Staff and/or Candidates Privacy Notice

 

< Back to policies & procedures

Our policy

This document will explain how Meddygfa Glan Cynon Surgery uses your personal data and explains your rights under data protection legislation.

This privacy notice applies to job applicants, prospective employees, current employees, former employees, agency workers and contractors of Meddygfa Glan Cynon Surgery.

Where an individual is unsuccessful in obtaining employment with the Practice, recruitment records will be retained in accordance with the NHS Records Management Code of Practice and the Practice Retention Schedule.

Meddygfa Glan Cynon Surgery is the data controller for personal information we collect and store. The practice is committed to protecting your personal information and respecting your privacy. We have a legal duty to explain how we use the personal information we hold about you as a staff member (this includes all employees, ex-employees, agency staff, contractors) at our practice.

 

What information we collect about you and how we use it

Information related to your employment

We use the information collected to carry out our activities and obligations as an employer and to fulfil the contract we have with you. This includes providing you access to services required for your role and managing our human resources processes, the information we may use includes:

  • Personal contact details such as your name, address, contact telephone numbers (landline and mobile) and personal email addresses.
  • Your date of birth, gender, and National Insurance number.
  • A copy of your passport or similar photographic identification and / or proof of address documents (only used to evidence your identity, these are not stored).
  • Marital status.
  • Employment and education history including your qualifications, job application, employment references, right to work information (under section 8 of the Asylum & Immigration Act 1996)
  • Location of employment.
  • Details of your attendance at work and periods of leave taken (including any reasons for leave for example, sickness, maternity, paternity)
  • Details of any secondary employment and any political, conflict of interest or gift declarations.
  • Basic checks and higher security clearance details (DBS, NMC, GMC etc) according to your job role.
  • Any criminal convictions that you declare to us.
  • Your responses to staff surveys if this data is not anonymised.

Information related to your salary and pension

We process this information for the payment of your salary, pension, and other employment related benefits. We also process it for the administration of statutory and contractual leave entitlements such as holiday or maternity leave; the information we may use includes: 

  • Information about your job role and your employment contract including; your start and leave dates, salary (including grade and salary band), any changes to your employment contract, working patterns (including any requests for flexible working).  
  • Details of your time spent working and any overtime, expenses or other payments claimed.
  • Details of any leave including sick leave, annua leave, special leave.
  • Pension details including membership of both state and occupational pension schemes (current and previous).
  • Your bank account details, payroll records and tax status information.
  • Details relating to Maternity, Paternity, Shared Parental and Adoption leave and pay. This includes forms applying for the relevant leave, copies of MATB1 forms/matching certificates and any other relevant documentation relating to the nature of the leave you will be taking.

Information relating to your performance and training

We use this information to assess your performance, to conduct pay and grading reviews and to deal with any employer/employee related disputes. We also use it to meet the training and development needs required for your role.

  • Information about your access to data held by us for the purposes of criminal enforcement if you are involved with this work. 
  • Information derived from monitoring IT acceptable use standards. 
  • Photos and CCTV images.

We use the following information to comply with our legal obligations and for equal opportunities monitoring.  We also use it to ensure the health, safety and wellbeing of our employees.

  • Health and wellbeing information either declared by you or obtained from health checks, eye examinations, occupational health referrals and reports, sick leave forms, health management questionnaires or fit notes i.e., Statement of Fitness for Work from your GP or hospital.
  • Accident records - if you have an accident at work.
  • Details of any desk assessments, access needs or reasonable adjustments.
  • Information you have provided regarding Protected Characteristics as defined by the Equality Act.  This includes racial or ethnic origin, religious beliefs, disability status, and gender identification and may be extended to include other protected characteristics.

We are committed to respecting individual users' reasonable expectations of privacy concerning the use of our IT systems (Information Technology) and equipment. However, we reserve the right to log and monitor such use in line with our Acceptable Use Policy.

Any targeted monitoring of staff will take place within the context of our disciplinary procedures.

 

How is your personal data collected?

Personal information about you will largely be collected directly from you during your recruitment and employment. Personal information may also be collected in certain circumstances through national checks such as DBS, NMC registration or GMC registration. Additionally, your information may be collected by CCTV systems within the Practice when your image is captured entering and leaving the practice premises.

 

Partners we may share your information with

We will disclose information about you, where legally obliged to – some of this may be routine (for example, HMRC), some on a case-by-case basis (for example, a warrant).  But all other requests will be handled on case-by-case basis in line with data protection law. Personal Information is only shared with those agencies and bodies who have a "need to know".

Where possible, we will always look to anonymise/pseudonymise your personal information to protect confidentiality, unless there is a legal basis that permits us to use it and will only ever use/share the minimum information necessary.  However, there are occasions where the practice is required by law to share information provided to us with other bodies i.e., bodies responsible for auditing or administering public funds in order to prevent and detect fraud.

