top of page

Data Retention and Security Policy

Purpose

The purpose of this policy is to ensure that White Rose Psychology Practice Ltd and its staff (meaning permanent, fixed term, and temporary staff, any third party representatives or sub-contractors, agency workers, volunteers, interns and Associates engaged with White Rose Psychology Practice Ltd are trained and aware of how to conduct their business practices in a manner compliant with the Data Protection Act 1998 (“DPA”) and the General Data Protection Regulations (GDPR:2016) and its principles to ensure that all Personally Identifiable Information (PII) is secure, accurate and up-to-date at all times. This policy forms part of the Associates agreement with White Rose Psychology Practice.

Scope

This policy applies to all members of the organisation and those contracted to work on behalf of White Rose Psychology Practice Ltd and is to be followed at all times. Its aim is to protect the rights of individuals and applies to all personal and sensitive information that is used, stored and transmitted either electronically or via paper-based methods.

Objectives

The objective of this policy is to protect the rights of individuals with regards to the personal information known and held about them by White Rose Psychology Practice Ltd in the course of business and ensure that every business practice, task and process carried out by White Rose Psychology Practice Ltd is compliant with each principle of the Data Protection Act 1998 and the General Data Protection Regulations (GDPR:2016).

White Rose Psychology Practice Ltd aim to ensure that staff are trained and aware of the guiding principles behind Data Protection of data, namely to ensure;

  • Confidentiality – Data will be handled with due regard to its sensitivity and appropriate security measures put in place to maintain its confidentiality

  • Integrity – That data which is held by White Rose Psychology Practice Ltd is up to date, accurate and can be relied upon.

  • Availability – That the data will be available to the data subject when they require the information.
     

This policy is therefore in place to ensure regulatory and legal compliance at all times with regards to handling and processing personal data.

Data protection policy statement

White Rose Psychology Practice Ltd is classed as both a Data Controller/Data Processor under the current Data Protection Act 1998. However White Rose Psychology Practice Ltd recognises that under the new General Data Protection Regulations (GDPR:2018) our obligations to ensure appropriate controls are in place irrespective of classification is of critical importance.

This policy confirms our commitment to protect the privacy of data to our customers, clients, employees and other interested parties. White Rose Psychology Practice Ltd has engaged in a programme of Information Security Management which is aligned to the international standard, ISO27001:2013 to ensure that the processes of personal information is conducted using best practice processes.

Basic principles regarding personal data processing

​The GDPR sets out a set of six guiding principles, which outline the responsibilities for organisations handling personal data. Article 5(2) of the GDPR states that the controller shall be responsible for, and be able to demonstrate, compliance. This is known as the ‘Principle of Accountability’. The remaining principles state that Personal data must be:

Lawfulness, fairness, and transparency

Processed lawfully, fairly and in a transparent manner in relation to individuals.

Purpose limitation

Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes.

Data minimisation

Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

Accuracy

Accurate and, where necessary, kept up to date; reasonable steps must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.

Storage period limitation

Kept in a form which permits identification of data subjects for no longer than is necessary for the purposed for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals

Integrity and confidentiality

Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).

Data processing

Transmitting personal data

Where personal data is to be transmitted (either electronically or in hard copy), staff are required to ensure that any such data is secured using appropriate measures (e.g. Use of encryption, passwords for electronic transmissions or using secure couriers).

Personal Data will only be transmitted in accordance with best practice and is only transmitted to a person authorised to receive it in compliance with these Data Protection principles.

Storing personal data

Personal data in hard copies (e.g. paper medical records, copy passport etc) are retained only for as long as is essential to the account and/or customer, employee or other interested party that they refer to.

 

Personal data in hard copy or electronic formats will be stored in accordance with best practice and in line with processes, which are part of our broader Information Security Management System (ISMS).

 

The management of Personal Data is controlled through this standard and White Rose Psychology Practice Ltd has committed to ongoing audit and review of policies, processes and practices associated to holding information in all its form.

Breaches of personal data

If any breach of the DPA or its Principles occurs, staffs are required to inform the Directors and ICO and the data subjects affected will be informed without undue delay., in line with White Rose Psychology Practice Ltd Incident Management processes.

