Your Privacy, Protected
How Sonar Informatics LTD collects, uses, retains and discloses personal information - and your rights under UK data protection law.
What is a Privacy Notice?
A privacy notice is a statement that describes how Sonar Informatics LTD collects, uses, retains and discloses personal information.
To ensure that we process your personal data fairly and lawfully we are required to inform you:
- Why we need your data
- How it will be used and
- Who it will be shared with
- How we keep it secure
- Your rights under UK data protection law.
This information also explains what rights you have to control how we use your information.
The law determines how Sonar Informatics LTD can use personal information. The key laws are: the Data Protection Act 1998 (DPA), the Human Rights Act 1998 (HRA), Relevant health service legislation, and the Common law duty of confidentiality.
Within these pages we describe instances where Sonar Informatics LTD is the "Data Controller", for the purposes of the Data Protection Act 1998 (DPA), and where we direct or commission the processing of patient data to help deliver better healthcare, or to assist the management of healthcare services.
Sonar Informatics LTD recognises the importance of protecting personal and confidential information in all that we do, all we direct or commission, and takes care to meet its legal duties.
Complaints about how we process your personal information
This part of the fair processing notice outlines the management of the notice, contact details and other access to information legislation.
In the first instance, you should contact us
Changes to our fair processing notice
We keep our fair processing notice under regular review and we will place any updates on this web page. This notice was last updated on 15/01/2018.
Data Protection Notification
How to contact us
Please contact us if you have any questions about our privacy notice or information we hold about you:
What information do we collect about you?
We only collect and use your information for the purposes of public health services of NHS England. These purposes include:
- Accounts and records
- Health administration and services
- Information and databank administration
- Research
What types of personal data do we handle?
We process personal information to enable us to support the provision of healthcare services to patients.
We also use information to support and monitor the health services commissioned in England to enable the delivery of high quality healthcare. This type of information will usually be provided to NHS England in an aggregate or anonymised form, so that we cannot identify an individual.
The types of personal information we use include:
- personal details such as names, addresses, telephone, NHS numbers
- family details for example next of kin details
- education, training, mostly frequently of clinicians such as GPs
- employment details, for example as to what occupational category
- services, for example details of the services access or offered by providers
- lifestyle and social circumstances
- details held in the patient's record, where we hold or manage the patient's record
- responses to surveys, where individuals have responded to surveys about healthcare issues
We also process sensitive classes of information that may include:
In terms of patient information, information may include:
How will we use information about you?
Your information is used to run and improve the NHS in England. It may be used to:
- Check and report on how effective NHS England and the services it commissions has been
- Investigate complaints, legal claims or important incidents
- Make sure services are planned to meet patients' needs in the future
- To improve the efficiency of healthcare services, by sharing information with other organisations for a specific, justified purpose and approved by Sonar Informatics' Caldicott Guardian.
Whenever possible all information that identifies you will be removed.
Retaining information
We will only retain information for as long as necessary. Records are maintained in line with the NHS England retention schedule which determines the length of time records should be kept.
Security of your information
We take our duty to protect your personal information and confidentiality seriously. We are committed to taking all reasonable measures to ensure the confidentiality and security of personal data for which we are responsible.
We have appointed a "Senior Information Risk Owner" (SIRO) who is accountable for the management of all information assets and any associated risks and incidents, and a "Caldicott Guardian" who is responsible for the management of patient information and patient confidentiality.
Sonar uses industry recognised security controls including:
- Encrypted communications, multi-factor authentication, audit logging
- Routine security monitoring, penetration testing, etc
These measures help protect information from unauthorised access, loss, alteration or disclosure.
How to access your personal information
The Data Protection Act 1998 gives you the right to see the information that Sonar Informatics holds about you and why. Requests must be made in writing and you will need to provide:
- adequate information [for example full name, address, date of birth, NHS number, etc.] so that your identity can be verified and your information located.
- an indication of what information you are requesting to enable us to locate this in an efficient manner.
For all other personal information held by Sonar Informatics, requests should be sent to the Customer Contact Centre.
We aim to comply with requests for access to personal data as quickly as possible. We will ensure that we deal with requests within 30 days of receipt unless there is a reason for delay that is justifiable under the Data Protection Act 1998.
We want to make sure that your personal information is accurate and up to date. If you think any information is inaccurate or incorrect then please let us know through the Customer Contact Centre.
Use of your NHS Number
If you are receiving support from a public health service e.g. The London Pharmacy Vaccination Service, New Medicine Service (NMS), Medicine Use Review (MUR), etc. Then we may share your NHS Number with the relevant clinician (GP, Pharmacy, Hospital, etc.) (Only if you have given explicit consent). This is so that SonarHealth and the relevant clinician (GP, Pharmacy, Hospital, etc) are using the same number to identify you whilst providing you care.
Your NHS Number is accessed through an NHS Service called the Personal Demographics Service (PDS), SonarHealth sends basic information such as your name, address and date of birth to the PDS in order to find your NHS Number. Once retrieved from the PDS the NHS Number is stored in the SonarHealth System.
The addition of the NHS Number to public health data will bring additional benefits:
- Better coordinated and safer care across public health care bodies enabled through the sharing of real-time information.
- Less paperwork and more efficient use of public health care resources.
You have the right to object to the processing of your NHS Number in this way. This will not stop you from receiving care, but will result in the benefits outlined above not being realised. To help you decide, we will discuss with you how this may affect our ability to provide you with care, and any other options you have.
If you wish to opt-out from the use of your NHS Number for public health care purposes, please contact us.
Recall of consent & data erasure New
The New GDPR Regulations gives you the right to recall of consent (when explicitly given to any service provider using SonarHealth) or to request your information be removed from the SonarHealth system. Requests must be made in writing and you will need to provide:
- adequate information [for example full name, address, date of birth, NHS number, etc.] so that your identity can be verified and your information located.
- an indication of what information you are requesting to enable us to locate this in an efficient manner.
For all other personal information held by Sonar Informatics, requests should be sent to the Customer Contact Centre.
We aim to comply with requests for access to personal data as quickly as possible. We will ensure that we deal with requests within 30 days of receipt unless there is a reason for delay that is justifiable under the Data Protection Act 1998.
We want to make sure that your personal information is accurate and up to date. If you think any information is inaccurate or incorrect then please let us know through the Customer Contact Centre.
