Service User Privacy Notice
1. Purpose
Equilibria Health (Glasgow) Ltd. & Equilibria Neurodivergence Service Ltd. is committed to managing information in a lawful, secure, confidential, and transparent manner. This policy sets out how personal data—including service user identifiable information—is collected, used, stored, shared, protected, and disposed of, in compliance with UK data protection legislation, professional standards, and best practice.
2. Scope
This policy applies to all service users, staff, contractors, and other parties who handle personal information on behalf of the organisation. It covers both electronic and paper-based records relating to service users, staff, and organisational processes.
3. Legal Framework and Responsibilities
The organisation complies with all relevant data protection laws, including the UK GDPR and the Data Protection Act 2018. Personal information will only be processed where there is a lawful basis such as consent, contract, or legal obligation. Individuals have rights under data protection law including access, rectification, and erasure.
4. Collection and Use of Personal Information
The organisation collects personal information necessary to provide clinical care and services. This may include:
1. Identifiers such as name, contact details, date of birth, gender, and pronouns
2. Health-related information including medical history, conditions, test results, allergies, and care needs
3. Emergency contacts and next of kin
4. Insurance and payment details where applicable
The lawful basis for processing personal data will be documented and explained to service users at the point of collection.
5. Privacy and Confidentiality
Equilibria Health is subject to a common law duty of confidentiality. Personal health information will not be disclosed without appropriate consent, except where there is an overriding legal requirement or where disclosure is necessary for safeguarding, public protection, or other statutory purposes.
Service user confidentiality is central to the organisation’s values and is supported by secure information governance arrangements.
6. Caldicott Principles and Guardian
The organisation adheres to the Caldicott Principles, which are a set of recognised standards for handling confidential health and care information:
1. Justify the use of confidential information
2. Use personal data only when necessary
3. Use the minimum required information
4. Restrict access on a need-to-know basis
5. Ensure those handling data understand their responsibilities
6. Comply with the law
7. Recognise that sharing information for care can be as important as protecting confidentiality
8. Inform service users about how their data is used
A Caldicott Guardian will be appointed as a senior lead with responsibility for ensuring that confidential information is used ethically, appropriately, and lawfully. The Caldicott Guardian provides oversight and advice for data governance decisions, particularly where disclosure may be sensitive or unclear.
Equilibria Health (Glasgow) Ltd. & Equilibria Neurodivergence Service Ltd.'s Caldicott Guardian is encompassed in the Head of Operations role.
7. Data Minimisation and Access Control
Personal data collected and held by the organisation will be:
1. Limited to what is necessary for the specified purpose
2. Adequate, relevant, and not excessive
3. Accessed only by authorised personnel on a need-to-know basis
Staff will receive guidance and training on information handling, confidentiality obligations, and secure information management procedures.
8. Security and Storage
All data is stored securely on encrypted, off-site servers with appropriate technical safeguards to prevent unauthorised access, loss or theft. Physical records are stored securely and access is controlled. Backup and recovery procedures are maintained in line with organisational and legal standards.
All of our data is held on secure off-site servers. All data centres used by Equilibria Health (Glasgow) Ltd. & Equilibria Neurodivergence Service Ltd. are protected in compliance with SAS 70 Type II (which includes access to the physical storage media based on biometric data and maximum protection against intrusion) and conform to the Safe Harbor standard.
9. Data Sharing
Personal information will only be shared with third parties where:
1. Consent has been obtained from the individual
2. There is a legal requirement to do so
3. It is justified in the public interest or for safeguarding purposes
4. It is necessary for service user care or statutory reporting
Where data is shared outside of the UK, appropriate safeguards are applied to comply with UK GDPR requirements.
10. Retention
Personal information is retained in accordance with applicable legislative and regulatory requirements.
Information collected for patient care and the provision of services, pharmaceutical products or other goods will generally be retained for seven years. This includes names, addresses, contact details, gender, pronoun preferences, dates of birth, National Insurance numbers, next of kin and emergency contact details, insurance information, medical history, care requirements and test results.
Information retained for the prevention, detection, investigation or prosecution of crime, including names, addresses and contact details, will be retained for seven years.
Information required for safeguarding or public protection purposes will be retained for seven years. This may include contact and emergency contact details, health information, care requirements and relevant test results.
Information used to provide patient app or portal functionality, including names, contact information and identification documents, will be retained for seven years.
Information connected with enquiries, complaints or claims will generally be retained for seven years. This includes names, contact details, addresses, correspondence and all patient notes prepared by a treating therapist or assessing psychologist.
Payment details and financial transaction information will be retained for five years.
Where information is relevant to an ongoing complaint, legal claim, investigation, safeguarding concern or regulatory requirement, it may be retained beyond the standard period until the matter has concluded and any additional retention requirements have been met.
10.5. Disposal
When personal data is no longer required, it will be disposed of securely and in a manner that protects confidentiality. Information will only be destroyed once the appropriate retention period has expired and there is no ongoing clinical, legal, or regulatory reason to retain.
At the end of the retention period:
-
Electronic records will be permanently deleted from live systems and, where practicable, from backups in accordance with the organisation's backup retention schedule.
-
Paper records will be cross-cut shredded or disposed of using a confidential waste disposal service that provides secure destruction.
-
Portable media (e.g. USB drives, hard drives) containing personal data will be securely wiped using industry-standard methods or physically destroyed where secure erasure is not possible.
-
A record of data destruction may be maintained where appropriate, including the date of destruction and the categories of records destroyed.
-
Data subject to ongoing legal proceedings, complaints, investigations, safeguarding concerns or statutory requirements will not be destroyed until those matters have been concluded and any extended retention requirements have been met.
All destruction of personal information will be carried out in accordance with the UK GDPR, the Data Protection Act 2018, NHS Records Management Code of Practice (where applicable).
11. Data Subject Rights
Individuals have rights under data protection law including:
1. The right of access to their personal data
2. The right to request correction of inaccurate data
3. The right to restriction of processing
4. The right to erasure (where lawful)
5. The right to object to processing
6. The right to data portability
Requests will be handled in line with statutory timeframes and organisational procedures.
12. Complaints and Breaches
Service users may raise concerns about data handling through the organisation’s complaints process. Serious data breaches must be reported to the Information Commissioner’s Office (ICO) where required by law.
13. Training and Awareness
All staff must complete relevant training in data protection, confidentiality, and information governance. Refresher training will be provided regularly to ensure compliance with evolving legal and professional requirements.
14. Policy Review
This policy will be reviewed and updated periodically to reflect changes in legislation, guidance, organisational practice, or technological developments. This policy is publicly available to view in accessible formats at www.equilibriahealth.com/datapolicy