Our privacy notice

GenesisCare UK has updated its privacy notice to reflect compliance with data protection law (current and future) and any secondary legislation and guidance implemented or issued as a result of these.

Covid-19 Measures

GenesisCare UK has put measures in place to ensure the safety of all patients and staff. Our services have been reorganised so that healthcare can be provided to those in need during the pandemic.

Zoom consultations

Consultations between doctors and patients will utilise ‘telehealth’ technology and patients may be invited to join a Zoom consultation through a link or a calendar invitation sent via email.

To allow you to connect to the consultation, Zoom will need certain information from you. This may be your email address, your computer IP address or mobile phone number. You can also enter your name but you do not need to. Zoom state that they do not retain this data for longer than necessary and they do not share it with any other organisation. Zoom must only process data in line with data protection legislation.  Zoom’s privacy policy can be found here: https://zoom.us/privacy

We do not record consultations. Any notes taken during the consultation about your healthcare will be added to your medical record which is held securely on our patient system. Further information relating to your personal data can be found below.

The lawful basis for this processing is legitimate interest, that is, the processing is necessary to support your healthcare using video communications; providing the ability to support treating doctors in the conduct of remote appointments and calls to their patients, which facilitates the continuity of care during the Covid-19 pandemic; and to provide assurance against any increased risk of infection face to face appointments would carry as a result.

COVID-19 – use of your data

PCR testing

In order to safeguard our staff, doctors, patients and visitors (including all their families), you will be required to complete a test for SARS-CoV-2, which will be on-going until all government shielding and social distancing measures due to SARS-CoV-2 have been lifted. Your nasal and throat swab sample will be couriered to the laboratory for processing. We will supply the laboratory with your basic ID details (name and DOB) to allow them to process and report your swab test result. The results of the swab test will be available to relevant members of the healthcare team and to your clinician, who will contact you should a positive result be received.

Innova Lateral Flow Antigen Test (LFT)

An LFT is a rapid test for Covid-19 which can be self-administered to allow to faster results which will further mitigate the risk of transmission. As a patient, you may be asked to complete an LFT before accessing certain GenesisCare services. You will be provided with a test kit on arriving at reception. All tests and results, irrespective of the outcome will be recorded by our reception team and reported to Public Health England.

Using your data and Sharing data with other healthcare bodies engaged in the COVID-19 response

Our lawful basis for processing your personal data is legitimate interest as the processing is necessary during the Covid-19 pandemic to control, and wherever possible, prevent the spread of infection. We may also be legally required to share personal data under the Notice issued by the Secretary of State under Regulation 3(4) of the Health Service Control of Patient Information Regulations issued on the 1st April 2020.  In relation to your special category data, the processing is necessary for the provision of health or social care or treatment or the management of health or social care systems and services.

To protect your health and care needs we may share your confidential information including health and care records with clinical and non-clinical staff internally within GenesisCare and with other health and care providers and other bodies engaged in disease surveillance for the purposes of protecting public health, providing healthcare services and monitoring and managing the outbreak. Further information about how health and care data is being used and shared by the NHS and other health and social care organisations to support the COVID-19 response can be found here.

About GenesisCare UK

GenesisCare UK is a trading name of Genesis Cancer Care UK Limited. We are a specialist, provider of cancer care diagnostic and treatment services in the UK. Our company registration is 05796994 and our registered office is Wilson House, Waterberry Drive, Waterlooville, Hampshire, PO7 7XX. GenesisCare is registered with the Information Commissioners Office, registration number Z9493925.

This privacy notice applies to anyone who asks about, buys or uses our services in any way (for example, by email, through our website, or by telephone). We take privacy seriously and we want you as our service user, to understand the information we collect about you, how we process and protect the personal information which we collect about you, from you and from third parties, so that you can be confident that the information is being used safely and in ways that are reasonably expected, and what rights you have in respect of your personal information.

When we refer to ‘we’, ‘us’ and ‘our’, means GenesisCare UK.

What information do we collect and use?

