1. Policy Statement
Thurrock & Brentwood Mind is committed to protecting the privacy and
confidentiality of all personal information it processes as part of its operations.
The organisation ensures that all data is collected, used, stored, and shared
lawfully and transparently in accordance with the UK General Data Protection
Regulation (UK GDPR), the Data Protection Act 2018, and the NHS Data
Security and Protection Toolkit (DSPT). This policy provides the internal
governance framework to ensure compliance with legal and ethical standards.
2. Purpose
The purpose of this policy is to define how Thurrock & Brentwood Mind
manages personal information across all departments and services. It sets out
how data is handled to maintain confidentiality, integrity, and availability,
ensuring individuals’ rights a re upheld and data is processed fairly and lawfully.
3. Scope
This policy applies to all personal and special category data processed by
Thurrock & Brentwood Mind. It covers all employees, trustees, volunteers,
contractors, and partner organisations who have access to information in any
form, including paper, electronic, verbal, and visual formats.
4. Legislative and Regulatory Framework
This policy is based on the following key legislation and standards:
• Data Protection Act 2018
• UK General Data Protection Regulation (UK GDPR)
• Human Rights Act 1998
• Common Law Duty of Confidentiality
• Freedom of Information Act 2000
• NHS Data Security and Protection Toolkit
• ICO Guidance on Privacy and Transparency
5. Roles and Responsibilities
Board: Approves this policy and ensures appropriate governance arrangements
are in place.
Chief Executive Officer: Holds overall accountability for compliance with data
protection legislation.
Data Protection Officer (DPO): Provides expert advice on data protection
compliance and acts as the contact point for the Information Commissioner’s
Office (ICO).
Managers: Ensure their teams process data lawfully, fairly, and securely in line
with this policy and complete required training.
All Staff and Volunteers: Must understand and comply with this policy, report
any data breaches, and ensure confidentiality of personal information.
6. Principles of Data Protection
Thurrock & Brentwood Mind adheres to the seven principles of data
protection under Article 5 of the UK GDPR:
1. Lawfulness, fairness and transparency.
2. Purpose limitation.
3. Data minimisation.
4. Accuracy.
5. Storage limitation.
6. Integrity and confidentiality.
7. Accountability.
7. Collection and Use of Personal Data
Personal information is collected for lawful and specific purposes related to
service delivery, employment, and governance. Data is processed only where
necessary and proportionate to organisational functions.
7.1 How we collect personal information about you?
We may collect personal information from you when you contact Thurrock &
Brentwood Mind to access a service, become a member, receive regular
newsletters, make a donation, apply for a job or volunteering opportunity, or
hire a room.
This information can be obtained through post, email, website, telephone or in
person.
Thurrock and Brentwood Mind collects data through the CCTV system (images
only, no audio) for various reasons:
To maintain health and safety of staff, volunteers, service users, contractors,
sub -contractors, visitors and members of the public.
To prevent, detect and investigate criminal activity and/or anti -social
behaviour.
7.2 What information do we collect?
The personal information we collect might include;
• Name
• Date of Birth
• Postal Address
• Email Address
• Telephone Numbers
• Other information about you, that you or a referring organisation
provides us with
• Images (static and moving)
We also record the following data which is classified as “special category”:
• Health and social care data about you, which might include both your
physical and mental health data.
• We also record data about your gender, age, disability, race, ethnic
origin, sexual orientation or religion.
We do not deliberately set out to capture any special category personal data
on camera. However, cameras may incidentally record information which falls
within these categories. Additionally, footage from cameras may be used as
evidence regarding criminal offences or related security measures.
7.3 What information we use
We will hold your personal information on our systems for as long as is
necessary for the relevant activity, or as long as is set out in any relevant
contract you hold with us e.g.:
• To provide you with a service
• To manage your tenancy
• To process a donation
• To receive feedback, views or comments on the services we provide
• To process an application (Job or volunteering opportunity)
• To meet our legal responsibilities e.g. Gift Aid
To review and update the information we hold about you at any time.
7.4 Credit/debit card details
If you make a donation online or for private services/ training, your card
information is not held by us, it is collected by our third – party payment
processors, who specialise in the secure online capture and processing of
credit/debit card transactions.
7.5 How we use your personal data
General use of your data
Without your personal data, we would not be able to provide many of the daily
services and benefits our members receive. Your data is also important in
helping us regularly review, analyse, and improve what we do.
