Privacy Notice – Employees

As employers we need to keep certain information so that we can remain your employer and manage payments. This is a combination of personal and financial information. We are required by law to hold certain types of data on those we employ under the Health and Social Care Act and this data is examined during CQC inspection visits. For more information about the CQC see: http://www.cqc.org.uk/

The type of information we keep incorporates, but is not limited to:

  • Personal details, including Name, address, contact details
  • Recruitment and employment checks
  • Financial (bank and salary)
  • Trade union membership
  • Personal Demographics
  • Relevant medical information
  • Professional registration
  • Employee relations (disciplinary, grievances, complaints, etc)
  • Criminal Record Checks (dependent on employee position)

We are also required by HMRC and various taxation laws, such as “The Income Tax (Pay As You Earn) Regulations 2003” to keep financial records.

1) Data Controller contact details

Frome Medical Practice
Frome Medical Centre
Enos Way
Frome
Somerset
BA11 2FH

Telephone: 01373 301301

2) Data Protection Officer contact details

Kevin Caldwell
GP Data Protection Officer
Somerset CCG
Wynford House
Lufton Way
Yeovil
Somerset
BA22 8HR

Telephone: 01935 384000

Email: somccg.GPDPO@nhs.net

3) Purpose of the  processing

To comply with the Health and Social Care Act and taxation law.

4) Lawful basis for  processing

The legal basis will be

Article 6(1)(c) “processing is necessary for compliance with a legal obligation to which the controller is subject.”

Article 6(b) Contract

and…

Article 9(2)(h) “processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3;”

5) Recipient or categories of recipients of the processed data

The data will be shared with the Care Quality Commission, its officers and staff and members of the inspection teams that visit us from time to time. Financial data will also be shared with HMRC.

6) Rights to object

You have the right to object to some or all of the information being shared with CQC. If you wish to do so please contact the practice.

7) Right to access and correct

You have the right to access the data that is being shared and have any inaccuracies corrected. There is no right to have records deleted except when ordered by a court of Law. There is no right to have UK taxation related data deleted except after certain statutory periods.

8) Retention period

The data will be retained for active use during the processing and thereafter according to NHS Policies, taxation and employment law.

9) Right to complain

You have the right to complain to the Information Commissioner’s Office, you can use this link https://ico.org.uk/global/contact-us/ or calling their helpline 0303 123 1113 (local rate) or 01625 545 745 (national rate).