❋ Data Protection Policy

‍ ‍

UMGH DATA PROTECTION POLICY

1.    INTRODUCTION

United Medical Group Healthcare is committed to protecting the rights and privacy of individuals and ensuring high levels of transparency and accountability in how personal data is collected, used, stored and shared.

This policy sets out the organisation’s commitment to meeting its data protection obligations, and the rights and responsibilities of individuals and staff, in accordance with the UK General Data Protection Regulation (UK GDPR).

2.     SCOPE

This policy applies to the personal data of clients, service users, visitors and members of the public. It does not apply to personal data relating to employees, workers or other internal business‑related processing activities, which are covered by separate policies.

 This policy sets out the standards United Medical Group Healthcare expects employees to follow to ensure compliance with applicable data protection law. Compliance with this policy is mandatory. Any breach may result in disciplinary action.

 The organisation maintains a record of its processing activities in accordance with UK GDPR requirements.

 3.     ACCESSIBILITY

 If any aspect of this policy or procedure causes difficulty due to a disability, or if English is not your first language and you require assistance, you should contact your HR representative, who will arrange appropriate support or adjustments.

 4.     DEFINITIONS

 Personal data 

Any information relating to an identified or identifiable natural person (‘data subject’). An identifiable person is one who can be identified directly or indirectly, for example by name, identification number, location data, online identifier, or factors relating to physical, physiological, genetic, mental, economic, cultural or social identity.

 Processing 

Any operation performed on personal data, whether automated or manual, including collection, recording, organisation, storage, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure or destruction.

  Special category data 

Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health information, sex life or sexual orientation.

 Criminal records data 

Information relating to criminal convictions, offences, allegations or proceedings.

 Data subject 

An individual whose personal data is processed by the organisation.

 

5.    DATA PROTECTION PRINCIPLES

United Medical Group Healthcare processes personal data in accordance with the UK GDPR data protection principles. These principles require that personal data must be:

a. Processed lawfully, fairly and transparently

Personal data must be collected and used in a way that is lawful, fair and clear to the data subject. Individuals must be informed about how their data is used through appropriate privacy notices.

b. Collected for specified, explicit and legitimate purposes

Personal data must only be collected for defined purposes and must not be used in ways that are incompatible with those purposes.

c. Adequate, relevant and limited to what is necessary

Only the minimum amount of personal data required for the intended purpose should be collected and processed.

d. Accurate and kept up to date

Reasonable steps must be taken to ensure personal data is accurate and, where necessary, updated. Inaccurate data must be corrected or deleted without delay.

e. Kept for no longer than necessary

Personal data must be retained only for as long as needed for the purposes for which it was collected. Retention periods must be applied in accordance with organisational policy and legal requirements.

 

f. Processed securely

Personal data must be protected against unauthorised or unlawful processing, accidental loss, destruction or damage through appropriate technical and organisational measures.

United Medical Group Healthcare is responsible for demonstrating compliance with these principles and maintaining appropriate records, controls and governance arrangements.

6.     LAWFUL BASES FOR PROCESSING

United Medical Group Healthcare processes personal data only where a lawful basis under UK GDPR applies. The organisation identifies and records the lawful basis for each processing activity within its Record of Processing Activities (ROPA).

The lawful bases used by the organisation are:

a. Consent

Processing is based on the freely given, specific, informed and unambiguous consent of the data subject. Consent can be withdrawn at any time.

b. Contract

Processing is necessary for the performance of a contract with the data subject, or to take steps at the data subject’s request before entering into a contract.

c. Legal Obligation

Processing is necessary to comply with a legal obligation to which the organisation is subject (e.g., safeguarding duties, regulatory reporting).

d. Vital Interests

Processing is necessary to protect the vital interests of the data subject or another individual, such as in medical or safeguarding emergencies.

e. Public Task

Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

 

f. Legitimate Interests

Processing is necessary for the organisation’s legitimate interests or those of a third party, except where such interests are overridden by the rights and freedoms of the data subject. Legitimate interests assessments (LIAs) are completed where required.

Special Category Data

United Medical Group Healthcare processes special category data only where a lawful basis and a separate condition for processing under Article 9 UK GDPR apply. These may include:

·  explicit consent

·  vital interests

·  provision of health or social care

·  safeguarding of children or vulnerable adults

·  reasons of substantial public interest

Appropriate policy documents and safeguards are maintained where required.

Criminal Records Data

Criminal records data is processed only where authorised by law and where necessary for safeguarding, risk assessment or regulatory compliance. Additional safeguards apply to this category of data.

     7. INDIVIDUAL RIGHTS

Under UK GDPR, data subjects have specific rights in relation to their personal data. United Medical Group Healthcare is committed to upholding these rights and ensuring individuals can exercise them easily and without undue delay. Requests relating to these rights are managed in accordance with the organisation’s Data Subject Rights Procedure.