For any request to transfer your data internationally outside the UK/EU, whist we don't anticipate any, should a request be received, it would be handled in accordance with data protection law and current advice from the Information Commissioner’s Office (ICO).

There are a number of circumstances where we MUST share information about you to comply or manage with:

  • Disciplinary/ investigation processes
    • Professional bodies
      • Nursing & Midwifery Council (NMC)
      • General Medical Council (GMC)
  • Legislative and/or statutory requirements.
  • A Court Order which may have been imposed on us.
  • A request for information from the police or a request for assistance from the Practice to the Police and/or other law enforcement agencies for the prevention and detection of crime and/or fraud if the crime is of a serious nature.

There are a number of circumstances where we MAY share information about you to comply or manage with some third parties:

  • Government agencies - Department of Work & Pensions and agencies that work on behalf of the Government ie, Capita, Environmental Audit requirements, Council (local requirements)
  • External auditors
  • HMRC for the purpose of collecting tax and national insurance contributions
    • Benefits
    • Investigations
    • Benefit in kind contributions
    • P60 calculations
  • Healthcare Inspectorate Wales (HIW) for the purposes of inspecting NHS services against a range of standards, policies, guidance and regulations.
  • NHS Wales Shared Services Partnership (NWSSP), Digital Health and Care Wales (DHCW) and NHS England for the purposes of issuing NHS Smart Cards and the Care Identity Service (CIS). Further information on CIS and how your data is processed is available on the NHS England Digital website.
 

Sharing of personal data with third parties

We may share staff personal data with trusted third-party service providers where necessary for business operations. Where this occurs, we ensure that appropriate data protection safeguards are in place.

For example:

  • We outsource certain HR functions, including the management of annual leave records and employment contract data, to our external provider, PeopleCloud (AvenSure).
  • This means relevant employee information may be securely shared with PeopleCloud/AvenSure for the purposes of administering HR processes.

All third-party providers are required to handle personal data in accordance with UK data protection legislation and only process data on our instructions.

We have data processing agreements in place with all third-party providers to ensure your information is kept secure and used only for specified purposes.

 

Our legal basis for processing your personal data

The Practice will only use and share your information where there is a legal basis to do so.

We need to know your personal, sensitive, and confidential data for the purposes or your employment. In general, under the UK GDPR, we will rely on one of the following legal bases: 

  • Article 6(1)(b) which relates to processing necessary for the performance of our contract with you 
  • Article 6(1)(c) so we can comply with our legal obligations as your employer

Where we process special category data, we will generally rely on one of the following conditions for processing:

  • Article 9(2)(b) which relates to carrying out our obligations and exercising our rights in employment and the safeguarding of your fundamental rights 
  • Article 9(2)(h) for the purposes of preventative or occupational medicine and assessing your working capacity as an employee 

Where we process information about staff criminal convictions and offences, the lawful basis we rely on to process this data are:

  • Article 10 UK GDPR – Processing of personal data relating to criminal convictions and offences.  
  • Section 10(5) in the Data Protection Act 2018, only if it meets Part 1,2,3 of Schedule 1.
 

Retention/maintenance of your personal information/storing your information

Your personal information is held in both paper and electronic forms for specified periods of time as set out in the Practice’s retention schedule. 

 

How to contact us

Please contact the practice if you have any questions about our privacy notice or the information we hold about you via the below methods:

Meddygfa Glan Cynon Surgery
Tŷ Calon Lân
Oxford Street
Mountain Ash
CF45 3HD

By phone: 01443 706700

 

Requests for confidential references

If you leave, or are thinking of leaving, we may be asked by your new or prospective employers to provide a reference.  Confidential references are covered by an exemption from disclosure under data protection law.  So, whilst the practice may choose to disclose, the data subject cannot use UK GDPR to request completion of these.

Confidential references – An exemption from UK GDPR applies if you give or receive a confidential reference for the purposes of prospective or actual:

  • education, training, or employment of an individual;
  • placement of an individual as a volunteer;
  • appointment of an individual to office; or
  • provision by an individual of any service.

It exempts you from the UK GDPR’s provisions on:

  • the right to be informed;
  • the right of access; and
  • all the principles, but only so far as they relate to the right to be informed and the right of access.
 

Contact details of our Data Protection Officer

The Practice is required to appoint a Data Protection Officer (DPO). This is an essential role in facilitating practice accountability and compliance with UK Data Protection Law.

Our Data Protection Officer is:

Digital Health and Care Wales (DHCW) 
Information Governance, Data Protection Officer Support Service 
6th Floor, Tŷ Glan-yr-Afon 
21 Cowbridge Road East 
Cardiff 
CF11 9AD

 

Your rights