menu

General Privacy Statement

Harbour Healthcare – General Privacy Statement

Protecting Privacy, Supporting Simply Good Care

At Harbour Healthcare, protecting your privacy is central to everything we do. We provide care services across England and Wales and handle personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

We are committed to ensuring that personal data is processed lawfully, fairly, and transparently. This notice explains how we collect, use, share, and protect your information when you receive care, work with us, visit our services, or interact with our organisation.

Data Controller

Harbour Healthcare Ltd is the data controller responsible for your personal information.
Data Protection Officer (DPO):
Sarah Campbell
The Lodge House, Dodge Hill
Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk

Regulation and Compliance

We are regulated by:
• Care Quality Commission (CQC) in England
• Care Inspectorate Wales (CIW)
We maintain strong governance arrangements including records of processing activities, risk management frameworks, and regular data protection reviews.

What is Personal Data?

Personal data is any information that identifies you, directly or indirectly. This includes names, contact details, identification numbers, and online identifiers.

What Information Do We Collect?

Personal Data

• Name, address, and contact details
• Employment or role information
• Emergency contact details
• Correspondence (emails, letters, calls)
• Visit and interaction records
• CCTV footage where applicable

Special Category Data

Where necessary and lawful, we may process:

• Health and care information
• Cultural, religious, or personal needs relevant to care
• Equality and diversity data
• Safeguarding information
• Criminal offence data (e.g. DBS checks)
We only collect this information where it is necessary to provide care, meet legal obligations, or support safeguarding.

How Do We Use Your Information?

We use your personal data to:

• Deliver safe and effective health and social care
• Manage and support our workforce
• Safeguard residents, staff, and visitors
• Meet legal and regulatory obligations
• Investigate incidents, complaints, and safeguarding concerns
• Communicate with individuals, families, and professionals
• Support operational management, reporting, and service improvement

Lawful Basis for Processing

We process personal data under the following lawful bases:
• Article 6(1)(c) – Legal obligation
• Article 6(1)(f) – Legitimate interests (safe and effective operation of services)
• Article 6(1)(b) – Contract (employment and service provision where applicable)

Where we process special category data, we rely on:
• Article 9(2)(h) – Health or social care provision
• Article 9(2)(b) – Employment and social protection
• Article 9(2)(g) – Substantial public interest (e.g. safeguarding)

We only rely on consent where you have a genuine choice, such as marketing or photography.

Sharing Your Information

We may share personal data where necessary and lawful with:

• NHS organisations (GPs, hospitals, Integrated Care Boards)
• Local authorities and safeguarding teams
• Regulators (CQC, CIW, ICO, HSE, DBS, NMC)
• Police, coroners, and legal authorities
• Approved suppliers and IT service providers
• Professional partners involved in care

All third parties are subject to appropriate contractual agreements and data protection requirements.

We do not sell personal data.

National Data Opt-Out

The National Data Opt-Out allows individuals to opt out of their confidential patient information being used for purposes beyond their direct care.

This does not apply where information is used for your individual care.

Where Harbour Healthcare uses information for planning, reporting, or analytical purposes, we apply the National Data Opt-Out where required in line with NHS guidance.

Capacity and Decision-Making

Where a resident does not have the mental capacity to make decisions about their personal data, we will act in accordance with the Mental Capacity Act 2005.

This means decisions about the use of personal information will be made in the individual’s best interests and may involve consultation with legally authorised representatives such as attorneys, deputies, or family members where appropriate.

We always aim to involve individuals as much as possible in decisions about their information.

International Transfers

Your information is usually stored within the UK or the European Economic Area (EEA).

Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
• International Data Transfer Agreements (IDTAs)
• Standard Contractual Clauses (SCCs)

How Long We Keep Your Information

We retain personal data in line with the NHS Records Management Code of Practice 2021, legal requirements, and organisational need.

Typical retention periods include:
• Care records: 8 years after death or discharge
• Staff records: 6 years after employment ends
• Financial records: 6 years
• CCTV footage: up to 30 days unless required for investigation

Emails and electronic communications (including Microsoft Teams) are managed in line with organisational retention policies. Routine communications may be automatically deleted after defined periods unless required for business, legal, safeguarding, or care record purposes.

Full details are available in our Records Retention and Destruction Policy.

How We Keep Your Information Secure

We use appropriate technical and organisational measures, including:
• Role-based access controls
• Encryption in transit and at rest
• Secure systems and infrastructure
• Audit logs and monitoring
• Staff training and confidentiality obligations

CCTV

CCTV may be used in communal and external areas for safety and safeguarding.
• CCTV is not used in private areas
• Access is restricted to authorised personnel
• Footage may be shared with police or regulators where lawful

Safeguarding and Legal Requirements

We may share personal data where required to:
• Protect individuals from harm
• Support safeguarding investigations
• Comply with legal or regulatory requirements
• Assist police, courts, or coroners

Your Rights

You have the right to:
• Be informed about how your data is used
• Access copies of your personal data
• Request correction of inaccurate information
• Request deletion where appropriate
• Restrict or object to processing
• Request data portability where applicable

If you have concerns about how your personal data is handled, please see the Complaints section below.

Requests can be made to the Data Protection Officer.

Deceased Individuals and Access to Records

Data protection law does not apply to personal data relating to individuals who have died. However, Harbour Healthcare continues to handle such information with care and confidentiality.

Access to health records of deceased individuals is managed in accordance with the Access to Health Records Act 1990 and relevant professional and legal guidance.

Requests may be considered from authorised individuals such as personal representatives or those with a legal claim arising from the individual’s death.

Accessing Care Records

Care records may include information about staff involved in your care. Only relevant information will be shared when responding to requests.

Proof of identity may be required.

Social Media and Marketing

• We may share general updates about our services
• Personal images or identifiable data will only be used with consent
• Marketing communications require explicit opt-in

Data Breaches

We have procedures in place to identify, investigate, and respond to personal data breaches. Where required, we notify affected individuals and the Information Commissioner’s Office (ICO).

Complaints

If you are unhappy with how your personal data is being used or handled, we encourage you to contact our Data Protection Officer in the first instance.

Data Protection Officer:
Sarah Campbell
Email: DPO-GDPR@harbourhealthcare.co.uk
We will investigate and respond in line with our data protection and complaints procedures.

If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Website: https://ico.org.uk/make-a-complaint
Telephone: 0303 123 1113

You can raise concerns with the ICO at any time and do not need to contact us first.

We take all complaints seriously and use them to improve our services and data protection practices.

Contact Us

For any data protection queries:
Sarah Campbell – Data Protection Officer
Email: DPO-GDPR@harbourhealthcare.co.uk

Organisations We Work With

We may share information with:
• NHS organisations
• Local authorities
• Regulators
• Approved suppliers and contractors
• Legal representatives

We are not responsible for the privacy practices of third-party organisations.

Version Control
Document Title: General Privacy Notice
Version: 2.0
Effective Date: July 2026
Review Date: Annually or upon significant change
Owner: Data Protection Officer