Staff Privacy Notice
The purpose of this Notice
This notice explains how Holmes Care Group Ltd. process personal data relating to current and former employees, workers, self-employed contractors and consultants, and voluntary workers, (you/your) and your rights in relation to the processing of your personal data. The information you provide to us will solely be used in connection with your employment with us.
The Company shall process staff personal data in order to function effectively. Personal data is processed for a variety of reasons (as set out below) and all such personal data will be collected and processed in accordance with the requirements of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA).
This notice does not form part of your contract with us.
About us
We are what is known as the 'controller' of personal data we gather and use. When we say 'we', 'us' or the 'Company' in this notice we mean Holmes Care Group Ltd.
In this notice:
- personal data means any information which can identify you directly or indirectly (whether itself or when combined with other data), regardless of the format or media on which the information is stored. This includes information that can identify you when combined with other information that is held separately (pseudonymous data).
- processing means any activity relating to your personal data including collection, use, alteration, storage, disclosure and destruction.
Changes to this notice
We may update this notice at any time and may provide you with further notices on specific occasions where we collect and process personal data about you. You should check this notice regularly to take notice of any changes, however where any change affects your rights and interests, we will make sure we bring this to your attention and clearly explain what this means for you.
What kinds of Personal Data we use
In the course of our working relationship with you, we will collect, store and use the following categories of personal data about you:
- Personal contact details such as name, title, addresses, telephone numbers, and personal email addresses;
- Date of birth;
- Gender;
- Next of kin and emergency contact information;
- National Insurance number;
- Bank account details, payroll records and tax status information;
- Salary, annual leave, pension and benefits information;
- Start date;
- Location of employment or workplace;
- Identification information (including a copy of driving licence, passport and utility bills);
- Recruitment information (including copies of right to work documentation, references and other information included in a CV or cover letter or as part of the application process);
- Employment records (including job titles, work history, working hours, training records and professional memberships);
- Compensation history;
- Performance information;
- Occupational health service information;
- Disciplinary and grievance information (including disciplinary matters, investigations, staff disputes and employment tribunals);
- CCTV footage and other information obtained through electronic means such as key fob records;
- Information about your use of our information and communications systems.
Some kinds of personal data are given special protection by law – these are called 'special category' data. We will sometimes collect, store and use the following types of 'special category' personal data:
- Trade union membership;
- Information about your health, including any medical condition, health and sickness records;
- Genetic information and biometric data (for example, photographs and images captured by our CCTV system);
- Information about your criminal convictions and offences (for example, DBS, PVG, SSSC, NMC and DVLA checks).
How we collect your personal data
We will obtain your personal data in different ways:
- Mostly, directly from you in the course of the application and recruitment process or during the course of your employment;
- During the recruitment process, from an employment agency or background check provider and your former employers]; and
How the Company uses personal data about you
We process personal data (including special categories of personal data) about you for the following purposes:
- primarily, so that we can fulfil our contractual obligations and legal obligations to you (for example, to pay you and provide benefits to you) and to exercise our legal rights; and
- to pursue legitimate interests of our own or those of third parties, provided your interests and fundamental rights do not override those interests, or where necessary to protect the interests of you or others (for example, monitoring misuse of our IT systems).
Lawful grounds for processing your personal data
We will only use your personal data when we are permitted to do so by law. We will use your personal data:
- to perform a contract Holmes Care Group Ltd. has entered into with you or take steps before entering into a contract with you at your request (for example, your employment contract or contract for services)
- to comply with our legal obligations for example, complying with employment and tax, immigration, health and safety and safeguarding laws, preventing and detecting crime, assisting the police and other authorities with their investigations
- where necessary for our legitimate interestsor those of a third party (e.g. CQC, CI, SSSC, NMC) provided your interests and rights do not override those interests (for example, evaluating the suitability of a candidate for a role or defending employment claims brought by you)
- to protect your vital interests or those of another person (for example, where we know or have reason to believe that you or another person may suffer harm)
In limited circumstances, we may ask you for consent to allow us to process certain personal data. If we do, we will provide you with the full details of the information that we would like and the reason we need it so that you can consider whether you wish to consent. Your consent must be freely given and you have the right to withdraw this at any time.
If you choose not to provide us with certain personal data you should be aware that we may not be able to carry out certain parts of our contract with you. For example, if you do not provide us with your bank account details, we will not be able to pay you.
Sharing your personal data with third parties
Where the Company has lawful grounds for doing so, we may share your personal data with third parties where required by law, where we have a legitimate interest, where it is necessary to administer the working relationship with you or, if necessary, with your consent. Those third parties include the following:
- Scottish Social Services Council (SSSC)
- Nursing and Midwifery Council (NMC)
- Care Quality Commissioner (CQC)
- Care Inspectorate (CI)
- UK Visas and Immigration
- HM Revenue and Customs (HMRC)
- pension schemes (NEST)
- payroll providers
- benefits providers
- trade unions
- potential employers (where a reference is requested)
- Department for Work and Pensions (DWP) as required by the Social Security Administration Act 1992
- Child Maintenance Service as required by the Child Support Information Regulations 2008
- Other Regulatory bodies
- Courts when required to do so to process payments for Attachments of Earnings
- IT service providers
Where we use third parties to process personal data on our behalf (acting as data processors), a written contract will be put in place to ensure that any personal data shared will be held in accordance with the requirements of data protection law and that such data processors have appropriate security measures in place in relation to your personal data. Parents, children, other family members and guardians are considered to be third parties and your personal data will not be disclosed to such persons unless you have given your consent or the disclosure is otherwise made in accordance with data protection law.
