Privacy Notice (GDPR)
For the purpose of applicable data protection legislation including the General Data Protection Regulation (EU 2016/679) and the Data Protection Act 2018, the GP practice responsible for your personal data is Canbury Medical Centre.
We, Canbury Medical Centre, will be known as the ‘Controller’ of the personal data you provide to us.
Your privacy is important to us, and we are committed to protecting and safeguarding your data privacy rights.
This privacy notice applies to personal information processed by or on behalf of the practice. It applies to the personal data of our patients and to the data you have given us about your carers/family members. It covers the following topics:
- Why do we need your data?
- What data do we collect about you?
- What is the legal basis for using your data?
- How do we store your data?
- How do we maintain the confidentiality of your data?
- How long do we keep your data?
- What are your data protection rights?
- Who do we share your data with?
- Are there other projects where your data may be shared?
- When is your consent not required?
- How can you access or change your data?
- What should you do if your personal information changes?
- Our Data Protection Officer.
- How to contact the appropriate authorities.
Why do we need your Data?
As your general practice, we need to know your personal, sensitive and confidential data in order to provide you with appropriate healthcare services. Your records are used to facilitate the care you receive, and to ensure you receive the best possible healthcare.
Information may be used within the GP practice for clinical audit, to monitor the quality of the service provided.
What Data do we collect about you?
We collect basic personal data about you which does not include any special types of information or location-based information. This includes your name, postal address and contact details such as email address and telephone number.
By providing the practice with your contact details, you are agreeing to the practice using those channels to communicate with you about your healthcare, i.e. by letter (postal address), by voice-mail or voice-message (telephone or mobile number), by text message (mobile number) or by email (email address). If you are unhappy or have a concern about our using any of the above channels, please let us know but using our online Feedback triage.
Special Category Personal Data
We also collect confidential data linked to your healthcare which is known as special category personal data, in the form of health information, religious belief (if required in a healthcare context) ethnicity and gender. This is obtained during the services we provide to you and through other health providers or third parties who have provided you with treatment or care, e.g. NHS Trusts, other GP surgeries, Walk-in clinics etc.
Records which the practice holds about you may include the following information:
- Details about you, such as your address, carer, legal representative, emergency contact details.
- Any contact the practice has had with you, such as appointments, clinic visits, emergency appointments etc.
- Notes and reports about your health.
- Details about your treatment and care.
- Results of investigations such as laboratory tests, x-rays etc.
- Relevant information from other health professionals, relatives or those who care for you.
NHS records may be electronic, on paper, or a mixture of both.
What is the Legal Basis for using your Data?
We are committed to protecting your privacy and will only use information collected lawfully in accordance with:
- Data Protection Act 2018.
- The General Data Protection Regulations 2016.
- Human Rights Act 1998.
- Common Law Duty of Confidentiality.
- Health and Social Care Act 2012.
- NHS Codes of Confidentiality, Information Security and Records Management.
Under the General Data Protection Regulation we will lawfully be using your information in accordance with:
- Article 6 (e) – “processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller”.
- Article 9 (h) – “processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems”.
For the processing of special categories data, the basis is:
- Article 9 (2) (b) – “processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law”.
These articles apply to the processing of information and the sharing of it with others for specific purposes.
How do we store your Data?
We have a Data Protection regime in place to oversee the effective and secure processing of your personal and special category (sensitive, confidential) data. No third parties have access to your personal data unless the law allows them to do so and appropriate safeguards have been put in place.
The practice uses the system EMIS Web to manage clinical information for your care and health. This system is provided by a company called EMIS Health Ltd which acts as a data processor on behalf of the practice. They also use a sub-processor, Amazon Web Services, which acts under written instructions from EMIS Health Ltd. Under no circumstances are any of these organisations allowed or able to access your information.
All the personal data we use is processed by our staff in the UK. However, for the purposes of IT hosting and maintenance, this information may be located on servers within the European Union.
In certain circumstances, you may have the right to withdraw your consent to the processing of data. These circumstances will be explained in subsequent sections of this document.
In some circumstances, we may need to store your data after your consent has been withdrawn, in order to comply with a legislative requirement.
How do we maintain the Confidentiality of your Data?
Our practice policy is to respect the privacy of our patients, their families and our staff and to maintain compliance with the General Data Protection Regulations (GDPR) and all UK specific Data Protection requirements. Our policy is to ensure all personal data related to our patients will be protected.
We use a combination of working practices and technology to ensure that your information is kept confidential and secure.
Every member of staff who works for an NHS organisation has a legal obligation to keep information about you confidential.
All employees and sub-contractors engaged by our practice are asked to sign a confidentiality agreement. The practice will, if required, sign a separate confidentiality agreement if the client deems it necessary. If a sub-contractor acts as a data processor for Canbury Medical Centre an appropriate contract will be established for the processing of your information.
