menu

Residents Privacy Policy

Harbour Healthcare – Residents Privacy Notice

Protecting Privacy, Supporting Simply Good Care

At Harbour Healthcare, protecting your privacy is central to everything we do. We operate care homes across England and Wales and process personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Notice explains how we collect, use, share, and protect your personal information when you receive care from us.

Data Controller

Harbour Healthcare Ltd is the data controller responsible for your personal information.

Data Protection Officer (DPO):
Sarah Campbell
The Lodge House, Dodge Hill
Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk

Regulation and Compliance

We are regulated by:

  • Care Quality Commission (CQC) in England
  • Care Inspectorate Wales (CIW)

We maintain strong governance arrangements including data protection policies, risk management processes, and regular compliance reviews.

What is Personal Data?

Personal data is any information that identifies you, directly or indirectly. This includes basic details such as your name and contact information, as well as more sensitive information such as your health and care records.

What Information Do We Collect?

We collect personal data from you and, where necessary, from others involved in your care.

Personal Data

  • Name, date of birth, address, and contact details
  • Care plans, preferences, and daily routines
  • Family and next-of-kin information
  • Financial and funding information
  • Correspondence (emails, calls, letters)
  • Photographs (where consent has been provided)

Special Category Data

  • Health and medical information
  • Cultural, religious, or personal needs relevant to care
  • Safeguarding and incident information
  • Equality and diversity data where relevant
  • Criminal offence data where required for safeguarding

Information from Other Sources

We may receive information from:

  • NHS systems (including GP Connect / PCS)
  • Shared care records such as the Devon and Cornwall Care Record (DCCR)
  • Local authorities and safeguarding teams
  • Healthcare professionals and emergency services

How We Use Your Information

We use your personal data to:

  • Deliver safe and effective health and social care
  • Develop and manage your care plan
  • Communicate with you, your family, and professionals
  • Maintain financial and administrative records
  • Safeguard residents, staff, and visitors
  • Comply with legal and regulatory requirements
  • Support investigations, incidents, and complaints

Lawful Basis for Processing

We process personal data under:

  • Article 6(1)(c) – Legal obligation
  • Article 6(1)(f) – Legitimate interests (to provide safe and effective care)
  • Article 6(1)(b) – Contract (where applicable to care arrangements)

For special category data, we rely on:

  • Article 9(2)(h) – Health or social care provision
  • Article 9(2)(g) – Substantial public interest (safeguarding)

Sharing Your Personal Information

We may share your information where necessary and lawful with:

  • NHS organisations (GPs, hospitals, Integrated Care Boards)
  • Shared care record systems including the Devon and Cornwall Care Record (DCCR)
  • Local authorities and safeguarding teams
  • Regulators (CQC, CIW, ICO, HSE)
  • Police, coroners, and legal authorities
  • Approved suppliers and service providers

All third parties are subject to appropriate data protection agreements.

We do not sell personal data.

Shared Care Records – Devon and Cornwall Care Record (DCCR)

We participate in shared care record systems, including the Devon and Cornwall Care Record (DCCR) where applicable.

These systems allow authorised health and care professionals to securely access and share relevant information to support your care, improve safety, and reduce duplication.

Your information is only accessed by professionals involved in your care and is protected by strict access controls and monitoring.

National Data Opt-Out

The National Data Opt-Out allows individuals to opt out of their confidential patient information being used for purposes beyond their direct care.

This does not apply where information is used for your direct care.

Where data is used for planning or reporting, we apply the National Data Opt-Out where required.

Capacity and Decision-Making

Where a resident does not have the mental capacity to make decisions about their personal data, we act in accordance with the Mental Capacity Act 2005.

Decisions about how personal information is used or shared will be made in the individual’s best interests and may involve legally authorised representatives such as attorneys, deputies, or family members where appropriate.

We always aim to involve residents in decisions about their information wherever possible.

CCTV

Some of our homes use CCTV in communal and external areas to support safety and safeguarding.

  • CCTV is never used in private areas such as bedrooms or bathrooms
  • Access to footage is restricted to authorised personnel
  • Footage may be shared with police or regulators where lawful

How Long We Keep Your Information

We retain personal data in line with the NHS Records Management Code of Practice 2021 and legal requirements.

Typical retention periods include:

  • Care records: 8 years after death or discharge
  • Safeguarding records: up to 10 years where required
  • CCTV footage: up to 30 days unless required for investigation

Full details are available in our Records Retention and Destruction Policy.

International Transfers

Your data is usually stored in the UK or European Economic Area (EEA).

Where data is transferred outside the UK, appropriate safeguards such as International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) are used.

How We Keep Your Information Secure

We use appropriate technical and organisational measures including:

  • Role-based access controls
  • Secure IT systems and encryption
  • Audit logging and monitoring
  • Staff training and confidentiality agreements

Your Rights

You have the right to:

  • Be informed about how your data is used
  • Access your personal data
  • Request correction of inaccurate information
  • Request deletion where appropriate
  • Restrict or object to processing

If you have concerns about how your data is handled, please see the Complaints section below.

Accessing Your Care Records

You can request access to your care records. These may include staff names involved in your care.

Only relevant information will be shared, and proof of identity may be required.

Social Media and Marketing

  • We may share general updates about life in our homes
  • Images or personal data will only be shared with your consent
  • Marketing communications require explicit opt-in

Data Breaches

We have procedures in place to identify, investigate, and respond to personal data breaches.

Where required, we notify affected individuals and the Information Commissioner’s Office (ICO).

Complaints

If you are unhappy with how your personal data is used or handled, please contact our Data Protection Officer.

Data Protection Officer:
Sarah Campbell
Email: DPO-GDPR@harbourhealthcare.co.uk

If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO):

Website: https://ico.org.uk/make-a-complaint
Telephone: 0303 123 1113

You do not need to contact us first.

We take all complaints seriously and use them to improve our services.

Further Information

For more details, please refer to our General Privacy Notice.

Version Control

Organisation: Harbour Healthcare
Document Title: Residents Privacy Notice
Version: 2.0
Effective Date: July 2025
Review Date: Annually or upon significant change
Owner: Data Protection Officer