Data Processing Notice
GP Support Hub and your Information
The GP Support Hub takes your privacy very seriously. W e are registered with the Information Commissioner as a Data Controller and our registration number is Z1409359. If you have any questions or wish to make a request in relation to your information, please contact the Suffolk GP Federation Privacy Officer at;
[email protected] Riverside Clinic 2 Landseer Road Ipswich IP3 0AZ Suffolk GP Federation is required to collect, use, store and share information about you, for the purposes of maintaining and progressing the employment relationship we have with you.
We do not transfer your information beyond the EU. We have specifically requested our data to stay in the UK from our contact management software supplier (FreshDesk).
How does the GP Support Hub collect my information?
We will collect information about you, either directly – when you make a request to the service, or indirectly – referrals and during the course of your employment with the Suffolk GP Federation or North East Essex.
The information we collect will be stored confidentially on computer and electronic systems. The information includes personal data:
- Basic details about you, such as name, address, email address, telephone number as well as Sensitive personal data give by you to us during contact with the GP Hub and where it is relevant to your request
- Qualifications
- Notes about your health and any disabilities. Only if you disclosed this to us.
GP Support Hub is permitted to collect, store, use and share this information, where necessary, under the General Data Protection Regulations Article 6 (1) (b) “for the purposes of a contract” and Article 9 (2) (b) “employment purposes”.
How does GP Support Hub use my information?
GP Support Hub will use your information for your employment in the following ways;
- Support the process of recruiting and on boarding you as a member of staff.
- Assist you to maintain records on your training and professional development.
- Support secondments and promotions.
- Returning to work after long term leave due to sickness, maternity leave etc.
To undertake some of these activities, your information will be shared internally across our teams. We will work to ensure that only the right people have your information and that they are only given the information they need it to assist you.
Who does GP Support Hub share my information with?
GP Support Hub works hard to ensure that only the right people have your information and that they are only given the information they need.
Personal data will never be made available to organisations not involved in your employment without letting you know and giving you a chance to object.
We have contracts in place with these organisations that prevent them from using it in any other way that how we tell them to. These contracts also require them to maintain good standards of security to ensure your confidentiality.
Will GP Support Hub share without asking me?
Sometimes we will be required by law to share your information and will not always be able to discuss this with you directly.
- Sharing with the police or tax authorities for the detection or prevention of crime.
- Where it is in the wider public interest – to keep the public safe for example.
- To safeguard children or vulnerable adults.
- Because the court has told us we must share.
What are my Information Rights?
Data protection law provides you with a number of rights that GP Hub is committed to supporting you with;
1) Right to Access
You have the right to obtain:
- Conformation that your information is being used, stored or shared by GP Support Hub
- A copy of information held about you.
- If you require a particular part of your record, tell us and this can reduce the time it takes to provide it.
- We will respond to your request within one month of receipt or will tell you when it might take longer.
- We are required to validate your identity including the identity of someone making a request on your behalf.
2) Right to Object or Withdraw Consent
We collect, use, store and share your information because we are permitted to by law; in order to deliver your support your employment, but you do have a right to object to us doing this. Our Data Protection Officer will be happy to speak with you about any concerns you have.
3) Right to Correction
If information about you is incorrect, you are entitled to request that we correct it. There may be occasions, where we are required by law to maintain the original information – our Data Protection Officer will talk to you about this and you may request that the information is not used during this time We will respond to your request within one month of receipt or will tell you when it might take longer.
4) Complaints
You also have the right to make complaints and request investigations into the way your information is used. Please contact our Data Protection Officer or visit the link below for more information.
Does GP Support Hub use profiling or automated decision making?
No GP Support Hub does not undertake automatic profiling or automated decision making in relation to your employment information.
Our Data Protection Officer will be happy to speak to you about this if you have concerns or objections.
How Does GP Support Hub Protect my information?
GP Support Hub are committed to ensuring the security and confidentiality of your information. There are a number of ways we do this;
- Staff receive regular training about protecting and using personal data.
- Policies are in place for staff to follow and are regularly reviewed.
- We check that only the minimum amount of data is shared or accessed.
- We use controlled access to systems, this helps ensure that the right people are accessing data – people with a ‘need to know’
- We use encrypted emails and storage which would make it difficult for someone to ‘intercept’ your information.
- We report and manage incidents to make sure we learn from them and improve.
- We put in place contracts that require providers and suppliers to protect your data as well.
How long does GP Support Hub store my information?
Suffolk GP Federation will retain / store your information for your 7 Years post- employment date as part of our obligations as an employer. W here items of your record can be removed at an earlier time, or be de-identified, this will happen to ensure that Suffolk GP Federation only hold information that is needed.