We will collect personal information which can include:

The contact details we collect are: telephone contact details, in order that we can call you, text or leave a message, postal and email addresses, so that we can send you invoicing information where relevant and which we may use to send confidential health information unless you have told us not to.

We will ask that you to provide your payment card details in order to fund your treatment where you are self –funding or to cover costs in the event of a shortfall of funds from insurers.

We will ask you for details of an emergency contact, with whom we can share information about the progress of your treatment and contact in the event of an emergency. By providing emergency contact details, you are giving us permission to keep him or her informed. It is your responsibility to notify us of any change to these emergency contact details so that we can ensure they are kept up-to-date and accurate. Where you provide us with information about other people, you must make sure that they have seen a copy of this privacy notice and are comfortable with you giving us their information.

CCTV recording is in use at some GenesisCare UK locations; this is used to ensure the security of property and premises and for preventing and investigating crime purposes only. Areas monitored by CCTV are sign-posted. The information processed can include visual images, personal appearances and behaviour. Where necessary or required, this information is shared with you, employees and agents, services providers, police forces, security organisations and persons making an enquiry.

We may also collect more sensitive information about you such as about your current or previous health, your diagnoses and medications; images you had taken in the course of care or treatment; your sex life or sexual orientation, your religion, race or ethnicity and genetic information relating to you. This may also include details of healthcare services provided previously by GenesisCare UK or by other healthcare providers and include details of any medication you have been prescribed. In this Privacy Notice, we refer to this sort of information as special category personal data.

GenesisCare UK collects ethnicity data about you upon registration with us. We use this data in an anonymised format to: Identify any risk factors for ethnic groups, as some ethnic groups are more at risk of specific diseases;

Access to and use of information concerning your physical or mental health is strictly controlled in order to ensure compliance with applicable data protection law and adherence to medical confidentiality guidance issued from time to time.

In many cases we pseudonymise or anonymise your information before we share it with others, or where we no longer require the information in identifiable form.

Anonymisation is the process of turning data into a form which does not identify individuals and where identification is not likely to take place.

Pseudonymisation is the processing of information in such a way that it can no longer be attributed to you without the use of additional information and where that additional information is kept separately. This allows for a much wider use of the information for statistical or other purposes.

Communicating with you

We will ask how you wish us to communicate with you when you register. We may ask if you wish us to leave voice messages, send SMS texts and/or write to you by email. You can change your mind at any time, please let us know.

It is important that you tell us immediately if your contact details have changed. 

Please note that we cannot be held responsible should you change your contact number or email address and not advise us. Equally we cannot be held responsible for onwards use or transmission of a text message after you have received it.

We may use a trusted SMS messaging service to provide a patient reminder service which means you will receive a discrete text message a few days before your appointment. Please tell your Centre if you wish to opt-out of this service.

You should not reply to these texts as they will not be responded to in real time. However such data will be monitored and treated confidentially in accordance with our policy. This service is managed in collaboration with GenesisCare Australia colleagues with whom appropriate inter-group data protection agreements are in place.

Who do we collect information from?

Information may be collected directly from you to support your direct care and treatment. This information can be collected when:

  • You use our services
  • You complete enquiry forms on GenesisCare UK websites
  • You submit a query to us including through our website, by email or by social media
  • You correspond with us by letter, email, telephone (calls from/to patients may be recorded for the purposes of staff training, customer service development and quality improvement) or social media, including where you reference GenesisCare UK in a public social media post
  • You take part in our marketing activities

In order to provide you with the best possible care, we collect personal information about you from other providers. These can include:

  • Records from other healthcare providers who have previously provided treatment to you, (this can include both private organisations and the NHS)
  • Records from your consultant (including those provided through their medical secretaries)
  • Information from other service providers who work with us in relation to diagnostics, care and treatment provided to you

We may collect information about you from third parties when:

  • You are referred to us for healthcare services
  • We liaise with current or former other service and support providers
  • We liaise with your emergency contact or family
  • We communicate with your medical insurance policy provider
  • We instruct debt collection agencies
  • We communicate with government agencies such as social and welfare organisations where it is legally required for the safety of the individual concerned, for example safeguarding

GenesisCare UK provides telehealth remote consultation functionality for doctor use with patients. This is a legitimate interest of both GenesisCare UK and the doctors and is our legal basis for doing so, i.e. the ability to support treating doctors in the conduct of remote appointments and calls to their patients, which facilitates the continuity of care during the Covid-19 pandemic crisis, and to provide assurance against any increased risk of infection face to face appointments would carry as a result. In the provision of this functionality GenesisCare may record your name, telephone number and IP address.