Some of this information will be held centrally and used for statistical purposes. Where this happens, we take strict measures to ensure that individual patients cannot be identified.
Sometimes your information may be requested to be used for research purposes. The practice will always gain your consent before releasing the information for this purpose in an identifiable format. In some circumstances you can Opt-out of the practice sharing any of your information for research purposes.
How long do we keep your Data?
We are required under UK law to keep your information and data for the full retention periods as specified by the NHS Records Management Code of Practice for Health and Social Care and in accordance with National Archives requirements.
More information on records retention can be found online at:
What are your Data Protection Rights?
If we already hold your personal data, you have certain rights in relation to it.
Right to Object
If we are using your data because we deem it necessary for our legitimate interests to do so, and you do not agree, you have the right to object. We will respond to your request within 30 days (although we may be allowed to extend this period in certain cases). Generally, we will only disagree with you if certain limited conditions apply.
Right to Withdraw Consent
Where we have obtained your consent to process your personal data for certain activities (for example a research project), or consent to market to you, you may withdraw your consent at any time.
Right to Erasure
In certain situations (for example, where we have processed your data unlawfully), you have the right to request us to erase your personal data. We will respond to your request within 30 days (although we may be allowed to extend this period in certain cases) and will only disagree with you if certain limited conditions apply.
Right of Data Portability
If you wish, you have the right to transfer your data from us to another data controller. We will help with this with a GP to GP data transfer and transfer of your hard copy notes.
National Data Opt-Out
The National Data Opt-Out is a service introduced on 25 May 2018 that allows people to opt out of their confidential patient information being used for research and planning purposes. The National Data Opt Out replaces the previous Type 2 Opt Out, which required NHS Digital not to share a patient’s confidential patient information for purposes beyond their individual care. Any patient who had a Type 2 Opt Out has had it automatically converted to a National Data Opt Out and has received a letter giving them more information and a leaflet explaining the new service. If a patient wants to change their choice, they can use the new service to do this.
You can find out more from the practice or by visiting:
If you wish to raise a query or request relating to any of the above, please contact us. We will seek to deal with it without undue delay, and in any event in accordance with the requirements of any applicable laws. We may keep a record of your communications to help us resolve any issues which you raise.
Who do we share your Data with?
We consider patient consent as being the key factor in dealing with your health information.
To provide around-the-clock safe care, we will make information available to trusted organisations for specific purposes unless you have asked us not to.
To support your care and improve the sharing of relevant information to our partner organisations when they are involved in looking after you, we will share information to other systems. The general principle is that information is passed to these systems unless you request that this does not happen, but that system users should ask for your consent before viewing your record.
Our partner organisations are:
- NHS trusts / foundation trusts.
- NHS commissioning support Units.
- Independent contractors such as dentists, opticians, pharmacists.
- Private sector providers.
- Voluntary sector providers.
- Ambulance trusts.
- Clinical Commissioning Groups.
- Social care services.
- NHS England (NHSE) and NHS Digital (NHSD).
- Multi Agency Safeguarding Hub (MASH).
- Local authorities.
- Education services.
- Fire and rescue services.
- Police and judicial services.
- Other ‘data processors’ which you will be informed of.
You will be informed who your data will be shared with, and in cases where your consent is required, you will be asked for it.
Below are some examples of when we would wish to share your information with trusted partners:
Primary Care Networks
We are a member of CCOB (Canbury, Churchill, Orchard, Berrylands) Primary Care Network. This means we work closely with a number of local practices and care organisations for the purpose of direct patient care. They will only be allowed to access your information if it is to support your healthcare needs. If you have any concerns about how your information may be accessed within our primary care network, we would encourage you to speak or write to us.
We provide extended access services to our patients which means you can access medical services outside of our normal working hours. In order to provide you with this service, we have formal arrangements in place with the Clinical Commissioning Group and with other practices whereby certain key hub practices offer this service on our behalf for you as a patient to access outside our opening hours. Those key hub practices will need to have access to your medical record to be able to offer you the service. We have robust data sharing agreements and other clear arrangements in place to ensure your data is always protected and used for those purposes only.
The practice may conduct Medicines Management Reviews of medications prescribed to its patients. This service performs a review of prescribed medications to ensure patients receive the most appropriate, up-to-date and cost-effective treatments. Our local NHS Clinical Commissioning Group employs specialist pharmacists and they may at times need to access your records to support and assist us with prescribing. This reason for this is to help us manage your care and treatment.
Individual Funding Requests
An Individual Funding Request is a request made on your behalf, with your consent, by a clinician, for the funding of specialised healthcare which falls outside the range of services and treatments that CCG has agreed to commission for the local population. An Individual Funding Request is considered when a case can be set out by a patient’s clinician that there are exceptional clinical circumstances which make the patient’s case different from other patients with the same condition who are at the same stage of their disease, or when the request is for a treatment that is regarded as new or experimental and where there are no other similar patients who would benefit from this treatment. A detailed response, including the criteria considered in arriving at the decision, will be provided to the patient’s clinician.