Data subjects have the following rights:

a. Right to be informed

Individuals have the right to clear and accessible information about how their personal data is collected, used, stored and shared. This is provided through privacy notices and other communications.

b. Right of access

Individuals have the right to request access to their personal data and receive a copy of the information held about them, along with an explanation of how it is processed.

 c. Right to rectification

Individuals have the right to request correction of inaccurate or incomplete personal data.

d. Right to erasure (‘right to be forgotten’)

Individuals may request the deletion of their personal data where there is no lawful basis for continued processing. This right does not apply where processing is required by law or necessary for safeguarding or clinical purposes.

e. Right to restrict processing

Individuals may request that the organisation restricts the processing of their personal data in certain circumstances, such as where accuracy is contested or processing is unlawful.

f. Right to data portability

Where processing is based on consent or contract and carried out by automated means, individuals have the right to receive their personal data in a structured, commonly used and machine‑readable format and to request that it is transferred to another controller.

g. Right to object

Individuals have the right to object to processing based on legitimate interests or public task. The organisation will consider the objection and cease processing unless there are compelling legitimate grounds or the processing is required for legal reasons.

h. Rights related to automated decision‑making and profiling

Individuals have the right not to be subject to decisions based solely on automated processing that have legal or significant effects. United Medical Group Healthcare does not carry out automated decision‑making or profiling in relation to service users.

Responding to Rights Requests

United Medical Group Healthcare will:

·     respond to rights requests within one month

·     verify the identity of the requester where necessary

·     assess whether the request can be fulfilled under UK GDPR

·     provide clear communication regarding outcomes

·     document all requests and responses

Where a request cannot be fulfilled due to legal or safeguarding obligations, the organisation will explain the reasons to the data subject.

  

Complaints

Individuals who are dissatisfied with how their personal data has been handled may raise a complaint with the organisation. They also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

8. DATA SHARING

United Medical Group Healthcare shares personal data only where it is lawful, necessary and proportionate to do so. The organisation ensures that any sharing of personal data complies with UK GDPR, safeguarding requirements and relevant professional standards.

Personal data may be shared with third parties in the following circumstances:

a. Where the data subject has given consent

Personal data may be shared when the individual has provided clear, informed consent for a specific purpose. Consent can be withdrawn at any time.

b. Where sharing is necessary for the performance of a contract

Information may be shared with third parties where required to deliver services requested by the data subject.

c. Where required to comply with a legal obligation

Personal data may be shared with regulatory bodies, safeguarding authorities, law enforcement or other statutory agencies where required by law.

d. Where necessary to protect vital interests

Information may be shared to protect the life or safety of the data subject or another individual, including in safeguarding or medical emergencies.

e. Where necessary for the provision of health or social care

Personal data may be shared with healthcare professionals, referrers or other agencies involved in the care of the data subject.

f. Where necessary for legitimate interests

Personal data may be shared where the organisation has a legitimate interest that is not overridden by the rights and freedoms of the data subject. Legitimate interests assessments (LIAs) are completed where required.

  

Data Sharing Agreements

Where United Medical Group Healthcare shares personal data with external organisations on a regular or ongoing basis, appropriate data sharing agreements or contracts are established. These agreements set out:

·     the purpose of sharing

·     responsibilities of each party

·     security requirements

·     retention and disposal arrangements

·     procedures for managing breaches

The organisation ensures that third parties receiving personal data provide adequate safeguards and comply with UK GDPR.

Sharing Data with Processors

Where personal data is shared with data processors, the organisation ensures:

·     a written contract is in place

·     processors act only on documented instructions

·     appropriate technical and organisational measures are maintained

·     data is not transferred outside the UK without appropriate safeguards

International Transfers

United Medical Group Healthcare does not routinely transfer personal data outside the UK. Where international transfers are necessary, the organisation ensures that:

·     an adequacy decision is in place, or

·     appropriate safeguards (such as Standard Contractual Clauses) are implemented

Data subjects will be informed where international transfers occur.

Safeguarding and Public Protection

Personal data may be shared without consent where necessary to safeguard children, young people or vulnerable adults, or to prevent serious harm. Such decisions are made in accordance with the organisation’s safeguarding policies and documented clearly.

