Privacy notice

Please read our privacy notice below to find out how we’ll use and protect your personal information. We will only process your personal information in compliance with Data Protection Legislation.

This Privacy Notice explains how your personal data will be used (collected, stored, used and destroyed), as part of this Programme.

The testing is being taken forward jointly by several organisations and means at different points in the process, different organisations will be processing your personal data. All processing of personal data is being done in compliance with data protection legislation. Each organisation will require a different level of information about you but all will use the minimum necessary to do what they are required to deliver their part of the Programme.

The organisations taking part are:

  • The NHS (including University Hospital Southampton NHS Foundation Trust Southampton Primary Care Limited, Southampton City Clinical Commissioning Group)
  • NHS Test and Trace and the local Health Protection Team
  • Southampton city council
  • Your organisation / employer

What personal data is being collected?

The details we may collect and process for you are:

  • first and last name
  • address, including postcode
  • mobile phone number
  • email address
  • date of birth
  • sex as registered at your GP
  • your test results (forming part of your medical record, by authorised NHS staff, including your GP, the NHS Track and Trace service and the local Health Protection Team to initiate contact tracing)
  • your GP surgery
  • your NHS Number
  • For staff, your employee / Payroll Number
  • your organisation / employer

How will my personal data be used?

Your details will be used to:

  • register you to participation in the Programme
  • match your contact details with health data stored by the NHS
  • deliver test packs to you at your home address, if necessary
  • communicate with you about the Programme
  • contact you with your test results by text message
  • contact you relating to a positive or inconclusive result to collect other medical information about your health relating to COVID-19
  • contacting employers to inform them of a positive result.
  • contact you to resolve any questions you might have about the Programme
  • Contact you if you consent to being asked about your experiences on the Programme
  • Contact you to gather feedback to inform improvements that could be made to a full end-to-end testing process

Webchat

Webchat allows you to speak to our customer advisors in real time using 'web chat' functionality to provide online support to citizens.

If you engage with our webchat, we may collect:

  • Your name and email address
  • Chat transcripts
  • Completed surveys
  • Automatic information, such as IP address, operating system and type of browser and the geographical location

Data from each 'chat' will be held for six months and may be used when looking into your enquiry and for quality purposes. You may be asked to complete a short survey on completion of your webchat. All answers for the survey are anonymised and will be used for service improvement.

How long will my personal data be kept?

The information processed by the NHS is kept for as long as it is required to provide you with direct care and to support NHS initiatives to fight COVID-19. Information held for direct care purposes are stored in line with the Records Management Code of Practice for Health and Social Care 2016. This means such information will be held for up to 8 years before it is deleted.

Any personal data gathered as part of this Programme for other purposes will be deleted at the end of the Programme.

What are my rights?

By law, you have a number of rights under data protection legislation, this testing programme does not take away or reduce these rights. You have the right to contact the us to ask for the following:

  • to be informed about the data held about you
  • to access the data held about you
  • to have the data held about you edited or updated where it is inaccurate or incomplete
  • to request that data held about you be erased
  • to request that the use of your data be restricted
  • to object to the use of your data

Further information about your data protection rights appears on the Information Commissioner’s website

Why our use of your personal data is lawful

In order for the use of your personal data to be lawful, we need to meet one (or more) conditions in the data protection legislation. For the purposes of this programme, the relevant conditions are:

For processing personal data:

  • Article 6(1)(e) to perform a public task carried out as part of our official authority.

For processing special category data by the NHS

  • Article 9(2)(i) – the processing is necessary for reasons of public interest in the area of public health
  • Data Protection Act 2018 – Schedule 1, Part 1, (2) (2) (f) – health or social care purposes
  • Regulations 3(1) and (4) of the Health Service (Control of Patient Information) Regulations 2002 (COPI) – the processing is necessary for a COVID-19 purpose

How can I find out more information or raise a complaint?

If you would like to raise a complaint about how your personal data is used as part of the Programme, you can contact the customer services team. Depending on your query, it will be forwarded to the Data Controller to resolve your issue.

If you have any data protection issues, please contact DataProtection@uhs.nhs.uk.

You may also complain to the Information Commissioner’s Office (ICO) if you believe that your personal data is handled in a way that is not lawful.