Context and overview
Key details
- Policy prepared by: Dr Lesley Taylor and Mrs Sarah Brady
- Policy became operational on: 24th May 2018 and has been subject to annual review
- Next review date: 25th July 2027 or before if any legislation is changed in the interim.
Introduction
Clinicians working with Spectrum North West need to gather and use certain information about individuals.
These can include customers and other people the organisation has a relationship with or may need to contact.
This policy describes how personal data must be collected, handled, shared and stored to meet Spectrum North West’s data protection standards and to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Personal data includes any information that allows an individual to be identified. It applies to information held electronically, manually, on paper or in any other format. Sensitive and special category data includes information provided for assessment or during therapeutic interventions, including health and diagnostic information where relevant.
Why this policy exists
This data protection policy ensures that any clinician working under the umbrella of Spectrum North West:
- Complies with data protection law and follows good practice
- Protects the rights of anyone working with us, customers and partners
- Is open about how it stores and processes individuals’ data
- Protects itself from the risks of a data breach
Data protection law
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 set out how organisations must collect, process, store and protect personal information.
These requirements apply regardless of whether information is held electronically, on paper or in any other format.
To comply with the law, personal information must be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; kept accurate and secure; retained only for as long as necessary; and processed in a manner that ensures appropriate confidentiality, integrity and accountability.
Under the UK GDPR, personal data must:
- Be processed lawfully, fairly and transparently.
- Be collected for specified, explicit and legitimate purposes.
- Be adequate, relevant and limited to what is necessary.
- Be accurate and kept up to date.
- Be retained only for as long as necessary.
- Be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
- Be processed in a way that enables accountability and demonstrates compliance with these principles.
People, risks and responsibilities
Policy scope
This policy applies to:
- All clinicians working under the umbrella of Spectrum North West
- Other people working on behalf of or alongside Spectrum North West
It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the Data Protection Act 1998. This can include:
- Names of individuals
- Postal addresses
- Email addresses
- Telephone numbers
- Transaction data- i.e. payments
- Any other information relating to individuals, including referral information or previous reports
We may receive some of this information via our contact form on the website or via email or telephone at a later date, when a client requests services or enquires about the services we offer. If a client provides us with contact information and does not go on to access services, their contact details are deleted.
We only use clients’ data to ensure the care clients receive in our assessments and interventions is appropriate, to identify each client and to maintain contact with clients.
As part of undertaking assessments and interventions, clinicians may collect and process special category data, including health and diagnostic information where this is necessary for the provision of clinical services. Such information is processed lawfully under the UK GDPR and Data Protection Act 2018 and is subject to enhanced safeguards.
Data Controller Details
For the purposes of processing clients’ personal data, our individual clinicians act as ‘Data Controllers.’
We are Spectrum North West, First Floor, 99c Knutsford Road, Grappenhall, Warrington, WA4 2NS.
Our generic email address is ad***@***************st.org
Data protection risks
This policy helps to protect clinicians working under the umbrella of Spectrum North West from some very real data security risks, including:
- Breaches of confidentiality. For instance, information being given out inappropriately.
- Failing to offer choice. For instance, all individuals should be free to choose how the company uses data relating to them.
- Reputational damage. For instance, the company could suffer if hackers successfully gained access to sensitive data.
Responsibilities
Every clinician who works with Spectrum North West has some responsibility for ensuring data is collected, stored and handled appropriately.
Everyone who handles personal data must ensure that it is handled and processed in line with this policy and data protection principles.
Data should only be collected for the purposes of carrying out any assessment or intervention.
All clinicians are responsible for ensuring they meet their legal obligations under the UK GDPR and Data Protection Act 2018, including maintaining any required registration with the Information Commissioner’s Office (ICO).
Each clinician works independently under the umbrella of Spectrum North West and will deal individually with any requests from individuals to see the data that clinician holds about them (also called ‘subject access requests’). A subject access referral can be requested to the individual clinician via our office address (above) or via our generic email.
No other companies handle data belonging to us unless permission is expressly given by clients, for example where clients ask us to liaise directly with other agencies, such as schools, colleges, companies, the NHS, local authorities, solicitors and other organisations. If a client asks us to do so, they are giving permission for us to share information with such organisations.
