Primary Care Contractor Organisation

Data Protection Notice regarding Independent Contractors

Introduction

During the course of NHS Lothian activities we will collect, store and process personal information about our prospective, current and former staff. For the purposes of this privacy notice, ‘staff’ includes applicants, employees, workers (including agency, casual and contracted staff), volunteers, trainees and those carrying out work experience.

We recognise the need to treat staff personal data in a fair and lawful manner. No personal information held by us will be processed unless the requirements for fair and lawful processing can be met. This privacy notice provides a summary of how we will ensure that we do that, by describing:

This notice also explains your rights regarding your personal information.

What laws are relevant to the handling of personal information?

The law determines how organisations can use personal information. The key legislation governing the use of information is listed below:

NHS Lothian is the ‘Data Controller’ (the holder, user and processor) of staff information.

The Health Board has an express statutory function under the National Health Service (Scotland) Act 1978 to maintain the lists of independent contractors.

The PCCO operates within the Regulations issued for the primary care environment as follows:

What types of personal information do we handle?

In order to carry out our activities and statutory obligations to maintain a Performer’s List, Dental List, Ophthalmic List and Pharmaceutical List we handle data in relation to:

The types of personal data may include but is not limited to:

Primary care contractor information

When you are no longer included on the relevant contractor list, we may continue to share your information as described in this notice, ie so long as this is fair and lawful.

What is the purpose of processing data?

Your personal data is collected by NHS Lothian and shared with NHS National Services Scotland for the purposes of maintaining the lists of independent contractors as required by statute. It will be captured and stored on electronic systems and will be used and shared by PCCO staff in NHS Lothian and other health board where you are working in any capacity.

Occupational health clearance information – referred to as the Occupational Health Passport “fit slip” – is shared with the PCCO by NHS Lothian and NHS Borders Occupational Health Departments. PCCO will not share this information with any other person or organisation.

We use information about you in order to:

Sharing your information

There are a number of reasons why we share information. This can be due to:

Any disclosures of personal data are always made on case-by-case basis, using the minimum personal data necessary for the specific purpose and circumstances and with the appropriate security controls in place. Information is only shared with those agencies and bodies who have a “need to know,” or where you have consented to the disclosure of your personal data to such persons.

In order to comply with our obligations we will need to share your information as follows:

Depending on the situation, where necessary we will share appropriate, relevant and proportionate personal information in compliance with the law, with the following:

Reasons why we share your personal informationWho we share your information with (the list below is not exhaustive)
For the purposes outlined abovePCCO staff, occupational health and NHS National Services Scotland
Professional registration purposesRegulatory bodies such as the General Medical Council, General Dental Council, General Optical Council, General Pharmaceutical Council
Contractual terms and conditions of serviceNHS National Service Scotland – Practitioner Services

Background on sharing and our responsibilities

Privacy laws do not generally require us to obtain your consent for the collection, use or disclosure of personal information for the purpose of establishing, managing or terminating your employment. In addition, we may collect, use or disclose your personal information without your knowledge or consent where we are permitted or required by law or regulatory requirements to do so.

Data Protection Legislation requires personal data to be processed fairly and lawfully. In practice, this means that NHS Lothian must:

NHS Lothian’s legal basis for collecting and using staff personal data and/or special category data such as health information, is because it is necessary to do so when contractors are on the relevant Health Board List or wish to be included on the relevant Health Board List.

Information about the rights of individuals under the Data Protection Legislation can be found within the NHS Lothian Data Protection Policy.

Security of your Information

We take our duty to protect your personal information and confidentiality very seriously and we are committed to taking all reasonable measures to ensure the confidentiality and security of personal data for which we are responsible, whether computerised or on paper.

At director level, we have appointed a Senior Information Risk Owner (SIRO) who is accountable for the management of all information assets and any associated risks and incidents, and a Caldicott Guardian who is responsible for the management of patient information and patient confidentiality. We also have a Data Protection Officer who advises the Board on data protection compliance and who liaises with the SIRO and Caldicott Guardian.

All staff are required to undertake regular information governance training and to be familiar with information governance policies and procedures. All NHS staff are also subject to the common law duty of confidentiality.

How do we collect your information?

Some of the information you provide on your application for admission to the Performers List, Dental List, Ophthalmic List or Pharmaceutical List will be included on the national general practitioner database (for GPs and optometrists) and local PCCO database for general dental practitioners. These databases are maintained in order to fulfil the statutory requirements for a Health Board to maintain a general medical practitioner performers list, dental list and pharmaceutical list.

We also collect information in a number of other ways, for example correspondence, forms, interview records, references, surveys.

Retaining information

We only keep your information for as long as it is necessary to fulfil the purposes for which the personal information was collected. As directed by the Scottish Government in the Records Management Code of Practice, we maintain a retention schedule as part of our Records Management Policy detailing the minimum retention period for the information and procedures for the safe disposal of personal information.

We may, instead of destroying or erasing your personal information, make it anonymous so that it cannot be associated with or tracked back to you.

How can you get access your personal data?

You have the right to access the information which NHS Lothian holds about you, and why, subject to any exemptions. Requests can be made in a number of ways, including in writing or verbally. You will need to provide:

You should direct your request to the Data Protection Officer – details can be found below.

Once we have received your request and you have provided us with enough information for us to locate your personal information, we will respond to your request without delay, within one month (30 days). However If your request is complex we may take longer, by up to two months, to respond. If this is the case we will tell you and explain the reason for the delay.

What if the data you hold about me is incorrect?

It is important that the information which we hold about you is up to date. Changes can be notified to the PCCO in order that the relevant database or list might be updated.

Complaints about how we process your personal information

In the first instance, you should contact the Data Protection Officer – contact details can be found below. Information about the rights of individuals under the Data Protection Act can be found online at www.ico.org.uk

Data Protection Registration

NHS Lothian is registered with the Information Commissioner’s Office as a data controller. Registration number Z5757124

The details are publicly available from the:-

Information Commissioner’s Office
Wycliffe House
Water Lane,
Wilmslow SK9 5AF
www.ico.org.uk

Data Protection Officer

If you wish to contact the Data Protection Officer you can contact them at:

Data Protection Officer
IT Governance
Woodlands House
74 Canaan Lane
Edinburgh
EH9 2TB
Phone – 0131 465 5444

Primary Care Contractor Organisation

If you wish to contact the PCCO you can contact them at:

Primary Care Contractor Organisation
NHS Lothian
Waverley Gate
2-4 Waterloo Place
Edinburgh
EH1 3EG

With acknowledgments to NHS Scotland and NHS England