These are the good practice guidelines we shall follow to protect GDPR:
Emails should be deleted when no longer required on inboxes/support tickets. Keeping data when it is no longer required is seen as a failure to take preventative measures to protect the information. Be aware that this is ALL emails as they all include client email addresses which is data. By archiving these they are still saved but in a secure way and more protected.
On email support requests sent from our website you will see an ‘opt-in’ box. If the client ticks this then we can tick on phorest they have opted in. Otherwise click ‘not now’ so they are not added to marketing.
A data breach is when any client data has been taken or could have been taken. (This could include theft of computers/laptops/issues with phorest if there was ever a data breach or stolen paper files. It also includes any employees taking client data from phorest system to contact privately. In these instances that is a legal data breach.)
If any employee becomes aware of a data breach they should inform the manager immediately. The manager then has 72 hours to report to the ICO.
Any client photos that can identify someone are taken as a form of confidential data. All photos should be kept on the Phorest system if they can identify the individual.
Messages should not be left on paper/in note book or diary if they include any client data such as phone numbers/email addresses. These could be lost/binned/misplaced which would be a data breach. Messages should be kept on slack or if you are writing down only include the last few digits of a client phone number as a reference and then the full number can be included on phorest.
Pins for the Phorest system must be updated regularly (at least every 6 months) and not shared between staff, If you believe someone else knows your PIN you should inform your manager immediately.
Digital consultation forms should be updated annually to ensure information remains accurate (or when any information needs changing if the client requests it to be updated).
For medical treatments such as IPL need to be reviewed at every appointment.
For under 16’s the parent or guardian should complete the form on their behalf. Under 16’s are not allowed to consent themselves to data being given. This must be done by a parent who gives their data on their behalf and signs the digital card. Children are considered vulnerable as are some adults with learning difficulties and therefore are afforded additional protection under GDPR
Staff Data is held on employees and this is maintained digitally on a password protected HR system or kept in a locked filing cabinet. Contact details are also maintained on Phorest which is pin protected. CCTV footage is held temporarily. No coverage in bathrooms/treatment rooms/staff rooms. We also work with a payroll provider who store payroll information digitally and password protected.