CaRi-heart technology
Revolutionary new technology to assess the risk of a serious heart condition or heart attack – many years before anything happens.
Your Personal Data is data which by itself or with other data available to HCA International Limited (HCA UK) can be used to identify you as an individual. Under data protection law, individuals have a right to be informed about how organisations use any personal data that they hold about them. We comply with this right by providing ‘Privacy Notices’ (sometimes called ‘fair processing notices’) to individuals where we are processing their personal data.
This Privacy Notice sets out how HCA will use your personal data. HCA UK is the Data Controller for the information that it collects and processes about you, and you are the 'data subject'. Our Data Protection Officer can be contacted at 2 Cavendish Square, London W1G 0PU or at DPO@hcahealthcare.co.uk if you have any questions.
What personal information do we collect from you and how do we use it?
Who do we share your personal information with?
How long do we keep your personal data?
Due to the current circumstances, if you submit a Subject Access Request (SAR) or other Data Subjects Rights request, please be aware that you may experience a delay in us responding to your request. This is because we are currently diverting resources to help with the response to the COVID-19 pandemic and ensuring the ongoing healthcare and treatment of our patients.
At this current time we are unable to collect any correspondence sent via post. If you need to get in touch regarding a SAR or other information request, please contact us via email at DPO@HCAHealthcare.co.uk
Whether or not you become an employee, we will use your personal data for the reasons set out below and if you become an employee we will continue to use it to manage the recruitment and on boarding process and your employment with us. We will collect most of this directly during the application journey but there may be sources of personal data collected indirectly, as set out later in this Policy.
The personal data we use may include:
*This information is not available to Hiring Managers during the recruitment process
If you are employed by HCA UK:
HCA UK may collect this information in a variety of ways. For example, data might be collected through application and other forms, CVs or resumes; obtained from your passport or other identity documents such as your driving licence; from on boarding forms, online HR systems completed by you at the start of or during employment (such as benefit nomination forms); from correspondence with you; or through interviews, meetings or other assessments. During the COVID -19 pandemic information may also be collected from Lab tests and thermal scanning procedures.
In some cases, the organisation may collect personal data about you from third parties, such as references supplied by former employers, information from employment background check providers, information from credit reference agencies and information from criminal records checks permitted by law.
We will tell you if providing some personal data is optional, including if we ask for your consent to process it. In all other cases, we expect you to provide your personal data so we can process your application and manage your employment with us.
Monitoring of communications
Subject to applicable laws, we may monitor and record calls, emails, text messages, social media messages and other communications in relation to our dealings with you. We will do this for regulatory compliance, self-regulatory practices, crime prevention and detection, to protect the security of our communications systems and procedures, to check for unlawful content, obscene or profane content, for quality control and staff training, and when we need to see a record of what has been said. We may also monitor activities on your network and systems’ accounts where necessary for these reasons and this is for our legitimate interests or other legal obligations.
Situational Judgement Tests (SJTs)
HCA use Situational Judgement Tests (SJTs) as part of our recruitment process. This is a psychological tool used to evaluate your behavioural and cognitive abilities when presented with hypothetical work-related situations. The tests are designed to measure your fit with our company and role based on cognitive abilities, personality traits and social skills. This helps us to make sure we hire suitable employees and recognizes that we need to consider temperament and interpersonal skills as well as qualifications. We use Situational Judgment Tests to give us an idea of your ingenuity, sociability, integrity and other crucial traits.
How we use your personal data and the legal basis for processing
We will process your personal data:
If you ask us to disclose your personal data to other people or organisations such as a company handling a claim on your behalf or an application for a mortgage; or otherwise agree to disclosures;
When we process any special categories of personal data about you at your request (e.g. racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning your health, sex life or sexual orientation).
You are free at any time to change your mind and withdraw your consent where we are relying on your consent to process your personal data. The consequence might be that we cannot continue to assist you with these activities.
Our lawful basis for using your data
We only collect and use personal information about you when the law allows us to. Most commonly we use it where we need to:
We may also use personal information about you where:
You have given us consent to use it in a certain way;
We have legitimate interests in processing the data – for example, where you have applied for another position and references are required as part of the recruitment process.
If we are processing special category data e.g. health related data we may do this for purposes relating to:
Who do we share your personal information with?
Subject to applicable data protection laws we may share your personal data with:
The HCA group of companies and associated companies including entities in the United States;
During these unprecedented times, HCA Healthcare’s main priority is the health and safety of our patients, colleagues and the wider community as well as supporting the NHS in responding to the COVID-19 pandemic. We are supporting the NHS in responding to the COVID-19 pandemic and this will remain our focus at this time.
As a result of these unique circumstances, HCA may need to share personal data with the NHS and other regulatory and government bodies (e.g. Care Quality Commission (CQC) for the purpose of supporting the response to the COVID-19 pandemic. This will be done in accordance with data protection laws and will include any amendments to legislation made by the Secretary of State. We will also consider any relevant guidance provided by the Information Commissioner’s Office.
Sharing of your Personal Data during the COVID-19 pandemic
During the COVID-19 pandemic your personal data may also be shared for the following purposes:
Understanding COVID-19 trends and risks to public health and controlling and preventing the spread of COVID -19;
We will regularly review this privacy statement and its applicability throughout the COVID-19 outbreak. We may also notify you in other ways from time to time about the processing of your personal information.
Your rights, under the data protection laws, are as follows (noting that these rights do not apply in all circumstances):
You may exercise these rights by contacting us on exercisingmydatarights@hcahealthcare.co.uk
You have the right to complain to the Information Commissioner's Office (ICO). It has enforcement powers and can investigate compliance with data protection law. Contact the ICO on www.ico.org.uk.
The following criteria are used to determine data retention periods for your personal data:
Your personal data may be transferred outside the UK and the European Economic Area. While some countries have adequate protections for personal data under applicable laws, in other countries steps will be necessary to ensure appropriate safeguards apply to it. These include imposing contractual obligations of adequacy or requiring the recipient to subscribe or be certified with an 'international framework' of protection.
For more details on all the above you can contact our DPO at DPO@hcahealthcare.co.uk and the HCA Privacy Notices