Do we share information?
We strive to capture the minimal amount of personal data, and only share with other organisations where the law permits us to do so or where we require and have gained your consent. We only share information with our authorised Data Processors for the sole purpose of processing the data in connection with the service we have procured from them. These processors must act at all times on our instructions as the Data Controller under the Data Protection legislation.
We host health information campaigns on behalf of Public Health England, where we are Data Processors. These campaigns may have separate privacy terms and consent requirements.
Before you submit any information, you will be informed why we are asking for specific information and it is up to you whether you provide it.
We do not sell individuals’ information.
Keeping information secure
We invest significant resources to protect your personal information, from loss, misuse, unauthorised access, modification or disclosure. However, no internet-based site can be 100% secure and so we cannot be held responsible for unauthorised or unintended access that is beyond our control.
How can you access, amend or withdraw the personal data you have given us?
To get in touch about these rights, please contact us via the Data Controller: email@example.com
We will seek to deal with your request without undue delay, and in any event within 1 month (subject to any extensions to which we are lawfully entitled).
*Please note that we may keep a record of your communications to help us resolve any issues that you raise.
Right to object:
If we are using your data because we have a legal basis to do so under the Health and Social Care Act, and you do not agree, you have the right to object. We will respond to your request within the required time frame (although we may be allowed to extend this period in certain cases). Generally, we will only disagree with you if certain limited conditions apply.
This right enables you to object to us processing your personal data where we do so for one of the following reasons: (i) to enable us to perform a public task or exercise official authority; (ii) to send you direct marketing communications; and (iii) for research or analytical purposes.
Right to withdraw consent:
Where we have obtained your consent to process your personal data, or consent to send you information, you may withdraw your consent at any time and we will cease to carry out the particular activity that you previously consented to, unless we consider that there is an alternative reason to justify our continued processing of your data for this purpose, in which case we will inform you of this condition.
Data access requests:
You may ask us to confirm what information we hold about you at any time, and request us to modify, update or delete such information. We may ask you to verify your identity and for more information about your request. We will not charge you for accessing the information. If we refuse your request for any legitimate reason, we will always tell you the reasons for doing so.
Right to rectification:
You also have the right to request that we rectify any inaccurate or incomplete personal data that we hold about you. If we have shared this personal data with third parties, we will notify them about the rectification unless this is impossible or involves disproportionate effort. Where appropriate, we will also tell you which third parties we have disclosed the inaccurate or incomplete personal data to. Where we think that it is reasonable for us not to comply with your request, we will explain our reasons for this decision.
Right to remove:
In certain situations, you have the right to request us to “remove” your personal data. We will respond to your request within the agreed timeframe (although we may be allowed to extend this period in certain cases) and will only disagree with you if certain limited conditions apply. If we do agree to your request, we will delete your data but will generally assume that you would prefer us to keep a note of your name on a register of individuals who would prefer not to be contacted. That way, we will minimise the chances of you being contacted in the future where your data are collected in unconnected circumstances. If you would prefer us not to do this, you are free to say so.
Normally, the information must meet one of the following criteria:
– The data is no longer necessary for the purpose for which we originally collected and/or processed it.
– Where previously given, you have withdrawn your consent to us processing your data, and there is no other valid reason for us to continue processing.
– The data has been processed unlawfully (i.e. in a manner that does not comply with existing Data Protection regulations).
– It is necessary for the data to be deleted for us to comply with our legal obligations as a data controller.
We would only be entitled to refuse to comply with your request for one of the following reasons:
– to exercise the right of freedom of expression and information
– to comply with legal obligations or for the performance of a public interest task or exercise of official authority
– for public health reasons in the public interest
– for archival, research or statistical purposes
– to exercise or defend a legal claim When complying with a valid request for the removal of data, we will take all reasonably practicable steps to delete the relevant data.
Right to restrict processing:
You have the right to request that we restrict our processing of your personal data in certain circumstances. This means that we can only continue to store your data and will not be able to carry out any further processing activities with it until either: (i) one of the circumstances listed below is resolved; (ii) you consent; or (iii) further processing is necessary for either the establishment, exercise or defence of legal claims, the protection of the rights of another individual, or reasons of important public interest.
The circumstances in which you are entitled to request that we restrict the processing of your personal data are:
– where you dispute the accuracy of the personal data that we are processing about you. In this case, our processing of your personal data will be restricted for the period during which the accuracy of the data is verified
– where you object to our processing of your personal data for our legitimate interests. Here, you can request that the data be restricted while we verify our grounds for processing your personal data
– where our processing of your data is unlawful, but you would prefer us to restrict our processing of it rather than erasing it
– where we have no further need to process your personal data but you require the data to establish, exercise or defend legal claims
– If we have shared your personal data with third parties, we will notify them about the restricted processing unless this is impossible or involves disproportionate effort. We will, of course, notify you before lifting any restriction on processing your personal data.
Purpose and legal basis for processing
NHS Digital operates the NHS website as directed by the Electronic Prescription Service, Health and Social Care Network, N3, NHS e-Referral Service, Secondary Use Service (SUS), Spine 2 (Named Programmes) Directions 2016 under the powers of sections 254(1) and (6), 274(2), 304(9) and (10) of the Health and Social Care Act 2012.
This direction supplements the Health and Social Care Information Centre (Systems Delivery Functions for the NHS website and Additional Systems Delivery Functions for the NHS website) Directions 2013.