Data protection/IG for public release of ukrdc stats
Summary of discussions 4th Aug 2026 including TG (data protection officer), WM, PM, SS and JM.
Separately with RS and RC.
Headlines presented to patient council 29-Jul although discussion was limited.
The case for presenting publicly accessible dashboards containing small numbers:
We know from the experience of RSTP and others before them that limiting access to data behind a registration barrier substantially reduces how many people access data. To be useful these data need to be visible to clinical staff, patients and regional networks.
In order to monitor improvement (or not) data needs to be contemporary and contain several recent periods. Quarters (we present the last 8, or 2 years) offers a bridge between today and the last annual report (for direct comparison with the numbers of individuals). Larger time periods would limit the opportunity to see change.
Many kidney centres now deliver relatively de-regulated services in their ‘satellite’ centres. In several cases these are almost fully independent in key planning decisions and culture. This is the geography at which improvement is likely to be made.
Key to the UKRR public purpose is the identification of disparities. We collect four key characteristics (age, sex, ethnicity and deprivation) and know from previous work that key outcomes vary by characteristic. Demonstrating differences is key to stimulating fairness.
Principles considered
To review critically whether the groups we are displaying are necessary to make the data usable, and to enlarge any groups as far as possible to reduce the frequency of small numbers.
Provided there is a good justification for displaying a particular group, then we are confident that the chance to positively identify any individual remains almost impossible - even in situations where only one person's data is shown.
An example would be presenting new patients, and identifying in a quarter one person at a main kidney centre starting treatment with peritoneal dialysis, and knowing from the visualisation that the person is a white man aged 35-55yrs living in an area of high deprivation. The actual person remains unidentifiable.
We currently do not cross tabulate characteristics with one another, limiting the extent to which additional characteristics of a person can be inferred.
Decisions
For the first public data-release we will be deliberately cautious, and demonstrate the data which is available, but not display all of it. If there is a strong response that more detailed information was necessary we would consider changing this in a future release.
In particular we will
Suppress any person having treatment in an adult kidney centre aged <18yrs. These numbers are often small, and the actual age of such people is in reality either 16 or 17years. For the time-being we will do this in tableau which will mean that the numbers presented by age will not quite add-up to the numbers displayed by other characteristic.
We will evaluate new age-bands which might prove more clinically relevant, but would also reduce the very small age band of <18. For example:
Aged <=25 (“young adults”). Provision of care can be different
Aged 26-59 (“working age”).
Aged 60-79 (“early retired”).
Aged 80+ (“older people”)
We will continue to present data by quarter.
At MAIN CENTRE level we will continue to display INCIDENT and PREVALENT numbers by ‘modality’, and (individually) by Age band, Sex, Ethnicity and IMD. This is current behaviour. Small numbers exist but they are infrequent. Characteristics are necessary to revealing disparities, and geography is vague (where does the centre cover) and large.
At SATELLITE LEVEL we will continue to display PREVALENT patient numbers including ‘modality’, but no longer (individually) by Age band, Sex, Ethnicity and IMD.
We will not display any data on INCIDENT patients at satellite level. Small numbers still exist at a main centre level but they are infrequent. Not presenting incident data at all (even at main centre), or not showing starting modality would substantially limit the value of the data.
We will suppress the sub-division by other characteristics within Tableau using a conditional filter (no longer the '+')