Tollgate Clinic – Your Information Your Rights (GDPR Compliant)
Level 2 Privacy Notice
The following leaflet describes what information we collect and hold about you, how we use it, who can access it and your rights with regards to accessing your information.
Who are we?
Tollgate Clinic is a Limited Company offering services to self-pay customers and to the NHS in the community, and are committed to making sure that they are safe, responsive and of high quality.
We provide services in Essex and in Hertfordshire
Tollgate Clinic is registered with the Information Commissioner’s Office (ICO) to process personal and special categories of information under the Data Protection Act and our registration number is Z2525693
Why we keep personal information about you
Weaim to provide you with the highest quality care. To do this, we must keep records about you and the care we provide for you.
Our staff are trained to handle your information correctly and protect your privacy. We aim to maintain high standards, adopt best practice for our record keeping and regularly check and report on how we are doing. Your information is never collected for direct marketing purposes, and is not sold on to any other third parties. Your information is not processed overseas.
Information is held for specified periods of time as set out in the Records Management Code of Practice for Health and Social Care.
What Information do we keep about you?
The information we hold may include:
- Basic details, such as your name, address and next of kin.
- Contacts we have had with you, such as clinic visits.
- Notes and reports about your health and any treatment or care you needed.
- Details about your treatment and care.
- Results of tests that may have been undertaken on our behalf as part of your care (i.e. Nerve Conduction Studies, Post Vasectomy Semenology Test, Biopsies)
- Unless you authorise us to we don’t access your health records information from other health professionals, relatives or those who care for you.
How do we collect Information about you?
We collect Information about you in a number of ways:
Information You Tell Us – Some of our services accept self-referrals which means that you can contact us directly to arrange an appointment and do not need to be referred by your G.P. You will be asked for certain information when you contact us to enable us to book you an appointment and to be able to provide appropriate care. You may also be asked to complete a form when you come in for your appointment so that we have pertinent information to be able to help you.
Information Others Tell Us – Where you are referred to us from another health care professional, for example you’re G.P, they will share relevant information about the care you have received from them to enable us to provide effective and safe care to you. The majority of our services store your health record on a system called SystmOne which is used widely across the NHS and care organisations to maintain accurate medical records about you.. You can choose which other organisations involved in your care can view your full medical record. Speak to your GP to set your choice or you can set them yourself using SystmOne. For more information please visit https://systmonline.tpp-uk.com/2/help/help.html
The NHS Personal Demographics Service– When we register you to receive care from one of our services, we receive information from the NHS Personal Demographic service. The Personal Demographics Service (PDS) is the national electronic database of NHS patient details such as name, address, date of birth and NHS Number (known as demographic information). This is to ensure that the information we hold about you is accurate and up to date and to ensure that you are entitled to receive NHS Care.
NHS Summary Care Record– To support you and provide high quality and safe health care it may very occasionally be necessary to access your NHS Summary Care Record. The NHS Summary Care Record is an electronic summary of key clinical information (including medicines, allergies and adverse reactions) sourced from your G.P Record. We will discuss this with you should the need arise to access this and will only do so this with your permission, unless another legal reason to access applies (please see below)
How do we hold your information?
We create and hold your records electronically and sometimes in hard copy where necessary. We may also hold paper records from previous contacts.
Any records we hold about you are held securely and are only accessible to those who are involved in your care or have a legitimate need to access. Electronic health records are accessed by use of an NHS Smartcard which are issued to our staff under strict NHS protocols. Any access by our staff to your health records is fully audited.
All of our staff and contractors receive appropriate and on-going training to ensure they are aware of their personal responsibilities and have contractual obligations to uphold confidentiality, enforceable through disciplinary procedures. Staff only have access to personal information where it is appropriate to their role and is strictly on a need-to-know basis.
How do we use your information?
Information collected about you to deliver your health care is also used to assist with:
- Making sure your care is of a high standard.
- Using statistical information to look after the health and wellbeing of the general public and planning services to meet the needs of the population.
- Assessing your condition against a set of risk criteria to ensure you are receiving the best possible care.
- Helping train staff and support research.
- Supporting the funding of your care.
- Reporting and investigation of complaints, claims and untoward incidents.
- Reporting events to the appropriate authorities when we are required to do so by law.
If you treatment is being funded by the NHS then the legal basis for the processing of data for these purposes is that as a provider of NHS care we have a public duty to care for its patients, as guided by the Department of Health and Data Protection law says it is appropriate to do so for health and social care treatment of patients, and the management of health or social care systems and services.
There may also be situations where we are under a duty to share your information. We are required by law to report certain information to the appropriate authorities. Occasions when we must pass on information include: Notification of new births, infectious diseases that may endanger others, such as meningitis and measles (but not HIV/AIDS), where a formal court order has been issued and sharing with the Care Quality Commission (CQC) to inspect the quality and safety of the care that we provide. We may also have to share your information when it is absolutely necessary for the prevention or detection of crime or prosecution of offenders or where there are serious risks to the public or our staff.
If you are funding your own treatment then the legal basis that the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Who can see your information?
Your information is only accessible to those involved in your care (clinical staff) or administration. Administrative staff include receptionists who check patients in for clinics and staff who assist with the administration of our clinics/ services (for example typing up letters and reports) These members of staff are bound by the same rules of confidentiality as our clinical staff.
Organisations that we may share information with:
- General Practitioners
- NHS Hospitals & Clinics
- Also, Subject to Strict Protocols : Education Services, Local Authority Services, Private Sector Providers, Children’s Centre’s, Commissioners of our Services, the Department of Health, the Family Health Service Authority (FHSA) and the Health Protection Agency
We will only share information with those who have a legitimate right to know
If we need to use your personal information for any reasons beyond those stated above, we will discuss this with you and ask for your permission to do so where you will have the option to agree or disagree. This is known as explicit consent. Data Protection laws gives individuals rights in respect of the personal information that we hold about you. These are:
- To ask for access to your information
- To ask for your information to be corrected if it is inaccurate or incomplete.
- To ask for your information to be deleted or erased. Please note that this does not apply to your health or care record, or where we process information for public health or scientific research purposes.
- To ask us to restrict the use of your information in some circumstances.
- To request your personal information to be transferred to other providers on certain occasions.
- Object to the use of your personal information: In certain circumstances you may also have the right to ‘object’ to the processing (i.e. sharing) of your information where the sharing would be for a purpose beyond your care and treatment (e.g. as part of a local/regional data sharing initiative). This ‘‘Data Opt-out’ initiative, developed by Dame Caldicott, is set to commence in March 2018 and conclude in March 2020. Further information can be found on the following website: https://digital.nhs.uk/national-data-opt-out
All requests for any of the above should be made to Paul Blacker our Data Protection Officer by telephone on 01206 987525
by email: email@example.com
or in writing 145 London Road, Stanway, Colchester, Essex, CO3 8NZ
Should you wish to lodge a complaint about the use of your information, please contact our General Manager Lisa Joy by telephone on on 01206 987525
By email: firstname.lastname@example.org
or in writing 145 London Road, Stanway, Colchester, Essex, CO3 8NZ
If you are still unhappy with the outcome of your enquiry you can write to: The Information Commissioner, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF – Telephone: 01625 545700