Privacy Notice
Cregagh Surgery
- Key Summary
We collect and use your personal data to provide safe healthcare, manage NHS services, support public health, and improve care.
We only use your data where lawful and necessary.
You have rights including access, correction, and objection.
You can complain to the Information Commissioner’s Office (ICO).
- Who We Are
Montgomery Road Medical Centre
36 Montgomery Road, Belfast, BT6 9HL
Tel: 02890 709079
Data Protection Officer: Mr Chris Steele
- What Information We Collect
Personal data: name, address, date of birth, contact details, NHS number.
Health data: medical records, diagnoses, treatments, test results.
Administrative data: correspondence and appointment records.
- How We Use Your Information
Direct care, service planning, NHS payments, public health, safeguarding, emergencies, research (where applicable), and legal obligations.
- Legal Basis for Processing
Article 6: public task, legal obligation, vital interests.
Article 9: healthcare provision, public health, research.
- Who We Share Your Information With
NHS providers, HSC organisations, out-of-hours services, public health authorities, and legal bodies where required.
- International Transfers
We do not routinely transfer your data outside the UK. Safeguards will apply if this changes.
- How Long We Keep Your Data
Medical records retained long-term per NHS guidance.
Complaints retained for 3 years.
Administrative records per retention schedules.
- Automated Decision-Making
Some risk stratification tools may be used but no decisions are made solely by automated means.
- Your Data Protection Rights
Access, rectification, erasure (limited), restriction, objection, portability, and withdrawal of consent where applicable.
- Your Right to Object
You can object to certain processing, though we may continue where legally required or necessary for care.
- How to Complain
Contact us first. You can also complain to the ICO:
https://ico.org.uk
Tel: 0303 123 1113
- How We Protect Your Data
We use a range of measures to protect your personal information, including:
- Secure NHS systems
- Access controls (staff only see what they need)
- Staff training and confidentiality policies
We use secure NHS-approved electronic systems to store and manage your information. These include electronic patient record systems, appointment and communication systems, and secure data-sharing platforms used across Health and Social Care services. All systems are subject to strict security and access controls.
- Communications
We may contact you via phone, text, or email for care purposes. You can opt out of non-essential messages.
- Additional Information
We ensure minimal data sharing and comply with confidentiality obligations at all times.
Review
This notice is reviewed regularly and updated as required to reflect legal or operational changes.