This privacy notice explains how Cardiff & Vale Health Charity (as Data Controller) will collect, use and protect personal data that you have submitted in the process of donating to the Health Charity.
How and why will your personal data be processed?
Personal data will be processed for the purpose of maintaining a register of the Health Charity’s donors, supporters and partners. We may use this information to contact you in the future regarding related topics.
Cardiff & Vale Health Charity will be supported in processing data by Cardiff and Vale University Health Board.
What is the legal basis for our use of your personal information?
The lawful basis that the UHB relies upon to process your personal data is:
• GDPR Article 6(1)(f) processing is necessary for the purposes of the legitimate interests pursued by the controller
As extra protection is provided for certain classes of information called ‘special category personal data’ such as health information, an additional lawful basis must be identified in order to process these classes of information, as outlined below:
• GDPR Article 9(2)(a) – your explicit consent
How will we store your personal information?
Your information will be stored securely and kept in accordance with the Records Management Code of Practice for Health and Social Care 2022.
For donations, this is currently 6 years from the close of the financial year to which the donation relates.
Under data protection law, you have rights including:
• Your right of access – You have the right to ask us for copies of your personal information.
• Your right to rectification – You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
• Your right to restriction of processing – You have the right to ask us to restrict the processing of your information in certain circumstances.
• Your right to object to processing – You have the right to object to the processing of your personal data in certain circumstances.
• You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
If you have a concern about the way in which your personal data has been processed, you can complain directly to Cardiff & Vale University Health Board’s Data Protection Officer at: Uhb.Dpo@wales.nhs.uk
You also have the right to complain to the Information Commissioner’s Office using the following details:
By post: The Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow,
Cheshire, SK9 5AF
Telephone: 0330 414 6421
Further advice and guidance from the ICO on this issue can be found on the ICO website