What is a Privacy Notice?
A Privacy Notice (sometimes referred to as a Fair Processing Notice) explains how the Practice collects, uses, stores and shares personal information about patients.
Being transparent and providing clear information about how we use your personal information is a key requirement of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This notice explains:
- What information we collect.
- How we collect it.
- Why we collect it.
- How we use it.
- Who we may share it with.
- How we keep it secure.
- Your rights regarding your information.
Fair Processing
Personal information must be processed fairly, lawfully and transparently. This means the Practice will:
- Only collect and use information where there is a lawful basis to do so.
- Use information only for appropriate healthcare and administrative purposes.
- Be open and transparent about how information is used.
- Take reasonable steps to ensure information is accurate and secure.
- Not use information in a way that would be unjustified or unlawful.
- Only share information where there is a legal basis or legitimate need to do so.
When deciding how information is used, we consider:
- What information is being collected.
- Why it is being collected.
- How it is collected.
- How it will be used.
- Who it may be shared with.
- The potential impact on patients.
- Whether patients would reasonably expect the information to be used in that way.
Your Information, Your Rights
This Privacy Notice explains how your GP Practice uses your personal information to provide healthcare services and support the effective management of NHS services.
We use information for:
- Managing patient records.
- Delivering healthcare services and treatment.
- Communicating with patients about their care.
- Supporting clinical audit and quality improvement activities.
- Participating in approved research activities.
- Planning and improving local healthcare services.
Data Controller
The Medical Centre (Doncaster) Limited is the Data Controller for the personal information we hold about our patients.
As the Data Controller, we determine how and why personal information is processed and ensure it is handled in accordance with applicable data protection legislation.
We have contracts and data processing agreements in place with third-party providers, including IT system suppliers, to ensure personal information is appropriately protected.
Our Data Protection Officer is:
Caroline Million
CM Associates
What Information Do We Collect and Use?
We collect information directly from patients and from other organisations involved in providing healthcare services.
This may include:
Personal Data
Information that identifies you, including:
- Name
- Address
- Postcode
- Date of birth
- NHS number
- Contact details
- Next of kin details
Special Category Data
Health and care information including:
- Medical history
- Clinical notes
- Diagnoses
- Treatments
- Medication records
- Test and investigation results
- Appointment details
- Hospital admissions and discharge information
- Social care information
- Ethnic origin
- Genetic information
- Sexual orientation where relevant to care
Your healthcare record may contain information provided by:
- Hospitals
- Community healthcare providers
- Mental health services
- Walk-in centres
- Social care providers
- Other healthcare professionals involved in your care
Records may be held electronically, on paper, or in a combination of both formats.
Why Do We Collect and Use Your Information?
The NHS Act 2006 and the Health and Social Care Act 2012 place duties on NHS organisations to provide healthcare services, improve quality, reduce inequalities, undertake service planning and support education and research.
We process information to:
- Protect vital interests.
- Deliver healthcare and treatment.
- Support preventative medicine and diagnosis.
- Provide health and social care services.
- Manage and improve NHS services.
- Conduct clinical audit and quality improvement.
- Support approved medical research activities.
- Meet legal and regulatory obligations.
- Perform tasks carried out in the public interest.
How Is Information Collected?
Information may be received:
- Directly from patients.
- Through secure NHS electronic systems.
- Via NHSmail.
- Through encrypted NHS network connections.
- From hospitals and other healthcare providers.
- Through paper correspondence and referrals.
Information is retained within electronic patient record systems and, where applicable, physical medical records.
Who Do We Share Information With?
To provide safe and effective healthcare, information may be shared with organisations involved in your care, including:
- Local GP practices providing extended access services.
- NHS hospital trusts.
- NHS 111 services.
- Out-of-hours providers.
- Community healthcare services.
- Social care services.
- Mental health services.
- Pharmacies.
- Care homes.
- Voluntary organisations commissioned to provide healthcare support services.
We only share information where there is an appropriate legal basis and where it is necessary to support healthcare delivery, statutory functions or legal obligations.
We may also receive information from these organisations to ensure your records remain accurate and up to date.
Where personal information is transferred outside the United Kingdom, appropriate safeguards will be applied in accordance with UK data protection legislation.
Sharing Electronic Patient Records within the NHS
Electronic patient records help healthcare professionals involved in your care access relevant information when required.
Information may be shared with:
- GP practices.
- Community services.
- Child health services.
- Urgent care providers.
- Community hospitals.
- Hospices and palliative care services.