Responsibilities

White Rose Psychology Practice Ltd recognises it has a responsibility to ensure that data is protected using appropriate technical and operational measures and as such has implemented a security framework which focuses on both operational and technical aspects of data protection. In this regard White Rose Psychology Practice Ltd have;

  • Implemented controls to ensure that Associates cannot gain access to information that is not necessary for them to carry out their job functions.

  • Put in place measures to ensure that all information held will be relevant, accurate and up-to-date and used only for the purpose for which it is required and was originally intended.

  • Committed to ensure information will not be kept for longer than is necessary and will be kept secure at all times.

 

White Rose Psychology Practice Ltd also recognises responsibility for ensuring that the data subjects data ‘rights’ are considered, when processing data.

The right of access by data subjects

Section 3 of the GDPR states that data subjects have rights in relation to their data including:

The right to be informed

Individuals have the right to be informed about how we use their personal data. This includes:

Who we are
Any legal reason for us requiring their data
How long we will keep their data for
The existence of their rights under the General Data Protection Regulations

The right of access

Individuals have the right to obtain:

Confirmation that their data is being processed by us
Access to the personal data we hold on them (through the ‘Subject Access Review’ process)

The right to rectification

Individuals have the right to have their personal data rectified if it is inaccurate or incomplete.

The right to erasure (the right to be forgotten).

Individuals have the right to request the deletion or removal of their personal data, where there is no compelling reason for its continued processing and where the data does not fall under the retention periods set out in the WRPP policy.

The right to restrict processing

Individuals have the right to request that we restrict further processing of their personal data where:

They contest the accuracy of the personal data we hold on them, until it has been rectified and verified
They have objected to us processing their personal data (where there is a legitimate reason for the processing such as a performance of a contract) until their objection has been fully considered and a decision made
Processing is unlawful and they request the process of their data be restricted instead of erased

The right to object

Where we process individuals personal data for the performance of their contract, they have the right to object to the processing however, this must be on grounds relating to their particular situation. In these circumstances, we will stop processing their personal data unless:

We can demonstrate compelling legitimate grounds for the processing, or
The processing is for the establishment, exercise or defence of legal claims.

Where we process individuals personal data for direct marketing purposes, they have the right to object at any time.

 

If they object to their personal data being processed for direct marketing purposes:

We will stop the processing as soon as we received their objection
We will deal with their objection at any time and free of charge

Rights in relation to automated decision making and profiling

Individuals have the right not to be subject to a decision when:

It is based on automated processing, and
It produces a legal effect or a similarly significant effect on them

We will not use individuals’ personal information for any automated decision-making or profiling purposes.

When acting as a data controller, White Rose Psychology Practice Ltd is responsible for providing data subjects with a reasonable access mechanism to enable them to exercise these rights.

Legal basis for processing

Article 6: Lawfulness of processing

Article 6 of the GDPR provides the legal basis under which personal data can be processed, and White Rose Psychology Practice Ltd uses the following, legal basis:

Employee Data – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

Marketing and Promotional Material – The ‘Legitimate Interests’ of individuals will be considered for marketing purposes, and only where clear Consent has been obtained or where previous indications of interest have been shown.

Under these conditions, White Rose Psychology Practice Ltd will apply the following legal basis for processing personal data:

Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject, which require protection of personal data, in particular where the data subject is a child.

In all other circumstances, White Rose Psychology Practice Ltd apply the following legal basis for processing personal data:

The data subject has given consent to the processing of his or her personal data for one or more specific purposes.

Where consent is obtained from individuals directly

The GDPR states:

Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject’s acceptance of the proposed processing of his or her personal data.

Silence, pre-ticked boxes or inactivity should not therefore constitute consent.

Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject’s consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.

Where required, White Rose Psychology Practice Ltd obtains consent from individuals at the Registration Stage, via appropriate means.  This is gained through the individual ticking a box, or signing a ‘Consent form’ and making a conscious decision to ‘opt in’.

Subject access requests

Under Article 15 of the GDPR, an individual has ‘The Right to Access’ personal information which is being held about them by. This information is to provided free of charge and individuals have the right to obtain:

the purposes of the processing;
the categories of personal data concerned;
the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
the right to lodge a complaint with a supervisory authority;
where the personal data are not collected from the data subject, any available information as to their source;

 

Although the information will be provided free of charge, where there is an excessive request for data, or repetitive requests a ‘reasonable fee’ may be charged based on the administrative cost of providing the information and information must be provided without delay and at the latest within one month of receipt.

