SKC Occupational Health Ltd as both the Data Controller and Data Processor is committed to protecting the rights of the individual and acknowledges that any personal data of yours that we handle will be processed in accordance with the current General Data Protection Regulations (GDPR) 2018

What Data will be collected?
The following data maybe collected, held, and shared by SKC OH Ltd:
• Personal information (e.g. Name, Address, Date of Birth)
• Characteristics (ethnicity, gender)
• Past and present Job roles
• Health Records

Who will it be collected from?
• Human Resources
• Managers
• Employees
• Occupational Health Physicians
• Other health professionals (e.g. GP, specialist, physio).

How will it be collected?
• Post
• E mail
• Verbal (either face to face, telephone or video consultations)
• Health Questionnaires
• Health Assessment (e.g. skin or vision assessment).

Why is it collected?
• For the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, to ensure the health and safety of the employees at work and to allow consideration of any adjustments that may be required to support their ability to work.
• Data may also be used for research, audit or statistics but will be anonymised if this is the case.
Lawful Basis for processing the information.
1. Article 6(1) (f) Processing is necessary for the purposes of the legitimate interests (see note 1) pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
2. Additional condition for the processing of Special Category Data Article 9(2) (h) Processing is necessary for the purposes of Occupational Medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health and
social care or treatment, or the management of health or social care systems and services on the basis of EU or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in in para 3 (below).
Article 9(3)2 Personal data may be processed for the purposes referred to in (2)(h) when those data are processed by or under the responsibility of a professional subject to the obligation of professional secrecy under EU or Member State law or rules established by national competent bodies.

How long will data be held for?
• Management referral information will be held for 6 years after the employee has left their job or 75 years of age (whichever is soonest) as recommended by the British Medical Association (BMA)
• Preplacement medicals will be discarded after 2 years if the employee doesn’t take up the offer of the job.
• 40 years in relation to Health Surveillance as required by the Health and Safety Executive (HSE)

How will the data be stored?
• Your records will be stored in accordance with SKC OH Ltd.’s medical records storage policy in accordance with GDPR regulations.
• Most of the information we hold is electronic. In some limited cases we do still hold paper records
• Our computer servers are located in England and your information is not stored or held outside the UK.
• Some records are kept digitally on a separate online drive and are password protected or encrypted.

Who will my information be shared with?
• Information about you will not be shared with third parties without your consent unless the law allows this, or there is a serious risk to life.
• Results of Health Surveillance will be passed on to the employer under Reg. 11 COSHH Regulations 2002 and ACOP 2103 for retention as required by the Health and Safety Executive (HSE).

What are your rights?
• You have the right to see any information held about you in your Occupational Health Clinical Record. The request should be made in writing and will be responded to within 4 weeks, without charge.
• You can also request that an amendment is attached to it if you believe any of the information held by SKC OH Ltd is inaccurate or misleading.
• You have the right to withdraw consent at any time, for any reason. Please ensure SKC Occupational Health has received this information.
• In the case of request for erasure, retention may be lawful (e.g. if required for legal compliance).

SK Chantry BSC Hons SCPHN-OH Dip HE RN Queens Nurse
Clinical Director SKC OH Ltd.

