Data Protection Policy
Introduction
This Data Protection Policy sets out mhs homes’ commitment and approach to data protection and ensures that we are clear about how personal data must be processed and mhs homes’ expectations for all those who process personal data on its behalf.
The policy’s objectives are:
Employee obligations in the protection of personal data
Data Controller obligations in the protection of personal data
Individuals rights in relation to their personal data
This policy applies to individuals who is engaged to process personal data in whatever form for or on behalf of mhs homes and Heart of Medway.
This includes:
Employees
Volunteers
Casual and temporary staff
Directors
Board and committee members and officers
Third-parties such as sub-contractors and suppliers
Anyone who mhs homes shares or discloses personal data with/to
Scope
This policy applies to all mhs employees, and must be applied when developing, approving, reviewing and implementing data protection processes.
Legal and regulatory overview
mhs will take actions as necessary to comply with the legal and professional obligations set out for records, and in particular:
a) The UK General Data Protection Regulations (UK GDPR), this law sets out the principles for processing data as well as individuals’ rights.
b) The Data Protection Act 2018 (DPA18) which provides further detail on how UK GDPR is applied.
c) Data Use and Access Act 2025 (DUAA) which modernised UK data protection law to balance individual privacy with data-driven innovation, introducing clearer rules on data subject rights, legitimate interests, and digital identity frameworks while maintaining alignment with UK GDPR.”
d) The Human Rights Act 1998. Article 8 requires organisations to respect the private life of an individual and any information held about them.
e) The Privacy and Electronic Communications Regulations (PECR), which sit alongside the DPA 2018 and UK GDPR. They give people specific privacy rights in relation to electronic communications including but not limited to marketing and cookies.
f) The Common Law Duty of Confidentiality, where if information is given in circumstances where it is expected that a duty of confidence applies, that information cannot normally be disclosed without the information provider’s consent.
Other related and connected laws include: Investigatory Powers Act and the Computer Misuse Act 1990
The Regulator of Social Housing Governance and Viability Standard (para 1.1) “Registered providers shall ensure effective governance arrangements that… comply with all relevant law.”
Social Tenant Access to Information Requirements (STAIR) - the Social Tenant Access to Information Requirements (STAIR) give tenants the right to access certain information about how their housing is managed. When responding to STAIR requests, we ensure compliance with UK GDPR by only sharing information lawfully and applying redaction or anonymisation where necessary. This approach balances transparency with the protection of personal data.”
Responsibilities
The Chief Executive is the accountable officer responsible for the management of MHS homes and Heart of Medway and must ensure appropriate mechanisms are in place to support service delivery and continuity so that there is protection of data and thus maintaining confidentiality within MHS homes and Heart of Medway.
The implementation of and compliance with this policy is delegated to the Data Protection Officer (DPO).
Data Protection Officer (DPO)
Due to the size and nature of mhs homes the requirement for a DPO is not mandated, however due to our size and the complex nature of the information we hold one is in post. The DPO will:
Maintain all data protection policies and supporting procedures.
Advise mhs homes and its employees of their data protection obligations.
Advise on Data Protection Impact Assessments, Records of Processing Activities, Information Asset Registers, Retention Schedules, Information Sharing Registers,
Ensure accurate logs are kept in line with Data Subject Access requests, Data breaches and CCTV footage requests are maintained.
Ensure that mandatory training for all new colleagues and annual refresher training for existing staff.
Act as the contact point for the ICO/ IC
Support the investigation of data protection breaches and, as appropriate, reporting them to the Information Commissioner.
Ensure data protection and support the running of MHS homes are the legal data controller under the Data Protection Legislation for the data it collects and processes.
Each Executive Director in their respective areas of responsibility must ensure that all staff members are aware of this policy, other relevant policies and procedures, and their responsibilities concerning the processing of personal data; and must ensure this policy is adhered to.
Senior Leadership Group, managers and team leaders are responsible for implementing this policy and championing data protection within their teams and in particular supporting the Information Asset Owners in ensuring that all data processing operations under their control or responsibility or commissioned by them are undertaken in compliance with this policy and other relevant data protection policies. They are also responsible for ensuring that anyone processing data is sufficiently aware of this policy and how it applies to their job role and sufficiently trained to carry out their duties in compliance with this policy.
