Last reviewed: 26-Jan 2026
Next review: 25-Jan-2027
This privacy notice explains how Shakespeare Health Centre uses your personal information.
It applies to all registered patients and their carers.
This notice has been adapted from British Medical Association (BMA), NHS England, and Information Commissioner’s Office (ICO) guidance to ensure it meets national standards and legal requirements.
Who we are
Shakespeare Health Centre
, Elers Road, Hayes UB3 1NY, 02037943119, nhsnwl.shacadmin@nhs.net
We are the Data Controller, which means we decide how and why your personal information is used.
Data Protection Officer (DPO)
The Data Protection Officer for North West London GP practices is:
Norman Ernest-Williams – e.norman-williams@nhs.net
For day-to-day questions about your information or to exercise your rights, please contact the practice manager using the details above.
What information we hold
We hold information needed to provide you with safe and effective healthcare, including:
- Your name, address, date of birth, NHS number, and contact details
- Information about your health, medical conditions, test results, treatments, and medications
- Information from other NHS organisations involved in your care (for example hospitals or community services)
Your medical record may also include information such as ethnicity or other relevant details where this is necessary for your care.
Health information is classed as special category data and is given extra legal protection.
Why we use your information
1. Direct care (your individual healthcare)
We use your information to:
- Provide GP, nursing, and wider primary care services
- Make referrals, prescribe medication, and review test results
- Communicate with you by SMS, email, phone, letter, NHS App, or in person
- Share relevant information with other NHS services involved in your care, such as hospitals, pharmacies, and out-of-hours services
Automated searches of GP records
We routinely use approved computer systems to search GP records to identify patients who may need:
- Reviews or recalls
- Screening invitations
- Long-term condition monitoring
- Preventive care or additional support
These searches help us provide proactive care.
All results are reviewed by trained staff or clinicians.
We do not make fully automated decisions about your care.
2. Risk stratification and population health
We may use approved NHS systems to analyse information from GP records to help identify patients who may be at higher risk of illness or complications. This supports early intervention and better care planning. Where used:
- Information may be linked with data from other NHS services
- Analysis is carried out using secure, NHS-approved systems
- Identifiable information is only seen by authorised staff at the practice
You may have the right to object to this processing in some circumstances. Please speak to the practice if you would like more information.
3. Screening programmes
We support national and local screening programmes, including (but not limited to):
- Cervical, breast, and bowel cancer screening
- NHS Health Checks
- Diabetic eye screening and other local programmes
We may share limited contact information so that you can be invited for screening. You can choose not to take part in screening.
More information about screening and opt-out options is available at:
https://www.gov.uk/topic/population-screening-programmes
or speak to the practice.
4. Research, audit, and service improvement
We also use information to:
- Check the quality and safety of care (clinical audit)
- Improve services
- Support medical research and health service planning when the law allows
Where possible, information used for these purposes is anonymised or de-identified. Some research may take place without consent where allowed by law and with strict safeguards.
Some studies will ask for your explicit consent before using identifiable information.
You can opt out of your confidential information being used for research and planning.
This does not affect your direct care.
National Data Opt-Out
The National Data Opt-Out allows you to choose whether your confidential information is used for research and planning. It does not apply to direct care.
You can find out more or register your choice at:
https://www.nhs.uk/your-nhs-data-matters/
When the law requires us to share information
In some circumstances, we must share information by law, including:
- With NHS England to support NHS systems and patient registration
- With the Care Quality Commission (CQC) for regulation and inspection
- With the UK Health Security Agency or local health protection teams to report certain infectious diseases
- With the Medical Examiner Service when a patient dies, to support independent review of the death.
- If ordered to do so by a court of law
In these cases, you may not have the right to object.
Safeguarding
Sometimes we need to share information to protect:
- Children
- Vulnerable adults
- Other individuals at risk of serious harm
These situations are rare.
We do not need your consent to share information for safeguarding where the law requires or allows this.
Who we share information with
We only share information when necessary and lawful.
NHS and care organisations
- Hospitals and community services
- Pharmacies and out-of-hours services
- Other NHS organisations involved in your care
Approved data processors
We use trusted organisations to support our services under strict contracts and instructions, including:
- Optum (formerly EMIS) – GP clinical system
- Docman – document management
- Surgery Connect – telephone and communication services
- NWL WSIC – population health and analytics
- Data Care Solutions (CuraSky) – clinical and administrative support services
- SmartLife Health – administrative and operational tools
These organisations are not allowed to use your information for their own purposes.
Remote access to information (including outside the UK)
Some administrative support may be provided by authorised staff working remotely, either within the UK or outside the UK.
- Your data remains stored in UK-based systems
- Remote staff access information securely under UK instructions only
- No local copies of data are kept
- Contracts, access controls, monitoring, and UK GDPR safeguards are in place
All staff are subject to the same confidentiality and data protection requirements.
Our lawful basis for using your information
Under UK GDPR, we use your information because:
- It is necessary to provide NHS care and manage health services
(Article 6(1)(e) and Article 9(2)(h))
- Some research, audit, and planning is carried out in the public interest or using de-identified data
(Article 6(1)(e) and Article 9(2)(j))
- In some cases, we are required to share information by law (Article 6(1)(c) and, where applicable, Article 9(2)(h) or Article 9(2)(i)).
We also comply with the common law duty of confidentiality.
How we keep your information secure
We follow NHS and industry standards to protect your information, including:
- Secure IT systems and access controls
- Staff training and confidentiality obligations
- Audit logs and monitoring
- Policies and procedures for data protection and information governance
How long we keep your information
Medical records are kept in line with the NHS Records Management Code of Practice.
Information is only kept for as long as legally required.
Your rights
You have the right to:
- Access your medical record
- Ask for incorrect information to be corrected
- Ask for processing to be restricted in certain circumstances
- Object to some uses of your information, such as research
Some rights are limited for medical records where we are legally required to keep information. To make a request, please contact the practice.
Other information
If applicable, we may also collect information through:
- CCTV on practice premises
- Recorded telephone calls
- Our website (cookies)
Separate notices or policies are available for these where required.
Complaints
If you have concerns about how your information is used, please contact the practice first. You also have the right to complain to the Information Commissioner’s Office (ICO):
https://ico.org.uk Tel: 0303 123 1113