Privacy and Fair Processing Notice

This section contains important details regarding how Wibsey and Queensbury Medical Practice manages patient data, the OpenSAFELY COVID-19 research platform, and the various security measures in place to protect your personal and health information. Here's a breakdown:


OpenSAFELY COVID-19 Service

    • Purpose: NHS England has set up OpenSAFELY for COVID-19-related research, clinical audits, health surveillance, and other related purposes.

    • Data Use: Patient data is pseudonymised (personal identifiers are replaced with pseudonyms) to protect individual privacy. Only approved users can access this data for analysis.

    • Opting Out: Patients who do not wish for their data to be used in this research can opt out by registering a Type 1 opt-out with their GP.


Security of Patient Information

    • Confidentiality and Security: The Practice is committed to protecting your personal and sensitive data. This includes medical records, contact details, and other personal information.

        • Caldicott Guardian: Ensures patient confidentiality is maintained in the handling of sensitive data.

          Designated Roles:


      Senior Information Risk Owner (SIRO): Ensures proper management of information assets.




Legal Basis for Data Processing (GDPR)

    • GDPR Compliance: Under the General Data Protection Regulation (GDPR), the Practice processes sensitive personal data (health records) and personal data for healthcare and public health purposes. This may include medical diagnoses, treatment plans, and management of health systems.

    • Legal Basis: The legal basis for processing includes public interest, vital interests (when necessary to protect someone's life), and healthcare provision.


Why Your Information Is Collected

The practice collects and stores your data to:

    • Ensure that healthcare professionals have the most accurate, up-to-date information for treatment decisions.

    • Provide you with high-quality care.

    • Improve healthcare services and carry out audits and research, where applicable.

This includes details like:

    • Name, address, NHS number, date of birth, and next of kin

    • Health conditions, diagnoses, treatments, allergies, and test results

    • Healthcare provider interactions (appointments, referrals, hospital admissions, etc.)


How Your Information Is Used

Your information is used to:

    • Ensure your healthcare professionals can assess your needs and provide effective care.

    • Maintain a shared Care Record for effective care across the healthcare system.

    • Ensure proper care quality and investigate complaints if needed.




Retention of Health Records

    • Record Retention: Health records are retained in line with the NHS Records Management Code of Practice. Once the retention period expires, records are destroyed confidentially.




When Your Information Is Shared

        • Social care services (with your permission)

          Direct Care Purposes: Information is shared with those involved in your care, including:



            • Other NHS practices and hospitals


            • Ambulance services

    • Indirect Care Purposes: Information may also be used for:


        • Service quality reviews


        • Payment for care services


        • Health research (with your consent)


        • Training of healthcare professionals


Sharing Without Consent

In exceptional circumstances, information may be shared without your consent, such as:

    • If you or others are at risk of serious harm.

    • If required by law (e.g., court orders, public health concerns, child protection).


Other Important Information

    • Call Recording: Calls to the practice may be recorded for quality control, training, and legal reasons.

    • SMS Text Messaging: The Practice may contact you via SMS for appointment reminders and healthcare updates. You can opt-out if you prefer.

    • CCTV: The Practice uses CCTV for security purposes, such as protecting staff and property. You can request to view CCTV footage that involves you.




Your Rights (GDPR)

Under GDPR, you have the following rights:

    • Access: Right to view the information held about you.

    • Correction: Right to rectify inaccurate data.

    • Erasure: Right to request deletion of data (except health records for public health).

    • Objection: Right to restrict or object to certain uses of your data.

    • Data Portability: Right to receive your data in a structured, commonly used format.




How to Access Your Records

If you would like to access your health records:

    1. Request in writing to the Access to Health Records Department.

    1. Provide sufficient information (e.g., name, date of birth, NHS number) to verify your identity.

    1. Requests are generally free of charge, though excessive or repeated requests may incur a reasonable fee.


Data Controller and Contact Information

    • The Data Controller for your information is Wibsey and Queensbury Medical Practice.




Raising Concerns

If you have concerns about how your data is being handled, you can:

    • Contact PALS (Patient Advice and Liaison Service).

    • Make a complaint to the Information Commissioner’s Office (ICO): www.ico.gov.uk.



Call 111 when you need medical help fast but it’s not a 999 emergencyNHS ChoicesThis site is brought to you by My Surgery Website