where we use other sources, such as Office for National Statistics population data, NHS workforce data or the National Cost Collection, they are aggregated public datasets joined only at area or organisation level.
Our legal basis for using the data
NHS England releases the data to us under section 261(2)(a) of the Health and Social Care Act 2012.
Because the data is pseudonymised, it is still personal data under data protection law, so we need a lawful basis to process it. Our lawful bases are:
- Article 6(1)(f) of the UK GDPR, legitimate interests. The interests are those of the health and care system in England, in planning, commissioning, delivering, evaluating and improving services, and our own interests in providing analysis that supports those aims. We have carried out a Legitimate Interests Assessment and concluded that this processing is necessary, proportionate, and not overridden by the interests of individuals, because the data cannot identify anyone and no decision is made about any individual.
- Article 9(2)(j) of the UK GDPR, archiving, research and statistics in the public interest, with the safeguards required by Article 89(1). Those safeguards include that the data is pseudonymised, that we do not attempt to reverse that, and that only aggregated results with small numbers suppressed leave our environment.
The common law duty of confidentiality is not engaged, because the data we receive is not confidential patient information.
The national data opt-out
The national data opt-out lets you stop your confidential patient information being used for purposes beyond your own care. It does not apply to the data we hold. That is because the data released to us is not confidential patient information as defined in sections 251(10) and 251(11) of the National Health Service Act 2006. It has been pseudonymised before release and we hold no identifiers.
This means that setting a national data opt-out will not remove your records from the data we receive. We recognise that people may want to know this plainly rather than find it out later. You can read about the opt-out, and set or change your choice, at nhs.uk/your-nhs-data-matters.
What we use the data for
We use the data to produce aggregated, non-identifiable analysis for organisations working in and with the health and care system. Analysis draws on up to eight years of history and models up to ten years forward. The permitted uses are:
- Benchmarking and productivity analysis, comparing organisations and systems against peers and national averages
- Population segmentation, risk stratification and forecasting, grouping populations by need, condition and risk for planning and prevention
- Demand, capacity and activity modelling, including patient flow
- Service evaluation and improvement, evaluating a defined service using its own data
- Care pathway mapping, variation and forecasting
- Health economics, resource use and cost-effectiveness
- Inequalities analysis, applied across all of the above
- Descriptive statistics and benchmarking of disease burden, epidemiology, natural history and outcomes
- Evidence for health technology assessment and market access
- Clinical trial feasibility, site selection and external control arms
- Development and operation of analytical and machine learning models for risk stratification, case finding, cohort selection and forecasting
Some examples of what this looks like in practice: modelling how many mental health beds a system will need in five years; sizing the maternity capacity gap across a group of hospitals; establishing the national baseline for outpatient attendances; identifying where a hospital’s costs differ from comparable hospitals and why; and segmenting a local population to show which groups account for the greatest share of need and spend.
Our analytical products
Some of this work is delivered through tools we have built and validated:
- CF Foresight, which predicts waiting lists, attendances, admissions, discharges and bed occupancy, and models the effect of planned changes on performance and patient flow.
- CF Insight and Collaboration Engine (ICE), which shows an integrated care system its population health outcomes relative to others, and lets it set and track improvement goals.
- CF Health Strata, which segments a population by need and cost to support planning and prevention.
Each product’s methodology is approved once by our Data Security Committee. Clients see only aggregated results with small numbers suppressed. They never see record-level data.
Who we work with
Historically our published notice referred only to NHS clients. That was incomplete. We use this data to support five groups of clients:
- NHS and wider public sector: integrated care boards, NHS trusts, primary care providers, NHS England and its regional teams, and government bodies such as the Department of Health and Social Care, NICE and the Office for Health Improvement and Disparities.
- Healthcare companies and NHS suppliers: independent and private providers, diagnostics and digital health companies, and suppliers of technology, workforce and medicines to the NHS.
- Life sciences: pharmaceutical, biotechnology and medical device companies, and their industry bodies.
- Academia and think tanks: universities and policy institutes.
- Charities and patient organisations: disease and patient organisations, cancer alliances and other not-for-profits.
The great majority of the work is direct support to NHS commissioners, providers and national NHS England programmes. Work for clients outside the NHS and public sector is a small minority, typically one or two projects a year, and each one has to pass a public interest test: it must show a benefit to the health and care system in England that is separate from the client’s own commercial interest. Examples include work with the Alzheimer’s Society on the economic burden of dementia, and work on the case for prostate cancer screening.
Every client, whoever they are, receives only aggregated results with small numbers suppressed. We do not sell, licence, share or transfer the data itself to anyone.
Artificial intelligence and machine learning
We use this data to develop, train, validate and run analytical and machine learning models. CF Foresight, which forecasts hospital admissions, discharges and occupancy, is one of them, as are the segmentation, risk stratification, benchmarking and comorbidity models that sit underneath our other tools.
These models support planning and management decisions at the level of cohorts, services and systems. They are not used to make or automate decisions about individual patients, and they could not be: we cannot identify anyone in the data. Specifically:
- Models are built and run only inside our secure UK environment, on pseudonymised data. Only aggregated, suppressed results leave it.
- Every new or substantially changed model goes to our Data Security Committee before any work starts, and has to pass a public benefit test, an ethics test and a data minimisation review.
- All model outputs are reviewed by a qualified analyst before release. Nothing is decided by an automated system alone.