Are there other Projects where your Data may be shared?
Other research projects
With your consent we would also like to use your name, contact details and email address to inform you of services that may benefit you. There may be occasions when authorised research facilities would like to invite you to participate in research, innovations, identifying trends or improving services. At any stage where we would like to use your data for anything other than the specified purposes and where there is no lawful requirement for us to share or process your data, we will ensure that you have the ability to consent or to opt out prior to any data processing taking place. This information is not shared with third parties or used for any marketing and you can unsubscribe at any time via phone, email or by informing the practice.
Data Provision Notice sharing information with NHS Digital for Planning and Research
The Practice is required to comply with the Health and Social Care Act 2012. NHS Digital have the power under the Health and Social Care Act 2012 Section 259 (1) to issue a Data Provision Notice. This mandates us to share information about you unless you tell us not to.
To opt out please complete the Type 1 Opt out form before 23rd June 2021 and return it to the Practice by email or hard copy.
You can see a list of the Data Provision Notices here:
When is your Consent not required?
We will only ever use or pass on information about you to others involved in your care if they have a genuine need for it. We will not disclose your information to any third party without your permission unless there are exceptional circumstances.
There are certain circumstances where we are required by law to disclose information, for example:
- Where there is a serious risk of harm or abuse to you or other people.
- Where a serious crime, such as assault, is being investigated or where it could be prevented.
- Notification of new births.
- Where we encounter infectious diseases that may endanger the safety of others, such as meningitis or measles (but not HIV/AIDS).
- Where a formal court order has been issued.
- Where there is a legal requirement, for example, if you had committed a Road Traffic Offence.
We are also required to act in accordance with Principle 7 of the Caldicott Review (Revised version 2013) which states: “The duty to share information can be as important as the duty to protect patient confidentiality.” This means that health and social care professionals should have the confidence to share information in the best interests of their patients within the framework set out by the Caldicott Principles.
How can you access or change your Data?
You have a right under the Data Protection legislation to request access to view or to obtain copies of the information the practice holds about you and to have it amended should it be inaccurate.
Your request should be made to the practice and we have a form (SAR – Subject Access Request) which you will need to complete. We are required to respond to you within one calendar month. Contact the practice online for more information.
For information from a hospital, you should write to them directly. You will need to give adequate information (full name, address, date of birth, NHS number and details of your request) so that your identity can be verified and your records located.
There is no charge to receive a copy of the information held about you.
What should you do if your Personal Information changes?
Please contact the practice as soon as any of your details change. This is especially important for changes of address or contact details (such as your mobile phone number).
The practice will from time to time ask you to confirm that the information we currently hold is accurate and up-to-date.
It is important to point out that we may amend this privacy notice from time to time.
Our Data Protection Officer
The local CCG has appointed Umar Sabat to act on behalf of GP practices to be the data protection officer.
He can be contacted on the following e-mail address Dpo.firstname.lastname@example.org.
If you have any concerns about how your data is shared, or if you would like to know more about your rights in respect of the personal data we hold about you, then please contact the practice data protection officer.
How to Contact the Appropriate Authorities
If you have any concerns about how your information is managed at your GP practice, please contact the GP practice manager or the data protection officer in the first instance.
If you are still unhappy following a review by the GP practice, you have a right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO), at the following address:
Our ICO Registration Number is Z5779557.
Risk stratification is an example of where your information may be used for your direct care or for purposes beyond your direct care.
Risk stratification is a process of identifying patients or groups of patients that are most likely to get a certain disease so that the right services can be provided to an individual or a population in general.
For example, “these patients are most likely to get diabetes in my GP practice, so I’m going to provide this care plan to those individuals” or “this number of patients is at risk of diabetes in this CCG, so I’m going to commission this service”.
Information to the Health Authority and other Health Organisations
Some information is sent electronically to the other parts of the NHS for administration and payment purposes. This can be statistical information that does not identify individuals or may include some personal details such as changes of address etc. in order to keep the practice list up to date. All NHS staff are bound by the same rules on data protection and confidentiality.
The practice is also requested by the NHS and Medical Research Council (MRC) to provide data for the clinical audit or research of certain diseases and conditions. This information will either be anonymous, so individuals cannot be identified or you will be asked for consent. You may be contacted to ask if you’re happy for your information to be used in this way. Your identifiable information will only be shared in this way where you have given your explicit consent.
Prescribing information is also requested to help compile statistics on how diseases are treated and the costs involved in treating some illnesses. All such information is anonymous; individual patients will not be recognisable from this information.