Data Controller: Claire Smith firstname.lastname@example.org
This policy outlines my commitment to you concerning your personal data and is in line with the new data protection policy which has been recently updated in May 2018 under The General Data Protection Regulation (GDPR) policy.
What data do I collect?
Personal data is any information that enables me to identify you as an individual. This information includes your name, age and contact details.
Special category sensitive data can include physical, medical or mental health conditions, prescribed medication and counselling session’s summaries.
How is your data used?
I only process information, which is necessary for me to conduct my business, any data that I have will be securely destroyed as soon as it is no longer required.
Personal data is required in order for me to contact my clients.
Special category sensitive data is required in order for me to make an informed clinical decision about the appropriate treatment plan for the client.
I meet with my supervisor twice a month and during that time we discuss client sessions, however I only refer to my clients by first name only.
In the event of an emergency i.e. if I think your health is at risk I may need to contact your GP or an emergency mental health care provider, however I would need your consent in order to do this.
The only time I may need to share your personal data with anyone without your consent is if the law requires me to, this might be where I need to inform certain authorities if I think you are intending to harm another person or an organisation (e.g. terrorism).
How long will the data be stored for?
In order for me to comply with professional requirements I securely store identifiable personal information and some special category sensitive information for clients for 7 years once counselling has finished.
I hold no information for clients who decide not to take up counselling beyond 6 months of their last contact with me.
Your rights regarding your personal data
As an individual you have the right under data protection legislation to make a written request for a copy of your information from me, including a description of the data I hold on you and for the purpose that I hold it. You have the right to correct any inaccuracies in the data that we process about you, you also have the right to object to your data being processed, to limit or restrict the use of your data and the right to withdraw consent to me using your personal data.
If you have any queries about this please do not hesitate to contact me.