Skip to content

GDPR Policy

This policy sets out how Mission Healthcare meets its responsibilities under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to every director, employee, bank worker, volunteer and contractor who handles personal information on our behalf. It sits alongside our Privacy Policy, which explains in plain language what we do with the information we hold about the people we support.

Last reviewed: September 2026. Next review: September 2027. Available in large print, easy read or another format on request.

Why this matters in care

We hold some of the most sensitive information there is: people’s health conditions, medication, mental capacity, finances and family circumstances. Handling it properly is not an administrative detail — it is part of treating people with dignity. Everyone who works for us is responsible for protecting the information they see, and that responsibility continues after they leave.

The principles we work to

The UK GDPR requires that personal information is:

  • processed lawfully, fairly and transparently
  • collected for specified, explicit and legitimate purposes only
  • adequate, relevant and limited to what is necessary
  • accurate and kept up to date
  • kept no longer than is necessary
  • kept secure, including against unlawful processing, loss or damage

We are accountable for meeting these principles and for being able to show that we meet them.

Responsibilities

  • The Directors are accountable for data protection at Mission Healthcare. They approve this policy, oversee our records, respond to requests from individuals and report breaches.
  • Care staff must record accurately and factually, keep records secure while they are in their possession, never discuss a client outside work, and never share information on personal messaging apps or social media.
  • Everyone must report a suspected breach as soon as they become aware of it — the same day, without exception.

Lawful bases

We identify and record a lawful basis before we process personal information. For care records we normally rely on contract, legal obligation and, for health information, Article 9(2)(h) of the UK GDPR — processing necessary for the provision of health and social care. We rely on consent only where a use is genuinely optional, such as marketing, and we make it easy to withdraw.

Keeping information secure

  • access is limited to the staff who need it for their role
  • paper records are kept in locked storage and never left in vehicles or homes
  • devices are password-protected, encrypted where possible and never shared
  • information is sent securely, and we check email addresses before sending
  • our suppliers are bound by written agreements requiring them to protect the information they hold for us
  • records are destroyed securely at the end of their retention period

Requests from individuals

Anyone can ask for a copy of the information we hold about them, ask us to correct it, ask us to delete or restrict it, object to our using it, or ask for it in a portable format. Requests can be made in any form, including verbally, and do not have to mention data protection or use any particular wording.

Any member of staff who receives such a request must pass it to a Director the same day. We respond within one month. We may extend this by a further two months for complex requests, and we will explain why if we do. We will confirm the identity of the person making the request, and where a representative acts on someone’s behalf we check that they are entitled to do so.

Personal data breaches

A breach is any incident where personal information is lost, stolen, destroyed, altered or disclosed to the wrong person — including a lost care folder, an email sent to the wrong address or a conversation overheard in public. Staff must report it immediately. We record every breach, take steps to limit the damage, and assess the risk to the people affected. Where the breach is likely to result in a risk to their rights and freedoms, we report it to the Information Commissioner’s Office within 72 hours, and we tell the people affected where the risk is high.

Sharing information with other professionals

We share information on a need-to-know basis with the GPs, nurses, therapists, social workers and commissioners involved in someone’s care, and with the local authority, the NHS or the police where the law requires it or where someone may be at risk of harm. Safeguarding always takes precedence over confidentiality: if a person is at risk, we share what is necessary to protect them. See our Safeguarding Policy.

Training, monitoring and review

Data protection is covered in induction and refreshed at least every year. Spot checks and supervision include how records are completed and stored. This policy is reviewed every year, and sooner if the law or our systems change.

Questions or concerns

Contact us on +44 7470 367 720 or at admin@missionhealthcare.co.uk. You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.