Your privacy is very important to us. We have developed this General Data Protection Regulation (GDPR) in order for you to understand how we collect, use, store, share, transmit, transfer, delete or otherwise process (collectively “process”) your Personal data. This General Data Protection Regulation (GDPR) describes the measures we take to ensure the protection of your Personal data. We also tell you how you can reach us to answer any questions you may have about data protection.
The purpose of this policy is to ensure that Shiloh Healthcare Services Ltd understands the key principles of the General Data Protection Regulation (GDPR).
This policy sets out the steps that need to be taken by Shiloh Healthcare Services Ltd to ensure that Shiloh Healthcare Services Ltd handles, uses and processes personal data in a way that meets the requirements of GDPR. It should be read alongside the suite of Shiloh Healthcare Services Ltd policies, procedures and guidance.
This policy applies to all staff at Shiloh Healthcare Services Ltd who process personal data about other staff, Service User/ Clients and any other living individuals as part of their role.
The following people may be affected by this policy:
The following stakeholders may be affected by this policy:
The objective of this policy is to ensure staff have a working knowledge into the principles and requirements of GDPR.
Alongside the suite of policies, procedures and guidance available Shiloh Healthcare Services Ltd can demonstrate that appropriate steps are taken to ensure Shiloh Healthcare Services Ltd complies with GDPR when handling and using personal data provided by both staff and Service User/ Clients.
This policy will assist with defining accountability and establishing ways of working in terms of the use, storage, retention and security of personal data.
This policy will assist with understanding the obligations of Shiloh Healthcare Services Ltd in respect of the rights of the staff and Service User/ Clients who have provided personal data and the steps Shiloh Healthcare Services Ltd should take if it breaches GDPR.
GDPR came into force on the 25 May 2018 and replaced the Data Protection Act 1998. Regardless of the impact of Brexit, GDPR will remain. GDPR provides greater protection to individuals and places greater obligations on organisations but can be dealt with in bite-size chunks to ensure that any impact on the provision of care and services is minimised.
All staff need to ensure the ways in which they handle personal data meet the requirements of GDPR.
Shiloh Healthcare Services Ltd.’s Approach to GDPR
Shiloh Healthcare Services Ltd is required to take a proportionate and
appropriate approach to GDPR compliance. Shiloh
Healthcare Services Ltd understands that not all organisations will need to take the
same steps – it will depend on the
volume and types of personal data processed by a particular organisation, as well as
the processes already in place to
protect personal data. We understand that if we process significant volumes of
personal data, including special
categories of data, or have unusual or complicated processes in place in terms of
the way we handle personal data, we
will consider obtaining legal advice specific to the processing we conduct and the
steps we may need to take.
GDPR does not apply to any personal data held about someone who has died. Both the Access to Medical Reports Act 1988 and the Access to Health Records 1990 will continue to apply.
Shiloh Healthcare Services Ltd.’s Process for Promoting Compliance
To ensure Shiloh Healthcare Services Ltd compliance with GDPR, a suite of documents
are available and should be read in
conjunction with this overarching policy to provide a framework:
Overview of Key Principles and Documents
The key principles and themes of each of the documents listed above are summarised
below:
Initial Audit and Privacy Impact Assessment
Shiloh Healthcare Services Ltd understands that we should conduct an audit of the
personal data we currently process.
This can be carried out internally by Shiloh Healthcare Services Ltd with the
assistance of key staff members. The audit
will reveal whether the ways in which Shiloh Healthcare Services Ltd processes
personal data meet the requirements of
GDPR and will also indicate whether Shiloh Healthcare Services Ltd should delete
some of the personal data it currently
holds. An initial Privacy Impact Assessment template is provided as part of the GDPR
documentation.
Key Terms
GDPR places obligations on all organisations that process personal data about a Data
Subject. A brief description of
those three key terms is included in the Definitions section of this document and
are expanded upon in the Key Terms
Guidance.
The requirements that Shiloh Healthcare Services Ltd need to meet vary depending on
whether Shiloh Healthcare Services
Ltd is a Data Controller or a Data Processor. We recognise that in most scenarios,
Shiloh Healthcare Services Ltd will
be a Data Controller. The meaning of Data Controller and Data Processor, together
with the roles they play under GDPR,
are explained in the Key Terms Guidance.
