DGS Health Privacy Policy
Below explains how we use any information you give to us, and the ways in which we protect your privacy.
How we use your information
DGS Health is committed to ensuring that your privacy is protected. However, where you are receiving a service from DGS Health we are required to share that information with other organisations as part of your treatment and care. This is to ensure that your health records are accurate and up to date.
We may also use your information to inform, improve and maintain the services that we are delivering. This information may be included in reports that used by employed members of DGS Health to show how we are improving and maintaining services, however any identifiable information which can identify you will be removed and anonymised to preserve your privacy and confidentiality.
We will not sell, distribute or lease your information to any third parties, unless we have your permission to do so.
For more information on how we use your information please contact Umar Sabat, Data Protection Officer via e-mail on umar.sabat@ig-health.co.uk
DGS Health are one of the partner organisations to the Kent and Medway Care Record (KMCR). The KMCR is an electronic care record which links your health and social care information held in different provider systems, to one platform. This allows health and social care professionals who have signed up to the KMCR to access the most up to date information to ensure you receive the best possible care and support by those supporting you. In order to enable this sharing of information, organisations who use the KMCR have agreements in place that allow the sharing of personal and special category data.
For further information about the Kent and Medway Care Record and the ways in which your data is used for this system please click here.
DGS Health uses GP Connect, a platform which allows different systems to communicate so that clinicians in different care settings can view a patient’s GP record. You can find the GP Connect Privacy Notice here.
Data Protection
DGS Health is committed to ensuring that any information it collects and retains is kept safe and secure and in line with the Data Protection Act 2018 and General Data Protection Regulations (GDPR).
DGS Health has completed a number of requirements associated with changes in Data Protection law this includes
- Appoint a Data Protection Officer
- Continually reviewing and updating our policies and procedures
- Reviewing our Information Asset Register – This is a register that lists all our databases which hold corporate and patient information
- Ensuring that there are Data Protection Impact Assessments in place where it has been determined that the information being processed is high risk due to the amount of sensitivity of the information. A Data Protection Impact Assessment policy is now in place.
- Ensuring that any privacy notices are in included or on documentation where this will require personal information to be used.
In addition to this, DGS Health will also ensure adherence to the 7 Caldicott Principles.
Principle 1 – Justify the purpose for using confidential information
Principle 2 – Don’t use personal confidential data unless it is absolutely necessary
Principle 3 – Use the minimum necessary personal confidential data
Principle 4 – Access to personal confidential data should be on a strict need to know basis
Principle 5 – Everyone with access to personal confidential data should be aware of their responsibilities
Principle 6 – Comply with the law
Principle 7 – The duty to share information can be important as the duty to protect patient confidentiality
Security
We ensure your information is always secure. In order to prevent unauthorised access or disclosure we have put in place safeguards that protect physical, electronic and managerial procedures to secure information we collect. Please see our policies that show our commitment to ensuring information is safe.
- Information Governance Policy
- Data Protection Impact Assessment Policy
- Confidentiality Policy
- Acceptable Use Policy
Employees and contractors
DGS Health needs to process data about you because we enter in a contract with you. In Some cases, DGS Health also processes your data to comply with a legal obligation.
Therefore, we may process your data in several different ways
- Maintain accurate up to date employment record and contact details
- Operate and keep a record of disciplinary
- Keep a record of application form
- Obtain occupational health and support for you, sharing your information with consent
- Ensure effective HR and business administration
- Provide references on request for current and former employees.
In addition to this DGS Health works with appointed contractors that deliver clinical services on our behalf and your information will be shared with them for the purpose of delivering clinical care.
Further information
Questions, comments and requests regarding this privacy policy are welcome and should be addressed to:
Data Protection Officer
The Old Rectory,
Springhead Road,
Northfleet, Gravesend,
Kent, DA11 8HN.