All colleagues
Have a duty to maintain the security of personal information
Have a duty to respect data subjects’ rights to confidentiality and to use
Personal data in legally compliant and socially responsible manner
Must contact the Data Protection Officer if they are not confident in or have
Concerns about data handling practices that they are undertaking or witnessing
Must complete appropriate training as required
Partner and third-party responsibilities. Any third party or organisation that is commissioned to process data or receives data from mhs or is able to access any personal data must enter into a legally enforceable agreement with Mhs the nature of which will be determined by the level of involvement with the data that is held/shared/accessed. Any such agreement must be approved by the Data Protection Officer.
The Information Commissioner’s Office (ICO) soon to be the Information Commission (IC)
The ICO/ IC is the supervisory body for data protection and has enforcement and sanctions powers under the UK GDPR. This includes powers to:
Issue fines for breaches
Request information, carry out data protection audits and access physical premises
Issue warnings and reprimands; and
Order compliance and to suspend or limit processing or data flows
mhs will comply fully with all requests from the ICO/ IC to investigate and/or review our data processing activities. Mhs will have regard to advice and guidance produced by the ICO as far as it relates to our data processing activities. In addition, Mhs shall consider any code of practice published by the ICO/ IC and will endeavour to align its own practices accordingly.
Policy detail
Personal data is used throughout MHS homes as part of normal day-to-day business. We have a duty to manage personal data responsibly and in line with data protection legislation. It is a public statement describing MHS homes approach to complying with its legal responsibilities in the data protection legislation and how it enables individual rights to be upheld and exercised.
The policy objectives are:
Establish mhs homes commitment, standards and aims in respect of data protection compliance; and
To provide information to data subjects, data processors, and the regulatory authorities about how mhs homes approaches data protection compliance
What is personal data?
For information to be personal data, it must relate to a living individual and enable that individual to be identified from it (either on its own or along with other information likely to come into MHS homes s possession).
The UK GDPR defines personal data as “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as:
Name
Identification number
Location data
Online identifier, or
It's also important to note that there are also special categories’ of personal data (often called sensitive’ personal data), this is made up of:
Personal data revealing racial or ethnic origin
Political opinions
Religious or philosophical beliefs
Trade union membership
Genetic data, biometric data
Data concerning health
Data concerning sexual orientation
Principles
All processing of personal data by MHS homes must comply with the principles in the GDPR. Article 5 of the GDPR requires that personal data shall be:
Processed lawfully, fairly and in a transparent manner (‘lawfulness, fairness and transparency’)
Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (‘purpose limitation’)
Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’)
Accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased, or rectified without delay (‘accuracy’)
Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (storage limitation’).
Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)
As a data ‘controller’ mhs homes is responsible for, and must be able to demonstrate, compliance with these principles (‘accountability’). Compliance will be achieved by ensuring:
Transparency
mhs homes will endeavor to provide sufficient information about how personal data are being processed to enable sufficient transparency about its handling of personal data. mhs homes will not deceive or mislead individuals when mhs homes collects their personal information. The Data Protection Officer is tasked with periodically reviewing the transparency of data processing operations. This will be enhanced by the introduction of the STAIR workstream.
Lawfulness and fairness
Before starting any processing of personal data mhs homes will ensure one of the six lawful basis for the processing under the GDPR has been established. They are:
Consent – The individual has given their clear and unambiguous consent (e.g. opt in, not opt out) for their data to be processed for one or more specific purposes. Where we rely on consent, we will ensure an individual can opt out as easily as they opted in.
Contract - The processing is necessary for a contract in place with the individual, or because they have asked that specific steps are taken before entering into a contract6.
Legal obligation - The processing is necessary to comply with the law (not including contractual obligations).
Vital interests – The processing is necessary to protect someone life.
Public task - The processing is necessary to perform a task in the public interest or in the exercise of official functions, and the task or function has a clear basis in law.
Legitimate interest - The processing is necessary for a legitimate interest unless there is a good reason to protect the individual personal data which overrides those legitimate interests. Where the lawful grounds are legitimate interests, a legitimate interest assessment (LIA) will be undertaken and documented.
