Collection of Personal Data

Notice updated July 2020

Introduction

For the health and safety of the customers and any staff in these premises, we are recording the name and contact details of everyone who enters to support NHS Scotland’s Test and Protect. This information will be used to enable NHS Scotland to contact you should you have been in the premises around the same time as someone who has tested positive for coronavirus. Contacting people who might have been exposed to the virus is an important step in stopping the spread.

Reasons for data collection

As stated above, the purpose for which we are processing your personal data is to assist with NHS Scotland’s Test and Protect strategy in relation to the coronavirus public health epidemic. This will involve the gathering and, when necessary, the sharing of information with NHS Scotland as the responsible body for Test and Protect. Your data will not be used for any other purpose.

In order to assist in the containment of the virus, we will only share your data when it is requested directly by NHS Scotland. This will only be in the unlikely event there is a cluster of coronavirus cases linked to the venue. Information will be transferred securely to NHS National Services Scotland who will use the data to contact trace those who were in the establishment at the same time as the positive case, and will provide guidance and support to those who may be advised to self-isolate.

Read further information on the NHS Scotland Test and Protect strategy on the NHS website at:

www.informationgovernance.scot.nhs.uk/use-of-your-data-for-track-trace-isolate-tti/

Type of data collected

Along with the date and time of your arrival and departure, we will collect the following personal data if applicable:

  • your name; and
  • contact telephone number

If you do not have a telephone number, you have the option to provide:

  • a postal address; or
  • an email address

Customer health information will not be requested or stored.

Lawful basis for collecting this data

Under data protection law, GDPR Article 6(1), we have a number of lawful bases that allow us to collect and process personal information. In this case, the lawful basis for processing your data is ‘legitimate interests’. Broadly speaking ‘legitimate interests’ means that we can process your personal information if we have a genuine and legitimate reason and we are not harming any

of your rights and interests. Our legitimate reason for processing your data is to assist with NHS Scotland’s Test and Protect strategy in relation to the coronavirus public health epidemic.

Before sharing any information we will carefully consider and balance any potential impact on you and your rights.

 

Data retention period

Your personal data will be retained only for the purposes stated in this privacy notice and will be held by us for no more than 3 weeks (21 days). All personal data will be held and disposed of in a safe and secure manner.

Your rights

As defined in the data protection law, GDPR Article(s) 12-23, you have the following

rights:

  • the right to be informed about the collection and use of your personal data. This

is outlined above.

  • the right to erasure. If at any point within the 21 days after your visit you decide you’d like us to delete the personal data you provided, please advise us and we will delete all information related to you.
  • the right to object to us processing your personal data. If you do so, we will delete all the personal data we hold in relation to you
  • the right to rectification. If the information held is in any way incorrect, you can contact the data controller and request that the information be rectified.

In certain circumstances exemptions to these rights may apply. Further information is available on the Information Commissioner’s Office website at: www.ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-dataprotection-regulation-gdpr/exemptions/

Complaint procedure

If you consider that your personal data has been misused or mishandled by us, you can raise this with the data controller. In this instance, the data controller is the manager of this venue.

If you remain dissatisfied you can make a complaint to the Information Commissioner, who is an independent regulator. The Information Commissioner can be contacted at:

Post:

Information Commissioner’s Office Wycliffe House

Water Lane

Wilmslow

Cheshire SK9 5AF

Telephone: 0303 123 1113

Email: casework@ico.org.uk

Any complaint to the Information Commissioner is without prejudice to your right to

seek redress through the courts.

Privacy Preference Center