Below are some examples of how we use your personal data to provide our
services, depending on your relationship with us.
• Interacting with you via our website, webchat (live chat) and social
media – for example, when you post a comment or share our social media
posts or anything on the website.
• Understanding how you use our website, so that we can learn about your
experience, fix any issues, and improve our digital presence.
• Staff training and service improvement
• Using data for analysing and reporting on key information, such as our
donor / membership demographics and how we are performing
• Using data to help with statutory reporting audit, compliance, and fraud
checks
• Physical and IT security monitoring. So that we know your personal data
is well protected.
8. Special Category and Sensitive Data
Special category data, such as information about health or ethnicity, will only
be processed where additional safeguards are applied in compliance with
Article 9 of UK GDPR.
9. Information Sharing and MHSDS Reporting
Data may be shared with NHS Digital or partner agencies under the Mental
Health Services Data Set (MHSDS) for statistical and reporting purposes.
9.1 Who sees your personal information?
The personal information we collect about you will be used by our staff and
volunteers, and by organisations that we work together with, to deliver
services to support you; and if required by law, legal and regulatory authorities.
Where a shared database is used with another organisation, information may
be shared at Multi Disciplinary Team meetings
• Organisations we work together with to provide services are: Essex
Partnership University NHS Foundation Trust – Crisis Sanctuary,
Sanctuary Plus, Admission Prevention and Early Discharge Service.
• Midlands Partnership NHS Foundation Trust – NHS Talking Therapies for
Anxiety and Depression (formerly known as IAPT), Recovery College ,
Individual Placement Support (IPS) for Employment and At Risk Mental
States (ARMS)
• South East and Central Essex Mind -Healthy Minds Community
Connectors
• Basildon Mind -Healthy Minds Community Connectors
• Thurrock Council -Unpaid Carers
• Thurrock Lifestyle Solutions CIC -Unpaid Carers
We work collaboratively with the following organisations to provide integrated
care and support.
• Choice Support – Crisis Sanctuary
• EPUT -Healthy Minds Community Connectors
• North East London NHS Foundation Trust – Southend, Essex and
Thurrock Child and Adolescent Mental Health Service (SET CAMHS) –
Positive Pathways Youth Transitions.
In exceptional circumstances i nformation will be shared where it is in the
interests of personal or public safety or where disclosure may prevent serious
harm to an individual or others. Or if ordered to do so by a court of law or to
fulfil a legal requirement.
With your consent, we will share your contact information with other Thurrock
& Brentwood Mind services to keep you informed of news, events, and
opportunities.
We will never sell your personal information to other organisations for
marketing purposes.
Access to CCTV images is highly limited and can be accessed securely by the
CEO, Deputy CEO and the Administrative Manager. CCTV footage and Ring
Doorbell footage and audio, will only be processed by internal staff who are
authorised to do so by the CEO, this includes staff where there is a legitimate
and lawful reason for their involvement, such as the HR & Quality Manager in
the event of an investigation.
9.2 Your Information and the NHS Mental Health Services Data Set
(MHSDS)
As part of our commitment to improving mental health services, we may share
certain information about the care and support you receive with the NHS
Mental Health Services Data Set (MHSDS) . This is a national data collection
managed by NHS England and NHS Digital.
9.3 Why We Share Your Data
The MHSDS collects information to:
• Improve the quality and safety of mental health services.
• Support planning and commissioning of services.
• Monitor and reduce health inequalities.
• Inform national and local policy decisions.
The data shared may include:
• Basic demographic details (e.g. age, gender, ethnicity).
• Information about your mental health needs and the support you
receive.
• Diagnoses and care outcomes.
This data does not include your name or direct contact details and is used in
a way that protects your privacy.
9.4 Our Legal Basis for Sharing
We share this data under a legal obligation as part of our role in delivering
NHS -funded mental health services. This is in line with the UK General Data
Protection Regulation (UK GDPR) and the Data Protection Act 2018.
9.5 Your Rights and How to Opt Out
You have the right to:
• Be informed about how your data is used.
• Access your data.
• Object to or restrict the use of your data in certain circumstances.
If you do not want your confidential patient information to be used for research
and planning purposes, you can opt out via the National Data Opt -Out service.
