Station Practice Privacy Notice
Station Practice Privacy Notice Appendix A
We've put some small files called cookies on your device to make our site work.
We would also like to use google translate cookies and analytical cookies to understand how our site is used and improve user experience. Analytical cookies send information to Google Analytics.
Let us know your preference. We will use a cookie to save your choice. Before you make your choice you can read more about our cookie policy.
You can change your cookie settings at any time using our cookie policy.
Your information, what you need to know
This privacy notice explains why we collect information about you, how that information will be used, how we keep it safe and confidential and what your rights are in relation to this.
Why we collect information about you
Health care professionals who provide you with care are required by law to maintain records about your health and any treatment or care you have received. These records help to provide you with the best possible healthcare and help us to protect your safety.
We collect and hold data for the purpose of providing healthcare services to our patients and running our organisation which includes monitoring the quality of care that we provide. In carrying out this role we will collect information about you which helps us respond to your queries or secure specialist services. We will keep your information in written form and/or in digital form.
Our Commitment to Data Privacy and Confidentiality Issues
As a GP practice, all of our GPs, staff and associated practitioners are committed to protecting your privacy and will only process data in accordance with the Data Protection Legislation. This includes the General Data Protection Regulation (EU) 2016/679 (GDPR), the Data Protection Act (DPA) 2018, the Law Enforcement Directive (Directive (EU) 2016/680) (LED) and any applicable national Laws implementing them as amended from time to time. The legislation requires us to process personal data only if there is a legitimate basis for doing so and that any processing must be fair and lawful.
In addition, consideration will also be given to all applicable Law concerning privacy, confidentiality, the processing and sharing of personal data including the Human Rights Act 1998, the Health and Social Care Act 2012 as amended by the Health and Social Care (Safety and Quality) Act 2015, the common law duty of confidentiality and the Privacy and Electronic Communications (EC Directive) Regulations.
Data we collect about you
Records which this GP Practice will hold or share about you will include the following:
How we use your information
Improvements in information technology are also making it possible for us to share data with other healthcare organisations for the purpose of providing you, your family and your community with better care. For example it is possible for healthcare professionals in other services to access your record with your permission when the practice is closed.
Whenever you use a health or care service, such as attending Accident & Emergency or using Community Care services, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment. The information collected about you when you use these services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:
This may only take place when there is a clear legal basis to use this information. All these uses help to provide better health and care for you, your family and future generations. Confidential patient information about your health and care is only used like this where allowed by law.
Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn’t needed.
A full list of details including the legal basis, any Data Processor involvement and the purposes for processing information can be found in our Privacy Notice.⇑
Right of Access to your information (Subject Access Request)
Under Data Protection Legislation everybody has the right have access to, or request a copy of, information we hold that can identify you, this includes your medical record, there are some safeguards regarding what you will have access and you may find information has been redacted or removed for the following reasons;
You do not need to give a reason to see your data and requests should be made in writing. We will ask you to complete a form in order that we can ensure that you have the correct information you require.
Forms to download:⇓
Accessing Your Medical Records
Individuals Rights under GDPR
Under GDPR 2016 the Law provides the following rights for individuals. The NHS uphold these rights in a number of ways.
Your right to opt out of data sharing and processing
The NHS Constitution states ‘You have a right to request that your personal and confidential information is not used beyond your own care and treatment and to have your objections considered’.
Type 1 Opt Out
This is an objection that prevents an individual’s personal confidential information from being shared outside of their general practice except when it is being used for the purposes of direct care, or in particular circumstances required by law, such as a public health emergency like an outbreak of a pandemic disease. If patients wish to apply a Type 1 Opt Out to their record they should make their wishes know to the practice manager.
National data opt-out
The national data opt-out was introduced on 25 May 2018, enabling patients to opt-out from the use of their data for research or planning purposes, in line with the recommendations of the National Data Guardian in her Review of Data Security, Consent and Opt-Outs.
The national data opt-out replaces the previous ‘type 2’ opt-out, which required NHS Digital not to share a patient’s confidential patient information for purposes beyond their individual care. Any patient that had a type 2 opt-out recorded on or before 11 October 2018 has had it automatically converted to a national data opt-out. Those aged 13 or over were sent a letter giving them more information and a leaflet explaining the national data opt-out. For more information go to National data opt out programme
If a patient does not want their confidential patient information from any organisation to be used by other health and care organisations for research and planning this can be done at: Make your choice about sharing data from your health records - NHS (www.nhs.uk) or by phoning the NHS Digital Contact Centre: 0300 303 5678.
To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters.
Data Protection Officer
Should you have any data protection questions or concerns, please contact: GP-IGEnquiries.scwcsu@nhs.net
Our current DPO is Laura Taw.