Reports and clinical documents should normally be shared via secure, access-controlled Microsoft 365 links, such as OneDrive or SharePoint. Access should be restricted to authorised recipients only. Where documents are sent as attachments, they must be encrypted and password protected. Passwords must never be shared in the same communication as the document and should be sent separately.
For referrals from organisations who are already data controllers for that client’s personal and sensitive data, we assume that organisation will hold the copy of the client’s report once complete. This would include referrals from the NHS/ICBs. We will delete all data following the assessment and will not deal with any subsequent Subject Access Requests for that client under the UK GDPR and Data Protection Act 2018.
Spectrum North West does not have a database of information. All information is stored by each clinician, either electronically or in paper format in a locked filing cabinet. Any reports or information stored on computers is kept securely and password protected. Any computers are protected by security hardware and software.
Spectrum North West uses Mango 13 Ltd and STOMM Ltd to advise us on our email system, provide technical support and to support with management of the Spectrum North West website. Neither of these companies has access to our emails or cloud documents on a routine basis. All our emails are encrypted via Office 365 and we also use OneDrive built into the Office 365 service to securely store our documents.
General guidelines for clinicians
- The only people able to access data covered by this policy should be those who need it for their clinical or administrative roles.
- Data should not be shared informally between administrators, clinicians or practitioners.
- A copy of this policy is provided to all clinicians working under the umbrella of Spectrum North West. It is the individual responsibility of each clinician to ensure they understand their responsibilities when handling personal data.
- Clinicians and administrators should keep all data secure by taking sensible precautions and following the guidance set out in this policy.
- Strong passwords must be used and should never be shared. Passwords used to protect reports or clinical documents must be communicated separately from those documents.
- Reports and clinical records should be shared via secure, access-controlled Microsoft 365 links wherever possible. Where documents are sent as attachments, they must be encrypted and password protected before sharing.
- Personal data should not be disclosed to unauthorised individuals or organisations.
- Spectrum North West does not sell clients’ personal data to third parties.Data should be regularly reviewed and updated where necessary. Information that is no longer required should be securely deleted or destroyed in accordance with the retention periods set out in this policy.
Data storage
These rules describe how and where data should be safely stored.
When data is stored on paper, it should be kept in a secure place where unauthorised people cannot see it.
These guidelines also apply to data that is usually stored electronically but has been printed out for some reason:
- When not required, the paper or files should be kept in a locked drawer or filing cabinet.
- Clinicians should make sure paper and printouts are not left where unauthorised people could see them, for example on a printer.
- Data printouts should be shredded and disposed of securely when no longer required.
When data is stored electronically, it must be protected from unauthorised access, accidental deletion and malicious hacking attempts:
- Data should be protected by strong passwords that are changed as the system requires.
- If data is stored on removable media (such as a USB/DVD), these should be kept locked away securely when not being used.
- Data should only be stored on secure drives and any videos/audio recording shared by clients should be shared securely.
- Data should be backed up frequently.
- All servers and computers containing data should be protected by approved security software and a firewall.
Data is stored for the duration of the assessment and for a number of years afterwards. In respect of adults, we keep data for 7 years. In respect of children, we keep data for 7 years or until the child reaches the age of 25, whichever comes first.
It is important to note that clinicians may differ in exactly which data they wish to keep – some clinicians may store ALL raw data (handwritten notes, score forms etc) whereas other clinicians may feel that the contents of the raw data is captured sufficiently in their report and that they do not feel they need to keep hand-written notes. Clinicians have an individual responsibility to work within ICO guidelines, and to this extent we do not monitor which data they choose to store – although we do keep a central copy of their finished reports, which is stored securely for the durations outlined above.
Once we have no lawful use for clients’ data we will dispose of it in a secure manner that maintains data security.
It is the client’s responsibility to ensure that information provided to clinicians at Spectrum North West is accurate. We work on the basis that information is accurate and truthful and that no other information is being withheld.
Data use
Personal data is of no value to clinicians at Spectrum North West unless they can make use of it as part of their work. However, it is when personal data is accessed and used that it can be at the greatest risk of loss, corruption or theft:
- When working with personal data, clinicians should ensure the screens of their computers are always locked when left unattended.
- Personal data should not be shared informally. Personal data should be shared only through secure approved systems. Reports and clinical documents should normally be shared through secure Microsoft 365 links with restricted recipient access. Where email attachments are used, documents must be encrypted and password protected, with passwords communicated separately.
