Holywell® Care Group Document control
Authorised by: Sabe Connor
Policy no. DP-002 Date authorised: 30/06/2022

Privacy Notice

Review date: 30/06/2023
220630 HCG DP-02 Privacy Notice v3.0


The Data Protection Act 2018 includes the GDPR, an EU directive, that came into force on 25 May 2018. This Act consolidates and strengthens current data protection safeguards as developed under the Data Protection Act 1998. The Information Commissioner’s Office (ICO) considers that organisations are already compliant with the current data protection laws will most likely find it easy to comply with the GDPR.

The Holywell® Care Group meets the requirements of the Data Protection Act. This privacy notice follows ICO guidelines and shows that we are committed to protecting personal information that our staff collect and process from our service users, employees and others; it also shows how the Holywell Care Group succeeds in doing this by providing an overview of our various policies and procedures.

The privacy notice is a public document, available to service users and their families, staff and any third parties who might provide their personal information for any purpose, and through all channels, including the Holywell Care Group’s website and intranet.

The privacy notice is used in association with our policy on Protecting Personal Data under the Data Protection Act 2018.

1. Business details

This is the privacy notice of the Holywell® Care Group.

Our registered office is at 9 Dalton Square, Lancaster, LA1 1WD.

The Group comprises Holywell Care Services, Holywell Home and Bridgeway Care Home, which are registered with the Care Quality Commission to provide a range of services including personal care to people in their own homes/accommodation and personal care with or without nursing in a residential setting.

The Holywell Care Group manages two care homes and provides services to people in their own homes from two other locations.

Holywell Children’s Services provide care and support to children and young people who are placed in care or who are in transition to independent living in the community.

Consequently, we collect and process a wide range of personal information.

2. Aims of this notice

The Holywell® Care Group is required by law to tell you about your rights and our obligations regarding our collecting and processing any of your personal information, which you might provide to us. We have policies and procedures to ensure that any personal information you supply is only with your active consent and will always be held securely and treated confidentially in line with the applicable regulations. We have listed the relevant documents in a later section (6, below) and can make any available to you upon request.

3. We collect Personal information about:

a)      Service users. As a registered care provider, we must collect some personal information on our service users, including financial information, which is essential to our being able to provide effective care and support. The information is contained in individual files (manual [paper-based] and electronic) and other record systems, all of which are subject to strict security and authorised access policies. Personal information that becomes inactive, e.g., from enquiries or prospective users who do not enter the service is also kept securely for as long as it is needed, before being safely disposed of.

b)      Employees and volunteers. The service operates a safe recruitment policy to comply with the regulations in which all personal information obtained, including CVs and references, is, like service users’ information, securely kept, retained and disposed of in line with data protection requirements. All employees are made aware of their right to access any information about them.

c)       Third parties. All personal information obtained about others associated with the delivery of the care service, including contractors, visitors, etc will be protected in the same ways as information on service users and employees.

4. How we collect information

Most personal information about service users, employees and third parties is collected directly from them or through form filling, mainly by hand, but also electronically for some purposes, for example, when they contact us through our website.

With service users, we might continue to build on the information provided in enquiry and referral forms, and, for example, from needs assessments, which feed into their care and support plans.

With employees, personal information is obtained directly and with consent through such means as CVs, references, testimonials and criminal records (DBS) checks. When recruiting staff, we seek each applicant’s explicit consent to obtain all the information needed by us before deciding to employ them.

All personal information obtained to meet our regulatory requirements will always be treated in line with our explicit consent, data protection and opt-out, and confidentiality policies.

Our website and databases are regularly checked by experts to ensure they meet all privacy standards and comply with our general data protection security and protection policies.

5. What we do with personal information

All personal information obtained on service users, employees and third parties is used only to ensure that we provide a service, which is consistent with our purpose of providing a person-centred care service, and that meets all regulatory standards and requirements. It will not be disclosed or shared for any other purpose.

6. How we keep your information safe

As already stated, Holywell has a range of policies that enable us to comply with all data protection requirements. The main policies are:

  1. Access to Employee Data
  2. Complaints
  3. Computer Security
  4. Confidentiality of Service Users’ Information
  5. Consent to Care and Treatment
  6. Data Protection and National Data Opt-out
  7. Record Keeping
  8. Information Governance under the General Data Protection Regulation
  9. Protecting Personal Data under the General Data Protection Regulation
  10. Safe Staff Recruitment and Selection
  11. Service Users’ Access to Records
  12. Sharing Information with Other Providers.

7. People with whom we might share information

We only share the personal information of service users, employees and others with their consent on a “need to know” basis, observing strict protocols in doing so. Most sharing of service users’ information is with other professionals and agencies involved with their care and treatment. Likewise, we would not disclose information about our employees without their clear agreement, for example, when providing a reference. Each data subject (person) is made aware that they may opt-out of sharing their personal data unrelated to their personal care plan.

The only exceptions to this general rule would be where we are required by law to provide information, such as helping with a criminal investigation. Even when seeking to notify the local authority of a safeguarding matter or the Care Quality Commission of an incident that requires us to notify it, we would only do so with consent or ensure that the information provided is treated in confidence.

Where we provide information for statistical purposes, the information is aggregated – meaning that it is provided anonymously – so that there is no privacy risk involved in its use, and we observe our National Data Opt-out policy.

8. How personal information held by Holywell can be accessed

We have procedures in place to enable any staff member, employee or third party whose personal information we hold and might process in some way to have access to that information on request. (See the policies listed in No. 6 above.) The right to access includes both the information and any uses that we might have made of the information.

9. How long we keep information

There are strict protocols in place that determine how long Holywell will keep the information, which are in line with the relevant legislation and regulations.

10. How we keep our privacy policies up to date

The staff appointed to control and process personal information in our organisation are delegated to assess all privacy risks continuously and to carry out comprehensive reviews of our data protection policies, procedures and protocols at least annually.

HOLYWELL is a registered trade mark of Connor Associates Limited.