The most appropriate legal basis to use will depend on the purpose of the data processing and the relationship mhs homes has with the individual. mhs homes will document which basis is being relied upon for each processing purpose and will record a justification for why it applies. This will be done before any new processing activity occurs. The team carrying out the processing will be responsible for keeping a record and must ensure the privacy notice (see below) is updated accordingly.
Anyone intending to process sensitive personal data must inform the Data Protection Officer, as an additional condition for processing special category data must be identified in addition to a lawful basis for general processing (as detailed above). The relevant process owner is responsible for ensuring that all of their processing activities undertaken or commissioned have been approved. No personal data will be used for any purpose other than that which it was collected and/or created for without the approval of the Data Protection Officer.
Purpose Limitation
Personal data will only be collected, created or otherwise obtained for specific, explicit and legitimate purposes. mhs homes will not rent or sell any personal information to third parties.
Data minimisation
mhs homes will strive to use a minimum of personal data in its data processing activities and will periodically review the relevance of the information that it collects.
Accuracy
mhs homes recognises that the accuracy of data is important. mhs homes will use its reasonable endeavors to maintain data as accurate and up to date as possible, in particular data which would have a detrimental impact on data subjects if it were inaccurate or out-of-date.
Colleagues are responsible for ensuring that personal data they have collected or created either directly or indirectly through the data processing activities they are responsible for and/or engage in are maintained accurate and up-to-date and that personal data whose accuracy cannot reasonably be assumed to be accurate and up to date are treated appropriately through erasure or anonymisation.
Storage limitation
mhs homes will ensure that it does not retain personal data for any longer than is necessary for the purposes for which they were collected and will apply appropriate measures at the end of the data useful life such as erasure or anonymization. Process owners, together with their DSC member and relevant Information Asset Owner will be responsible for determining the retention period for personal data under their control and must ensure that their retention schedule is accurate, maintained and adhered to. The Data Protection Officer will review all retention periods for personal data logged on the retention schedule. The DSC will oversee annual retention audits to ensure compliance with the retention schedules.
Information security
Information security is everyone responsibility. The ICT Security policy makes staff aware of their expected behaviors when using the MHS homes IT network and equipment. The health and safety policy sets out office security protocols. Staff contracts also detail expected behaviors in relation to data protection and confidentiality. Staff must adhere to these requirements and those set out in relevant policies to mitigate risks to information and to avoid regulatory action.
mhs homes will ensure that any personal data that it processes or commissions is processed in a manner using appropriate technical and organisational security measures to prevent and protect against unauthorised or unlawful processing and against accidental loss, destruction or damage.
mhs homes will implement appropriate security measures such as access controls. Further detail about information security can be found in the ICT Security policy and procedures.
Records management
Records are our corporate memory, providing evidence of actions and decisions and representing a vital asset to support daily functions and operations. Records are any piece of recorded information, captured and stored in any medium or format. Good records support policy formation and managerial decision-making, and protect the interests of mhs homes and our partners, and the rights of our customers and colleagues. They support consistency, continuity, efficiency and productivity and help mhs homes deliver services in consistent and equitable ways. Further information is available within the Records Management and lifecycle policy.
Records of Processing Activities
Records of Processing Activities will be maintained by Information Asset Administrators for each team which are reviewed annually. The ROPA will be further developed to ensure that this includes the recording of information assets in preparation for the Social Tenant Access to Information Requirements (STAIR).
This will support accountability and demonstrate that mhs homes most valuable, sensitive and confidential information is logged and handled legally, securely and efficiently in accordance with business needs. It ensures the management of information supports the efficient location and retrieval of corporate records where and when needed. It also provides a way of identifying risks posed to information assets.
Information asset management is an integral part of good management practice. mhs homes aims to support Information Asset Owners with the guidance, controls and systems necessary to improve the quality and impact of well managed information resulting in:
Lower costs associated with all areas of information management
Better and faster resolution of past and current information issues
More robust procedures around regulatory and compliance activities
More effective information sharing while still protecting sensitive content
Greater transparency across all information related activities
Increase in value of information through better use
Reduced risk of loss or disclosure which could have damaging consequences.
