Aim and Scope of Policy
The policy, which is in line with UK data protection laws, shows how this care service complies with the data protection requirements found in the respective national care standards and regulations on good governance of record keeping resulting in records that are comprehensively fit for purpose and securely maintained.
The respective national care standards are as follows (refer to as required).
- England: Regulation 17: “Good Governance”, of the Health and Social Care Act (Regulated Activities) Regulations 2014.
- Scotland: My Support, My Life, particularly Section 4: “I have confidence in the organisation providing my care and support”.
- Wales: Regulation 59 “Records”, of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017.
All standards require full, accurate, up-to-date records on service users, staff and other aspects concerning the running of the service to be kept in line with data protection, confidentiality, secure storage and authorised access policies and procedures.
This care provider also understands that all records required for the protection of service users and for the effective and efficient running of the care service should be collected, maintained and kept according to the Data Protection Act 2018 and the General Data Protection Regulation (GDPR).
This policy applies to all manual and electronic records kept by the service in relation to service users, including those involved with them, whose personal data might be found on their records, all staff and any third parties (agencies and professionals) with whom anyone’s personal data information held by the service might have to be disclosed or shared.
The policy should be used with other relevant record-keeping and information governance policies.
This privacy notice tells you what to expect us to do with your personal information.
- Contact details
- What information we collect, use, and why
- Lawful bases and data protection rights
- Where we get personal information from
- How long we keep information
- Who we share information with
- How to complain
Contact details
Innovative Start Limited, 1 Cliveden Office Village, Lancaster Road, Cressex Business Park, HIGH WYCOMBE, Buckinghamshire, HP12 3YZ, GB
What information we collect, use, and why
We collect or use the following information to provide patient care, services, pharmaceutical products and other goods:
- Name, address and contact details
- Gender
- Pronoun preferences
- Date of birth
- NHS/HSC/CHI number
- Hospital number
- National Insurance number
- Next of Kin details including any support networks
- Emergency contact details
- Photographs
- Health information (including medical conditions, allergies, medical requirements and medical history)
- Information about care needs (including disabilities, home conditions, medication and dietary requirements and general care provisions)
- Test results (including psychological evaluations, scans, bloods, x-rays, tissue tests and genetic tests)
- Payment details (including card or bank information for transfers and direct debits)
- Records of meetings and decisions
We also collect the following information to provide patient care, services, pharmaceutical products and other goods:
- Racial or ethnic origin
- Health information
We collect or use the following information for safeguarding or public protection reasons:
- Name, address and contact details
- NHS/HSC/CHI number
- Hospital number
- Emergency contact details
- Photographs
- Health information (including medical conditions, allergies, medical requirements and medical history)
- Information about care needs (including disabilities, home conditions, dietary requirements and general care provisions)
- Relevant information from previous investigations
- Test results (including psychological evaluations, scans, bloods, x-rays, tissue tests and genetic tests)
- Records of meetings and decisions
We also collect the following information for safeguarding or public protection reasons:
- Health information
We collect or use the following personal information for patient app or portal functionality:
- Names and contact details
- Medical history
We also collect the following information for patient app or portal functionality:
- Health information
We collect or use the following personal information to comply with legal requirements:
- Name
- Contact information
- Identification documents
- Health and safety information
- Financial information
- Insurance details
- Safeguarding information
- Criminal offence data
We also collect the following information to comply with legal requirements:
- Health information
We collect or use the following personal information for recruitment purposes:
- Contact details (eg name, address, telephone number or personal email address)
- Date of birth
- National Insurance number
- Copies of passports or other photo ID
- Employment history (eg job application, employment references or secondary employment)
- Education history (eg qualifications)
- Right to work information
- Details of any criminal convictions (eg Disclosure Barring Service (DBS), Access NI or Disclosure Scotland checks )
- Security clearance details (eg basic checks and higher security clearance)
We also collect the following information for recruitment purposes:
- Health information
Lawful bases and data protection rights
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are in brief set out below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
- Your right of access – You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. You can read more about this right here.
- Your right to rectification – You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. You can read more about this right here.
- Your right to erasure – You have the right to ask us to delete your personal information. You can read more about this right here.
- Your right to restriction of processing – You have the right to ask us to limit how we can use your personal information. You can read more about this right here.
- Your right to object to processing – You have the right to object to the processing of your personal data. You can read more about this right here.
- Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. You can read more about this right here.
- Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. You can read more about this right here.
If you make a request, we must respond to you without undue delay and in any event within one month.
To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.
Purposes for which we use your personal information
Below is a list of the ways that we may use your personal information, and which of the reasons (or legal bases) we rely on to do so. This is also where we tell you what our legitimate interests are.