What is your information used for?

We use your information for a number of purposes. Whenever we use your information, we must have a legal justification under data protection law for its use. The legal justification will depend on the purpose for which we intend using your information.

Our legal justification for processing your Personal Data will fall into the categories below:

  • Necessary for you to receive healthcare services
  • Necessary to fulfil our contract with you for the provision of care and treatment
  • Necessary to comply with the law – This applies where we have a legal or regulatory obligation to use your personal information
  • Necessary for our Legitimate Interests – This means where our business interests justify us using your information and that business need does not impact unjustly on your rights as an individual
  • You have provided your consent to our use of your personal information

Our legal justification for processing your Special Category Personal Data will fall into one of the categories below:

  • Necessary for the purposes of preventive medicine, for medical diagnosis and the provision of health or social care or treatment
  • You have given your explicit consent for one or more specified purposes
  • Necessary to protect your vital interests or the vital interests of another person
  • Necessary for reasons of public interest in the area of public health
  • Necessary for archiving purposes in the public interest, scientific research or statistical purposes
  • Necessary to establish, exercise or defend legal claims

We have set out individually those purposes for which we will use your data below.

Please note that failure to provide your information further to a contractual requirement with us or a consultant may mean that we are unable to register you as a patient or facilitate the provision of your healthcare on the GenesisCare UK’s systems.

When you come to us for care and treatment, we use your personal information, which will include special category personal data, in order to provide this.

This is necessary to enable us to provide you with healthcare and treatment and to fulfil our contract with you for the provision of such care. We use your personal information to ensure our accounting and invoicing activities are accurate and up-to-date. We have an appropriate business need to use your information which does not overly prejudice you. This supports the provision of your healthcare and is necessary for us to establish, exercise or defend our legal rights.

Clinical Audit
We are accountable for ensuring safe clinical and operational practices are implemented and maintained. We undertake regular audits of compliance to ensure the delivery of standards of treatment, for quality assurance, to ensure services can meet patient needs in the future and to assess adherence to policy and procedure. We do this on the basis of a legitimate and appropriate business interest and the public interest in statistical and scientific research, and with appropriate safeguards in place.

One of the national programmes we are legally obliged to participate in is operated by the Private Healthcare Information Network (PHIN). PHIN collects and publishes information about the activity and performance of healthcare providers and doctors providing private care. PHIN has its own privacy notice which can be accessed via its website. Whilst the information we are obliged to provide includes some of your personal data, PHIN cannot identify you from it for although your NHS number is included, PHIN does not have access to any patient systems. Any information that is published by PHIN will always be in an anonymised statistical form.

We may also be asked to share information with UK registries for which ethical approval is not necessarily required but which form part of the National Clinical Audit programme. GenesisCare UK provides information to the National Cancer Registration and Analysis Service (NCRAS) which promotes research, monitoring and the improvement of cancer care. This will remain an opt-out scenario, and to opt out you will need to contact the NCRAS; a leaflet is provided in your welcome pack with the contact details.

We will collect your data to support national data collections and Information Standards such as the National Radiotherapy Dataset. The purpose of this collection is to support consistent data and inform the planning, provision and commissioning of radiotherapy services

We may do so without your consent provided that the particular audit registry or data collection has received statutory approval, or where the information will be provided in a purely anonymous form, otherwise your consent will be needed. Where your consent is required, the registry organisation may have consent processes of their own, otherwise we will obtain that consent from you.

Clinical training, education and Research
GenesisCare UK participates in clinical training, education and medical research and shares data with ethically approved third party research organisations.

