Document

Horsham Wellbeing Privacy Notice

The following Privacy Notice applies to Horsham District Council Wellbeing team.

This Notice explains how personal information is going to be used, what it is used for, who it might be shared with and why and for how long it is to be kept.

The Council (HDC) is fully committed to complying with The Data Protection Act 2018 and the UK General Data Protection Regulation (GDPR).

We ensure that your personal data is processed fairly, lawfully kept safe and secure and retained for no longer than is necessary.

The Data Protection Officer for HDC is the Head of Legal and Democratic Services.

If you have any concerns or questions about how we look after your personal information, please contact the Data Protection Officer at dpa@horsham.gov.uk

What information is collected?

  • Personal information including name, DOB, age, address, telephone number, email
  • Sensitive personal data including medical conditions, referral sources, lifestyle concerns and outcome data, NHS Health check results, disability, sex, ethnicity
  • Any feedback you provide on our services.
  • We may also take photographs at our events to use for general marketing and publicity (we will not publish these without your consent).

Why do we collect your personal information?

  • To provide evidence and analysis of the service we are providing. The information we hold is stored in protected folders that only the Wellbeing Team have access to. The information we share with Public Health West Sussex is anonymised so is not personal identifiable to anyone viewing it.
  • To hold a record of your details and contact with us in order to provide you with a Horsham Wellbeing service.
  • To refer you to another organisation for support and information should you agree you need help from a different service that we do not offer
  • To notify your GP or other health and social care professional of the outcome of the intervention and/or ongoing service should we have received a referral from them on your behalf or there be a concern.
  • Deliver and develop the services and support we provide you.
  • Check the quality of services. Data Controller Horsham District Council is registered as a Data Controller with The Information Commissioner’s Office (Registration Number Z7294458). Horsham District Council are joint Data controllers with Chichester District Council and Provide who provide the control centre to answer lifeline calls.
  • Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
  • Processing is necessary to protect the vital interests of a data subject or another person.
  • Processing is necessary for compliance with a legal obligation. The Legal Basis for Processing Special Category Data
  • Processing is necessary for the reason of substantial public interest.
  • Processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent.

Who we share data with?

We pass data to:

  • Public Health West Sussex (anonymised so is not personal identifiable to anyone viewing it)
  • Other partner agencies involved with the Delivery of Horsham District Councils Wellbeing Service (where you have given permission for us to do this)
  • Your GP where you have had an NHS Health Check
  • Agencies with whom we have a duty to co-operate, such as the police.

For users of our Smoking Cessation, NHS Health Check and Alcohol Advice services:

  • We enter your data onto the PharmOutcomes system. This is a secure, web-based clinical and service management data collection and communications platform that allows patient-facing entry of service information and personal sensitive data.

We will not share data with third parties for marketing purposes. Transfer outside the European Economic Area If your data needs to be transferred, we will make sure that an adequate level of protection is in place.

Retention periods

Personal data will be retained for a maximum period of 3 years from the point of your case being closed.

Rights: you have the right to

1. Be informed of data processing (which is covered by this Privacy Notice).

2. Access your personal information (known as a Subject Access Request).

3. Have inaccuracies corrected.

4. Have information erased.

5. Restrict processing.

6. Data portability.

7. Intervention in respect of automated decision making/profiling.

8. Withdraw Consent (see below).

9. Complain to the Information Commissioner’s Office (See below). To exercise any of these rights please contact the Data Protection Officer at dpa@horsham.gov.uk

Your rights

You have the right to:

1. Be informed of data processing (which is covered by this Privacy Notice).

2. Access your personal information (known as a Subject Access Request).

3. Have inaccuracies corrected.

4. Have information erased.

5. Restrict processing.

6. Data portability.

7. Intervention in respect of automated decision making/profiling.

8. Withdraw Consent (see below).

9. Complain to the Information Commissioner’s Office (See below).

To exercise any of these rights please contact the Data Protection Officer at dpa@horsham.gov.uk

Withdrawal of consent

The lawful basis upon which HDC process personal data is set out in this notice. However, where personal data is solely processed on the basis of consent, you will have the right to withdraw that consent.

Where can I get advice?

If you have any worries or questions about how your personal information is handled, please contact our Data Protection Officer at dpa@horsham.gov.uk

For independent advice about data protection, privacy and data rights, you can contact the Information Commissioner’s Office (ICO) at: Information Commissioner’s Office, Wycliffe House Water Lane Wilmslow Cheshire DK9 5AF

Tel: 0303 123 1113 (local rate) or 01625 545 745 if you prefer to use a national rate number.

Alternatively, visit www.ico.org.uk or email casework@ico.org.uk