We are writing to you to provide information required by the General Data Protection Regulation which will come into force May 2018.
1. Business details
This is the privacy notice of Minchinhampton Centre for the Elderly comprising Horsfall House and Horsfall House Homecare.
Our registered office is at Minchinhampton Centre for the Elderly, Horsfall House, Windmill Road, Minchinhampton, Glos, GL6 9EY.
Horsfall House is registered with the Care Quality Commission to provide accommodation for persons who require nursing or personal care.
Horsfall House Homecare is registered with the Care Quality Commission to provide personal care to people in their own homes.
2. Aims of this notice
Horsfall House and Horsfall House Homecare are required by law to tell you about your rights and our obligations egarding our collecting and processing any of your personal information, which you might provide to us. We have a range of policies and procedures to ensure that any personal information you supply is only with your active consent and will always be held securely and treated confidentially in line with the applicable regulations.
We have listed the relevant documents in a later section (6) and can make any available
3. What personal information we collect about service users, employees, and third parties
1. Service users. As a registered care provider, we must collect some personal information on our service users, including financial information, which is essential to our being able to provide effective care and support. The information is contained in individual files (manual and electronic) and other record systems, all of which are subject to strict security and authorised access policies. Personal information that becomes inactive, eg from enquiries or prospective users who do not enter the service is also kept securely for as long as it is needed, before being safely disposed of.
2. Employees and volunteers. The service operates a safe recruitment policy to comply with the regulations in which all personal information obtained, including CVs and references, is, like service users’ information, securely kept, retained and disposed of in line with data protection requirements. All employees are aware of their right to access any information about them.
3. Third parties. All personal information obtained about others associated with the delivery of the care service, including contractors, visitors, etc will be protected in the same ways as information on service users and employees.
4. How we collect information
The bulk of service users’, employees’ and thirds parties’ personal information is collected directly from them or through form filling, mainly manually, but also electronically for some purposes, eg when contacting the service through its website, and through our care planning processes.
With service users, we might continue to build on the information provided in enquiry and referral forms, and, for example, from needs assessments, which feed into their care and support plans.
With employees, personal information is obtained directly and with consent through such means as references, testimonials and criminal records (DBS) checks. When recruiting staff, we seek applicant’s explicit consent to obtain all the information needed for us to decide to employ them.
All personal information obtained to meet our regulatory requirements will always be treated in line with our explicit consent, data protection and confidentiality policies.
Our website and databases are regularly checked by experts to ensure they meet all privacy standards and comply with our general data protection security and protection policies.
5. What we do with personal information
All personal information obtained on service users, employees and third parties is used only to ensure that we provide a service, which is consistent with our purpose of providing a person-centred care service, which meets all regulatory standards and requirements. It will not be disclosed or shared for any other purpose.
6. How we keep your information safe
As already stated, the service has a range of policies that enable us to comply with all data protection requirements. Foremost are:
• Data Protection
• Service Users’ Access to Records
7. With whom we might share information
We only share the personal information of service users, employees and others with their consent on a “need to know” basis, observing strict protocols in doing so. Most information sharing of service users’ information is with other professionals and agencies involved with their care and treatment. Likewise, we would not disclose information about our employees without their clear agreement, eg when providing a reference.
The only exceptions to this general rule would be where we are required by law to provide information, eg to help with a criminal investigation. Even when seeking to notify the local authority of a safeguarding matter or the Care Quality Commission of an incident that requires us to notify it, we would only do so with consent or ensure that the information provided is treated in confidence.
Where we provide information for statistical purposes, the information is aggregated and provided anonymously so that there is no privacy risk involved in its use.
8. How personal information held by the care provider can be accessed
There are procedures in place to enable any staff member, employee or third party whose personal information we possess and might process in some way to have access to that information on request. (See the policies listed in No. 6 above.) The right to access includes both the information and any uses which we might have made of the information.
9. How long we keep information
There are strict protocols in place that determine how long the organisation will keep the information, which are in line with the relevant legislation and regulations.
10. How we keep our privacy policies up to date
The staff appointed to control and process personal information in our organisation are delegated to assess all privacy risks continuously and to carry out comprehensive reviews of our data protection policies, procedures and protocols at least annually.
If you require any further information concerning the matters detailed above please do not hesitate to contact us.
The data that we keep about you is your data and we ensure that we keep it confidential and that it is used appropriately. You have the following rights when it comes to your data
1. You have the right to request a copy of all of the data we keep about you. Generally, we will not charge for this service;
2. You have the right to ask us to correct any data we have which you believe to be inaccurate. You can also request that we restrict all processing of your data while we consider your rectification request;
3. You have the right to request that we erase any of your personal data which is no longer necessary for the purpose we originally collected it for. We retain our data in line with the Information Governance Alliance’s guidelines (https://digital.nhs.uk/data-and-information/looking-after-information/data-security-and-information-governance/codes-of-practice-for-handling-information-in-health-and-care/records-management-code-of-practice-for-health-and-social-care-2016).
4. You may also request that we restrict processing if we no longer require your personal data for the purpose we originally collected it for, but you do not wish for it to be erased.
5. You can ask for your data to be erased if we have asked for your consent to process your data. You can withdraw consent at any time – please contact us to do so.
6. If we are processing your data as part of our legitimate interests as an organisation or in order to complete a task in the public interest, you have the right to object to that processing. We will restrict all processing of this data while we look into your objection.
You may need to provide adequate information for our staff to be able to identify you, for example, a passport or driver’s licence. This is to make sure that data is not shared with the wrong person inappropriately. We will always respond to your request as soon as possible and at the latest within one month.
If you would like to complain about how we have dealt with your request, please contact:
Information Commissioner’s Office