 

We are able to extend the period of compliance by a further two months where requests are complex or numerous. If this is the case, we must inform the individual within one month of the receipt of the request and explain why the extension is necessary.

 

It is important that we verify the identity of the person making the request, using ‘reasonable means’. If the request is made electronically, we will provide the information in a commonly used electronic format (e.g. CSV, or PDF).

Definitions

To ensure White Rose Psychology Practice Ltd understands its obligations to the protection of Personal Information, the following definitions apply and are based on current understanding of these terms within UK and European law, and specifically in Article 4 of the GDPR.

Personal data

Any information relating to an identified or identifiable natural person (“Data Subject”) who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Sensitive personal data

Personal data which are, by their nature, particularly sensitive in relation to fundamental rights and freedoms merit specific protection as the context of their processing could create significant risks to the fundamental rights and freedoms. Those personal data include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.

Data controller

The natural or legal person, public authority, agency or any other body, which alone or jointly with others, determines the purposes and means of the processing of personal data.

Processing

An operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of the data.

Anonymisation

Irreversibly de-identifying personal data such that the person cannot be identified by using reasonable time, cost, and technology either by the controller or by any other person to identify that individual. The personal data processing principles do not apply to anonymized data as it is no longer personal data.

Data retention

WRPP will keep some forms of information for longer than others. Information should not be kept indefinitely, unless there are specific requirements. In line with the General Data Protection Regulation (2018) ‘All personal data will be held as long as necessary’. As part of WRPP’s Data Protection Policy and practice personal data will be retained for the appropriate period of time – neither too long nor too short. The WRPP Retention Criteria will be highlighted in detail below.

WRPP administration team

(Retaining client data through referrals that come in through third party organisations and self-referrals via WRPP website, email, or phone)

 

All client information that is received through rehabilitation companies, allied health professionals, solicitors and schools will be passed on to an Associate of WRPP and retained until the Associate has confirmed they are taking the referral and deleted immediately after. A record of this data transfer will be recorded (reference number, date, referral taken). When data is no longer required by WRPP it will be appropriately destroyed by removing it from the Office 365 cloud based platform.
Information held of WRPP Associates will be retained until they no longer work for WRPP and will be deleted immediately after they finish working with WRPP.

Advice for WRPP associates

(Retaining client data)

 

All information gathered by WRPP Associates on our ADULT clients will be retained for 7 years in line with BPS Standards and NHS guidance.
All information gathered by WRPP Associates on CHILDREN AND YOUNG PEOPLE will be retained until the child or young person is 25 years of age in line with BPS Standards and NHS guidance.

Process for the safe destruction of data

Associates

Press the delete button on the website and delete information from the external hard disc and search and delete emails.

 

Name of data subject,
Copy of request and
Confirmation of date of destruction and
Name of data controller performing this action to be saved in the Process for the safe destruction of data file on the external hard disc.
Confirmation to be sent by data controller to data subject.

Clients

Press the delete button on the website and delete information from the external hard disc and search and delete emails.

 

Name of data subject,
copy of request and
confirmation of date of destruction and
Name of data controller performing this action to be saved in the Process for the safe destruction of data file on the external hard disc.
Confirmation to be sent by data controller to data subject.

Data security

All WRPP Associates and Administration should only access data associated with WRPP through the Microsoft Office 365 platform.  All our data will be stored within Office 365 to ensure safety and protection of the data. ‘Office 365 is a GDPR-complaint service committed to assisting you in building a secure framework for satisfying your GDPR responsibilities’

Office 365

Microsoft designed Office and Office 365 with industry-leading security measures and privacy policies to safeguard your data in the cloud, including the categories of personal data identified by the GDPR. Office and Office 365 can help you on your journey to reducing risks and achieving compliance with the GDPR.


One essential step to meeting the GDPR obligations is discovering and controlling what personal data you hold and where it resides. There are many Office 365 solutions that can help you identify or manage access to personal data

 

Data Loss Prevention(DLP) in Office and Office 365 can identify over 80 common sensitive data types including financial, medical, and personally identifiable information. In addition, DLP allows organizations to configure actions to be taken upon identification to protect sensitive information and prevent its accidental disclosure.