 

 

 

 

 

 

          9. DATA RETENTION AND DISPOSAL

United Medical Group Healthcare retains personal data only for as long as necessary to fulfil the purposes for which it was collected, to meet legal or regulatory requirements, or to defend potential legal claims. Retention periods are defined within the organisation’s Data Retention Schedule and applied consistently across all processing activities.

a. Retention of Personal Data

Personal data is retained in accordance with:

·     statutory requirements

·     professional guidelines

·     safeguarding obligations

·     contractual commitments

·     organisational needs

Retention periods vary depending on the type of data and the purpose of processing. The organisation maintains a clear schedule specifying how long each category of data is kept.

b. Secure Storage During Retention

Throughout the retention period, personal data is stored securely using appropriate technical and organisational measures to prevent unauthorised access, loss, or damage.

c. Disposal of Personal Data

When personal data is no longer required, it is disposed of securely. Disposal methods include:

·         secure deletion from electronic systems

·         secure destruction of physical records

·         removal from backup systems in line with technical capability

Disposal processes ensure that personal data cannot be reconstructed or retrieved.

d. Archiving

Where data must be retained for extended periods for legal, safeguarding or clinical reasons, it may be archived. Archived data is:

·     stored securely

·     accessed only when necessary

·     subject to restricted permissions

 

 

e. Documentation and Accountability

The organisation maintains records of retention and disposal activities to demonstrate compliance with UK GDPR. Staff must follow the Data Retention Schedule and seek guidance from the Data Protection Officer where uncertainty exists.

10. DATA BREACH MANAGEMENT

United Medical Group Healthcare takes all personal data breaches seriously. A personal data breach is any incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This includes breaches that occur through human error, system failure, malicious activity or inadequate security controls.

The organisation has a Data Breach Procedure that must be followed in all cases.

a. Identifying a Breach

A breach may include:

·             loss or theft of personal data

·             unauthorised access to systems or records

·             sending personal data to the wrong recipient

·             accidental deletion or alteration of records

·             failure of technical or organisational security measures

·             cyber‑attacks, malware or phishing incidents

All staff must be vigilant and report any suspected breach immediately.

b. Reporting a Breach

Any staff member who becomes aware of a potential or actual breach must report it without delay to the Data Protection Officer (DPO) or Governance Lead. Early reporting is essential to minimise harm and meet legal obligations.

Reports must include:

·             a description of the incident

·             the type of data involved

·             the number of individuals affected

·             any immediate actions taken

c. Assessing a Breach

The DPO will assess:

·             the nature and sensitivity of the data

·             the potential impact on individuals

·             whether the breach is likely to result in a risk to rights and freedoms

·             whether notification to the ICO is required

·             whether affected individuals need to be informed

This assessment is documented and retained as part of the organisation’s accountability obligations.

d. Notification to the ICO

Where a breach is likely to result in a risk to the rights and freedoms of individuals, the organisation will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, in accordance with UK GDPR.

The notification will include:

·             the nature of the breach

·             categories and approximate number of individuals affected

·             likely consequences

·             measures taken or proposed to address the breach

e. Notification to Individuals

Where a breach is likely to result in a high risk to individuals, the organisation will inform affected individuals without undue delay. Communications will be clear, direct and include:

·             a description of the breach

·             likely consequences

·             steps individuals can take to protect themselves

·             actions the organisation has taken

·             contact details for further support

f. Containment and Recovery

The organisation will take immediate steps to:

·             contain the breach

·             recover lost data where possible

·             secure systems

·             prevent further unauthorised access

·             implement corrective actions

Technical and organisational measures will be reviewed and strengthened where necessary.

g. Learning and Review

All breaches, regardless of severity, are reviewed to identify:

·             root causes

·             lessons learned

·             improvements to policies, procedures or systems

·             training needs

The organisation maintains a breach log as part of its accountability obligations.

 

 

Roles and Responsibilities

United Medical Group Healthcare ensures that responsibilities for data protection are clearly defined and understood across the organisation. All staff have a role in protecting personal data, and specific responsibilities are assigned to key roles to ensure compliance with UK GDPR.

a. Board of Directors

The Board has overall accountability for ensuring that United Medical Group Healthcare complies with data protection legislation. The Board:

·     approves data protection policies

·     ensures appropriate resources are allocated

·     oversees organisational governance arrangements

·     receives assurance reports on compliance and breaches

b. Data Protection Officer (DPO)

The Data Protection Officer is responsible for overseeing data protection compliance across the organisation. The DPO:

·     advises on data protection obligations

·     monitors compliance with UK GDPR

·     oversees data protection policies and procedures

·     manages data subject rights requests

·     provides guidance on DPIAs

·     investigates and reports personal data breaches

·     acts as the contact point for the ICO

The DPO must operate independently and report directly to senior management.

c. Governance Lead

The Governance Lead supports the DPO and ensures that data protection requirements are embedded within organisational policies, procedures and quality assurance processes. Responsibilities include:

 

 

 

·     maintaining the Record of Processing Activities (ROPA)