Easier to provide standardised information systems, policies, procedures, and standard
Better, clearer, more effective training on good information practices
Better monitoring and tracking of quality, security, and other key indicators
Privacy by design and default
mhs homes will embrace the data protection principles and foster a culture of privacy by design and by default considering the potential impact of new initiatives and change on individual privacy. It shall ensure that measures are in place to encourage all those involved in data processing activities to adopt a model of continuous improvement to the technical and organisational measures that implement the data protection principles and safeguards into processing activities.
mhs homes shall strive to ensure that by default, only personal data which are necessary for each specific purpose of the processing are processed and that the extent of the processing, period of their storage and their accessibility are carefully considered.
Data Protection Impact Assessments
A Data Protection Impact Assessment (DPIA) will be carried out for all new initiatives which involve the use of personal data including:
New or significant change to IT systems storing personal data
Any changes to how MHS homes share or manages personal data e.g. a new surveillance system
Policy reviews resulting in new ways of managing personal data
Staff responsible for managing the project/ change must complete a DPIA before the project starts. The Data Protection Officer is responsible for reviewing completed DPIAs and maintaining the register of DPIAs.
Information Asset Owners are responsible for ensuring there teams work with the POD to ensure there is an understanding the risks presented by their processing activities and maintaining a register of the identified processing risks and for its periodic review. Teams will be responsible for conducting a DPIA before beginning any new data processing activity, especially if that processing is likely to result in a high risk to individuals.
Detailed guidance on completing a DPIA alongside screening questions and a full DPIA template is available within the Privacy by design and default procedure.
Automated Decision‑Making and Profiling
mhs homes does not currently undertake any processing that involves solely automated decision‑making or profiling which produces legal or similarly significant effects on individuals. However, before introducing any such activity, a Data Protection Impact Assessment (DPIA) must be completed and reviewed by the Data Protection Officer. This ensures that risks to individuals are identified and mitigated, and that appropriate safeguards—such as transparency, human intervention, and the ability to challenge decisions – are in place prior to implementation.
Privacy notices
To ensure lawful, fair and transparent processing, all gateways soliciting personal data on the website, or in any hard copy form will have appropriate statements clearly explaining why and how personal data is processed.
A privacy notice, explaining in detail all data processing activities carried out by or on behalf of mhs homes, including the lawful basis for processing, is published on the website and updated as and when required.
Individual rights
mhs homes commits to upholding individuals’ rights in relation to the processing of their data under the GDPR. These are detailed below:
The right to be informed – individuals must be told why their data is collected and how it will be used. This must be done in an easily understood way. This can be done in a layered approach, with some information being provided at the point data is collected but with a clear signpost to where more information can be found
The right of access – often referred to as subject access requests (SAR), this gives individuals the right to obtain confirmation that their data is being processed and access to their personal data
The right to rectification - individuals can make a request to have inaccurate personal data rectified, or completed if it is incomplete
The right to erasure – also known as the right to be forgotten, this gives individuals the right to request that their data be deleted
The right to restrict processing – an individual can request that the processing of their data is restricted or suppressed
The right to data portability - individuals have the right to receive personal data they have provided to a controller in a structured, commonly used and machine-readable format
The right to object – this allows individuals to object to certain types of processing, for example if it is undertaken as part of the performance of a task in the public interest or if the processing is for direct marketing.
Rights in relation to automated decision making and profiling
It should be noted that these rights are not absolute, are dependent on the legal basis for processing and will not apply in all circumstances. The rights of individuals are completed via the Data Protection Officer and managed in line with the Data Subject Rights procedure.
Data breaches and managing incidents
mhs homes will ensure that all employees and those with access to personal data are aware of it and know how to report a personal data breach as soon as they become aware of a breach taking place. All colleagues have a responsibility to report data breaches in line with the data breach procedure.
mhs homes will log all personal data breaches and will investigate each incident without delay. Appropriate remedial action will be taken as soon as possible to isolate and contain the breach, evaluate and minimise its impact, and to recover from the effects of the breach. Data protection near misses will also be recorded and investigated in the same manner as data protection breaches.