- Care homes.
- Mental health trusts.
- Hospitals.
- Social care organisations.
- Pharmacies.
Shared records support coordinated care and help ensure healthcare professionals have access to accurate information when needed.
Patients may request restrictions on the sharing of their records. Please contact the Practice if you wish to discuss available options.
Where appropriate, patients may subsequently request that previously applied restrictions are reviewed.
Mobile Telephone Communications
If you provide a mobile telephone number, we may use it to:
- Send appointment reminders.
- Notify you about healthcare services.
- Invite you to screening or vaccination programmes.
- Communicate important information relating to your care.
Change of Personal Details
It is important that your personal information remains accurate.
Please inform the Practice if:
- Your name changes.
- Your address changes.
- Your contact details change.
- Any information we hold about you is incorrect.
Keeping records up to date helps ensure you receive appropriate care and communications.
Practice Website and Cookies
The Practice website uses cookies to improve functionality and user experience.
You may choose whether to accept non-essential cookies when visiting the website. Further information can be found within the website's Cookie Policy.
How We Maintain the Confidentiality of Your Records
We are committed to protecting your privacy and maintaining the confidentiality of your information.
All staff working within NHS organisations have legal and professional obligations to protect confidential information.
We support confidentiality through:
- Mandatory annual training.
- Access controls and role-based permissions.
- Secure information systems.
- Data sharing agreements.
- Information governance policies and procedures.
Information is only accessed by individuals who have a legitimate need to do so.
Records Retention
Personal information is retained only for as long as necessary.
We manage records in accordance with the NHS Records Management Code of Practice and applicable legal requirements.
Retention periods vary depending on the type of record and applicable legal obligations.
Consent and Objections
Do I Need to Give Consent?
UK GDPR identifies several lawful bases for processing personal information.
In many circumstances, healthcare organisations do not rely on consent to process information required for the provision of healthcare services, as processing is necessary for healthcare provision, public task responsibilities and compliance with legal obligations.
Where consent is required for a specific purpose, we will seek it directly from you and record your decision appropriately.
What Happens if I Withdraw Consent or Object?
Where consent is the lawful basis for processing, you have the right to withdraw that consent at any time.
You also have the right to object to certain uses of your information.
Please contact the Practice if you wish to discuss any objection or withdrawal of consent.
Clinical Audit and Research
Information may be used for clinical audit activities to monitor, review and improve the quality of services provided.
Where information is used for statistical purposes, appropriate safeguards are applied to minimise the risk of patient identification.
The Practice may also participate in approved research activities.
Where required, consent will be sought before identifiable information is disclosed for research purposes.
Patients will be informed about significant new information-sharing initiatives and provided with information about any available opt-out arrangements.
Invoice Validation
Where NHS treatment has been provided, personal information may be shared securely for commissioning, contract management and payment validation purposes.
This may include:
- Name.
- Address.
- Date of treatment.
- NHS number.
- Relevant service information.
Information is shared only where necessary to support NHS financial and commissioning responsibilities.
Health Risk Screening and Risk Stratification
Risk stratification is a process used to identify patients who may be at increased risk of deteriorating health or unplanned hospital admission.
Information that may be used includes:
- Age.
- Gender.
- Diagnoses.
- Long-term conditions.
- Medication history.
- Hospital attendance history.
- Community care involvement.
The purpose is to:
- Improve patient outcomes.
- Prevent avoidable hospital admissions.
- Identify patients requiring additional support.
- Improve service planning.
The process is primarily automated and reports may subsequently be reviewed by appropriate clinical staff.
Patients may object to this use of their information. However, doing so may affect our ability to provide proactive care and support.
Your Right of Access to Your Records
Under UK GDPR and the Data Protection Act 2018, you have the right to request access to personal information held about you.
This is known as a Subject Access Request.
Requests can be made to any organisation that holds your information, including healthcare providers involved in your care.
Some information may be exempt from disclosure where release could:
- Cause serious harm.
- Prejudice the rights of another individual.
- Breach legal obligations.
To request access to your GP records, please contact us.
Complaints
If you have concerns about how your personal information has been handled, please contact the Practice Manager in writing in the first instance.
We will investigate your concerns and provide a response.
If you remain dissatisfied, you may raise your concerns The National ombudsman office
Data Protection Registration
The Practice is registered with the Information Commissioner's Office (ICO) as a Data Controller.
Registration Number: Z7421556
Patients have the right to complain to the Information Commissioner's Office.
Website: www.ico.org.uk