WHAT WE USE YOUR PERSONAL INFORMATION FOR | OUR REASON(S) FOR PROCESSING | OUR LEGITIMATE INTERESTS (WHERE APPLICABLE) |
· To manage our relationship with you. · To communicate with you about your membership or Benenden Health products you have purchased. · To develop and carry out marketing activities. · To conduct analysis and research activities to improve and develop our products and services. · To analyse the reaction to our advertising activity. · To create anonymised look-alike audiences for marketing purposes. | · Fulfilling contracts. · Our legal duty. · Your consent. · Our legitimate interests. | · Keeping our records up to date. · Working out which of our products and services may interest you and telling you about them. · Defining audiences to market our products to. · Seeking your consent when we need it to contact you. · Being efficient about how we fulfil our legal and contractual duties. |
· To provide you with the services we can offer when members request assistance. · To manage how we work with other companies that provide services to us and our members or customers. | · Fulfilling contracts. · Our legal duty. · Our legitimate interests. | · Being efficient about how we fulfil our legal and contractual duties. |
· To administer payments relating to membership. · To administer payments relating to product sales. · To administer payments for services we can offer when members request assistance. | · Fulfilling contracts. · Our legal duty. · Our legitimate interests. | · Being efficient about how we fulfil our legal and contractual duties. · Complying with regulations that apply to us. |
· To detect, investigate, report and seek to prevent financial crime. · To manage risk for us and our members or customers. · To comply with regulations that apply to us. · To respond to complaints and seek to resolve them. | · Fulfilling contracts. · Our legal duty. · Our legitimate interests. | · Developing and improving how we deal with financial crime. · Complying with regulations that apply to us. · Being efficient about how we fulfil our legal and contractual duties. |
· To run our business in an efficient and proper way. This includes managing our financial position, business capability, planning, communications, corporate governance and audit. | · Our legal duty. · Our legitimate interests. | · Complying with regulations that apply to us. · Being efficient about how we fulfil our legal and contractual duties. |
· To exercise our rights as set out in agreements or contracts. | · Fulfilling contracts. |
Where we get personal information from
- Directly from you
- Regulatory authorities
- Family members or carers
- Social services
- Councils and other public sector organisations
How long we keep information
Innovative Start is committed to handling personal data responsibly and transparently. In accordance with NHS data retention standards, we securely store personal information only as long as necessary to provide services, meet legal obligations, and uphold our legitimate interests. Personal data collected may be retained for up to 10 years where it supports the delivery of care services, regulatory compliance, or where it may be required for legal or financial auditing purposes.
Upon reaching the end of this period, or earlier if no longer required, all personal data will be securely destroyed in line with best practices and regulatory guidelines.
Innovative Start adheres to the following data retention schedule to ensure compliance with legal requirements and best practices. The table below outlines the categories of personal data, the purpose of retention, and the retention period:
Data Category | Purpose of Retention | Retention Period |
Client Information | To provide care services and support | Up to 10 years after last service date |
Employee Records | To meet employment, legal, and regulatory obligations | Up to 10 years after employment ends |
Financial Records | For auditing and compliance purposes | Up to 10 years from the end of the financial year |
Medical Records | To ensure continuity of care and meet regulatory standards | Up to 10 years after last treatment |
Consent Forms | To confirm consent for processing personal data | Up to 10 years after consent is obtained |
Marketing Data | To manage and evaluate marketing campaigns | Until the individual opts out or up to 2 years after last contact |
Upon reaching the end of the specified retention period, personal data will be securely deleted or anonymised, ensuring that it cannot be reconstructed or re-identified.
Who we share information with
Others we share personal information with
- Other health providers (eg GPs and consultants)
- Emergency services
- Legal bodies or authorities
- Local authorities or councils
- Relevant regulatory authorities
- Organisations we’re legally obliged to share personal information with
Duty of confidentiality
We are subject to a common law duty of confidentiality. However, there are circumstances where we will share relevant health and care information. These are where:
- you’ve provided us with your consent (we have taken it as implied to provide you with care, or you have given it explicitly for other uses);
- we have a legal requirement (including court orders) to collect, share or use the data;
- on a case-by-case basis, the public interest to collect, share and use the data overrides the public interest served by protecting the duty of confidentiality (for example sharing information with the police to support the detection or prevention of serious crime);
- If in England or Wales – the requirements of The Health Service (Control of Patient Information) Regulations 2002 are satisfied; or
- If in Scotland – we have the authority to share provided by the Chief Medical Officer for Scotland, the Chief Executive of NHS Scotland, the Public Benefit and Privacy Panel for Health and Social Care or other similar governance and scrutiny process.
National data opt-out
We comply with England’s national data opt-out because we’re using confidential patient information for purposes beyond individual care. To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters.
How to complain
If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.
If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint
Last updated
30 October 2024