- We test models for bias and equity, comparing how accurately they perform across age, sex, ethnicity and deprivation groups, and investigate and correct material differences before the outputs are used.
- Models, and the parameters inside them, are never shared, sold or reused outside the purposes NHS England has approved.
- We consider whether a model can be developed or tested on a reduced dataset, or on synthetic data, before using the full dataset.
We do not use this data to build or train general-purpose or commercial AI products unrelated to the health and care system.
How we decide what the data can be used for
NHS England has given us delegated authority to approve specific uses of the data within the scope of our agreement. We take that seriously and have built a formal process around it.
Our Data Security Committee is a constituted sub-committee of our Information Governance Working Group. It is chaired by our Senior Information Risk Owner, and its members are the Director of Data, Analytics and Intelligence, who is also our Data Protection Officer, the Caldicott Guardian, the Information Governance Lead, the Lead Platform Engineer, and a representative from each part of the business. It has written terms of reference covering quoracy, membership, ethics, patient and public involvement, access by commercial organisations, and how benefit to the health and care system is judged.
Every proposed use of the data is submitted in writing, categorised, and approved against set criteria. The level of scrutiny depends on what is being asked:
- Established products and previously validated analyses run through a pipeline the Committee has already approved, overseen by our head of analytics, with every request logged.
- Tailored analyses that use established methods to answer a specific question go to the Committee or to a lead acting under its delegation.
- Anything using a new method or dataset, and any development or retraining of a machine learning model, is held at a decision gate for the full Committee, against enhanced criteria including demonstrable benefit to the health and care system, data minimisation and ethics.
Separately from that, any request where the client is not an NHS or public sector body goes to the full Committee whatever the analysis involves, and has to pass the public interest test.
We keep an internal register of approved uses, recording for each project what data is used, the lawful basis, the expected benefit and the deletion date. It is reviewed monthly. We report to NHS England every year on how the data has been used and what benefits it has produced, and NHS England publishes approved uses in its own Data Uses Register.
Where the data is held and who can see it
The data is held and processed only in the United Kingdom, in our own secure cloud environment. It never leaves England and Wales. The environment has three layers:
- The data is hosted on Amazon Web Services (AWS), on UK infrastructure certified to ISO 27001.
- It is held and governed in a Databricks lakehouse running on that AWS infrastructure, which acts as our data warehouse.
- Our staff query it through Hedwig, an interface we built and control that sits on top of the lakehouse.
AWS and Databricks are our data processors. Both are named in our agreement with NHS England. Neither can read the data: it is accessible only to CF staff who have been individually granted access.
Only CF employees can access the data, and only from CF-issued, encrypted, corporately managed laptops, over a secure connection with multi-factor authentication. Personal devices are never permitted. Access is limited to two groups: no more than 20 primary users, who can see record-level data and must complete mandatory information governance training and platform training before access is granted; all CF employees are secondary users, who can only see aggregated datasets that primary users have already produced. Every access and every download is logged and audited, and reports go to the Data Security Committee monthly.
What we do not do
- We do not release record-level data. It never leaves our secure environment, and no client or third party ever receives it.
- We do not attempt to identify anyone, and we do not hold the means to do so.
- We do not make or automate decisions about individual people.
- We do not use the data for marketing, sales targeting, insurance, or any other commercial purpose unrelated to improving health and care.
- We do not sell, licence or transfer the data to anyone.
- We do not send the data outside the United Kingdom.
All results we publish or share have small numbers suppressed in line with the HES Analysis Guide, so that no one could be picked out of a small count.
How long we keep the data
We keep a rolling eight years of data, plus the current year to date. When a new full year arrives, the oldest year is securely destroyed within four weeks, in line with NHS England’s Data Destruction policy, and a Data Destruction Certificate is produced.
Aggregated outputs produced for a project are held in a controlled location and deleted five months after the project closes. The deletion is recorded in our Information Asset Register and checked monthly.
If our agreement with NHS England ends, the data is destroyed in accordance with that agreement and a certificate is provided to NHS England.
Your rights
Data protection law gives you rights over your personal data, including the right to ask what is held about you, to have inaccurate data corrected, to object to processing, and to have data erased in some circumstances.
There is an important practical limit here. We cannot identify you in the data we hold. We have no name, NHS number or other identifier, and no key to the pseudonyms. Under Article 11 of the UK GDPR, where a controller cannot identify a data subject, the rights of access, rectification, erasure, restriction and portability do not apply, because we cannot locate your records in order to act on them, and we are not required, and not permitted, to collect extra information about you in order to try.
What you can do:
- To ask about the NHS records held about you, or to exercise your rights over them, contact the NHS organisation that treated you, or NHS England, which is the source of this data.
- To stop your confidential patient information being used beyond your own care more generally, set a national data opt-out at nhs.uk/your-nhs-data-matters. As explained above, this will not affect the data we receive, because that data is not confidential patient information.
- To ask us a question about this notice, to object to what we are doing, or to complain, contact us using the details below. We will answer, whether or not we can locate any records.
If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113.
Contact us
https://www.carnallfarrar.com/
Carnall Farrar Limited, 13th Floor, 1 Lyric Square, Hammersmith, London W6 0NB
Changes to this Privacy Policy
We keep our Privacy Policy under regular review. This Privacy Policy was last updated in June 2026.



