Privacy

Privacy notice

As data controllers, GPs have fair processing responsibilities under the Data Protection Act 2018 and the General Data Protection Regulation (GDPR). This means ensuring that your personal confidential data (PCD) is handled in ways that are safe, transparent and what you would reasonably expect. Please find documents and links below.

Data Protection Officer (DPO)

If you have any concerns about how your data is shared, then please contact the Practice Data Protection Officer, Caldicott Guardian or IG Lead.

If you would like to know more about your rights in respect of the personal data that we hold about you, please use the contact details below:

IG Lead: Dr John Martin, GP Partner

Caldicott Guardian: Julie Oliver, Practice Manager

Data Protection Officer:

Head of Information Governance MLCSU,
Heron House, 120 Grove Road, Fenton, Stoke-on-Trent, ST4 4LX
Tel 01782 916875

Email [email protected]

Please read our Privacy Notice Introduction below or download our Full Privacy Notice

Introduction

This privacy notice lets you know what happens to any personal data that you give to us, or any information that we may collect from you or about you from other organisations. Please see our Full Privacy Notice.

This privacy notice applies to personal information processed by or on behalf of The Castle Medical Group.

This Notice explains:

  • Who we are and how we use your personal information?
  • Information about our Data Protection Officer
  • What kinds of personal information we hold about you and what information we use
  • The legal grounds for processing your personal information, including when we share it with other organisations.
  • What to do if your personal information changes
  • For how long your personal information is retained for/stored by us
  • What your rights are under Data Protection laws

The General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA18) became law on 25th May 2018. The GDPR is a single EU-wide regulation on the protection of confidential and sensitive information and the DPA18 implements the regulations into comprehensive UK legislation. Following the decision for the UK to leave the European Union and following the end of the transition period, from January 1st, 2021, the UK has been subject to an Adequacy Agreement which will allow data to continue to be shared with European Union Countries without further safeguarding being necessary. This is to allow the European Commission suitable time to grant the UK with adequacy status, meaning they have met the required standards in ensuring data transfers to and from the UK are safe. All references to GDPR will now be referred to as UK GDPR.

For the purpose of applicable data protection legislation (including UK GDPR) and the Data Protection Act 2018 the practice responsible for your personal data, and referred to at the Data Controller, is The Castle Medical Group.

This Notice describes how we collect, use, and process your personal data, and how in doing so, we comply with our legal obligations to you. Your privacy is important to us, and we are committed to protecting and safeguarding your data privacy rights.

Date published: 20th September, 2023
Date last updated: 26th May, 2026