Data sharing
Having the confidence to share personal data and confidential information when it is appropriate to do so can play a crucial role in providing a better, more efficient service to customers, colleagues and other stakeholders. It is important that colleagues understand the circumstances when it is appropriate to share information, and the safeguards that should be in place before doing so.
External partners, contractors and suppliers) mhs homes will only share personal data with or otherwise disclose personal data to other organisations and third parties where there is a legal basis for doing so and the data sharing is necessary for specified purposes. Where data sharing is regular, routine or pre-planned, a suitably legally enforceable agreement must be put in place to govern how the data should be managed.
These ensure that mhs homes shares certain routine information legally. Before sharing any information under a Data Sharing Agreement mhs homes will ensure the agreement covers the type of information we want to disclose and follows the specific procedure or authorisation process to ensure we share data fairly and lawfully. Data sharing agreements must be approved by and logged on the appropriate register by the Data Protection Officer.
Appropriate risk assessments will be undertaken, prior to any data sharing taking place, on those with whom we intend to share personal data. This policy extends to appointing others to process personal data on our behalf, sharing personal data with organisations, and providing information to ad hoc requests for information such as those which may be received from the police and other authorities.
We may also decide, or be asked, to share data in situations which are not covered by any routine data sharing agreement. In some cases a decision may need to be made in conditions of real urgency, for example in an emergency situation. In these circumstances, if someone is at serious risk you should share the minimum required data. If someone is not at immediate risk and you are unsure what to do or uncomfortable making a decision (e.g., police requesting CCTV data or information about a colleague) advice should be sought from the Data Protection Officer.
Children’s data
Special measures will be taken by mhs if it processes personal data relating to children under the age of 13 years including the nature of privacy information provided, approach to information rights requests and protection of their welfare and safeguarding requirements.
Personal data relating to criminal convictions and offences
Where mhs is processing personal data relating to criminal convictions and offences it shall implement suitable measures including a policy document that satisfies the requirements of the Data Protection Act 2018 Schedule 1 Parts 3 and 4.
Information relating to people who have died
Although UK GDPR only applies to living individuals, we must apply the same level of confidentiality to a deceased person information, as we would to a living person information.
mhs homes receives a request for information relating to a person who has died, it will only be appropriate in most cases to release information to the deceased person executor to their will, or personal representatives (usually their next of kin). mhs homes will only share necessary and relevant information.
Data processors
mhs homes reserves the right to contract out data processing activities or operations involving the processing of personal data in the interests of business efficiency and effectiveness. No third- party data processors will be appointed who are unable to provide satisfactory assurances that they will handle personal data in accordance with the data protection legislation.
People wishing to appoint a data processor will ensure that appropriate data protection and information security due diligence is undertaken on the proposed data processor prior to their appointment. The DPO will provide advice and guidance in respect of this.
All contracts with third parties that involve the processing of personal data will include specific contractual clauses setting out the third parties’ obligations in relation to compliance with the UK GDPR. A register of such agreements/arrangements is maintained by the DPO. The appropriate process owner must advise the DPO when the register needs to be updated.
No employee is permitted to commission or appoint a third party to process data on behalf of mhs homes without adhering to this policy.
Sharing of information within mhs homes
It is important to note that the rules surrounding data sharing also apply to the sharing of information within mhs homes. For example, confidential information held on mhs homes systems should be locked down and only accessible to those who need the information to carry out their work.
Transferring data outside of the United Kingdom
mhs homes will neither transfer or permit personal data to be transferred or processed outside the United Kingdom without the conditions laid down in the data protection legislation being met to ensure that the level of protection of personal data are not undermined.
Any transfer or processing of personal data that mhs homes undertakes or commissions outside of the UK, whether directly or indirectly, must be approved and may only take place if one of the following is satisfied:
The receiver is in a third country or territory, or is an international organisation, or in a particular sector in a country or territory, covered by UK 'adequacy regulations'
If there are no UK adequacy regulations about the country, territory, international organisation, or particular sector in a country or territory for your restricted transfer, the transfer is subject to 'appropriate safeguards' as detailed within Article 46 of the UK GDPR and supported by a completes transfer risk assessment signed off by the DPO
mhs homes will ensure that when adopting new services or technology that will process personal data, adequate steps are taken to check where the data will be hosted. Individuals’ rights must be enforceable and effective legal remedies for individuals must be available following the transfer. Data transfers outside of the UK will be reviewed on a case-by-case basis by the Data Protection Officer.