Special categories of data attract a greater level of protection, and the
consequences for breaching GDPR in relation to
special categories of data may be more severe than breaches relating to other types
of personal data. This information
is also covered in more detail in the Key Terms Guidance.
Key Principles
There are 6 key principles of GDPR which Shiloh Healthcare Services Ltd must comply
with. These 6 principles are very
similar to the key principles that were set out in the Data Protection Act 1998.
They are:
Procedure
All staff should review the GDPR policies and procedures and guidance that will be produced over the next few months.
Shiloh Healthcare Services Ltd will nominate a person or team to be responsible for data protection and GDPR compliance (if a formal Data Protection Officer is not required, somebody with an understanding of the requirements who can act as a day-to-day point of contact will be chosen).
The Registered Manager should ensure all staff understand the policies and procedures provided, including how to deal with a Subject Access Request and what to do if a member of staff breaches GDPR.
The Registered Manager will consider providing training internally about GDPR (in particular, the Key Principles of GDPR) to all staff members.
Shiloh Healthcare Services Ltd will conduct an audit of the personal data currently held by Shiloh Healthcare Services Ltd (the initial Privacy Impact Assessment template provided will be used for this purpose).
Shiloh Healthcare Services Ltd will delete any personal data that Shiloh Healthcare Services Ltd no longer needs, based on the results of the audit conducted, taking into account any relevant guidance, such as the Records Management Code of Practice for Health and Social Care 2016.
Shiloh Healthcare Services Ltd will, if necessary, put in place new measures or processes to ensure that personal data continues to be processed in line with GDPR.
Shiloh Healthcare Services Ltd will, if necessary, finalise and circulate a Fair Processing Notice to Service User/ Clients.
Shiloh Healthcare Services Ltd will ensure proper consent is obtained from each Service User/ Clients in line with GDPR regulations (the Consent Form provided can be used for this purpose). Shiloh Healthcare Services Ltd will review the additional steps that Shiloh Healthcare Services Ltd should be taken to ensure that Shiloh Healthcare Services Ltd obtains consent from parents, guardians, carers or other representatives where Shiloh Healthcare Services Ltd works with children or those who lack capacity.
Shiloh Healthcare Services Ltd will ensure that processes and procedures are in place to respond to requests made by Data Subjects (including Subject Access Requests) and to deal appropriately with any breaches or potential breaches of GDPR.
The Registered Manager will maintain a log of decisions taken and incidents that occur in respect of the personal data processed by Shiloh Healthcare Services Ltd using the Shiloh Healthcare Services Ltd Privacy Impact Assessment template.
Definitions
Data Subject - The individual about whom Shiloh Healthcare Services Ltd has collected personal data
Data Protection Act 2018 - The Data Protection Act 2018 is a United Kingdom Act of Parliament that updates data protection laws in the UK. It sits alongside the General Data Protection Regulation and implements the EU’s Law Enforcement Directive
GDPR - General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union. It was adopted on 14 April 2016 and after a two-year transition period became enforceable on 25 May 2018
Personal Data - Any information about a living person including but not limited to names, email addresses, postal addresses, job roles, photographs, CCTV and special categories of data, defined below
Process or Processing - Doing anything with personal data, including but not limited to collecting, storing, holding, using, amending or transferring it. You do not need to be doing anything actively with the personal data – at the point you collect it, you are processing it
Special Categories of Data - Has an equivalent meaning to “Sensitive Personal Data” under the Data Protection Act 2018. Special Categories of Data include but are not limited to medical and health records (including information collected as a result of providing health care services) and information about a person’s religious beliefs, ethnic origin and race, sexual orientation and political views
Key Facts – Professionals: Professionals providing this service should be aware of the following:
Key Facts– People Affected by The Service People affected by this service should be aware of the following:
Further Reading
As well as the information in the ‘Underpinning Knowledge’ section of the review
sheet we recommend that you add to your
understanding in this policy area by considering the following materials:
The Records Management Code of Practice for Health and Social Care 2016 has been
issued by the Information Governance
Alliance for the Department of Health. It is available on the NHS Digital website
https://digital.nhs.uk/article/1202/Records-Management-Code-of-Practice-for-Health-and-Social-Care-2016
Outstanding Practice
© Shilo Healthcare Services (Ltd). All Rights Reserved. Designed by SkepStudio