Queens Medical Centre
Opening hours Monday to Friday (8am to 6:30pm)
Lynton Health Centre
Monday, Wednesday and Friday (8am to
6:30pm)
Staff Privacy Policy
Purpose
The purpose of this policy and protocol is to outline our privacy policy to those concerned, and to satisfy the requirements outlined in the General Data Protection Regulations.
Statement
The Fuller and Forbes Partnership includes the following interrelated organisations:
Scope
This privacy notice is relevant to current and former staff, including full-time and part-time permanent and fixed-term employees in professional and non-professional roles, contractors and locums, and other outsourced and non-permanent workers.
Each of the organisations has a data controller registered with the Information Commissioners office. The named Data Protection Officer, Mr Methven Forbes who can be contacted via methven.forbes@nhs.net.
Details
During the course of your time working at the with us you directly or indirectly. If and when you cease to the employed by us, we will continue to hold some data that we hold about you for a predefined period of time in order to fulfil our remaining tasks and obligations.
The information we may hold about you include:
How do we obtain this information?
Much of this data we will have asked you to provide to us directly when you started your employment. Alternatively, we may have asked you for it during your employment, or you may have provided it to us independently in order for us to help you with something.
If we do not receive information directly from you, we either generate it ourselves (such as your clinical system username and smartcard details), or we receive it from third parties, such as, HM Revenue and Customs (HMRC), Pensions scheme providers, Disclosure and Barring Service, Occupational Health, Individuals or organisations that you named as a referee
We request data from you when you:
Why do we hold this information?
We take our obligations around the handling of data very seriously, and it is therefore important for you to know the various lawful bases that we rely on under data protection law for the processing of your personal data.
In order to be able to process your data lawfully, we must rely on a specific lawful basis, depending on the main reason why we need the data. Below we will explain these lawful bases and when they might be used.
Necessary for the organisation to comply with a legal obligation
We process data about you under this legal basis when we need to in order to comply with UK legislation, such as in the areas of employment for tax purposes or to comply with the Equality Act, or laws around health and safety in the workplace.
Necessary for the organisation to perform a contract with you
We process your data in order to carry out the contract of employment we have with you, or to enter into it in the first place – for example, ensure you can work in the UK, pay you a salary and keep records of disciplinary, complaint or grievance proceedings.
Necessary for the purposes of the organisation's legitimate interests
Sometimes we will process your data because we have identified a 'legitimate interest' in doing so. The legitimate interests we identify are determined through an assessment made by weighing our requirements against the impact of the processing on you. This is done to make sure that our legitimate interests will never override your right to privacy and the freedoms that require the protection of your personal data.
Examples of when we will process your data in our legitimate interests are:
Necessary to protect your vital interests or those of another person
On rare occasions, we may need to access or share your information in order to protect your life or that of another person, for example in an emergency situation where we cannot gain your consent or to do so could endanger life. We will only rely on vital interests in extremely limited circumstances when no other legal basis is available.
You have given us your consent to process your data for a specific purpose
We may sometimes ask for your consent to do something that involves use of your personal data. We will do this where no other lawful basis applies and where it makes sense to give you the highest level of control over how your data is used by us.
For this reason, we will not ask for your consent very often where your data is being processed for employment reasons because one of the other lawful bases listed above will often be more appropriate.
However, you would be asked to specifically consent to the processing of your data if, for example, we wished to use your image in marketing materials; wished to send you marketing, or to process your data where we cannot rely on one of the above bases.
Processing your 'special category' personal data
Sensitive personal data, called "special category" data in the legislation, receives extra protection under data protection law. The organisation can only process it if we have an additional lawful basis to rely on and meet higher standards for safeguarding it.
Special category data is defined as information which reveals:
Of the lawful bases available to us, those the organisation is mostly likely to rely on in relation to staff data are the following:
Processing is necessary for us to carry out our obligations or exercise our (or your) rights under employment, social security and social protection law. This would apply when, for example, we:
Processing is necessary for purposes of preventive or occupational medicine and to assess your working capacity as an employee. This would apply when we obtain advice from medical professionals at an occupational health service with regards to adjusting your working practices due to a health condition.
Processing is necessary to protect your life or someone else's. We will rely on this basis on rare occasions when we cannot reasonably get your consent for whatever reason.
Processing is necessary for statistical purposes. Where this is based on UK law, respects your right to data protection and where measures are taken to safeguard your rights and freedoms, such as through the collection of minimal data.
How long is your information kept by the organisation?
As a principle, information about you will not be kept for longer than it is needed for the purpose it was collected.
The organisation has records retention schedules which document for how long different information is required. These are currently in the process of being updated, so may not contain the most up to date information.
As the retention schedules indicate, we need to keep different data for differing periods of time, and you will always be told how long your personal information will be kept, or how we calculate this – this will either be when you give it to us, or if you don't give it to us yourself, as soon as possible after we obtain or receive it.
If you have any queries regarding how long we keep your data that are not answered in the schedules, please email the data protection lead.
Some basic information about our former staff is transferred to the organisation Archives for permanent preservation so that it can be professionally managed in order to facilitate future historical research enquiries. All relevant safeguards are met in relation to this archival processing.
When it is no longer required in line with its retention period, personal information is securely and permanently destroyed.
How is your information shared by us?
Whilst you are working with us, we will need to share certain information both internally between departments and with external parties.
As a principle, only minimal information will be shared as necessary and only where we have identified a lawful basis or exemption for doing so, and the data is proportionate to the need. There is guidance and governance in place to help staff to ensure that only the necessary data is made available to other departments or third parties who would not otherwise have access to it.
Some information must be shared by HR with other departments to complete essential tasks related to your employment, such as payroll, occupational health, pensions and arranging access to IT services.
Other purposes for which personal data may need to be shared internally, including:
Third parties with whom information about staff may need to be shared by the organisation:
In most cases, information about how your data is shared will be given to you closer to the time by the relevant department.
How do we protect your information?
We take the security of your data seriously. Details on organisation wide measures surrounding IT security can be found in our Data Security Awareness training and related policies on our intranet which sets out the definition of commitment to and requirements of Information Technology and Security. It specifies regulations to be implemented to secure information and technology that the organisation manages and to protect against the consequences of breaches of confidentiality, failures of integrity and interruption of availability.
We have internal policies and controls in place to try to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by our employees in the performance of their duties.
Where we engage third parties to process personal data on our behalf, they do so on the basis of written instructions contained within a contract, are under a duty of confidentiality and are obliged to implement appropriate technical and organisational measures to ensure the security of data.
What rights do you have in relation to the way we process your data?
As an individual whose data we process (a data subject), you have certain rights in relation to the processing.
You have the right to:
Make a complaint
If you have any concerns about the way that we have handled your personal data please email the Data Protection lead as we would like to have the opportunity to resolve your concerns.
If you're still unhappy, you have the right to complain to the Information Commissioner's Office (an independent body set up to advise on information rights for the UK) about the way in which we process your personal data. More details can be found at https://ico.org.uk/make-a-complaint/
We use cookies on this website to help improve our service. Cookies let us anonymously see how our site is used. Cookies also allow us to show content which is most relevant to you.
Please see Privacy policy for more information.