{"id":842,"date":"2018-10-11T14:55:39","date_gmt":"2018-10-11T13:55:39","guid":{"rendered":"http:\/\/www.lshdental.co.uk\/hillcroft\/?page_id=842"},"modified":"2018-10-11T14:55:39","modified_gmt":"2018-10-11T13:55:39","slug":"data-protection-and-information-security-policy","status":"publish","type":"page","link":"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/","title":{"rendered":"Data Protection and Information Security Policy"},"content":{"rendered":"<p>This practice is committed to complying with the Data Protection Act 2018, the General Data Protection Regulation (GDPR), GDC, NHS and other data protection requirements relating to our work. We only keep relevant information about employees for the purposes of employment and about patients to provide them with safe and appropriate health care.<\/p>\n<p>The person responsible for Data Protection is the Information Governance Lead Stephanie Magi.<\/p>\n<h2><em>Our lawful basis for processing personal data is:<\/em><\/h2>\n<ul>\n<li>Consent of the data subject<\/li>\n<li>Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract<\/li>\n<li>[Other]<\/li>\n<\/ul>\n<h2>Our lawful basis for processing special category data is:<\/h2>\n<ul>\n<li><em>Processing is necessary for the purposes of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional.<\/em><\/li>\n<\/ul>\n<h2><em>Consent<\/em><\/h2>\n<p>The practice offers individuals real choice and control. Our consent procedures put individuals in charge to build customer trust and engagement. Our consent for marketing requires a positive opt-in, we don\u2019t use pre-ticked boxes or any other method of default consent. We make it easy for people to withdraw consent, tell them how to and keep contemporaneous evidence of consent. Consent to marketing is never a precondition of a service.<\/p>\n<h2><em>Data protection officer (DPO)<\/em><\/h2>\n<p>NHS practice: Our DPO is the Information Governance Lead is Stephanie Magi<\/p>\n<p>Fully private practice: We do not have a Data Protection Officer as we do not process large volumes of data.<\/p>\n<p><em>Pseudonymisation<\/em><br \/>\nPseudonymisation means transforming personal data so that it cannot be attributed to an individual unless there is additional information.<\/p>\n<ul>\n<li>Pseudonymisation \u2013 the data can be tracked back to the original data subject<\/li>\n<li>Anonymisation \u2013 that data cannot be tracked back to the original data subject<\/li>\n<\/ul>\n<p>Examples of pseudonymisation we use are:<\/p>\n<ul>\n<li>We never identify patients in research, patient feedback reports or other publicly available information<\/li>\n<li>When we store and transmit electronic data it is encrypted and the encryption key is kept separate from the data<\/li>\n<\/ul>\n<h2><em>Data breaches<\/em><\/h2>\n<p>We report certain types of personal data breaches to the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach results in a high risk of adversely affecting individuals\u2019 rights and freedoms we also inform those individuals without undue delay. We keep contemporaneous records of any personal data breaches, whether or not we need to notify.<\/p>\n<h2><em>Right to be informed<\/em><\/h2>\n<p>We provide \u2018fair processing information\u2019, through our Privacy Notice, which provides transparency about how we use personal data.<\/p>\n<h2><em>Right of Access<\/em><\/h2>\n<p>Individuals have the right to access their personal data and supplementary information. The right of access allows individuals to be aware of and verify the lawfulness of the processing. If an individual contacts the practice to access their data they will be provided with, as requested:<\/p>\n<ul>\n<li>Confirmation that their data is being processed<\/li>\n<li>Access to their personal data<\/li>\n<li>Any other supplementary information or rights as found below and in our Privacy Notice<\/li>\n<\/ul>\n<h2><em>Right to erasure<\/em><\/h2>\n<p>The right to erasure is also known as \u2018the right to be forgotten\u2019. The practice will delete personal data on request of an individual where there is no compelling reason for its continued processing. The right to erasure applies to individuals who are not patients at the practice. If the individual is or has been a patient, the clinical records will be retained according to the retention periods in Record Retention.<\/p>\n<h2><em>Right of rectification<\/em><\/h2>\n<p>Individuals have the right to have personal data rectified if it is inaccurate or incomplete.<\/p>\n<h2><em>Right to restriction<\/em><\/h2>\n<p>Individuals have a right to \u2018block\u2019 or suppress the processing of their personal data. If requested we will store their personal data but stop processing it. We will retain just enough information about the individual to ensure that the restriction is respected in the future.<\/p>\n<h2><em>Right to object<\/em><\/h2>\n<p>Individuals have the right to object to direct marketing and processing for purposes of scientific research and statistics.<\/p>\n<h2><em>Data portability<\/em><\/h2>\n<p>An individual can request the practice to transfer their data in electronic or other format.<\/p>\n<p>We implement technical and organisational m<\/p>\n<h2><em>Privacy by design<\/em><\/h2>\n<p>easures to integrate data protection into our processing activities. Our data protection and information governance management systems and procedures take Privacy by design as their core attribute to promote privacy and data compliance.<\/p>\n<h2><em>Records<\/em><\/h2>\n<p>We keep records of processing activities for future reference.<\/p>\n<h2><em>Privacy impact assessment<\/em><\/h2>\n<p>To identify the most effective way to comply with their data protection obligations and meet individuals\u2019 expectations of privacy we review our Privacy Impact Assessment annually.