9.6 How to Opt Out:
• Online : Visit www.nhs.uk/your -nhs-data -matters
• NHS App : Go to “Your Health” > “Choose if data from your health
records is shared for research and planning”
• Phone or Post : Call 0300 303 5678 or write to NHS Digital
You would also need to contact us directly if you wish to opt out of your data
being submitted to the MHSDS through our service. Please email
DPO@tbmind.org.uk or speak to a member of our team.
10. Individual Rights
Individuals have the right to be informed, access their data, request
rectification, erasure, restrict processing, data portability, and object.
Requests must be submitted to the DPO.
10.1 What rights do you have?
You have a number of rights relating to the processing of your personal data,
subject to some exceptions defined by law.
You can contact the data protection office by email, phone or post (using the
contact details below) if you would like to request any of the following:
• To be told how your personal information will be used, as set out in this
privacy policy
• To ask what information we hold about you and request a copy of that
information, subject to any exemptions
• To raise a valid objection to your personal data being processed
• To have your personally identifiable data deleted in certain situations
• To ask for your records to be updated, if you believe they are inaccurate
• For processing of your personal data to be restricted, which you can do
in certain circumstances
Please include your name, email address and postal address in your request.
We may also ask for proof of your identity.
We will confirm that we have received your request within five working days,
provide a response within 30 calendar days.
You can also lodge a complaint at any time about our processing of your
personal data. If you have any questions, comments or concerns about any
aspect of this policy, you can contact the Data Protection Officer.
11. Confidentiality and Security
All staff must ensure data is stored securely, electronic data is encrypted, and
paper files are kept in locked cabinets. Confidential discussions must be held
in private.
Everyone working for Thurrock & Brentwood Mind has a legal duty to keep
information about you confidential and secure.
When we pass on any information, we will ensure it is kept confidential and
secure.
Anyone who receives information from us is also under a legal duty to keep it
confidential and secure.
We only store your information for as long as is needed and in accordance with
our retention policy.
12. Ownership of Service User Records
Thurrock & Brentwood Mind owns all service user records, including
practitioner notes. This ensures that the organisation maintains control over
the records, complies with legal obligations, and manages retention and
destruction in accordance with regulatory requirements.
Thurrock & Brentwood Mind is responsible for:
• Secure storage of all records (physical and/or electronic).
• Compliance with data protection legislation.
• Responding to legal requests, including subpoenas.
• Ensuring records are destroyed securely after the retention period.
Practitioner notes are considered part of the service user record and are
therefore owned by Thurrock & Brentwood Mind. Practitioners maintain
these notes in line with organisational policy and confidentiality standards.
13. Data Retention and Disposal
Data will be retained only as long as necessary for legal or operational
purposes, following the Retention and Disposal Policy. Records will be securely
deleted or shredded when no longer required.
13.1 Updating your information –
If you wish to update your information we hold about you, please contact
reception@tbmind.org.uk or write to Thurrock & Brentwood Mind, 152 Bridge
Road, Grays, Essex RM17 6DB
14 . Cookies and Website Information
The organisation’s website uses cookies to improve functionality. Users can
manage cookie preferences through their browser.
14 .1 Links to other websites
This Privacy Policy only applies to Thurrock & Brentwood Mind’s website.
Unfortunately, we cannot be responsible for the privacy policies of other sites
even if you access them using links from our website.
14.2 Cookies
Cookies are widely used pieces of software containing numbers or letters that
are installed on your device; computer, mobile phone or tablet when you visit a
website. Cookies let websites recognise your device but can’t identify you.
They help the site work better and gather information about how you use the
site. This helps us to provide you with a good experie nce when you come to our
website and allows us to improve our site. To find out more about cookies:
http://www.allaboutcookies.org/cookies
You can choose to opt out of cookies, but if you do this may affect your
experience of using our site.
15. Complaints and Contact Information
Complaints regarding data handling should be directed to the DPO at
reception@tbmind.org.uk or to the Information Commissioner’s Office via
www.ico.org.uk.
16 . Monitoring and Review
The DPO will monitor compliance through audits and policy reviews every two
years or sooner if required.
17. Equality Impact Assessment
This policy ensures fairness and equality in managing personal data. No adverse
impacts were identified in the assessment.
18 . Associated Documents
– Data Protection and Confidentiality Policy
– Information Governance and Security Policy
– Information Sharing and Consent Policy
– Retention and Disposal Policy
19 . References
• Data Protection Act 2018
• UK GDPR
• Freedom of Information Act 2000
• NHS DSPT
• ICO Guidance on Data Protectio