- Personal data should not be transferred internationally unless appropriate safeguards are in place and there is a lawful basis for the transfer, in accordance with UK GDPR requirements.
- Employees should not save copies of personal data to their own computers. Always access and update the central copy of any data.
Data accuracy
The law requires clinicians working under the umbrella of Spectrum North West to take reasonable steps to ensure data is kept accurate and up to date.
The more important it is that the personal data is accurate, the greater the effort clinicians should put into ensuring its accuracy.
It is the responsibility of all clinicians who work with data to take reasonable steps to ensure it is kept as accurate and up to date as possible.
- Data will be held in as few places as necessary. Clinicians should not create any unnecessary additional data sets.
- Clinicians should take every opportunity to ensure data is updated. For instance, by confirming a client’s details when they contact us or undertake any direct work with them.
- Clinicians are responsible for updating information and will make it easy for data subjects to update the information they hold about them. For instance, by informing the individual clinician who is working with them, either in person or via our address (above).
- Data should be updated as inaccuracies are discovered. For instance, if a client can no longer be reached on their stored telephone number.
Subject access requests
All individuals who are the subject of personal data held by clinicians working under the umbrella of Spectrum North West are entitled to:
- Ask what information the clinician holds about them and why.
- Ask how to gain access to it.
- Be informed how to keep it up to date.
- Be informed how they are meeting data protection obligations.
If an individual contacts clinicians requesting this information, this is called a subject access request.
Subject access requests from individuals should be made by email or by post, addressed to the individual clinician who is dealing with their case via our address, or in person.
Subject Access Requests will normally be provided free of charge. A reasonable administrative fee may be charged where a request is manifestly unfounded or excessive, or where additional copies of information are requested, in accordance with the UK GDPR and Data Protection Act 2018.
Clinicians working under the umbrella of Spectrum North West will aim to provide the relevant information without undue delay and within one calendar month of receiving a valid request and verifying the identity and consent of the requester. Where a request is complex or multiple requests have been received from the same individual, this period may be extended where permitted by law.
Disclosing data for other reasons
In certain circumstances, the UK GDPR and Data Protection Act 2018 permit personal data to be disclosed to law enforcement agencies or other statutory bodies without the consent of the data subject where there is a lawful basis for doing so.
Under these circumstances, clinicians working under the umbrella of Spectrum North West will disclose requested data. However, the individual clinician will ensure the request is legitimate, seeking assistance from other clinicians involved and taking legal advice where necessary.
Providing information
Clinicians working under the umbrella of Spectrum North West aim to ensure that individuals are aware that their data is being processed, and that they understand:
- How the data is being used
- How to exercise their rights
To these ends, we have a privacy statement, setting out how data relating to individuals is used by the clinicians working with us.
Privacy Statement
The personal data we collect will be used for the following purposes:
To undertake any assessments or interventions under the umbrella of Spectrum North West.
The personal data we collect includes name, date of birth, address and only information relevant to the specific assessment or intervention we have agreed to undertake. This may include special category data, such as health and diagnostic information, information from previous assessments and information given during any direct work with the client and their family, where consent is given or another lawful basis applies.
The information will be collected and held securely according to the terms of the policy set out above.
By asking us to undertake any work with you or your child, you are consenting and giving us permission to hold your data for the purposes specified above, where consent is the relevant lawful basis. Where another lawful basis applies, we will process information in accordance with UK GDPR and the Data Protection Act 2018.
Clinicians working under the umbrella of Spectrum North West will not pass on your data to third parties unless specifically asked to by the client for purposes of sharing the assessment or intervention undertaken with the client, or unless there is another lawful basis for sharing the information.
Reports and clinical documents will normally be shared via secure, access-controlled Microsoft 365 links. Where documents are sent as attachments, they will be encrypted and password protected, with passwords sent separately.
You have a right to access data we hold about you. You may make a subject access request according to the policy as stated above. You may also correct any relevant inaccuracies in the information we hold.
If you wish to complain about a data protection issue, we ask you to contact the individual clinician at Spectrum North West, at the address above. You have a right to complain at any time to the supervisory authority in the UK for data protection matters, the Information Commissioner’s Office (ICO).