We will share your personal information only to the extent that it is necessary to do so in assisting research and as permitted by law. Some research projects and/or registries have received statutory approval such that consent may not be required in order to use your personal data.

In the event that consent is required then either the research organisations themselves will obtain this from you themselves or we will obtain consent from you. The only exception to gaining consent is where information, including images are fully anonymised and have no ability to identify the specific individual to whom they relate.

Where your consent is not required, we have a legitimate interest in helping with medical research and have put in place appropriate safeguards to protect your privacy. Information collected during treatment, including images, may be used for education, audit and research (which may be published in medical journals). All data will be anonymised and used in a way so that no individual will be identified.

The use is necessary in the public interest for statistical and scientific research purposes.

GenesisCare UK works with other organisations to support the development of technological innovations for patient treatment and to monitor the patient and organisational outcomes. We will share your personal information only to the extent that it is necessary to do so, and only where adequate safeguards are in place.

Clinical Trials
You may be advised or recommended to participate in a clinical trial, your consultant will explain how your data is shared with the organisation running the trial and as part of the sign up to the trail you will be asked to consent to this data sharing.

You may raise queries, concerns, or even make complaints with GenesisCare UK and we take those communications seriously. It is important that we resolve such matters properly and fully to the satisfaction of all concerned, and we will need to use your personal information to do so. We do this in order to provide you with healthcare and treatment, manage our services and we have an appropriate business interest which does not overly prejudice you. This use is also necessary for us to establish, exercise or defend our legal rights.

When registering you for care or treatment, we will ask you for details of an emergency contact, with whom we can share information about the progress of your treatment and contact in the event of an emergency. By providing emergency contact details, you are giving us permission (consenting) to keep him or her informed.

Other healthcare professionals or organisations may need to know about your treatment in order for them to provide you with safe and effective care, and so we may need to share your personal information with them. We have a legitimate interest in ensuring that other healthcare professionals who are routinely involved in your care have full details of your treatment. The use is necessary for reasons of substantial public interest under UK law. This use is also necessary for us to establish, exercise and defend our legal rights.

Further details on the third parties who may need access to your information is set out below.
GenesisCare UK has a legal obligation under the Health & Social Care Act 2015 to use your NHS number where reasonably available, and this unique identifier will be used for all data sharing associated with facilitating the care of NHS patients.

As a provider of healthcare, we are subject to a wide range of legal and regulatory responsibilities. Where we are required by law or by regulators to provide personal information, the use is necessary for the provision of healthcare or treatment and the management of healthcare systems and we have a legal obligation to do so. In the unlikely event that GenesisCare UK or its consultants are the subject of legal actions or complaints it is necessary to access your personal information in order to investigate and respond to those actions (limited to the extent necessary and relevant to the subject-matter) to enable us to establish, exercise or defend our legal rights.

GenesisCare UK is a quality-conscious organisation. We look to learn from you to improve the experience of future patients where possible. We will use your personal information to identify where improvements can be made, such as reviewing recorded phone calls to assess whether anything can be learnt and asking for your opinion on your experience with GenesisCare UK. We have an appropriate business need to use your information which does not overly prejudice you. We need to use the information in order to manage the healthcare services we deliver and in order to identify and carry out any necessary improvements.

We have an appropriate business need to use your information which does not overly prejudice you and the use is necessary for us to comply with our legal obligations. In the event that we use special categories information about you for this purpose, it would be because the use is necessary for the provision of healthcare or treatment or the management of healthcare services and systems or the use is necessary to establish, exercise or defend legal claims.

If we were to sell or transfer a centre or part of our business to another organisation, your patient records would also transfer to the new owner. Limited information may also be shared, where required, with legal and other professional advisors involved in that transaction. Your records would be transferred to minimise the disruption to current and past patients caused by the sale or transfer and to ensure that we and a new owner were able to comply with our legal obligations regarding the retention of patients’ and other clients’ medical records and to ensure continuity of care.

