This privacy notices advises you on how the Trust collects and uses your personal information that is provided to us via a request for information.
What Information we collect
- Your full name (first name and surname)
- Your address (full postal address in the case of a subject access request)
- Your email address (as used when making your request for information)
- Your request
- Any personal information held by the Trust disclosed to you in response to a subject access request (SAR)
How we collect your information
The bulk of information we collect has been provided to us by you for one of the following reasons:
- When you make an FOI request (or EIR request)
- When you have made a subject access request as is your right under the Data Protection Act 2018
How we use your information
We use the information that you have provided in order to answer your request for information made under the relevant access to information legislation (either FOI Act/EIR Regulations or the Data Protection Act 2018). We will only use your information when the law allows us to do so or where it is necessary to allow us to complete one or more of our official functions. Most commonly, we will use your personal information where:
- We need to comply with a legal obligation
- It’s necessary for the performance of a task carried out in the public interest or in the exercise of our official authority as a public body
- To help us confirm your identity when you contact us
- To provide and improve our service to you
- In limited circumstances (and we would explain these circumstances at the time should they apply), we may ask you for your consent to use your personal information. However your consent is not required if any of the above points apply.
Who we share your data with
- Your personal information may be shared within the Trust to allow us to undertake and complete your request, to allow us to identify and locate information held about you, for example.
- We will need to share your request with the Information Commissioner’s Office to answer any complaint made to the Commissioner
- We will share your information with Digital Interactive Ltd., our 3rd party Data Processor and the suppliers of the software used to manage our Requests for Information.
- We will share your information if we are required to do so by law or regulation e.g. Court Order, or to prevent fraud or other crime
We will NOT:
- Use your personal information for the purposes of data analytics
- Share your information with third parties for marketing purposes
- Sell or rent your personal information to other third parties
Our Lawful Basis for processing your personal information
Under the Data Protection Act 2018 (and the UK GDPR), we rely on the following lawful bases to process your personal information:
- We have a legal obligation as a data controller to provide you with access to information under the different Requests for Information legislation
- We require your information to allow us to perform a public task
- We have a legitimate public interest
- We have your consent.
Special category data is that which is particularly sensitive (for example your health record data) and this requires a higher level of protection.
To allow us to use this data we need to provide further and additional justification for collecting, storing and using special category data.
If required, we will process special category data in the following circumstances:
- Where we have a legal obligation to do so
- Where it is in the public interest to do so and is necessary to:
- Allow the Trust to undertake its functions as a public authority
- For the prevention, investigation, detection or prosecution of criminal offences
Transferring Data Abroad
The Trust does not share your personal information outside of the UK without ensuring that sufficient safeguards are in place that meet the ICO’s criteria, together with the requirements of the UK GDPR.
Automated Decision Making
There are restrictions on decision-making based solely on automated means (i.e. without any human involvement), this includes restrictions on profiling. In terms of FOI requests, the Trust does not utilise automated decision-making without human involvement. If you have any queries, please contact the Trust’s Data Protection Officer.
How we store your Personal information
Information on this subject is available at the Trust’s over-arching privacy notice which can be found here.
How long do we keep your information
Your personal information is stored in accordance with the NHS Records Management Code of Practice
Your rights under the Data Protection Act 2018
Information on this subject is available at the Trust’s over-arching privacy notice which can be found here.
How to contact us
Information on this subject is available at the Trust’s over-arching privacy notice which can be found here.
How to complain
Information on this subject is available at the Trust’s over-arching privacy notice which can be found here.