·     coordinating audits and compliance checks

·     supporting breach investigations

·     ensuring staff training is up to date

d. Senior Management

Senior managers are responsible for ensuring that data protection requirements are implemented within their teams. They must:

·     ensure staff follow policies and procedures

·     identify and manage data protection risks

·     support staff in responding to rights requests

·     escalate concerns to the DPO promptly

e. All Employees

All employees have a duty to protect personal data. Staff must:

·     comply with this policy and related procedures

·     complete mandatory data protection training

·     report suspected breaches immediately

·     follow secure handling, storage and disposal practices

·     ensure personal data is processed lawfully and appropriately

Failure to comply with data protection requirements may result in disciplinary action.

f. Contractors and Third Parties

Contractors and third‑party providers who process personal data on behalf of United Medical Group Healthcare must:

·     comply with contractual data protection requirements

·     implement appropriate security measures

·     report breaches without delay

·     process data only on documented instructions

The organisation ensures that appropriate contracts and safeguards are in place.

 

 

 

 

 

11. TRAINING AND AWARENESS

United Medical Group Healthcare ensures that all staff understand their responsibilities under UK GDPR and are equipped to handle personal data securely and lawfully. Data protection training is mandatory for all employees and forms part of the organisation’s wider governance and compliance framework.

a. Mandatory Training

All employees must complete data protection training as part of their induction. This training covers:

·     the principles of UK GDPR

·     lawful bases for processing

·     individual rights

·     secure handling of personal data

·     recognising and reporting data breaches

·     organisational policies and procedures

Completion of induction training is recorded and monitored.

b. Refresher Training

Staff must complete refresher training at least annually. Refresher training ensures that employees:

·     remain up to date with legal requirements

·     understand changes to organisational policies

·     are aware of emerging risks and best practice

·     maintain high standards of data protection compliance

Attendance is monitored and non‑completion is escalated to line managers.

c. Role‑Specific Training

Additional training is provided to staff whose roles involve:

·     handling large volumes of personal data

·     processing special category or criminal records data

·     managing data subject rights requests

·     investigating data breaches

·     conducting DPIAs

·     overseeing governance or compliance

This ensures that staff with enhanced responsibilities have the knowledge and skills required to fulfil their duties.

 d. Awareness and Communication

United Medical Group Healthcare promotes ongoing awareness of data protection through:

·     policy updates

·     internal communications

·     reminders about secure practices

·     lessons learned from incidents

·     guidance issued by the DPO

Staff are encouraged to seek advice from the DPO or Governance Lead whenever they are unsure about data protection requirements.

e. Accountability

Training records are maintained as part of the organisation’s accountability obligations. Managers are responsible for ensuring that their teams complete required training and follow data protection procedures.

12. POLICY REVIEW AND MONITORING

United Medical Group Healthcare is committed to maintaining high standards of data protection and ensuring that this policy remains accurate, effective and aligned with legal and regulatory requirements. The organisation monitors compliance with this policy and reviews it regularly.

a. Policy Review

This policy is reviewed at least annually, or sooner if:

·      there are changes to UK GDPR or other relevant legislation

·      new guidance is issued by the ICO or other regulatory bodies

·      organisational processes or systems change

·      audits or incidents identify areas for improvement

The Data Protection Officer is responsible for coordinating the review process and ensuring that updates are approved by the Board of Directors.

b. Monitoring Compliance

Compliance with this policy is monitored through:

·      internal audits

·      review of data protection practices

·      monitoring of training completion

 ·      breach investigations and lessons learned

·      oversight of data subject rights requests

·      checks on data sharing arrangements and contracts

Findings are reported to senior management and the Board as part of the organisation’s governance framework.

c. Continuous Improvement

United Medical Group Healthcare is committed to continuous improvement in data protection. The organisation:

·     updates procedures and controls where necessary

·     strengthens technical and organisational measures

·     incorporates learning from incidents and audits

·     ensures staff receive updated guidance and training

This approach supports a culture of accountability and responsible data handling.

d. Non‑Compliance

Failure to comply with this policy may result in disciplinary action. Serious breaches may also lead to regulatory investigation or legal consequences. Staff must report concerns or potential non‑compliance to the Data Protection Officer or Governance Lead.

Distribution

This policy is distributed to:

·     All employees

·     Senior management

·     Governance and compliance teams

·     Contractors and third parties where relevant

Staff are notified of updates through internal communication channels and must ensure they are familiar with the current version.

Associated Documents

This policy should be read alongside:

·  Privacy Notice; Data Breach Procedure

·  Data Subject Rights Procedure

·  Data Retention Schedule

·  Information Security Policy

·  Safeguarding Policies; Record of Processing Activities (ROPA); DPIA Procedure


 

 

 

 

 

‍ ‍
‍ ‍

‍ ‍