Marketing related to the promotion of our organisation and services, as an educational resource, within presentations or within journalistic articles or material.  We use personal data including photographs, video and audio in our marketing materials related to the promotion of our organisation and services, as an educational resource, within presentations or within journalistic articles or material. These materials will be published online and within printed media, used in promotional videos at events, used in advertising and broadcast and used for educational purposes. This may include special categories of data such as information relating to your health.  We will use your other details only to identify you to help us ensure your right to erasure, or in footage as explicitly discussed.  We will only do this where we have a lawful basis to do so and have informed you that this will take place.  We will provide you with our Privacy Notice for Use of Images, Photography and Filming if your personal data will be used for these purposes and were necessary we will seek your explicit consent.

This is a team of medical consultants who will discuss a treatment plan for you via the GenesisCare UK eMDT platform (developed and supported by our processor, Context Health).  You will be referred to consultants in your specialist reference group who will have access to your medical data, to the diagnostic images held on the radiology system (PACS) and to your Care Plan preferences.  Consultants working together in the eMDT will discuss your case to achieve the best possible outcome. All eMDT consultants sign a strict privacy agreement as a condition of participating and are bound by data protection legislation.  The data will be held on the platform for one year and a day and thereafter deleted unless you are a GenesisCare patient in which case your treatment data will be saved in our patient systems in accordance with standard lawful practice.  Data processed in the eMDT function is jointly controlled by GenesisCare and the Consultants and a legal arrangement is in place between the parties.  Data processed in the audit function is controlled by GenesisCare.  Data processed in relation to patient outcomes is controlled jointly by the collaborating Consultants.

We support the continuous development of and improvement to technological functionalities in the systems we use to provide cancer care and treatment. We are sometimes asked by our third party partners to provide data to support their commercial development.  Where we provide sample data for these activities we ensure that robust data protection agreements are in place with our systems suppliers and our specialist IT team anonymise your data prior to sharing so that it cannot be connected to you.

Who Do We Share Your Information With?

It is important that you understand that we may share your information with others. We may share your personal information within our group of companies and with third parties.

Sharing within the GenesisCare group

We may share your personal information within the GenesisCare group of companies.

Sharing with your medical consultant

As a GenesisCare UK patient, your treatment may be provided by a medical consultant. Medical consultants who provide you with care are required by law to maintain records about your health and any treatment or care you have received. They also make decisions about what information is collected about you, and may maintain their own set of medical records in relation to the treatment that they provide as well as sharing the records relating to your care and treatment that GenesisCare UK maintains. Consultants control this information which means they must individually comply with the data protection legislation and relevant guidance when handling your personal information and should therefore also make available to you their own privacy notice. In respect of your direct health care and treatment received through GenesisCare UK, GenesisCare UK jointly controls your information with your consultant. This means that as joint controllers, together we determine the means and purpose of processing your information for your care and treatment.

Consultants who work with GenesisCare UK (including their medical secretaries) are expected to handle your personal data in accordance with the principles set out within this Privacy Notice. This means that whenever they use your personal data, they will do so as set out in this Privacy Notice. In addition, GenesisCare and Consultants are required to adhere to the Joint Patient Data Sharing and Management Policy which we can provide to you upon request.

Consultants working with GenesisCare UK (including their medical secretaries) may process your personal information at a non-GenesisCare UK site.

If you want to find out more about the arrangements between GenesisCare UK and consultants for handling your information please let us know by contacting our Data Protection Officer (DPO), details at the foot of this Privacy Notice.

Sharing with the NHS

We may share data with an NHS Trust which has commissioned our services so that we can jointly support your care and treatment.

This means that we may collect, transfer, share and manage your data jointly in our healthcare systems for the purposes of healthcare services and related administration under a formal joint controller arrangement. Such a joint controller arrangement will set out our respective responsibilities to you with respect to:

  • Our compliance with the data protection law generally;
  • Our responsibilities for dealing with your rights as data subjects; and
  • Our respective duties for provision of information to you.

Where joint controller relationships exist both parties must comply with data protection standards and both are responsible for addressing your rights and freedoms.

If you want to find out more about the arrangements between GenesisCare UK and NHS Trusts for handling your information please contact our DPO.

