The practice aims to meet the requirements of the Data Protection Act 2018, the General Data Protection Regulation (GDPR], the guidelines on the Information Commissioner’s website as well as our professional guidelines and requirements.
The data controller is Brijesh Patel who is also the information Governance Lead and the Data Protection Officer.
This Privacy Notice is available at reception.
You will be asked to provide personal information when joining the practice. The purpose of us processing this data is to provide optimum health care to you.
The categories of data we process are:
- Personal data for the purposes of staff and self-employed team member management
- Personal data for the purposes of direct mail/email/text
- Special category data including health records for the purposes of the delivery of health care
- Special category data including health records and details of criminal record checks for managing employees and contracted team members
We never pass your personal details to a third party unless we have a contract for them to process data on our behalf and will otherwise keep it confidential. If we intend to refer a patient to another practitioner or to secondary care such as a hospital we will gain the individual’s permission before the referral is made and the personal data is shared.
- Personal data is stored in the EU whether in digital or hard copy format
- Personal data is obtained when a patient joins the practice, when a patient is referred to the practice
The lawful basis for processing special category data such as patients’ and employees’ health data is:
- Processing is necessary for the purposes of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional
The lawful basis of processing personal data such as name, address, email or phone number is:
- Consent of the data subject
- Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract
The retention period for special data in patient records is a minimum of 10 years and may be longer for complex records in order to meet our legal requirements. The retention period for staff records is 6 years. The retention periods for other personal data is 2 years after it was last processed. Details of other retention periods are available in the Record Retention procedure available from the practice.
You have the following personal data rights:
- The right to be informed
- The right of access
- The right to rectification
- The right to erasure (clinical records must be retained for a certain time period)
- The right to restrict processing
- The right to data portability
- The right to object
Further details of these rights can be seen in our Information Governance Procedures or at the Information Commissioner’s website. Here are some practical examples of your rights:
- If you are a patient of the practice you have the right to withdraw consent for important notifications, newsletters, surveys or marketing. You can inform us to correct errors in your personal details or withdraw consent from communication methods such as telephone, email or text. You have the right to obtain a free copy of your patient records within one month.
- If you are not a patient of the practice you have the right to withdraw consent for processing personal data, to have a free copy of it within one month, to correct errors in it or to ask us to delete it. You can also withdraw consent from communication methods such as telephone, email or text.
We have carried out a Privacy Impact Assessment and you can request a copy from the details below. The details of how we ensure security of personal data is in our Security Risk Assessment and Information Governance Procedures.
Comments, suggestions and complaints
Please contact the practice manager at the practice for a comment, suggestion or a complaint about your data processing at firstname.lastname@example.org or call 020 8660 8923 or by writing to or visiting the practice at 22 Brighton road, Purley, Surrey, CR8 3AD. We take complaints very seriously.
If you are unhappy with our response or if you need any advice you should contact the Information Commissioner’s Office (ICO). Their telephone number is 0303 123 1113, you can also chat online with an advisor. The ICO can investigate your claim and take action against anyone who’s misused personal data. You can also visit their website for information on how to make a data protection complaint.
Related practice procedures
You can also use these contact details to request copies of the following practice policies or procedures:
- Data Protection and Information Security Policy ,Consent Policy
- Privacy Impact Assessment ,Information Governance Procedures
This document was created using an SEQ Legal template.
(2) About cookies
A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser, and stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.
Cookies can be used by web servers to identity and track users as they navigate different pages on a website, and to identify users returning to a website.
Cookies may be either "persistent" cookies or "session" cookies. A persistent cookie consists of a text file sent by a web server to a web browser, which will be stored by the browser and will remain valid until its set expiry date (unless deleted by the user before the expiry date). A session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.
(3) Cookies on this website
We use session cookies and persistent cookies on this website.
We may send to you the following cookies:
__utma __utmb __utmc __utmz - these are third party cookies that are placed on your device to allow us use the Google analytics service. __utma is a persistent cookie. __utmb and __utmc are session cookies that last for a maximum of 30 minutes. __utmz is a persistent cookie that lasts for 6 months. These cookies are used to collect information about how visitors use our sites. We use the information to compile reports and to help us improve the site. The cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the site from and the pages they visited. Further information are available about these cookies here: http://www.google.co.uk/intl/en/analytics/privacyoverview.html.
Cookies do not contain any information that personally identifies you, but personal information that we store about you may be linked, by us, to the information stored in and obtained from cookies.
We may use the information we obtain from your use of our cookies for the following purposes:
(1) to recognise your computer when you visit our website;
(2) to improve the website's usability;
(3) to analyse the use of our website;
(4) in the administration of this website.
(5) Third party cookies
When you use our website, you may also be sent third party cookies.
Our service providers may send you cookies. They may use the information they obtain from your use of their cookies.
(6) Blocking cookies
Most browsers allow you to refuse to accept cookies. For example:
(1) in Internet Explorer you can refuse all cookies by clicking "Tools", "Internet Options", "Privacy", and selecting "Block all cookies" using the sliding selector
(2) in Firefox you can block all cookies by clicking "Tools", "Options", and un-checking "Accept cookies from sites" in the "Privacy" box.
Blocking all cookies will, however, have a negative impact upon the usability of many websites.
(7) Deleting cookies
You can also delete cookies already stored on your computer:
(1) in Internet Explorer, you must manually delete cookie files;
(2) in Firefox, you can delete cookies by, first ensuring that cookies are to be deleted when you "clear private data" (this setting can be changed by clicking "Tools", "Options" and "Settings" in the "Private Data" box) and then clicking "Clear private data" in the "Tools" menu.
Obviously, doing this may have a negative impact on the usability of many websites.
(8) Contact us
If you have any questions about our cookies or this Cookies Policy, please use the website contact form.
policy courtesy of SEQ Legal