Privacy Policy

1. Introduction

Seren Gobaith Independent Hospital is an independent mental health hospital based in Rhyl, Wales. This statement explains how the hospital collects, uses, shares, and protects personal information belonging to patients, staff, visitors, and other individuals it comes into contact with in the course of its work.

This statement is written to be clear and accessible. Anyone who would like this information in another format, including large print, easy read, audio, or Welsh language, should contact the Registered Manager (Owen.Evans@serengobaith.com).

2. Who We Are

Seren Gobaith Independent Hospital is the data controller for personal information processed in connection with the care and treatment of patients, and in connection with the employment and management of staff. 

The hospital is registered with, and regulated by, Healthcare Inspectorate Wales under the Independent Health Care (Wales) Regulations 2011.

The hospital provides care across five wards, supporting patients with a range of needs within a locked rehabilitation, low secure, and acute admissions care environment.  

Because of the nature of this care, the hospital often processes detailed and sensitive information, and takes its responsibilities under data protection law particularly seriously.

3. Our Regulatory Status

Seren Gobaith Independent Hospital is registered with Healthcare Inspectorate Wales, the independent regulator of healthcare in Wales. Healthcare Inspectorate Wales inspects the hospital against the Health and Care Standards and the Independent Health Care (Wales) Regulations 2011, and may review records, policies, and personal information held by the hospital as part of its regulatory function.

Sharing information with Healthcare Inspectorate Wales, and with other statutory bodies exercising a legal function, is a normal and lawful part of the hospital’s operation. Further detail on how this sharing takes place is set out in section 7 of this statement.

4. What Personal Information We Collect

Depending on a person’s relationship with the hospital, the information collected may include:

  • Personal details, including name, date of birth, address, and contact information.
  • Health and care information, including diagnoses, treatment plans, medication records, risk assessments, and clinical notes.
  • Information relating to detention or admission status under the Mental Health Act 1983, where this applies.
  • Next of kin, family, and advocate contact details.
  • Information about safeguarding concerns, incidents, and complaints
  • Employment information for staff, including recruitment, training, supervision, and performance records.
  • Images from closed circuit television, where cameras are in operation for the safety of patients and staff
  • Visitor details, including identity checks carried out for security and safeguarding purposes

5. Special Category and Sensitive Information

Much of the information the hospital holds about patients is special category data under data protection law, because it relates to health, and in some cases to other protected characteristics. 

The hospital applies additional safeguards to this information, including restricted access, secure storage, and clear policies on who may view or share it, and for what purpose.

6. How We Use Personal Information

The hospital uses personal information to:

  • Provide safe, effective, and appropriate care and treatment to patients
  • Meet legal obligations, including those arising under the Mental Health Act 1983 and associated Code of Practice
  • Support clinical governance, quality assurance, and audit activity within the hospital
  • Respond to safeguarding concerns and protect the welfare of patients and other
  • Manage staff employment, training, supervision, and appraisal. 
  • Maintain the security of the hospital site and the safety of everyone within it
  •  Meet reporting obligations to Healthcare Inspectorate Wales and other statutory or commissioning bodies
  • Handle complaints, incidents, and legal proceedings fairly and appropriately

7. Our Lawful Basis for Using Information

The hospital relies on the following lawful bases under the United Kingdom General Data Protection Regulation and the Data Protection Act 2018:

  • Vital interests, where necessary to protect someone’s life 
  • Legal obligation, where the hospital must act in a certain way under law, including the Mental Health Act 1983
  • Public task, where processing is necessary for the provision of health or social care
  • Contract, in relation to staff employment and certain commissioning arrangements
  • Where information falls within special category data, the hospital also relies on one or more of the specific conditions set out in Article 9 of the United Kingdom General Data Protection Regulation, most commonly the provision of health or social care, and the establishment or defence of legal claims.

8. Who We Share Information With

The hospital may share personal information, were lawful and necessary, with:

  • Healthcare Inspectorate Wales, in the course of its regulatory and inspection functions

Commissioners of care, including health boards and local authorities responsible for funding a patient’s placement

  • Other health and social care professionals involved in a patient’s care, such as general practitioners and community mental health teams
  • The Mental Health Tribunal for Wales, and legal representatives, where relevant to a patient’s detention or discharge
  •  The police and other statutory agencies, where required by law or necessary to protect someone from harm
  • The Information Commissioner’s Office (ICO), where required in the course of a data protection matter

The hospital does not sell personal information, and does not share personal information for marketing purposes. 

Any sharing outside of the categories above would only take place with appropriate legal grounds, and, where required, the individual’s knowledge or consent.

9. How Long We Keep Information

Personal information is kept for as long as necessary to fulfil the purposes described in this statement, and in line with the NHS Wales Records Management Code of Practice and other applicable retention guidance. Health records are generally retained for a minimum of the periods set out in that guidance, after which they are securely destroyed or, in limited circumstances, retained for historical or research purposes with appropriate safeguards.

10. Keeping Information Secure

The hospital maintains technical and organisational measures to protect personal information against unauthorised access, loss, or damage. These measures include restricted access to clinical systems, staff training on confidentiality, secure storage of physical records, and regular review of information governance practice as part of the hospital’s Quality Assurance Framework.

11. Your Rights

Individuals have the following rights in relation to their personal information:

The right to be informed about how information is used

  • The right to access a copy of personal information held about them
  • The right to have inaccurate information corrected
  • The right to request erasure of information, in certain circumstances
  • The right to restrict or object to certain processing, in certain circumstance. 

The right to data portability, where this applies 

Some of these rights are limited where information is held for the purposes of care under the Mental Health Act 1983, or where release could cause serious harm to the patient or another person. Any such limitation will be explained clearly if it applies.

Requests relating to these rights should be made to the Registered Manager using the contact details at the end of this statement.

11. Making a Complaint

Anyone with concerns about how their personal information has been handled is encouraged to raise this with the Registered Manager in the first instance. If the matter is not resolved to the individual’s satisfaction, a complaint can be made to:

  • Healthcare Inspectorate Wales, as the regulator of independent healthcare in Wales
  • The Information Commissioner’s Office, as the independent regulator for data protection matters

12. Changes to This Statement

This statement is reviewed at least every 3 years, or sooner if there is a change in law, guidance, or hospital practice that affects how personal information is handled. The date of the most recent review is shown at the top of this document.