Sharing with your private medical insurer

Where the cost of your treatment and care is covered by insurance, we share your information with your insurer or the administrator of the applicable scheme of insurance. Both GenesisCare UK and your insurer are controllers of this personal information. This means that each of us individually may determine the means and the purpose of any processing of the information we hold.
Generally, we share information in order to allow each other to exercise its rights or comply with its obligations under the healthcare services arrangement we have in place, and in the case of the insurer, to manage claims and administer the schemes for insured members.
Specifically, your information may be used in the following shared activities:

  • The provision of clinical quality information
  • The pre-authorisation of treatment on your behalf
  • Invoicing for services provided
  • The notification of any serious incidents
  • Assisting and cooperating in the investigation of any member complaints
  • Allowing your insurer to inspect and audit our facilities

You may exercise your rights against either GenesisCare UK or your insurer where we are both controllers of the same information for the same processing purpose. Where we independently hold further information, or process information for purposes in addition to the shared purposes stated above, you should direct any communication concerning your rights to the applicable holder/processor.

Sharing with Public Health England

The law requires us to share data for public health reasons, for example to prevent the spread of infectious diseases or other diseases which threaten the health of the population. We will report the relevant information to local health protection team or Public Health England.

We make notifications to Public Health England and other statutory bodies in compliance with our legal obligations and where necessary to protect the vital interests of individuals.

This processing is necessary for reasons of public interest in the area of public health such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care on the basis of UK law.

Sharing with third parties

  • We may share your personal information with the third parties listed below for the purposes identified within this privacy notice:
  • A doctor, nurse, carer, pharmacist, and pathology and radiology staff involved in the analysis and reporting of diagnostic tests or any other healthcare professional involved in your treatment
  • Other members of support staff involved in the delivery of your care, like receptionists and medical secretaries
  • Anyone that you ask us to communicate with or provide as an emergency contact
  • NHS organisations
  • Other private sector healthcare providers
  • Your GP
  • Voluntary organisations providing on-going support
  • Ancillary service and support providers where you opt to accept those services, such as the GenesisCare Exercise Clinic, counsellors and therapists
  • Taxi providers where transport assistance for treatment is provided for insured patients
  • National and other professional research/education/audit programmes and registries, as identified under Purpose 3 above
  • Government bodies and local authority departments
  • Our regulators, like the Care Quality Commission
  • The police and other third parties where reasonably necessary for the prevention or detection of crime
  • Our insurers
  • Debt collection agencies
  • Third parties to the extent required by law, regulation or court orders and statutory requests for information
  • Service providers we use to support our business. These processors are trusted partners that work with us and are authorised to use your personal information only as necessary to provide these services to us. We require these third parties to comply strictly with our instructions and data protection law and we ensure appropriate controls are in place. We enter into written contracts with all our processors
  • Our third party service providers such as auditors, lawyers, marketing agencies and tax advisers
  • Selected third parties in connection with any sale, transfer or disposal of our business. We may communicate with these third parties in a variety of ways including, but not limited to, email, post, fax and telephone.

Sharing data with the Private Healthcare Information Network (PHIN)

Genesis Care participate in initiatives to monitor safety and quality, to help ensure that patients are getting the best possible outcomes from their treatment and care. The Competition and Markets Authority Private Healthcare Market Investigation Order 2014 (“the Order”) established the Private Healthcare Information Network (“PHIN”), as an organisation who will monitor outcomes of patients who receive private treatment.

Healthcare providers providing private care are required by law to send PHIN details of each treatment episode. This will include personal data. By Article 21 of the Order, we are required to provide PHIN with information related to your treatment, including your:

  • National Health Service (NHS) number, or in the case of patients from outside the UK, a suitable equivalent identifier e.g. passport number
  • Your age
  • Your gender
  • Your ethnicity or race
  • Your diagnosis (what you are receiving treatment for)
  • Other data about your state of health
  • The procedure you have undergone
  • The date you came into hospital, and the date you left
  • Your postcode.

