Privacy Notice: Public Health
Plain English explanation
Public health encompasses everything from national smoking and alcohol policies, the management of epidemics such as flu, the control of large scale infections such as TB and Hepatitis B to local outbreaks of food poisoning or Measles. Certain illnesses are also notifiable; the doctors treating the patient are required by law to inform the Public Health Authorities, for instance Scarlet Fever.
This will necessarily mean the subjects personal and health information being shared with the Public Health organisations.
Some of the relevant legislation includes:
- The Health Protection (Notification) Regulations 2010 (SI 2010/659)
- The Health Protection (Local Authority Powers) Regulations 2010 (SI 2010/657)
- The Health Protection (Part 2A Orders) Regulations 2010 (SI 2010/658)
- Public Health (Control of Disease) Act 1984
- Public Health (Infectious Diseases) Regulations 1988
- The Health Service (Control of Patient Information) Regulations 2002
We are required by Articles in the General Data Protection Regulations to provide you with the information in the following 9 subsections.
1. Data Controller
Phoenix Medical Practice
33 Bell Lane,
Rochester, Kent ME1 3SX
2. Data Protection Officer
Lolu Adeniji & Patrick Mwondela
NHS Medway Clinical Commissioning Group
Unit A. Compass Centre North
Pembroke Road, Chatham Maritime
Kent ME4 4YG
3. Purpose of the processing
There are occasions when medical data needs to be shared with Public Health England, the Local Authority Director of Public Health, or the Health Protection Agency, either under a legal obligation or for reasons of public interest or their equivalents in the devolved nations.
4. Lawful basis for the processing
The processing of personal data in the delivery of direct care and for providers’ administrative purposes in this surgery and in support of direct care elsewhere is supported under the following Article 6 and 9 conditions of the GDPR:
- Article 6(1)(c) “processing is necessary for compliance with a legal obligation to which the controller is subject.”
- Article 9(2)(i) “processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices,..”
5. Recipient of the processed data
Or categories of recipients of the processed data
The data will be shared with Public Health England and equivalents in the devolved nations.
6. Rights to object
You have the right to object to some or all of the information being shared with the recipients. Contact the Data Controller or the practice.
7. Right to access and correct
You have the right to access the data that is being shared and have any inaccuracies corrected. There is no right to have accurate medical records deleted except when ordered by a court of Law.
8. Retention period
The data will be retained for active use during the period of the public interest and according to legal requirements and Public Health England’s criteria on storing identifiable data.
Right to Complain
You have the right to complain to the Information Commissioner's Office. You can visit the ICO Website or call their helpline Tel: 0303 123 1113 (local rate) or 01625 545 745 (national rate) There are National Offices for Scotland, Northern Ireland and Wales, (see ICO website).
By using this site, you agree that we may store and access cookies on your device. Find out about our cookies.
Functional Cookies are enabled by default at all times so that we can save your preferences for cookie settings and ensure site works and delivers best experience.
3rd Party Cookies
This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.
Keeping this cookie enabled helps us to improve our website.