Please upgrade your browser to improve your experience of the National Care Association website.
If you have any queries or problems and you would like to speak to one of our team then please fill in the contact form below and we will get back to you as soon as possible. Alternatively you can ring our office on 01634 716615.
National Care Association
Suite 4
Beaufort House
Beaufort Court
Sir Thomas Langley Road
Rochester
ME2 4FB
The information contained here is for general guidance purposes only, you will need to refer to the ICO for the most up to date accurate information.
Due to the breadth of organisations across the care provider sector, you will need to assess the materials on this site, and external sites, for suitability to your organisation. Professional legal advice should be consulted for specific issues.
General Data Protection Regulations come into force from 25th May 2018. Every organisation that holds and processes personal data will be affected. This includes your care service!
GDPR is a legal requirement on ALL organisations across all business and charity sectors to be able to evidence compliance by May 25th 2018. If your business is compliant with the Data Protection Act then whilst GDPR is more onerous it should not be too difficult to become compliant with GDPR.
Personal data includes but is not limited to; any information that can identify an individual, email addresses, telephone numbers, HR records, DBS information, medical records, photos, ID numbers and home addresses.
Under the new regulations you must ensure that your care service has a lawful basis for processing personal data, otherwise it must not take place. You may process personal data if:
NCA sponsor QCS applies the principle of legitimate interest to care providers: "it is in the legitimate interest of a care home to process the service user's name, contact information and next of kin. This may also be permitted on the grounds of fulfillment of a contract."
Legitimate interest will not apply if personal data is used for any other purpose, for example where the interests of the organisation override the interests, rights or freedoms of the individual / data subject.
Staff Data - You can process your staff's personal data in relation to usual HR / Admin purposes. Consent will be needed if their data is used for any other purposes, for example phoning an employee on their personal phone regarding work.
Process
Technology
Make sure you are doing the simple things:
People
"The rules governing how personal information is used will become much stricter and GDPR introduces regulations that significantly widen the control owners of personal data have. This means that companies will have to clearly demonstrate that they have consent to hold personal data and justify why they need it, switching the onus from an opt out approach to ensuring that individuals opt in, the regulations are consent centric." Hallidays
Credit: NHS Digital
Cyber security is the the safeguards taken to avoid disruption from an attack on data, computers or mobile devices, covering safeguarding confidentiality and privacy and the availability and integrity of data.
Security breaches can occur when we use paper records, send information using fax machines and even verbally. Or the can occur with digital information which is potentially more severe, with information poteyntially distributed to a wider audience with ease. This can cost a business in terms of expense, recovery time and through damage to reputation. All staff must be aware of how to implement protective measures.
Digital working - the safe storage, collection and sharing of confidential Information. "This is the responsibility of everyone who works in social care. It’s a vital component of how we ensure the dignity and privacy of the people we support and a requirement of law." (Skills for Care)
Data should only be accessed by the people who legitimately need it. Hold all Data securely and allow for controls that mean anyone who doesn’t need access to certain files to conduct their day-to-day job, can’t have it.
Information Commissioners Office (ICO) Helpline
The ICO has launched a new helpline aimed at SMEs and charities to advise you how to be GDPR compliant by 25 May 2018. The service includes an additional, personal support feature for those that have specific questions.
Call 0303 123 1113 and select option 4.
How can our sponsors and suppliers assist?
anonymisation - a process to ensure that data can no longer identify any person.
consent - to gain consent/permission individuals must 'opt in'. Consent must be a "freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she by statement or clear affirmative action, signifies agreement to the process of personal data relating to him or her."
contract - for GDPR a contract is one of the 6 lawful bases for processing personal data. This means that you can rely on this basis if you need to process someone’s data in order to fulfil a contractual obligation.
cyber - computers or other digital information systems.
cyber security - methods undertaken to protect digital information systems.
data breach - incident resulting in personal or sensitive data being lost, altered or viewed by unauthorised individuals.
data controller - person/public authority/body who decides how data is going to be processed and why it needs to be processed.
data processor - those who processes data on behalf of a data controller.
data subject - the living individual which the data is about.
fair processing - conditions which must be met to legally process personal data.
legitimate interest - means the data subject would reasonably expect you to process their data in the manner in which it is being processed.
personal data - data or information is personal when it can be used to identify a living individual.
processing - any way in which data can be collected, stored, used or organised.
©2024 National Care Association. All rights reserved.