Privacy Notice
Privacy Notice
We want to make sure you feel confident about how your data will be collected and reasonably used as part of your journey with NCT. If you have any questions about how we use your personal data or believe any of your rights have been infringed, please contact our Data Protection Officer by emailing dataprotection@nct.org.uk.
This privacy notice was last updated May 2024.
Who we are and our contact details
NCT is a registered charity (in England and Wales, no. 801395 and in Scotland, no. SC041592), and a company (in England and Wales, no.2370573). Our contact details are:
Address:
- Brunel House, 11 The Promenade, Clifton Down, Bristol BS8 3NG.
Phone number:
- 0300 330 0700
Email address:
Website:
We are registered with the Information Commissioner’s Office [ICO] as an organisation that collects and uses personal data, a “Data Controller”.
Data Protection Officer contact details
Our Data Protection Officer is responsible for monitoring our compliance with data protection laws. You can contact them with queries or concerns relating to the use of your personal data at dataprotection@nct.org.uk.
How we get your personal data
We collect your personal data by one of the following ways:
Directly – this means you have given us your personal data. This will be when you contact us directly to use our infant feeding service.
Indirectly – this means someone else has given us your personal data. This includes:
- Hospitals – when you have been discharged, the hospital shares your data with NCT so that we can contact you about infant feeding support.
- Community Midwives and Health Visitors – when they make a referral on your behalf for you to use our infant feeding support service. They will ask for your consent to share your data.
- Mind Charity specialist teams - when they make a referral on your behalf for you to use our infant feeding support service. They will ask for your consent to share your data.
We also collect personal data about you when you visit our website. We will collect your IP address and other information from the cookies that are deposited on the device you are using. You can control which cookies are deposited to your device and you can change your settings at any time you wish. To find out more about the cookies we use on our website, please read our Cookie Policy.
Personal data we collect about you
Personal data is any information that relates to a person who is or can be identified from it. We will collect (directly and indirectly) and use some or all the following types of personal data:
- Full Name
- Home Address
- Postcode
- Gender
- Date of birth (yours and your baby)
- Marital Status
- GP
- NHS Number
- Telephone Number
- Health Data
- Ethnic Origin
How we use your personal data
We need your personal data to allow us to:
- provide infant feeding support – your data is used directly for your care, and also to manage the services we provide, investigate complaints or to be used as evidence as part of an investigation into your care.
- provide reports on this service to our funders, e.g. Local Authoritites and NHS Commissioning Bodies. No identifiable data is shared, only statistical data is shared which is fully anonymised.
If our purposes of processing change
We will only use your personal data for the purposes set out above, unless we reasonably consider that we need to use it for another purpose that is compatible with any of the above. If we need to use your personal data for an unrelated purpose, we will always inform you about this and explain the GDPR lawful ground which allows us to do so.
The GDPR lawful basis we rely on to collect and use your personal data
We can only collect and use your personal data when we have a lawful basis to do so. The lawful basis we rely on depends on the reason we need your personal data, which are set out above. Our lawful bases are:
Consent
We rely on your consent to provide our infant feeding support to you. You always have the choice to provide your personal data to us and there will be no detriment to you should you decide not to give your consent. If you have given us your consent to process your personal data, you can always withdraw that consent later.
Contractual Obligation
We provide our infant feeding support service under contract to our funders, e.g. Local Authorities and NHS Commissioning Bodies. We have a contractual obligation to provide anonymised statistical information about service users to those funders.
Vital Interests
In rare situations, we might need to share your personal data with the emergency or care services if we believe it is in your ‘vital interests’, or those of another person (i.e., a vulnerable person or a child), to do so. For example:
- if you are taken ill, or
- if any safeguarding concerns are raised.
Public Task/Public Interest
When the hospital shares your personal data with us so that we can provide our infant feeding support service to you, it is done so because the NHS is a public body, and they are sharing information in relation to your continued health care which will be carried out by NCT.
Legitimate Interest
We only rely on legitimate interests to process your personal data when the privacy risk to you is low, and your personal data is being used in ways that you would reasonably expect. For example, to contact you about our infant feeding support service once you have been discharged from hospital. You always have the right to object to any processing when we rely on legitimate interests, however this is not an absolute right, and we may be able to continue with the processing.
The GDPR conditions we rely on to collect and use your special category personal data
When we collect and use personal data that falls under the GDPR definition of special category personal data (e.g. health data, racial or ethnic origin data) we need to identify a GDPR condition to allow us to process your special category personal data. This condition is in addition to the GDPR lawful basis which is set out above.
