At Harbour Healthcare, protecting your privacy is at the heart of everything we do. We operate homes across England and Wales and handle your personal information in line with UK GDPR and the Data Protection Act 2018.
We collect and use your information for clear, lawful purposes and take all measures to keep it secure. Transparency and accountability are central to our approach.
Harbour Healthcare Ltd is the data controller responsible for your personal information. Each home may hold individual registrations with the Information Commissioner’s Office (ICO).
Sarah Campbell – DPO
The Lodge House, Dodge Hill, Heaton Norris, Stockport, Cheshire SK4 1RD
Email: DPO-GDPR@harbourhealthcare.co.uk
Our services are regulated by the Care Quality Commission (CQC) in England and the Care Inspectorate Wales (CIW). We adhere to strict data protection standards to ensure your information is secure and your rights are respected.
Personal data is any information that can identify you. This includes basic details (name, address, contact) and more sensitive information (health records, care history, photographs, family details).
We collect information directly from you, your relatives, GPs, healthcare professionals, local authorities, emergency services, and where necessary, other third parties. This includes:
NHS systems (including Connect GP (PCS)), DCCR, local authorities, emergency services.
We may use your information to:
We may share your information with:
We never sell your data or share it for marketing without explicit consent.
Please note that the organisations listed are examples and this list is not exhaustive. Resident information may also be shared with other appropriate parties, such as regulators, safeguarding teams, law enforcement, or legal representatives, where required by law, contractual obligations, or in the public interest
Some homes operate CCTV in communal and external areas (entrances, corridors, lounges, dining areas, gardens, car parks). CCTV is never used in private areas
such as bedrooms, bathrooms, or toilets.
Consent is sought only when you have a genuine choice (photographs, optional marketing, surveys). Refusal does not affect core care.
Where consent is not required, processing relies on
(legal obligation, safeguarding, legitimate interest).
Under UK GDPR, you can:
Requests are handled by the DPO in line with legal timeframes.
Care records may include staff names and roles involved in your care. Staff information unrelated to your care is not shared.
Records can be requested in paper or electronic form. Proof of identity may be required.
Information is retained only as long as necessary for legal or care purposes.
Full details are available in our Records Retention and Destruction Policy on our website alongside the privacy policies.
If a breach occurs, it will be managed according to GDPR and Data Protection Act 2018. Affected individuals and the ICO will be notified if required. Contact the DPO for any concerns.
Information may be shared with:
Data is generally stored in the UK. Transfers outside the UK (e.g., cloud services) use appropriate safeguards such as standard contractual clauses.
If you are unhappy with how we use your information, contact our
first. You also have the right to complain to the ICO: ICO Complaints
Harbour Healthcare | Version 1.0 | January 2026 – January 2027