Seren Gobaith Independent Hospital is an independent mental health hospital based in Rhyl, Wales. This statement explains how the hospital collects, uses, shares, and protects personal information belonging to patients, staff, visitors, and other individuals it comes into contact with in the course of its work.
This statement is written to be clear and accessible. Anyone who would like this information in another format, including large print, easy read, audio, or Welsh language, should contact the Registered Manager (Owen.Evans@serengobaith.com).
Seren Gobaith Independent Hospital is the data controller for personal information processed in connection with the care and treatment of patients, and in connection with the employment and management of staff.
The hospital is registered with, and regulated by, Healthcare Inspectorate Wales under the Independent Health Care (Wales) Regulations 2011.
The hospital provides care across five wards, supporting patients with a range of needs within a locked rehabilitation, low secure, and acute admissions care environment.
Because of the nature of this care, the hospital often processes detailed and sensitive information, and takes its responsibilities under data protection law particularly seriously.
Seren Gobaith Independent Hospital is registered with Healthcare Inspectorate Wales, the independent regulator of healthcare in Wales. Healthcare Inspectorate Wales inspects the hospital against the Health and Care Standards and the Independent Health Care (Wales) Regulations 2011, and may review records, policies, and personal information held by the hospital as part of its regulatory function.
Sharing information with Healthcare Inspectorate Wales, and with other statutory bodies exercising a legal function, is a normal and lawful part of the hospital’s operation. Further detail on how this sharing takes place is set out in section 7 of this statement.
Depending on a person’s relationship with the hospital, the information collected may include:
Much of the information the hospital holds about patients is special category data under data protection law, because it relates to health, and in some cases to other protected characteristics.
The hospital applies additional safeguards to this information, including restricted access, secure storage, and clear policies on who may view or share it, and for what purpose.
The hospital uses personal information to:
The hospital relies on the following lawful bases under the United Kingdom General Data Protection Regulation and the Data Protection Act 2018:
The hospital may share personal information, were lawful and necessary, with:
Commissioners of care, including health boards and local authorities responsible for funding a patient’s placement
The hospital does not sell personal information, and does not share personal information for marketing purposes.
Any sharing outside of the categories above would only take place with appropriate legal grounds, and, where required, the individual’s knowledge or consent.
Personal information is kept for as long as necessary to fulfil the purposes described in this statement, and in line with the NHS Wales Records Management Code of Practice and other applicable retention guidance. Health records are generally retained for a minimum of the periods set out in that guidance, after which they are securely destroyed or, in limited circumstances, retained for historical or research purposes with appropriate safeguards.
The hospital maintains technical and organisational measures to protect personal information against unauthorised access, loss, or damage. These measures include restricted access to clinical systems, staff training on confidentiality, secure storage of physical records, and regular review of information governance practice as part of the hospital’s Quality Assurance Framework.
Individuals have the following rights in relation to their personal information:
The right to be informed about how information is used
The right to data portability, where this applies
Some of these rights are limited where information is held for the purposes of care under the Mental Health Act 1983, or where release could cause serious harm to the patient or another person. Any such limitation will be explained clearly if it applies.
Requests relating to these rights should be made to the Registered Manager using the contact details at the end of this statement.
Anyone with concerns about how their personal information has been handled is encouraged to raise this with the Registered Manager in the first instance. If the matter is not resolved to the individual’s satisfaction, a complaint can be made to:
This statement is reviewed at least every 3 years, or sooner if there is a change in law, guidance, or hospital practice that affects how personal information is handled. The date of the most recent review is shown at the top of this document.