<\/p>\n<h2><em>Information security<\/em><\/h2>\n<p>Information Governance Procedures includes the following information security procedures:<\/p>\n<ul>\n<li>Team members follow the \u2018Staff Confidentiality Code of Conduct\u2019, which clarifies their legal duty to maintain confidentiality, to protect personal information and provides guidance on how and when personal or special category data can be disclosed<\/li>\n<li>How to manage a data breach, including reporting<\/li>\n<li>A comprehensive set of procedures, risk assessments and activities to prevent the data we hold being accidentally or deliberately compromised and to respond to a breach in a timely manner<\/li>\n<li>The requirements and responsibilities if team members use personal equipment such as computer, laptop, tablet or mobile phone for practice business<\/li>\n<\/ul>\n<h2><em>Review<\/em><\/h2>\n<p>This policy and the data protection and information governance procedures it relates to are reviewed annually.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This practice is committed to complying with the Data Protection Act 2018, the General Data Protection Regulation (GDPR), GDC, NHS and other data protection requirements relating to our work. We only keep relevant information about employees for the purposes of employment and about patients to provide them with safe and appropriate health care. The person&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-842","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.3.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Data Protection and Information Security Policy - Dentist Woolton - Hillcroft Dental Practice<\/title>\n<meta name=\"description\" content=\"Data Protection and Information Security Policy at Hillcroft Dental Practice. Book your appointment with our friendly dentists in Woolton today!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data Protection and Information Security Policy - Dentist Woolton - Hillcroft Dental Practice\" \/>\n<meta property=\"og:description\" content=\"Data Protection and Information Security Policy at Hillcroft Dental Practice. Book your appointment with our friendly dentists in Woolton today!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"LSH | Hill Croft Dental Practice\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/\",\"url\":\"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/\",\"name\":\"Data Protection and Information Security Policy - Dentist Woolton - Hillcroft Dental Practice\",\"isPartOf\":{\"@id\":\"https:\/\/lshdental.co.uk\/hillcroft\/#website\"},\"datePublished\":\"2018-10-11T13:55:39+00:00\",\"description\":\"Data Protection and Information Security Policy at Hillcroft Dental Practice. Book your appointment with our friendly dentists in Woolton today!\",\"breadcrumb\":{\"@id\":\"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/lshdental.co.uk\/hillcroft\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data Protection and Information Security Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/lshdental.co.uk\/hillcroft\/#website\",\"url\":\"https:\/\/lshdental.co.uk\/hillcroft\/\",\"name\":\"LSH | Hill Croft Dental Practice\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/lshdental.co.uk\/hillcroft\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data Protection and Information Security Policy - Dentist Woolton - Hillcroft Dental Practice","description":"Data Protection and Information Security Policy at Hillcroft Dental Practice. Book your appointment with our friendly dentists in Woolton today!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/","og_locale":"en_GB","og_type":"article","og_title":"Data Protection and Information Security Policy - Dentist Woolton - Hillcroft Dental Practice","og_description":"Data Protection and Information Security Policy at Hillcroft Dental Practice. Book your appointment with our friendly dentists in Woolton today!","og_url":"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/","og_site_name":"LSH | Hill Croft Dental Practice","twitter_card":"summary_large_image","twitter_misc":{"Estimated reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/","url":"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/","name":"Data Protection and Information Security Policy - Dentist Woolton - Hillcroft Dental Practice","isPartOf":{"@id":"https:\/\/lshdental.co.uk\/hillcroft\/#website"},"datePublished":"2018-10-11T13:55:39+00:00","description":"Data Protection and Information Security Policy at Hillcroft Dental Practice. Book your appointment with our friendly dentists in Woolton today!","breadcrumb":{"@id":"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/lshdental.co.uk\/hillcroft\/data-protection-and-information-security-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lshdental.co.uk\/hillcroft\/"},{"@type":"ListItem","position":2,"name":"Data Protection and Information Security Policy"}]},{"@type":"WebSite","@id":"https:\/\/lshdental.co.uk\/hillcroft\/#website","url":"https:\/\/lshdental.co.uk\/hillcroft\/","name":"LSH | Hill Croft Dental Practice","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lshdental.co.uk\/hillcroft\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"}]}},"_links":{"self":[{"href":"https:\/\/lshdental.co.uk\/hillcroft\/wp-json\/wp\/v2\/pages\/842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lshdental.co.uk\/hillcroft\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/lshdental.co.uk\/hillcroft\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/lshdental.co.uk\/hillcroft\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lshdental.co.uk\/hillcroft\/wp-json\/wp\/v2\/comments?post=842"}],"version-history":[{"count":0,"href":"https:\/\/lshdental.co.uk\/hillcroft\/wp-json\/wp\/v2\/pages\/842\/revisions"}],"wp:attachment":[{"href":"https:\/\/lshdental.co.uk\/hillcroft\/wp-json\/wp\/v2\/media?parent=842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}