At Harbour Healthcare, protecting your privacy is at the heart of everything we do. With homes across England and Wales, we handle your personal information with the highest standards of care, fully in line with UK GDPR and the Data Protection Act 2018.
We collect and use your information for clear, lawful purposes and take all measures to keep it secure. Transparency and accountability are central to our approach — we want you to understand how your data is collected, used, shared, and safeguarded.
We use your information to provide employment, deliver care, and support residents with kindness and person-centered attention. This statement explains how your personal information is processed, stored, and protected.
Harbour Healthcare Ltd is the data controller responsible for your personal information. Each home may hold individual registrations with the Information Commissioner’s Office (ICO).
Data Protection Officer (DPO):
Sarah Campbell – DPO
The Lodge House, Dodge Hill, Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk
Our services are regulated by the Care Quality Commission (CQC) in England and the Care Inspectorate Wales (CIW). We follow strict data protection standards to keep your information secure and your rights protected.
Personal data is any information that can identify you, directly or indirectly. This includes name, contact information, identification numbers, visual images, or other unique identifiers.
We may collect information when you visit, work, or interact with our homes. This may include:
Special Category / Sensitive Data:
We only collect sensitive information when necessary and in line with the law.
We may use your information to:
Legal Basis for Processing:
Special Category Data:
We may share data with:
We do not sell personal data or use it for marketing without consent.
Some health and care information may be shared securely via DCCR or Connect GP (PCS) to support continuity of care, reduce duplication, and improve safety.
More information is available on the DCCR public website.
Consent is only required where you have a genuine choice, such as optional marketing, surveys, or photographs. Refusal does not affect core care or employment services.
Under UK GDPR, you can:
Requests are handled by the DPO within legal timeframes.
Care records may include staff names and roles involved in care or services. Unrelated staff information will not be shared. Records can be requested in paper or electronic form. Proof of identity may be required.
Data is generally stored in the UK. Transfers outside the UK use appropriate safeguards, such as standard contractual clauses.
Information is retained only as long as necessary for legal obligations or the purpose for which it was collected.
Full details are available in our Records Retention and Destruction Policy on our website alongside the privacy policies.
CCTV may be used in communal and external areas for safety and security. CCTV is not in all homes and never in private areas. Footage is accessed only by authorised staff and may be shared with Police, local authorities, regulators, or legal representatives where lawful. Clear signage is displayed.
Information may be shared with:
Breaches will be managed according to GDPR and the Data Protection Act 2018. Affected individuals and the ICO will be notified where required. Contact the DPO for concerns.
Sarah Campbell – Data Protection Officer (DPO)
Harbour Healthcare Ltd
The Lodge House, Dodge Hill, Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk
If unhappy with how your data is handled, contact the DPO first. You also have the right to complain to the ICO: ICO Complaints
Data may be shared with:
Harbour Healthcare is not responsible for third-party privacy statements; contact these organisations directly for queries.
Harbour Healthcare | Version 1.0 | January 2026 – January 2027