Clarity Healthcare Ltd is an Occupational Health (OH) provider which has been requested by your employer to process data relating to yourself, the data subject, for Occupational Health purposes. The term “process” or “processing” covers how the data is obtained and stored and includes collection, recording, storage, disclosure by transmission, erasure and destruction.
Clarity Healthcare Ltd will be what’s known as a ‘controller in common’ of the personal data you provide to us, along with your employer, and is committed to protecting the rights of data subjects in line with the new General Data Protection Regulations (GDPR), otherwise known as the Data Protection Act 2018.
Lawful basis for processing
In accordance with GDPR Article 6(1), Clarity Healthcare’s lawful basis for processing is for occupational health purposes. The aim of occupational health is to prevent work-related illness and injury by encouraging safe working practices.
Under Article 9(2)H of GDPR (special category data), processing of occupational health records is necessary for the purpose of preventative or occupational medicine, for the assessment of working capacity of the employee, medical diagnosis, the provision of health and social care or treatment, or the management of health and social care systems.
As a result, the occupational health records obtained by Clarity Healthcare Ltd are processed under “legal obligation”: a declaration is required to be signed by the data subject which does not fall under consent, meaning consent cannot be withdrawn and the records will be retained for a specific period. Details of this can be found under the section “how long we keep your data”.
All data held under “consent” will be retained for a specific period unless the data subject chooses to withdraw consent and exercises their right to be forgotten. If any such request arises, the individual should contact the Clarity Healthcare Ltd Data Protection Officer.
The categories of information that we collect, hold and share include:
- Personal Information e.g. Name, Address, Date of Birth, NI number, Job Role
- Personal Characteristics e.g. Gender
- Special category data e.g records relating to occupational health, biometric data, wellbeing data, sickness absence records
Why we need your data
We need to know your personal and special category data in accordance with the relevant occupational health legislation to prevent work-related illness and injury by encouraging safe working practices, in line with this overall contract.
What we do with your data
All data obtained is held on our secure system to jointly (along with your employer) manage any reasonable adjustments or recommendations for all data subjects within the workplace. This data is also used for recall purposes, to enable all data subject’s to be reviewed in a timeframe agreed with their employer to ensure no occupational health related issues have arisen since the last medical was completed.
All the personal data we process is maintained by our employed staff in the UK however there may be some occasions where a third-party supplier is used, in the instances of counselling, physicians, physiotherapy, noise and dust assessments, ergonomic assessments and infrequent sickness absence consultations. In any instance where a third-party supplier is used, we will obtain written authorisation from yourself prior to releasing your records.
We have a Data Protection Policy in place to oversee the effective and secure processing of your personal and special category data. More information on this can be made available by our Data Protection Officer on request.
How long we keep your data
Sometimes there are legal reasons to retain the information we have obtained for the duration of your employment or longer. In other cases, this is not necessary. If there is no longer a reason to keep your information, it will be destroyed.
Any medicals required under specific legislation, such as COSHH, may mean your records are stored for 40-50 years. Further guidance on this can be found on the HSE website.
We depend on your employer to inform us of a change in your employment status and what hazards you may be exposed to in work.
What we would also like to do with your data
In addition to maintaining occupational health records and using this to determine your suitability for a job role, there will be some occasions where your personal and special category data is used to create trend reports which are then used to report future occupational health client requirements or for research and analysis purposes. In these instances, all personal and special category data will be pseudonymised.
What are your rights?
You have a statutory right of access to your occupational health records, or to authorise a third party (such as a legal advisor) to exercise that right on your behalf. The request should be made in writing clearly outlining which records you wish to see.
We will ensure any requested information is provided to you without delay and at the latest within one calendar month of receipt. If the request is complex, we may extend this timeframe by a further two calendar months and will endeavor to inform you of this and why the extension is necessary.
All subject access requests or requests for information will be processed free of charge, unless the request is manifestly unfounded, excessive and/or repetitive. In these instances, an admin fee will be applicable.
You can request an amendment is attached to your occupational health records if you believe any of the information is inaccurate or misleading. You do not have a “right to erasure” if the information is necessary for the purposes of preventative or occupational medicine e.g. where the processing is necessary for the working capacity of an employee, for medical diagnosis, or for the provision of or management of health or social care.
If you wish to raise a complaint on how we have handled your personal data, you can contact us to have the matter investigated. Our Data Protection Officer details are below:
|Address:||Clarity Healthcare Ltd, The Key Group, 15-16 The Embankment, River View, Heaton Mersey, Stockport, SK4 3GN|
|Landline Telephone Number:||0161 443 0068|
|Mobile Telephone Number:||07891 583 565|
If you are not satisfied with our response or believe we are not processing your personal data in accordance with the law you can complain to the Information Commissioner’s Office https://ico.org.uk/