PHIN also collect NHS patient data to enable it to consider all the treatment carried out by a particular consultant or provider, and to monitor outcomes, with a view to forming a complete and fair picture of the nature and quality of their services. For NHS patients, PHIN collect the same information as for private patients listed above, save that NHS numbers are not collected.

PHIN, like us, will apply the highest standards of confidentiality. Any information that is published by PHIN will always be in anonymised (unidentifiable) statistical form and will not be shared or analysed for any purpose other than those stated.

Further information about how PHIN uses information, including its Privacy Notice is available at www.phin.org.uk. We will be happy to print a copy for you if you prefer.

How long do we keep your personal information for?

We retain information in accordance with our legal obligations and national best practice. We ensure compliance through regular auditing and ensure information is securely disposed of when it has reached the end of its retention period. We implement data retention periods for different categories of personal data and/or different processing purposes, including where appropriate, archiving periods. We will only keep your personal information for as long as reasonably necessary in order to support patient care and continuity of care; support evidence-based clinical practice and to assist clinical and other audits; to support our legitimate business interests and to comply with our legal and regulatory requirements.

GenesisCare UK’s retention policy for most medical records is 30 years. A copy of the policy can be provided upon request.

International transfers of your personal information

GenesisCare UK is part of a global organisation and we (or third parties acting on our behalf) may store or process personal information within the GenesisCare group of companies for administrative and management purposes. The group companies are located in Spain and Australia and the United States. This processing is based on our own or a third party’s legitimate business interests.

As a global organisation we may engage global suppliers for the provision of services to the GenesisCare Group of companies and such suppliers may also be located outside the UK.

Where we transfer your personal data to a third country or international organisation, we will ensure adequate safeguards and measures are in place to protect your personal data from unlawful use and ensure your fundamental rights are capable of being upheld. We would normally achieve this by:

  • Only transferring personal data to countries deemed capable of providing an adequate level of protection; or
  • Implementing Standard Contractual Clauses; and
  • Adopting technical, organisational and contractual measures, where required

In certain situations, it may be possible to legitimise the transfer by relying on a derogation. For example, if:

  • You have explicitly consented to the proposed transfer; or
  • The transfer is necessary for the performance of a contract.

If your permanent address is outside the UK, or your treatment is continuing outside the UK, we may send details of your treatment to individuals specifically to promote your ongoing care.

In all cases any transfer of your personal information will be compliant with applicable data protection law. If you would like further information regarding the steps we take to safeguard your personal information when making international transfers, please contact the DPO using the details at the foot of this Privacy Notice.

Your Rights and Your Personal Information

Under data protection law you have a number of specific rights in relation to the personal information that we hold about you. These include rights to know what information we hold about you and how it is used. You may exercise these rights at any time by contacting us using the details set out at the top of this privacy notice and without adversely affecting your care.

We will not usually charge for handling a request to exercise your rights. If we cannot comply with your request to exercise your rights we will usually tell you why.

There are some special rules about how these rights apply to health information as set out in legislation including the Data Protection Act as well as any secondary legislation which regulates the use of personal information.

If you make a large number of requests or it is clear that it is not reasonable for us to comply with a request then we do not have to respond. Alternatively, we can charge for responding.
1. The right to be informed – This is fulfilled through our privacy notices.
2. The right of access to your personal information – This includes details of the information we hold about you. You are usually entitled to a copy of the personal information we hold about you and details about how we use it. Your information will usually be provided to you in writing, unless otherwise requested. If you have made the request electronically (e.g. by email) the information will be provided to you by electronic means where possible. Please note that in some cases we may not be able to fully comply with your request, for example if your request involves the personal data of another person and it would not be fair to that person to provide it to you. The information will normally be provided free of charge and, unless there are grounds for extending the statutory deadline, the information will be provided to you within one month of receipt of your request. Please note we will generally also ask for confirmation of your identity and may need further information from you in order to locate the information, in which case the time period starts for providing the information to you starts from the date we have that detail.
3. The right to rectification – This enables you to require that incomplete information is completed, or incorrect information is corrected. This ensures your information is accurate and up-to-date. Unless there are grounds for extending the statutory deadline, we will respond within one month of receipt of a rectification request.
4. The right to erasure – This is also known as the right to be forgotten. In some circumstances, you have the right to request that we delete the personal information we hold about you. The broad principle underpinning this right is to enable you to request the deletion or removal of personal data where there is no compelling reason for its continued processing. If we have disclosed the personal data in question to third parties, we will inform them about the erasure of the personal data, unless it is impossible or involves disproportionate effort to do so. However, there are exceptions to this right and in certain circumstances we can refuse to delete the information in question.
For example, we do not have to comply with your request if:

