At Harbour Healthcare, we work with a range of organisations to deliver safe, effective, and person-centred care. This Privacy Notice explains how and why personal data may be shared with partner organisations, and how it is protected.
Data Controller
Harbour Healthcare Ltd is the data controller responsible for personal information we share.
Data Protection Officer (DPO):
Sarah Campbell
The Lodge House, Dodge Hill
Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk
We process and share personal data in accordance with:
• UK General Data Protection Regulation (UK GDPR)
• Data Protection Act 2018
We maintain robust governance arrangements including records of processing activities, data sharing agreements, and regular compliance monitoring.
We may share personal data with partner organisations to:
• Provide safe and effective health and social care
• Support safeguarding and protect individuals
• Meet legal and regulatory obligations
• Support investigations, incidents, and complaints
• Work collaboratively with health and care partners
Depending on the purpose, we may share:
• Resident care information (including health and care data)
• Staff information where relevant to care or investigations
• Visitor information where required for safety or safeguarding
• CCTV footage from communal areas where necessary
Where special category data is shared, we ensure appropriate legal conditions and safeguards are in place.
We may share information with the following types of organisations:
Health and Care Organisations
• NHS organisations (including GP surgeries, hospitals, and Integrated Care Boards)
• NHS Wales / Local Health Boards
• Shared care record systems, including the Devon and Cornwall Care Record (DCCR), and GP access systems such as GP Connect
Local Government and Safeguarding
• Local authorities (adult social care and safeguarding teams)
• Multi-Agency Safeguarding Hubs (MASH)
• Local Government & Social Care Ombudsman
Regulators and Professional Bodies
• Care Quality Commission (CQC)
• Care Inspectorate Wales (CIW)
• Disclosure and Barring Service (DBS)
• Health and Safety Executive (HSE)
• Information Commissioner’s Office (ICO)
• Nursing and Midwifery Council (NMC)
Law Enforcement and Legal Authorities
• Police and emergency services
• Coroners
• Courts and legal representatives
• Suppliers and Service Providers
• Approved contractors and IT providers who process data on our behalf under contractual agreements
This list is not exhaustive. Personal data may also be shared with other organisations where lawful and necessary.
We share personal data under the following lawful bases:
• Article 6(1)(c) – Legal obligation
• Article 6(1)(f) – Legitimate interests (safe and effective care delivery)
• Article 6(1)(b) – Contract (where applicable)
Where we share special category data, we rely on:
• Article 9(2)(h) – Health or social care provision
• Article 9(2)(g) – Substantial public interest (e.g. safeguarding)
• Article 9(2)(b) – Employment and social protection (where relevant)
Where an individual does not have the mental capacity to make decisions about their personal data, we act in accordance with the Mental Capacity Act 2005.
Decisions about sharing personal information will be made in the individual’s best interests and may involve legally authorised representatives such as attorneys, deputies, or family members where appropriate.
National Data Opt-Out
The National Data Opt-Out allows individuals to opt out of their confidential patient information being used for purposes beyond their individual care.
This does not apply where information is used for direct care.
Where data is shared for planning, reporting, or wider system purposes, we apply the National Data Opt-Out where required.
Shared Care Records – Devon and Cornwall Care Record (DCCR)
Harbour Healthcare participates in shared care record systems, including the Devon and Cornwall Care Record (DCCR), where applicable.
These systems allow authorised health and care professionals to access and share relevant information to support direct care, improve safety, and reduce duplication.
Information shared through these systems is used only for direct care purposes and is accessed by authorised professionals involved in an individual’s care.
Access is controlled through role-based permissions and is subject to audit and monitoring.
Personal data is usually processed within the UK or the European Economic Area (EEA).
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
• International Data Transfer Agreements (IDTAs)
• Standard Contractual Clauses (SCCs)
We retain personal data in line with legal requirements, organisational need, and the NHS Records Management Code of Practice 2021.
Typical retention periods include:
• Care records: 8 years after death or discharge
• Safeguarding and incident records: up to 10 years where required
• CCTV footage: up to 30 days unless required for investigation
All personal data is stored securely, with access restricted to authorised personnel.
CCTV may be used in communal and external areas for safety and safeguarding.
• CCTV is not used in private areas
• Access is restricted
• Footage may be shared with police or regulators where lawful
We have procedures in place to identify, investigate, and respond to personal data breaches.
Where required, we notify affected individuals and the Information Commissioner’s Office (ICO).
You have the right to:
• Access your personal data
• Request correction of inaccurate information
• Request deletion where appropriate
• Restrict or object to processing
If you have concerns about how your data is handled, please see the Complaints section below.
If you are unhappy with how your personal data is shared or handled, please contact our Data Protection Officer.
Data Protection Officer:
Sarah Campbell
Email: DPO-GDPR@harbourhealthcare.co.uk
If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO):
Website: https://ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
You do not need to contact us first.
For more detail, please refer to our General Privacy Notice.
Version Control
Organisation: Harbour Healthcare
Document Title: Organisations We Work With Privacy Notice
Version: 2.0
Effective Date: July 26
Review Date: Annually or upon change
Owner: Data Protection Officer