Protecting Privacy, Supporting Simply Good Care
At Harbour Healthcare, protecting your privacy is central to everything we do. We operate care homes across England and Wales and process personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Notice explains how we collect, use, share, and protect your personal information when you receive care from us.
Data Controller
Harbour Healthcare Ltd is the data controller responsible for your personal information.
Data Protection Officer (DPO):
Sarah Campbell
The Lodge House, Dodge Hill
Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk
Regulation and Compliance
We are regulated by:
We maintain strong governance arrangements including data protection policies, risk management processes, and regular compliance reviews.
What is Personal Data?
Personal data is any information that identifies you, directly or indirectly. This includes basic details such as your name and contact information, as well as more sensitive information such as your health and care records.
What Information Do We Collect?
We collect personal data from you and, where necessary, from others involved in your care.
Personal Data
Special Category Data
Information from Other Sources
We may receive information from:
How We Use Your Information
We use your personal data to:
Lawful Basis for Processing
We process personal data under:
For special category data, we rely on:
Sharing Your Personal Information
We may share your information where necessary and lawful with:
All third parties are subject to appropriate data protection agreements.
We do not sell personal data.
Shared Care Records – Devon and Cornwall Care Record (DCCR)
We participate in shared care record systems, including the Devon and Cornwall Care Record (DCCR) where applicable.
These systems allow authorised health and care professionals to securely access and share relevant information to support your care, improve safety, and reduce duplication.
Your information is only accessed by professionals involved in your care and is protected by strict access controls and monitoring.
National Data Opt-Out
The National Data Opt-Out allows individuals to opt out of their confidential patient information being used for purposes beyond their direct care.
This does not apply where information is used for your direct care.
Where data is used for planning or reporting, we apply the National Data Opt-Out where required.
Capacity and Decision-Making
Where a resident does not have the mental capacity to make decisions about their personal data, we act in accordance with the Mental Capacity Act 2005.
Decisions about how personal information is used or shared will be made in the individual’s best interests and may involve legally authorised representatives such as attorneys, deputies, or family members where appropriate.
We always aim to involve residents in decisions about their information wherever possible.
CCTV
Some of our homes use CCTV in communal and external areas to support safety and safeguarding.
How Long We Keep Your Information
We retain personal data in line with the NHS Records Management Code of Practice 2021 and legal requirements.
Typical retention periods include:
Full details are available in our Records Retention and Destruction Policy.
International Transfers
Your data is usually stored in the UK or European Economic Area (EEA).
Where data is transferred outside the UK, appropriate safeguards such as International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) are used.
How We Keep Your Information Secure
We use appropriate technical and organisational measures including:
Your Rights
You have the right to:
If you have concerns about how your data is handled, please see the Complaints section below.
Accessing Your Care Records
You can request access to your care records. These may include staff names involved in your care.
Only relevant information will be shared, and proof of identity may be required.
Social Media and Marketing
Data Breaches
We have procedures in place to identify, investigate, and respond to personal data breaches.
Where required, we notify affected individuals and the Information Commissioner’s Office (ICO).
Complaints
If you are unhappy with how your personal data is used or handled, please contact our Data Protection Officer.
Data Protection Officer:
Sarah Campbell
Email: DPO-GDPR@harbourhealthcare.co.uk
If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO):
Website: https://ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
You do not need to contact us first.
We take all complaints seriously and use them to improve our services.
Further Information
For more details, please refer to our General Privacy Notice.
Version Control
Organisation: Harbour Healthcare
Document Title: Residents Privacy Notice
Version: 2.0
Effective Date: July 2025
Review Date: Annually or upon significant change
Owner: Data Protection Officer