Direct marketing
The Privacy and Electronic Communications Regulations 2003 (PECR) sit alongside the UK GDPR and set out specific rules around electronic marketing. Direct marketing is defined as: “the communication (by whatever means) of advertising or marketing material which is directed to particular individuals”. PECR rules are stricter for direct marketing to individual users (e.g. contacting someone via their personal email) than for corporate users (e.g. contacting someone via their work or company email).
Advice published by the ICO/IC confirms that in many cases promotional messages that are necessary for an organisations task or functions do not constitute direct marketing.
The Data Protection Officer should be consulted immediately should teams wish to engage in direct marketing to ensure to ensure that the correct processes are following and we do not infringe on the rights and freedoms of our customers. A large proportion of fines issued by the ICO are as a result of grossly inappropriate marketing practices. The right to object to direct marketing must be explicitly offered to data subjects in an easy to understand form of words, so that it is clearly distinguishable from other information.
A data subject’s objection to direct marketing must be promptly honored. If a customer opts out at any time, their details should be suppressed as soon as possible. Suppression involves retaining just enough information to ensure that marketing preferences are respected in the future.
Confidentiality and professional conduct
All colleagues must maintain strict confidentiality when discussing customers, or staff, particularly in relation to sensitive or personal matters. Information should only be shared on a genuine need‑to‑know basis and through approved channels. Gossiping about customers or collegues, whether in person, by email, or on messaging sites for example but not limited to teams or whatapps via both work or personal devices, is strictly prohibited and may constitute a breach of data protection and employment policies. To reinforce integrity and transparency, all employees are required to complete a Conflicts of Interest Declaration annually and update it promptly if circumstances change. These measures help safeguard trust, protect privacy, and uphold our legal and ethical obligations.
Data Protection compliance when working from home
It is important to maintain the integrity and security of the personal data that we process on a daily basis for our customers and employees.
All employees must ensure they continue to adhere to this policy and Information Security policies, procedures and processes, when working from home. Employees must:
Keep up office protocol. Lock your screen and clear your workspace at the end of your working day. The most commonly used ways of doing this are by simultaneously pressing ‘control, alt, delete’ and then clicking ‘Lock’ or simultaneously pressing the ‘windows’ key and letter ‘L’ key on your keyboard.
Continue to save files on shared drives only, as this is the most secure place for them. Do not save any business personal data or business confidential data onto your desktop. Files saved on the desktop are not secure and your teams will be unable to access anything you have been working on, if you are absent.
Keep all paper-based files you have taken home with you as secure as you would in the office. Return all paperwork to your offices and if it is no longer required, only dispose of it when you return to the office, in the secure confidential waste bins. If you have a cross shredder, this can be used, ensuring it separated at the time of disposal
Data Protection complaints
In accordance with the Data (Use and Access) Act 2025 (DUAA), all data protection complaints must follow the prescribed process. Individuals are required to submit their complaint directly to the organization acting as the data controller before escalating the matter to the ICO/ IC .
All complaints relating to data protection should be addressed to the Data Protection Officer (DPO) at: [email protected]
The DPO will review and investigate each complaint in accordance with the organization’s mhs homes Complaints Policy, ensuring that all investigations are conducted promptly, thoroughly, and in compliance with applicable legal and regulatory requirements.
Training
mhs homes will ensure that all staff, employees, workers and those who it engages to process personal data are provided with appropriate training in the application of this and other data protection policies and procedures and in their data protection responsibilities. The DPO will undertake data protection awareness raising activities to keep data protection front of mind. Data Protection training will also be a compulsory element in inductions. All formal training and awareness raising activities will be recorded via Itrent with refresher training provided annually.
Approval details
| Date approved | 05/01/2026 |
| Implementation date | 01/04/2026 |
| Review date | 25/03/2029 |
| Approved by | Board |
