2018 個人資料（私隱）保護法及條例--- 病人須知
Personal Data | General Data Protection Regulation (GDPR) 2018 --- Notice to Patient
關於向華康社健康門診及心理諮詢服務（下稱「華康社」）及其合作夥伴機構（包括英國華人醫療健康服務有限責任公司 「英華康」，倫敦華人社區中心，觸媒心理諮詢服務公司「Catalyst Therapy」）提供個人資料前，請細閱本須知。
Please read this notice before you provide any personal data to Chinese Community Health and Wellbeing Services （CCHWS) and any of its partners including UK Chinese Medical Limited， London Chinese Community Centre, and Catalyst Therapy & Training Company.
As your Doctors/Nurses/Counsellors providers, CCHWS may ask you to provide your personal Dara (including health information) or obtain from any appropriate third party regarding your medical historian any relevant information for your health care purposes and /or generally for medical care and treatment purpose and/ or for the purposes stated below.
When you provide personal data to us, please make sure that the data is accurate and complete. If you do not provide us with the information required or if the information provided is inaccurate or incomplete, our ability to provide appropriate health care to you may be affected.
Please note that your personal data may be made available to:
Your attending doctors, therapists and authorised staff of CCHWS group to access and view your medical records; or
Other doctors /health care providers who require it for the purposes related to your health care; or
The Court if ordered or subpoenaed by the Court, or to such other authorised personnel as we are required by law; or
Related parties for auditing and accounting, research and service quality control purposes of CCHWS.
If you wish to access and or/ correct your personal data under the Data Protection Act 2018 and General Data Protection Regulation, please contact our staff member during office hour.
Who we are
We are Chinese Community Health Wellbeing Services (referred to as “we”, “our” or “us”), a not-for-profit group which is registered as charity, Charity registration no.xxxx, address at ___ Contact email: email@example.com.
We work along with medical and counselling service providers to provide free medical services and counselling appointments . We are not medical practitioners, consultants or doctors and we do not provide any medical advice or treatment. We act as an agent for our partners. We cannot give medical advice to you. However our service partners may provide you such advisory services.
We collect and process your personal information in accordance with this privacy notice and in compliance with the relevant data protection Regulation and law in the UK and Europe. We are registered on the Information Commissioner’s Office Register of Data Controllers under registration number xxx . The CCHWS is committed to complying with the requirements of the legislation governing client confidentiality including: Confidentiality Code of Company 1998, Data Protection Act 1998 and GDPR.
For the purpose of this policy, confidential information is defined as all the information that is learned in a professional role including personal details, medical history, what treatment a client is having and how much it costs. The definition of personal details includes, but is not limited by, such details as name, age, address, contact details. Note that even the fact that a client attends the service is confidential.
We collect your personal data in the performance of an agreement or to provide a service requested by you.
Information we collect and how we collect
We initially collect Name, email, contact ways and message through on-line contact form under your online consent, which is on our website. After that, we either send you a formal consent form through secured link or when you attend your appointment with health professional at clinics and these consents will be in stored in a secured space.
For those patients who were required by health professionals for medical history, previous diagnoses and previous medical reports, patient registration form and medical records release authorisation form will be sent to them first to sign.
Where we store your data
All information you provide to us on line is stored on our secured servers. The data delivered through secured business emails will be stored on our secure google cloud. Any on line payment transactions will be encrypted using SSL and HTTPS technology.
We take every reasonable measure and precaution to protect and secure your personal data. We work hard to protect your personal data, however, any on line data transmission is at its own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
How long we keep your data
We are required under UK tax law to keep your basic personal data (name, address, contact details) for a minimum of 7 years after which time it will be destroyed. CCHWS only ever retains personal information for as long as necessary and we have retention policies & management record policies in place and regular review to meet these obligations.
Where you have consented to us using your details for direct marketing, we will keep such data until you notify us otherwise and/or withdraw your consent.
Disclosures of your personal information
We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes (such as travel and translation etc) with your consent and in accordance with our instructions.
We will share your name, contact information and your relevant medical records with Medical Service Providers to enable the performance of the agreement you enter with us for a specific service. This information will only be shared when you have given us your consent. We will send you relevant documentation prior to us commencing our services that will allow you to provide your consent.
Where relevant, we will use Heydoc/Wix to handle and store some of our clients' details for the services they agreed from us. The only information we provide them with is your name, address and contact details to meet their business and legal requirements.
Where relevant, we will share your personal data with your insurers. This information will only be shared when you have given us your consent. We will send you relevant documentation prior to us commencing our services that will allow you to provide your consent.
The Data Protection Laws gives you Data Rights. These include:
The right to access information held about you
You also have the right to correct any errors or omissions with your personal data
Seek your personal data to be erased or forgotten
Move your personal data to a similar organisation
Opting out of automated decision making
Objecting to how we process your information.
It is free to use these rights, but we reserve the right to charge a reasonable fee if we feel there are excessive requests. We require proof of ID to be able to process your request and we will try to respond to all legitimate requests within one month. If it will take us longer to comply due to the complexity or volume of requests, we will notify you.