ERS Medical Privacy Notice
ERS Medical respects your rights to data privacy and data protection when you communicate (online or offline) with us through our website, Contact Centre of Operations and our ambulance and courier staff as they complete their work.
If you have a question about this Privacy Notice or how we use your personal information, please email firstname.lastname@example.org or write to us at ERS Medical, Hetton Court, The Oval, Leeds LS10 2AT.
What is a Privacy Notice?
To ensure that we process your personal data fairly and lawfully we are required to inform you:
This information also explains what rights you have to control how we use your information.
The law determines how organisations can use personal information. The key laws are: The Data Protection Act (DPA), the Human Rights Act (HRA), relevant health service legislation, and the common law duty of confidentiality.
ERS Medical is a ‘Data Processor’ and depending on the data a ‘Data Controller’, for the purposes of the Data Protection Act.
ERS Medical recognises the importance of protecting all personal and confidential information in all that we do, and takes care to meet its legal duties.
This part of the fair processing notice outlines the management of the notice, contact details and other access to information legislation.
How we Control Data
ERS Medical has a extensive Business Management System (BMS), which has policies, procedures and work instructions, detailing how we provide strict controls on both Data Security and Information Governance. The specific sections of our BMS that covers these areas are:
Complaints About how we Process Your Personal Information
In the first instance, you should contact the ERS Medical Contact Centre of Operations on 0333 240 4999 or by accessing our webpage at:
The ERS Medical Contact Centre of Operations is open 24 hours a day 365 day a year, to receive and handle your call.
You can also email ERS Medical at email@example.com
What Information ERS Medical collects about you.
We only collect and use your information for the lawful purposes of administering the business of ERS Medical. These purposes include:
What types of personal data does ERS Medical handle?
We process personal information to enable us to support the provision of healthcare services to patients, maintain our own accounts and records, promote our service, and to support and manage our employees. We also process personal information about health care workers that deliver services throughout ERS Medical.
We also use information to support and monitor commissioned health services in England and Scotland to enable us to deliver high quality healthcare. This type of information will usually be provided by and to the NHS in an aggregate or anonymised form, so that we cannot identify an individual.
The types of personal information we use include:
We may also process sensitive classes of information that may include:
This information will generally relate to our staff. In terms of patient information, information may include, but not be limited to:
How will ERS Medical use information about you?
Your information is used to run and improve ERS Medical. It may be used to:
We may keep your information in written form or on a computer. Whenever possible all information that identifies you will be removed.
Storing and Protecting your Information
ERS Medical only stores Personal Identifiable Information (PII) within the United Kingdom. Physical records are stored in ERS Medical premises which all have security monitoring systems in place. Digital records are secured and encrypted, for protection on ERS Medical designated servers only. We do not share our storage facilities with other organisations. This service is managed and monitored, for ERS Medical, by our contracted IT provider.
Sharing your Information
There are many reasons why we share information. This can be due to:
We do not share your data with bodies outside of the European Economic Area.
We are aware of the requirements to ensure your data is protected against accidental loss or disclosure, destruction and abuse. We have implemented processes to guard against such.
ERS Medical will only retain information for as long as necessary. Records are maintained in line with our internal retention schedule which determines the length of time records should be kept.
Protecting your information
We take our duty to protect your personal information and confidentiality seriously. We are committed to taking all reasonable measures to ensure the confidentiality and security of personal data for which we are responsible, whether computerised or on paper.
We have appointed a Senior Information Risk Owner (SIRO) who is accountable for the management of all information assets and any associated risks and incidents, and a ‘Caldicott Guardian’ who is responsible for the management of patient information and patient confidentiality.
All staff are required to undertake annual information governance training.
Under the ERS Medical Handbook and Code of Conduct, all our staff are also required to protect your information, and inform you of how your information will be used. This includes, in most circumstances, allowing you to decide if and how your information can be shared.
Everyone working for ERS Medical is subject to the common law duty of confidentiality. Information provided in confidence will only be used for the purposes advised and consented to by the service user, unless it is required or permitted by the law.
Information for Job Applicants
ERS Medical holds a separate Privacy Notice for Job Applicants and this can be found on our website and or on request when applying for a position within ERS Medical.
You have the following rights in relation to the personal data we hold on you:
In addition to the above rights, you also have the unrestricted right to withdraw consent, that you have previously provided, to our processing of your data at any time. Withdrawing your consent means that we will stop processing the data that you had previously given us consent to use. There will be no consequences for withdrawing your consent. However, in some cases, we may continue to use the data where so permitted by having a legitimate reason for doing so.
If you wish to exercise any of the rights explained above, please contact the Data Protection Officer at ERS Medical. Please email firstname.lastname@example.org or write to us at ERS Medical, Hetton Court, The Oval, Leeds LS10 2AT.
Processing of Special Categories of Personal Data
Article 9 of the EU GDPR provide some special considerations for certain types of data. ERS Medical reserves the right to use these special provisions, especially Section H or Article 9, which states an exemption to the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purposes of uniquely identifying a natural person, data concerning health or data concerning a natural person’ sex life or sexual orientation shall be prohibited.
Section H: Processing is necessary for the purpose or preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnoses, the provision of health or social care or treatment or the management of health and social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3 of article 9.
How to Access Your Information
The Data Protection Act and the General Data Protection Regulations (GDPR) gives you the right to see the information that ERS Medical or any organisation holds about you and why.
Right of Access (Subject Access Request)
The Data Protection Act and the General Data Protection Regulations (GDPR) gives you the right to see the information that ERS Medical holds about you and why. These are commonly referred to as Subject Access Requests and these requests must be made in writing to ERS Medical and you will need to provide us with:
Where a fee is applicable under the terms of the Data Protection Act and subsequent legislation, we will inform you in writing. In due course our disbursement scheme (which outlines these fees) will be available.
We aim to comply with requests for access to personal data as quickly as possible. We will endeavour to deal with all requests within 1 month of receipt, unless the request is highly complex, where we may need to extend this period out. If this occurs we will contact the applicant and explain the why the extension is necessary.
We want to make sure that your personal information is accurate and up to date. If you think any information is inaccurate or incorrect then please let us know through or Contact Centre of Operations (CCO) on 0333 240 4999 or by accessing our webpage at: http://ersmedical.co.uk/contact