Data Protection Act 1998
The Department of Health’s data protection policy
We regard the lawful and correct treatment of personal information by the Department of Health as an important element of our business and maintaining the confidence of those with whom we deal. We ensure that our organisation treats personal information lawfully and correctly.
Therefore the Department of Health will fully endorse and will, through appropriate management, strict application of criteria and controls, adhere to the 8 Principles of Data Protection as described in the Data Protection Act 1998. The Information Commissioner’s guidance provides further details about the data protection principles.
The Department of Health will also ensure that:
- there is someone with specific responsibility for Data Protection in the organisation. The nominated person is the Data Protection Manager.
- everyone managing and handling personal information understands that they are contractually responsible for following good data protection practice, is appropriately trained to do so and is appropriately supervised;
- requests for information about handling personal information will be promptly and courteously dealt with;
- methods of handling personal information are clearly described, a regular review and audit is made of the way personal information is managed; and methods of handling personal information are regularly assessed and evaluated;
The Department of Health does not charge a fee to those wishing to make subject access requests under the Data Protection Act.
How to make a subject access request
The Data Protection Act allows you to find out what information we hold about you on computer and in some paper records. This is known as the ‘right of subject access’. We have provided a sample request letter with a further information form that should also be completed. All requests for access to your personal data, held by the Department of Health, should be made in writing to:
The Data Protection Manager
Department of Health
Room 3D Skipton House
80 London Road
London SE1 6LH
Statistics on Subject Access Request
The Department of Heath is required to supply you with your personal data within 40 days of receiving a valid request. If we cannot meet this deadline, we will keep you informed of progress towards fulfilling your request.
The Information Charter
Our promises to you can be viewed in our Information Charter