 

Advanced Data Governance uses intelligence and machine-assisted insights to help you find, classify, set policies on, and take action to manage the lifecycle of the data that is most important to your organization.
Office 365 eDiscoverysearch can be used to find text and metadata in content across your Office 365 assets—SharePoint Online, OneDrive for Business, Skype for Business Online, and Exchange Online. In addition, powered by machine learning technologies, Office 365 Advanced eDiscovery can help you identify documents that are relevant to a particular subject (for example, a compliance investigation) quickly and with better precision than traditional keyword searches or manual reviews of vast quantities of documents.


Customer Lockbox for Office 365 can help you meet compliance obligations for explicit data access authorization during service operations. When a Microsoft service engineer needs access to your data, access control is extended to you so that you can grant final approval for access. Actions taken are logged and accessible to you so that they can be audited.

 

Another core requirement of the GDPR is protecting personal data against security threats. Current Office 365 features that safeguard data and identify when a data breach occurs include:
Advanced Threat Protection in Exchange Online Protection helps protect your email against new, sophisticated malware attacks in real time. It also allows you to create policies that help prevent your users from accessing malicious attachments or malicious websites linked through email.
Threat Intelligence helps you proactively uncover and protect against advanced threats in Office 365. Deep insights into threats—provided by Microsoft’s global presence, the Intelligent Security Graph, and input from cyber threat hunters—help you quickly and effectively enable alerts, dynamic policies, and security solutions. Advanced Security Management enables you to identify high-risk and abnormal usage, alerting you to potential breaches. In addition, it allows you to set up activity policies to track and respond to high risk actions.
Office 365 audit logs allow you to monitor and track user and administrator activities across workloads in Office 365, which help with early detection and investigation of security and compliance issues.

RMail encryption services

The use of Rmail or other encryption services by the WRPP ADMIN TEAM will allow us to send end to end encrypted emails, which require two-factor authentication to access.


For example the RPost Software and Service do not store any email or authenticating information relating to email processed by the Software or Service, except in the case of the sender opting to use the large file transfer service or in some instances, a managed receipt archive service.
RMail makes secure email simple and accessible and is the Winner of the World Mail Aware for ‘’Best in Security’’, Rmail is the only HIPAA-compliant secure email provided that addresses privacy and compliance requirements while offering a radically simple user experience

 

RMail uses 256-bit AES-encrypted PDF wrapper to protect your sensitive emails and attachments. With options for secure end-to-end delivery, RMail lets you rest assured that your secure email message will only be read by its intended recipients.

 

Only RMail provides true direct deliveryof your encrypted message and attachments into your recipient’s inbox. Your recipients won’t need to register for an account, open a web browser, or otherwise leave their inbox to access your secure message.

 

If you are required to encrypt personally identifiable information by laws such as HIPAA, HITECH, or FSA , sending compliant encrypted email is only half of the equation. The other half is legal proof. The Registered Receipt record with every email sent telling you the delivery status, time of delivery, and exact message content will serve as court-admissible certified proof of delivery and can prove your compliance with privacy laws such as HIPAA legal proof of compliance and can prove WRPP met our obligations should a dispute arise.

 

WRPP Associates are not obliged to use RMail and may be using other encryption services such as, Stayprivate.com at https://www.stayprivate.com

Data policy and terms of use for clients

How WRPP protects your personal data

Associates of White Rose Psychology Practice are registered with the Health and Care Professions Council (HCPC). All registrants must work within the ethical framework of HCPC standards of conduct, performance and ethics. All information will be kept on Microsoft Office 365, a GDPR Compliant secure platform.

Consent to treatment

WRPP Associates will obtain your consent for assessment and or treatment on a consent form at your first meeting.

Storing records

Your personal data is never kept for longer than is necessary and is only held for WRPPs’ legitimate business use. We do not sell or pass your data to a third party for promotional purposes unless you specifically agree to be contacted for such purposes or unless we are required to do so by law. The WRPP Associate who has assessed or treated you is required to keep your records for a standard retention period of 6 years plus current (i.e., 7 years). Any records relating to your referral will be deleted by central WRPP administration 4 months following your initial referral.

