PRIVACY AND DATA PROTECTION SECURITY STATEMENT
This statement outlines Elgin Counselling Services procedures for collecting, storing and
processing personal data. Personal data relating to a living individual who can be identified from the data or from other information from that data, in order to comply with the Data Protection Act (DPA) 2018.
This statement covers all the principles under the DPA.
These are known as the ‘data protection principles and ensures that information is:
-
Used fairly and lawfully.
-
Used for limited, specifically stated purposes.
-
Used in a way that is adequate, relevant and not excessive.
-
Kept for no longer than necessary.
-
Kept safe and secure.
-
Not transferred outside the European Economic Area (EEA) without adequate
-
protection.
Contact details of the person responsible for taking the lead on compliance:
Samantha Cockerell, www.elgincounselling.co.uk is responsible for personal
data, information on procedures dealing with both internal and external
access requests and how the information collected is used.
What is meant by informational privacy:
The ability of a person to control, edit, manage and delete information about themselves and to decide how and to what extent such information is communicated to others. Intrusion can come in the form of the collection of excessive personal information, disclosure of personal information without consent and misuse of such information. It can include the collection of information through the surveillance or monitoring of how people act in public on private spaces and through the monitoring of communications whether by post, phone or online and extends to monitoring the records of the sender and recipients as well as the content of messages.
Why I need the information I hold about an individual:
I need to request and store your details in order to administer and deliver the service you have requested, and to comply with any legal or professional body responsibilities that ensue in the delivery of that service.
What I am going to use it for:
To make contact with you, to record the relevant personal contact details you give consent for me to hold, and to record session notes. To send invoices where appropriate.
Where this information is stored:
I hold your handwritten notes, which are coded to ensure anonymity, in a lockable file, your contact details are held in a separate lockable file and at no point come together. Only your first name or initials are held on my mobile phone and will be deleted at the end of therapy. Your initials only are written in my diary.
For clients who are referred through a Solicitor for trauma therapy, a report may be requested at the start and end of therapy, this will be saved on my computer, and will be password protected. This is the only exception to handwritten notes.
When and how I delete the information I hold about you:
On request or 6 years after our last contact, I delete by electronic means and destroy paper records by shredding. For clients under the age of eighteen, notes are kept until your 25th Birthday or six years after the last contact, whichever is later.
When I pass on personal information:
I will only share personal information as follows:
If during my contact time with you I become aware that there is a safeguarding risk to either you or another person, I will contact whomever we agreed upon at our first session and/or college/professional body/emergency services/where appropriate.
My supervisor will be handed all my counselling-related paperwork should I become indisposed and will destroy notes accordingly.
When you request me to do so.
Where I need to comply with a legal requirement to do so (a court order for example).
For clients who are referred through a Solicitor for trauma therapy, a report may be requested at the start and end of therapy, this will be emailed to the relevant person, copied to the client, and will be password protected. This is the only exception to handwritten notes.
I do not use CCTV or recording equipment on my premises. However, I do hire rooms that are held within organisations that may do so. This will be advised to you if required.
I also use Facebook for promotion purposes.
You can request a copy of your records at any time and have the right to have these deleted, please see the guidance at https://ico.org.uk/for-the-public/personal/information .