Holmes Care Group Ltd requires these third parties to comply strictly with our instructions and they do not use your personal information for their own business purposes unless you have explicitly consented to the use of your personal information in this way.
Please note that we may need to share your personal information with a regulator or to otherwise comply with the law, and the list above is not necessarily exhaustive.
Where your personal data are stored
Most personal data about you, including your personnel file, will be stored on servers within the UK or elsewhere within the European Economic Area (EEA) or in physical secure paper filing cabinets in the UK. We will ensure your personal data is transferred securely and your personal data will not be transferred outside of the EEA.
How we keep your personal data secure
Holmes Care Group Ltd has put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used or accessed in any unauthorised way or altered or disclosed. In addition, the Company limits access to your personal data to the persons and organisations, including those described above, who have a lawful and legitimate need to access it.
The Company has also put in place procedures to deal with any suspected personal data security breach and will notify you and any applicable regulator of a suspected breach where legally required to do so (please see GDPR policy, available via the Employee Zone website, for further information).
How long we will retain your personal data
Your personal information will be retained on our systems for the duration of your employment or as long as necessary to fulfil the purposes for which the information was collected, or as required by law and to satisfy any legal, regulatory, accounting or reporting requirements.
Specified retention periods are applied to each category of personal data that we may process about you. In setting these retention periods, the Company has taken into account:
- the nature, sensitivity and volume of the personal data
- the potential risk of harm to you arising from the continued retention of the personal data
- the purposes for which the Company may process your personal data
- whether the Company is required to retain any personal data by law or in accordance with its legitimate interests
Generally speaking, all relevant correspondence in relation to your employment or engagement will be held by Human Resources and retained for six years after you have left the Company or your engagement has ceased, after which time it will be securely disposed of. Basic information about your employment or engagement (appointment, dates of service etc) will be retained indefinitely.
If notice of a claim or Pre-Action or Early Conciliation correspondence is received, then we may retain and process relevant personal data to defend the claim for the duration of the proceedings. Whilst we may dispose of any personal data after the conclusion of the claim, please be aware that all litigation documents disclosed or evidence given may be a matter of public record indefinitely.
Your responsibilities
You must ensure that any personal data collected and processed by you in the course of performing your duties and obligations is held in accordance with the Holmes Care Group Data Protection Policy (which can be found on the Employee Zone website or you can ask your Manager for a copy).
Members of staff are able to notify the Company of any changes to their contact details via their home administrator or line manager, and via our annual data update forms. It is important the Company has an accurate record of staff details in case there is a need to make contact with staff in emergency circumstances.
Your rights
You have a number of rights in relation to the processing of your personal data by the Company:
- Access: You have the right to request access to and be provided with a copy of the personal data held about you together with certain information about the processing of such personal data to check that the Company is processing it lawfully and fairly.
- Correction: You have the right to request correction of any inaccurate or incomplete personal data held about you.
- Deletion: You have the right to request erasure of any personal data held about you where there is no good reason for the Company to continue processing it or where you have exercised your right to object to the processing of your personal data.
- Restriction: You have the right to request restriction of how the Company processes your personal data; for example, to confirm its accuracy or the Company’s reasons for holding it or as an alternative to its erasure.
- Objection: You have the right to object to the Company’s processing of any personal data which is based on the legitimate interests of the Company or those of a third party based on your particular circumstances. You also have the right to object to the Company processing your personal data for direct marketing purposes.
- Portability: You have the right to receive or request that the Company transfers a copy of your personal data in an electronic format to you or a third party
- No automated-decision making: Automated decision-making takes place when an electronic system uses personal data to make a decision without human intervention. You have the right not to be subject to automated decisions that will create legal effects or have a similar significant impact on you, unless you have given us your consent, it is necessary for a contract between you and us or is otherwise permitted by law. You also have certain rights to challenge decisions made about you. We do not currently carry out automated decision-making in the course of you working with us, but we will notify you in advance if this changes.
- Complaints: You have the right to complain to the Information Commissioner’s Office (ICO) or any other EU supervisory authority in relation to how the Company processes your personal data at https://ico.org.uk/ .
In order to exercise any of these rights you should contact the Company's Data Protection Team at GDPR@holmes-care.co.uk. The Company may be entitled to refuse any request in certain circumstances and where this is the case, you will be notified accordingly.
You will not have to pay any fee to exercise any of the above rights, though the Company may charge a reasonable fee or refuse to comply with your request if any request is clearly unfounded or excessive. Where this is the case, you will be notified accordingly.
To protect the confidentiality of your personal data the Company may ask you to verify your identity before fulfilling any request in relation to your personal data.