Confidentiality

Your personal record will be processed and stored by the WRPP Associate who has treated you. They will process and store confidential information about you in a manner that avoids inadvertent disclosure.

Right to access your personal information

You have the right to request a copy of the personal information WRPP holds about you and to have any inaccuracies corrected. We will ask for confirmation of your identity before we disclose any personal information. Please address requests to the Associate who treated you or to enquiries@yorkshirepsychologypractice.co.uk and we will reply within one month.

Children and young people

WRPP Terms and Conditions requests parental or guardian consent for any child under 16 years of age. The WRPP Associate who has assessed or treated you is required to keep your records for a standard retention period until the child is aged 25 years. Any records relating to your referral will be deleted by central WRPP administration 4 months following your initial referral.

Data policy and terms of use for associates

This document outlines the terms and conditions and data policy for the usage of the WRPP website and WRPP business purposes. Any personal information that you provide on this website is controlled by White Rose Psychology Practice (Data controller)

Associates personal information

Occasionally you will be asked to submit personal information about yourself (e.g. name, practice / home address and email address updated CV, DBS and professional indemnity, record of training) in order to receive or use services on our websites. Such services include events, newsletters, publications, information and advice.

By entering your details in the fields requested and pressing ‘Submit’, you are consenting to the processing of your information by WRPP and its agents in accordance with this Data Policy.

You may also provide personal information to us when you contact us by email, telephone or letter. Whenever you provide such personal information, we will treat that information in accordance with this policy. Our services are designed to give you the information that you have requested. WRPP will, at all times, act in accordance with current legislation and aim to meet current Internet best practice.

Use and storage of your personal information

When you supply any personal information to WRPP we have legal obligations towards you in the way we deal with that information. We must collect the information fairly, that is, we must explain how we will use it. This Data Policy explains how we will use your personal information.

 

We will use personal information provided by you or gathered by WRPP for the following purposes:

To process and respond to requests, enquiries and complaints received from you;
To provide services requested by you;
To communicate with you about services provided by you and to you e.g. training;
To update our records;
To analyse trends and profiles;
For audit purposes;
To carry out customer satisfaction research;
To prevent or detect fraud;
To recommend products and services that we believe will be of interest to you;
To enable third parties to carry out any of the purposes above on our behalf.

 

Your personal email or phone number may be used to allow WRPP to contact you for ‘service administration purposes’; this means that WRPP may contact you for a number of purposes related to the service you have signed up for. For example, we may wish to provide you with referred work, password reminders or notify you that the particular service has been suspended or changed.

 

We will hold your personal information on our systems for as long as is necessary for the purposes set out above and we will remove it when the purposes have been met and you leave and you leave WRPP.

Sharing of your personal information

WRPP may share your personal information with third parties in the following ways:

We sometimes use agents and service providers to process personal information on our behalf. For example, we use third parties to carry out inspections, to send postal mail and to maintain our IT systems. Where we use agents and service providers to process your personal information, we will ensure that they have adequate security measures in place and are governed by  our privacy policies in respect to the use of your personal information.

 

We will release your personal information when we are required to do so by law.

 

We will release your personal information to others when you have given your consent to that release.

 

WRPP may occasionally present a promotion of a service with a third-party company e.g. Court report Writing services or Children and Families Services.

If we plan to share your information we will make sure that we have your consent first.

 

In some circumstances we may transfer your personal information to countries outside of the European Economic Area, where data protection safeguards are not as high as they are in the UK. If this occurs we will ensure that adequate procedures are put into place to protect your personal information.

Access to your personal information

Associates have the right to request a copy of the personal information WRPP holds about you and to have any inaccuracies corrected. We will ask for confirmation of identity before we disclose any personal information.

 

Please address requests to enquiries@yorkshirepsychologypractice.co.uk

Complaints procedure

Anybody who wishes to make a complaint regarding their experience of WRPP please request a complaints form from administrator@yorkshirepsychologypractice.co.uk and send this via post (West Hill House, Allerton Hill, Leeds, LS7 3BQ) or via email.

This policy

This policy is reviewed as part of the ongoing process to improve Data Protection and Information Security by the White Rose Psychology Practice Ltd and is reviewed annually.

bottom of page