menu

Privacy Statement for Staff

Harbour Healthcare – Staff Privacy Notice

Protecting Privacy, Supporting Simply Good Employment Practices

At Harbour Healthcare, protecting your personal information is as important as protecting the residents in our care. We process staff personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Notice explains how we collect, use, share, and protect your personal information as an employee, worker, contractor, or agency staff member.

Data Controller

Harbour Healthcare Ltd is the data controller responsible for your personal information.

Data Protection Officer (DPO):
Sarah Campbell
The Lodge House, Dodge Hill
Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk

Regulation and Compliance

We comply with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018

We maintain robust governance arrangements including data protection policies, audit processes, and regular compliance reviews.

What Information We Collect

We may collect and process the following personal data:

Personal Data

  • Name, date of birth, and contact details
  • Employment details, job role, and work history
  • Training and professional development records
  • Emergency contact details
  • Payroll and financial information (e.g. bank details)
  • Communication records (emails, messages, calls)
  • System access logs and activity records

Special Category Data

Where necessary and lawful, we may process:

  • Health information (e.g. sickness absence, occupational health)
  • Equality and diversity data (e.g. ethnicity, disability)
  • Trade union membership (where applicable)

Criminal Offence Data

  • DBS checks and safeguarding-related information, processed in line with legal requirements

How We Use Your Information

We use your personal data to:

  • Manage your employment and contractual relationship
  • Process payroll, pensions, and benefits
  • Support training, development, and workforce planning
  • Ensure health, safety, and wellbeing at work
  • Safeguard residents, staff, and visitors
  • Manage performance, conduct, and disciplinary processes
  • Comply with legal, regulatory, and safeguarding obligations
  • Respond to lawful requests from regulators, law enforcement, or legal bodies

Lawful Basis for Processing

We process your personal data under:

  • Article 6(1)(b) – Contract (employment relationship)
  • Article 6(1)(c) – Legal obligation (employment law, safeguarding, health and safety)

Where relevant, we also rely on:

  • Article 6(1)(f) – Legitimate interests (safe and effective service delivery)

For special category data, we rely on:

  • Article 9(2)(b) – Employment and social protection
  • Article 9(2)(g) – Substantial public interest (safeguarding and workforce compliance)

Sharing Your Information

We may share your personal data where necessary and lawful with:

  • Regulators (CQC, CIW, ICO, HSE, DBS)
  • NHS organisations (e.g. occupational health services where required)
  • Local authorities and safeguarding teams
  • Law enforcement or emergency services
  • Legal representatives, coroners, or courts
  • Payroll, HR, and IT system providers

All third parties are subject to appropriate contracts and data protection requirements.

Accessing Your Data (Subject Access Requests)

You have the right to request access to your personal data.

Employment records may include references to other staff (e.g. managers, colleagues) where relevant to your employment or incidents.

Information unrelated to your request will not be disclosed.

Proof of identity may be required before information is released.

How Long We Keep Your Information

We retain staff data in line with legal requirements and the NHS Records Management Code of Practice 2021.

Typical retention periods include:

  • Staff records: 6 years after employment ends
  • Payroll and financial records: 6 years
  • Recruitment records: 6–12 months (if unsuccessful)
  • DBS information: retained in line with DBS Code of Practice

Emails and electronic communications (including Microsoft Teams) are managed in line with organisational retention policies. Routine communications may be automatically deleted after defined periods unless required for business, legal, or safeguarding purposes.

How We Keep Your Information Secure

We use appropriate security measures, including:

  • Role-based access controls
  • Secure systems and encryption
  • Audit logging and monitoring
  • Confidentiality agreements and training

CCTV and Monitoring

Some locations use CCTV in communal and external areas to support safety and safeguarding.

  • CCTV is not used in private areas
  • It is not used for routine staff performance monitoring
  • Footage is accessed only when necessary and by authorised personnel

We may also monitor system access and usage to maintain security and compliance.

International Transfers

Staff data is primarily stored in the UK or European Economic Area (EEA).

Where data is transferred outside the UK, appropriate safeguards such as International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) are in place.

Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Request deletion where appropriate
  • Restrict or object to processing
  • Request data portability where applicable

If you have concerns about how your data is handled, please see the Complaints section below.

Social Media and Communications

  • Personal data or images will not be shared externally without consent
  • Staff are expected to follow organisational policies when using social media

Data Breaches

We have procedures in place to identify, investigate, and respond to data breaches.

Where required, we notify affected individuals and the Information Commissioner’s Office (ICO).

Complaints

If you are unhappy with how your personal data is used or handled, please contact our Data Protection Officer.

Data Protection Officer:
Sarah Campbell
Email: DPO-GDPR@harbourhealthcare.co.uk

If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO):

Website: https://ico.org.uk/make-a-complaint
Telephone: 0303 123 1113

You do not need to contact us first.

We take all complaints seriously and use them to improve our data protection practices.

Further Information

For more information, please refer to our General Privacy Notice.

Version Control

Organisation: Harbour Healthcare
Document Title: Staff Privacy Notice
Version: 2.0
Effective Date: July 2026
Review Date: Annually or upon significant change
Owner: Data Protection Officer