Harbour Healthcare – Staff Privacy Notice
Protecting Privacy, Supporting Simply Good Employment Practices
At Harbour Healthcare, protecting your personal information is as important as protecting the residents in our care. We process staff personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Notice explains how we collect, use, share, and protect your personal information as an employee, worker, contractor, or agency staff member.
Data Controller
Harbour Healthcare Ltd is the data controller responsible for your personal information.
Data Protection Officer (DPO):
Sarah Campbell
The Lodge House, Dodge Hill
Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk
Regulation and Compliance
We comply with:
We maintain robust governance arrangements including data protection policies, audit processes, and regular compliance reviews.
What Information We Collect
We may collect and process the following personal data:
Personal Data
Special Category Data
Where necessary and lawful, we may process:
Criminal Offence Data
How We Use Your Information
We use your personal data to:
Lawful Basis for Processing
We process your personal data under:
Where relevant, we also rely on:
For special category data, we rely on:
Sharing Your Information
We may share your personal data where necessary and lawful with:
All third parties are subject to appropriate contracts and data protection requirements.
Accessing Your Data (Subject Access Requests)
You have the right to request access to your personal data.
Employment records may include references to other staff (e.g. managers, colleagues) where relevant to your employment or incidents.
Information unrelated to your request will not be disclosed.
Proof of identity may be required before information is released.
How Long We Keep Your Information
We retain staff data in line with legal requirements and the NHS Records Management Code of Practice 2021.
Typical retention periods include:
Emails and electronic communications (including Microsoft Teams) are managed in line with organisational retention policies. Routine communications may be automatically deleted after defined periods unless required for business, legal, or safeguarding purposes.
How We Keep Your Information Secure
We use appropriate security measures, including:
CCTV and Monitoring
Some locations use CCTV in communal and external areas to support safety and safeguarding.
We may also monitor system access and usage to maintain security and compliance.
International Transfers
Staff data is primarily stored in the UK or European Economic Area (EEA).
Where data is transferred outside the UK, appropriate safeguards such as International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) are in place.
Your Rights
You have the right to:
If you have concerns about how your data is handled, please see the Complaints section below.
Social Media and Communications
Data Breaches
We have procedures in place to identify, investigate, and respond to data breaches.
Where required, we notify affected individuals and the Information Commissioner’s Office (ICO).
Complaints
If you are unhappy with how your personal data is used or handled, please contact our Data Protection Officer.
Data Protection Officer:
Sarah Campbell
Email: DPO-GDPR@harbourhealthcare.co.uk
If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO):
Website: https://ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
You do not need to contact us first.
We take all complaints seriously and use them to improve our data protection practices.
Further Information
For more information, please refer to our General Privacy Notice.
Version Control
Organisation: Harbour Healthcare
Document Title: Staff Privacy Notice
Version: 2.0
Effective Date: July 2026
Review Date: Annually or upon significant change
Owner: Data Protection Officer