Data Protection Policy

Scope of the Policy

This policy applies to the work of homeopath Karen Gwynn.

It sets out the requirements I must follow when gathering personal information for professional purposes. It explains how personal information will be collected, stored and managed in accordance with data protection principles and the General Data Protection Regulation.

This policy is reviewed on an ongoing basis to help ensure continued compliance. It should be read alongside my Privacy Policy.

Why This Policy Exists

This data protection policy ensures that I:

  • Comply with data protection law and follow good practice.

  • Protect the rights of patients.

  • Am open about how I store and process patients’ data.

  • Protect myself against the risks of a data breach.

Data Protection Principles

The General Data Protection Regulation identifies eight data protection principles:

  1. Personal data must be processed lawfully, fairly and transparently.

  2. Personal data may only be collected for specified, explicit and legitimate purposes. It must not be processed further in a way that is incompatible with those purposes.

  3. The collection of personal data must be adequate, relevant and limited to what is necessary for the purpose for which it is collected.

  4. Personal data must be accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that inaccurate personal data is erased or corrected without delay.

  5. Personal data that allows individuals to be identified must not be kept for longer than necessary.

  6. Personal data must be processed in accordance with individuals’ rights.

  7. Personal data must be processed securely. This includes protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

  8. Personal data must not be transferred to a country or territory outside the European Union unless that country or territory provides an adequate level of protection for individuals’ rights and freedoms in relation to the processing of personal data.

Some of these principles are explained in more detail below.

Lawful, Fair and Transparent Data Processing

I request personal information from patients and potential patients for the purpose of consulting with them and providing advice and guidance on homeopathic treatments.

Forms used to request personal information will contain a privacy statement explaining:

  • Why the information is being requested.

  • How the information will be used.

Patients will be asked to provide consent for their data to be held. A record of this consent, together with the patient’s information, will be stored securely.

Patients will be informed that they may withdraw their consent at any time and will be told what to do should they wish to do so.

Processing for Specified, Explicit and Legititimate Purposes

Patients will be informed about how their information will be used. I will take reasonable steps to ensure that patients’ information is not used inappropriately.

Appropriate uses of information provided by patients include:

  • Communicating with patients to arrange, change or cancel consultations.

  • Assessing the conditions and concerns reported by patients.

  • Devising and prescribing relevant remedies and/or therapies.

I will ensure that patients’ information is managed in a way that does not infringe their individual rights. These rights include:

  • The right to be informed.

  • The right of access.

  • The right to rectification.

  • The right to erasure.

  • The right to restrict processing.

  • The right to data portability.

  • The right to object.

  • The right to raise a concern or complaint.

Adequate, Relevant and Limited Data Processing

Patients will only be asked to provide information that is relevant to supporting consultations and prescriptions.

This may include:

  • Name.

  • Date of birth.

  • Gender.

  • Postal address.

  • Email address.

  • Telephone number.

  • Medical history.

Where additional information is required, it will be obtained with the patient’s specific consent. The patient will be informed why the information is required and how it will be used.

There may be occasional circumstances in which a patient’s information needs to be shared with a third party, such as following an accident or incident involving statutory authorities.

Where sharing information is in the best interests of the patient or myself, or where I have a substantiated concern, it may not be necessary to obtain the patient’s consent.

Accuracy of Data and Keeping Data Up to Date

I am responsible for taking reasonable steps to ensure that patients’ information is kept up to date.

Patients are responsible for informing me if any of their personal information changes.

Accountability and Governance

I am responsible for ensuring that my practice remains compliant with data protection requirements and can provide evidence of that compliance.

Anyone from whom personal data is collected will be asked to provide written consent where appropriate. Evidence of this consent will be stored securely as a record of compliance.

Secure Processing

I am responsible for ensuring that personal data is stored and processed securely.

Measures include:

  • Using strong passwords for information held within computer systems.

  • Restricting access to computer-based and paper-based files.

  • Using password protection on laptops and computers that contain or provide access to personal information.

  • Using password-protected or secure cloud-based systems.

  • Maintaining appropriate antivirus and firewall software to protect computer-based systems.

Subject Access Requests

Patients are entitled to request access to the personal information I hold about them.

Requests must be made to me in writing.

On receipt of a request, I will formally acknowledge it and respond within 14 days, unless exceptional circumstances prevent the request from being completed within that time.

I will provide a written response detailing the relevant information held about the patient. A record will be kept of the date the request was received and the date the response was provided.

Data Breach Notification

If a data breach occurs, I will take appropriate action to minimise any harm.

I will inform affected patients where I believe their personal information may have been compromised. Where necessary, the Information Commissioner’s Office will also be notified.

If a patient contacts me because they believe a data breach has occurred, I will ask them to provide an outline of their concerns.

Where the initial contact is made by telephone, I will ask the patient to follow it up with an email or letter setting out the details of their concern.

The concern will then be investigated fully and a response will be provided to the patient.

All suspected breaches will be subject to a full investigation. Appropriate records will be kept, and everyone involved will be informed of the outcome where appropriate.

Data Protection Concerns and Complaints Procedure

To raise a data protection concern or complaint:

  • Contact Karen in writing using the contact details below and explain the nature of your concern or complaint.

  • I will acknowledge receipt of the concern or complaint within 30 days.

  • Concerns and complaints will be investigated thoroughly and responded to within a reasonable timeframe.

  • Complainants will be kept informed of progress, and an outcome will be provided as quickly as reasonably possible.

Contact Information

Karen Gwynn
4 Fulton Close
Harwood Park
Bromsgrove
Worcestershire
B60 2HA

Email: [email protected]
Telephone: 01527 872122
Mobile: 07527 495417

Next Policy Review

The next policy review is due on 1 July 2028.