Data Protection Policy
-
Ensure Compliance:
-
The Data Protection Act 2018 is the UK's implementation of the General Data Protection Regulation (GDPR)
-
Paris Clinic Ltd. is registered in the UK, Isle of Man Douglas company number 137437C.
-
Paris Clinic is committed to complying privacy and data protection laws, including
-
The General Data Protection Regulation
-
EU Regulation 2016/679
-
-
-
Data Collection and Use:
-
Paris Clinic handles personal data relating to:
-
Employees
-
Patients
-
Potential patients with registered interest
-
-
-
Data Access and Sharing:
-
Specify who has access to the data, under what circumstances data can be shared with third parties, and the measures taken to ensure data security during sharing.
-
-
Data Retention:
-
All personal data will be help as long as it is necessary for the purpose for which it was collected. No credit card details will be stored.
-
-
Data Security:
-
Describe the security measures in place to protect data from unauthorized access, breaches, and other security threats. This includes encryption, access controls, and regular security audits.
-
-
Data Subject Rights:
-
Inform data subjects of their rights, such as the right to access, correct, delete, and port their data, as well as the right to withdraw consent for data processing.
-
-
Compliance and Legal Requirements:
-
As Paris Clinic Ltd. provides a medical service, we have a legal and regulatory obligation to obtain and record certain medical information. If an individual is not willing to provide “explicit consent” to us processing relevant medical or sensitive personal data then we will have to refuse treatment or services.
-
-
Roles and Responsibilities:
-
Derek Paris is the Data Protection Officer
-
-
Training and Awareness:
-
Implement regular training programs for employees to raise awareness about data protection practices and their responsibilities.
-
-
Incident Response:
-
Establish procedures for responding to data breaches or security incidents, including notification requirements and steps to mitigate damage.
-
-
Policy Review and Updates:
-
Regularly review and update the policy to reflect changes in data protection laws, organizational practices, and emerging threats.
-
Best Practices
-
Transparency: Be clear and transparent with data subjects about how their data is used and protected.
-
Accountability: Take responsibility for data protection and demonstrate compliance with data protection regulations.
-
Continuous Improvement: Regularly assess and improve data protection measures to address new risks and challenges.