  • it is necessary to keep your information for reasons of public interest, including public health,
  • for the purposes of establishing, exercising or defending legal claims,
  • where we have overriding legitimate business interests for processing the information,
    where the processing is necessary for medical diagnosis; for the provision of health or social care; or for the management of health or social care systems or services and where the data is being processed by or under the responsibility of a professional subject to a legal obligation of professional secrecy (e.g. a health professional), or
  • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes where the right is likely to render impossible or seriously impair the achievement of the research objectives.

If you make such a request and we comply with it, please be aware that we will retain a note of your name, the request made and the date we complied with it.
5. The right to restriction of processing – In some circumstances you have a right to ‘block’ or suppress processing of personal data. When processing is restricted, we are permitted to store the personal data, but not further process it other than in relation to the establishment, exercise or defence of legal claims or for reasons of important public interest. We are able to retain just enough information about you to ensure that the restriction is respected in future.
6. The right to data portability – Where you have provided the information to us, and where the processing is being carried out by automated means and based on your consent or pursuant to the performance of a contract with you, you have the right to obtain the information that GenesisCare UK processes about you and use it for your own purposes. This means you have the right to receive the personal information or where it is technically feasible, have the information transferred to an individual or organisation of your choice, and the information must be provided by us in an electronic format.
7. The right to object – you have the right to object to processing based on our legitimate business interests (including profiling), direct marketing (including profiling) and processing for purposes of scientific or historical research or statistical research purposes. The objection must be on grounds relating to your particular situation.
8. The right not to be subject to automated decisions – (i.e. decisions that are made about you by computer alone) that have a legal or other significant effect on you. GenesisCare UK does not carry out automated decision-making in relation to patients.. In the event that our policy in this respect changes, we shall update this privacy notice.
9. Your right to withdraw consent – In some cases to comply with data protection legislation we need your consent in order to use your personal information.
Where we rely on this, you have the right to withdraw your consent to our continuing and further use of your personal information. You can do this by contacting our DPO whose details are at the foot off this privacy notice.
10. Your right to complain to the Information Commissioners Office – You can complain to the Information Commissioner’s Office if you are unhappy with the way that we have dealt with a request from you to exercise any of these rights, or if you think we have not complied with our legal obligations. Whilst you are not obliged to do so, we would appreciate you making us aware of any issue prior to notifying the Information Commissioner’s Office and giving us the opportunity to respond. Please contact:

You can contact the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues, at casework@ico.org.uk, or at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF or telephone 0303 123 1113 (local rate call).  Website: https://ico.org.uk/

Making a complaint will not affect any other legal rights or remedies that you have.

Securing your data

We have implemented appropriate technical and organisational security to protect your personal information. This includes;


If you have any queries or would like to exercise your rights or to establish whether any rights apply to you, please speak with the GenesisCare Health Care Professional who is involved in your care.
You can also contact our Data Protection Officer:
Email: DPO@genesiscare.co.uk or write to GenesisCare, 69 Alma Rd, Windsor SL4 3HD, marking your communication “Private and Confidential – FAO GenesisCare Data Protection Officer”
Telephone: 07841 207263

Updates to this Privacy Notice
We may update this Privacy Notice from time to time to ensure that it remains accurate. In the event that these changes result in any material difference to the manner in which we process your personal data then we will provide you with an updated copy of the Policy and signpost you to the specific changes.

Data Protection Impact Assessments

GenesisCare carries out Data Protection Impact Assessments to identify and minimise the data protection risks of data processing activities undertaken.