Data Protection Policy – GDPR
Policy Number: DOC 003
Date Implemented / Last Reviewed: July 24, 2025
Next Review Date: July 24, 2026
Policy Statement
Tomaaron Care Services LTD is committed to protecting the privacy and rights of our staff, clients, and stakeholders in accordance with the UK General Data Protection Regulation (UK GDPR), tailored by the Data Protection Act 2018.
We recognise our obligation to maintain transparency and accountability in how we collect, store, and use personal data. This policy outlines our approach to ensuring that personal data is processed lawfully, fairly, securely, and with respect for individual rights.
Scope and Compliance
This policy applies to all staff, contractors, and anyone working on behalf of Tomaaron Care Services LTD who has access to personal data. Breaches of this policy or of data protection legislation will be treated as serious misconduct and may result in disciplinary action.
The policy is reviewed regularly and updated in line with changes to UK GDPR and other relevant legislation.
What is Personal Data?
Personal data refers to any information relating to an identifiable individual. It can be in digital or paper form and includes names, contact details, health information, employment records, photos, and CCTV footage.
Data Controller and Responsibilities
Tomaaron Care Services LTD is the Data Controller. We have appointed a Data Protection Officer (DPO) to oversee our compliance and respond to any concerns.
Our Senior Leadership Team is responsible for ensuring data protection procedures are embedded across all operational areas.
Data Protection Principles
We adhere to the following GDPR principles:
- Lawfulness, Fairness & Transparency
We process personal data in a lawful and transparent manner and inform individuals of how their data will be used. - Purpose Limitation
We collect personal data for specified, legitimate purposes and do not use it for unrelated activities without additional consent. - Data Minimisation
We only collect and retain personal data that is relevant and necessary. - Accuracy
We ensure that data is accurate and, where necessary, kept up to date. - Storage Limitation
We do not retain personal data longer than necessary. Data is securely destroyed or archived when no longer required. - Integrity and Confidentiality
We protect data against unauthorised access, accidental loss, or damage through robust technical and organisational measures. - Accountability
We maintain records of our processing activities and can demonstrate compliance with all data protection obligations.
Individual Rights
Under GDPR, individuals have the right to:
- Be informed about how their data is used
- Access their personal data (Subject Access Requests)
- Rectify incorrect or outdated data
- Request erasure (‘right to be forgotten’)
- Restrict processing of their data
- Object to processing for direct marketing
- Data portability (receive their data in a readable format)
- Not be subject to automated decision-making without safeguards
Subject Access Requests should be submitted in writing to our DPO. We will respond within one calendar month.
Data Security
We ensure personal data is kept secure and accessible only to authorised individuals. Measures include:
- Lockable filing systems
- Password-protected systems
- Screen privacy and lock policies
- Secure destruction of hardcopy records
- Wiping of digital media prior to disposal
Staff working remotely must apply the same standards of data security at all times.
Third-Party Access & Data Sharing
We only share personal data with third parties where lawful, and in line with GDPR. This may include:
- Regulatory authorities
- Health professionals (where necessary)
- Law enforcement (if legally required)
We never sell personal data to third parties.
Website & International Transfers
We do not transfer personal data outside the UK or European Economic Area (EEA) without appropriate safeguards in place.
We ensure consent is obtained before publishing any personal data (including photos) on our website: https://tomaaroncare.co.uk
Our website includes a clear Privacy Notice detailing how data collected online is handled.
Marketing and Consent
Consent is obtained explicitly and clearly when required, particularly when handling sensitive personal data. Consent must be informed, voluntary, and given without pressure.
We do not rely on passive opt-ins or assume consent through silence.
CCTV
We use CCTV in some locations to protect staff and visitors. CCTV footage is considered personal data and is managed in accordance with this policy. It is only accessed by authorised personnel and stored securely.
Emails
Emails may be accessed by authorised staff in accordance with our IT and Communications policy. All Tomaaron Care Services email users are reminded that the content of emails may be subject to disclosure under the Freedom of Information Act and Data Protection Act.
Review & Monitoring
This policy is reviewed annually and whenever there is a significant change in legislation or internal processes. We encourage all staff and stakeholders to remain familiar with its contents.
For further guidance, see the Information Commissioner’s Office (ICO):
www.ico.org.uk
Contact
For any data protection queries or Subject Access Requests, please contact:
Data Protection Officer
Tomaaron Care Services LTD
Spaces, Office 1.49, 9 Greyfriars Road Reading, RG1 1NU
info@tomaaroncare.co.uk
07778 909813