The conditions we rely on to collect and use your special category personal data are:
Explicit Consent
You have given us your explicit consent for us to collect and use your personal data to allow us to deliver our infant feeding support service to you.
Health & Social Care
We collect and use your personal data to provide and manage your health or social care in relation to infant feeding support.
Public Health
We provide our infant feeding support services under contract to our funders, e.g. Local Authorities and NHS Commissioning Bodies, as there are clear benefits to the wider public and society as a whole in relation to infant feeding.
Data Sharing
We will only share your personal data with other organisations when required to by law or when GDPR allows us to do so.
We share anonymised statistical data with our funders, e.g. Local Authorities and NHS Commissioning Bodies. This means our funders are not able to identify anyone from the information we share with them.
Data Processors
There may be times when we need to work with other trusted businesses to help us process your personal data along your journey with us. These other businesses are known as “data processors” as they are acting on our behalf and under strict instruction from us on what they can and cannot do with the personal data.
When we do use other businesses to process personal data on our behalf, we always ensure we have appropriate UK GDPR compliant contracts in place with each one.
A data processor is not allowed to do anything with your personal data other than what we have instructed them to do with it. They will not share your personal data with any other business apart from us unless they are required to do so by law. They will hold it securely and retain it for the period we instruct.
We use the following data processors:
- Upshot
- Microsoft365
Transferring personal data outside of the UK
Sometimes it is not possible for us to process and store your personal data solely in the UK. When your personal data does need to be transferred or stored outside of the UK, we make sure we comply with the specific requirements set out in UK GDPR for us to undertake this.
We will only transfer personal data outside of the UK when one of the following GDPR provisions are in place to safeguard your personal data:
- an “adequacy decision” is in place with the country where the personal data is being transferred to;
- an “appropriate safeguard” as set out in UK GDPR is in place - these include using Standard Contractual Clauses and the UK’s International Data Transfer Agreements; and
- an “exception” as set out in UK GDPR can be relied on if there is no adequacy decision or appropriate safeguard in place, for example, we could rely on your explicit consent to make the transfer of personal data.
How long we keep your personal data
We only keep your personal data for as long as is necessary for us to fulfil the purposes we collected it for. We are contractually required to keep your personal data in relation to the provision of infant feeding support service for 6 years in line with the contracts we have with the Local Authorities or the NHS Commissioning Bodies.
There may be times when we anonymise personal data, this means you can no longer be identified. We retain anonymised personal data for longer so that we can use it for long-term trend analysis and reporting.
Your rights
Depending on the purpose and GDPR lawful grounds we rely on for processing your personal data, there are various rights available to you. You can:
- request access to the personal data we keep about you and be given specific information about the processing - this right always applies regardless of the processing activity we undertake.
- request we rectify personal data we hold about you if you believe it to be inaccurate - this right always applies regardless of the processing activity we undertake.
- request us to delete your personal data - this right only applies in specific circumstances; this means we don’t always need to comply with this type of request.
- request a restriction of the processing of your personal data - this right only applies in specific circumstances; this means we don’t always need to comply with this type of request.
- object to the processing when we have relied on the “legitimate interest” lawful ground to undertake the processing activity and you believe we have infringed your rights - we don’t always have to comply with such objections if we can demonstrate compelling grounds to continue with the processing.
- transfer your personal data from us to another service provider or give it to you - this right only applies to personal data you have given to us and when the processing is based on your consent or contractual basis and the processing is automated.
We do not undertake any solely automated decision making, including profiling, about you.
To find out more about the rights that apply to individuals under GDPR please refer to the guidance on the Information Commissioner’s Office website - https://ico.org.uk/for-the-public/.
If you want to exercise one of your rights, please contact our Data Protection Officer by emailing dataprotection@nct.org.uk. We shall respond to a valid request within one month of receiving it.
How to make a complaint about us to the Information Commissioner’s Office
If you are not happy with how we are processing your personal data, or you believe we have not dealt with one of your rights correctly you are entitled to make a complaint to the ICO. The ICO has several ways in which you can get in touch with them, including post, email, and online forms. For full details how to make a complaint please refer to their website - https://ico.org.uk/make-a-complaint/.
Changes to our Privacy Notice
We keep our Privacy Notice under review to ensure it remains accurate and up to date and we reserve the right to modify it at any time.