Privacy Policy and Cookies

CSH Surrey (Central Surrey Health LTD) is a Data Controller and is registered with the Information Commissioner’s Office (ICO), registration number is Z9948287. Our registered address is CSH Surrey, Dukes Court, 4th Floor Block A, Duke Street, Woking GU21 5BH and our company registration number is 5700920.

As an organisation, we are committed to protecting your information and respecting your privacy in accordance with the Data Protection Act 2018 (DPA18) and the UK General Data Protection Regulation (UK GDPR) 2018.

This notice explains what information we collect, why we collect it and how we keep it secure. It also explains your rights and our legal obligation. We undertake information audits to establish clear lines on what personal data we hold and what we do with it.

Notification of changes to this privacy notice

This privacy notice was last updated May 2022. If we use your personal data for any new purposes, updates will be made to the policy information and changes communicated, where necessary in accordance with current legislation. For all queries relating to our privacy policy, please email:

How the NHS and care services use your information 

CSH Surrey is one of many organisations working in the health and care system to improve care for patients and the public.

Whenever you use a health or care service, such as using Community Care services, important information about you is collected to help ensure you get the best possible care and treatment.

The information collected about you when you use these services can also be provided to other approved organisations, where there is a legal basis, to help with planning services, improving care provided, research into developing new treatments and preventing illness. All of these help to provide better care for you, your family and future generations. Confidential personal information about your health and care is only used in this way where permitted by law and would never be used for insurance or marketing purposes without your explicit consent.

You have a choice about whether you want your confidential patient information to be used in this way.

To find out more about the wider use of confidential information and to register your choice to opt out if you do not want your data to be used in this way, visit If you do choose to opt-out you can still consent to your data being used for specific purposes.

If you are not happy with this use of information you do not need to do anything. You can change your choice at any time.

For patients 

How we use your information

What information we collect?

If you are a patient, we hold records about you which may include:

Personal information such as, name, address, date of birth, gender, telephone number (s), email address(s), next of kin, emergency contact information, ethnicity, disability, religion, registered GP, clinical information.

The health professionals caring for you keep records about your health, treatment and care you receive with the NHS. The information in the record may come from you or other care providers e.g. GP, social care or hospital. The maintenance of these records will ensure that you receive the best possible care. These may be written down on paper or held on a computer and they include:

  • Basic personal details about you such as name, address, date of birth, next of kin etc
  • Contacts we have had with you such as appointment or clinic visits
  • Notes and reports about your health, treatment and care
  • Results of x-rays, scans and laboratory tests

Relevant information from people who care for you and know you well such as health professionals, relatives and carers.

It is essential that your details are accurate and up to date. Always check that your personal details are correct when you visit us and please inform us of any changes as soon as possible.

Why do we collect this information?

CSH Surrey aims to provide you with the highest quality of health care. To do this we must keep records about you, your health and the care we have provided, or plan to provide to you. Health records are held on paper and electronically, and we have a legal duty to keep these confidential, accurate and secure at all times in line with the Data Protection Act 2018 (DPA18) and the UK General Data Protection Regulation (UK GDPR).

We aim to maintain high standards, adopt best practice for our record keeping and regularly check and report on how we are doing. Your information is never collected for direct marketing purposes and is not sold on to any other third parties. Information is held for specified periods of time as set out in this policy under your rights.

CSH Surrey has to provide a legal basis for the processing of your information under UK GDPR.

If we need to use your personal information for any reason beyond those stated within this policy, CSH Surrey will communicate these changes before starting any new processing activity.  

How we keep in touch:

  • Text message
  • Email
  • Telephone calls

Our obligations

We have a duty to:

  • Inform you of the legal basis for processing your information, as required under the Data Protection legislation.

Our Legal Basis for Processing Personal Data

Our business is based on statutory powers which underpin the legal bases that apply for the purposes of the UK GDPR. The legal bases for most of our processing are:

Article 6(1)(e) – processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

For entering into and managing contracts with the individuals concerned, for example our employees, the legal basis is:

Article 6(1)(b) – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

Where we have a specific legal obligation that requires the processing of personal data, the legal basis is:

Article 6(1)(c) – processing is necessary for compliance with a legal obligation to which the controller is subject.

Where we process special categories data, for example data including health, racial or ethnic origin, or sexual orientation, we need to meet an additional condition in the UK GDPR. Where we are processing special categories personal data for purposes related to the commissioning and provision of health services the condition is:

Article 9(2)(h) – processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services

Where we process special categories data for employment or safeguarding purposes the condition is:

Article 9(2)(b) – processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law

CSH Surrey may rely on the following legal bases when processing your personal information:

When required to comply with the law. This may be in circumstances to:

Communicating when things go wrong: we have a duty to which is set out under The Health and Social Care Act 2008 (HSC) 2008 to report incidents, set out in the HSC 2008.
Safeguard individuals, set out in the (Safeguarding Vulnerable Groups Act 2006), Children Act 1989 & 2004.
Notify officials of infectious diseases which present significant risk to human health and the wider public, set out in The Public Health (Control of Disease) Act 1984 and the Health Protection (Notification) Regulations 2010.
Support other organisations with their regulatory requirements, eg Care Quality Commission (CQC), Information Commissioner's Office (ICO).
Support detection, investigation or to prevent a serious crime, monitor referral to treatment times and ensuring compliance with the NHS Constitution and the NHS Operating Framework, conduct audits to measure compliance with the law (e.g. Confidentiality Audits), respond to the rights of individuals requests under data protection law, share information relating to vulnerable individuals with emergency services in the event of an emergency (Civil Contingencies Act 2004). 
To support court orders requiring us to share information.

Vital interests

To protect someone’s life. This may be in circumstances to:

  • Share information to safeguard an individual and therefore prevent harm. 

Public task

When carrying out statutory, governmental or statutory functions. This may be in circumstances to:

Deliver patient care, when responding to complaints or concerns relating to the delivery of care, when monitoring patient pathways, to share information about a patient for their direct care (subject to both the common law duty of confidence, data protection legislation), and statutory duty under section 251B of the Health and Social Care Act 2012, to manage waiting lists, performance against national targets, activity monitoring e.g. number of referrals, when undertaking local clinical audits, commission funding for treatment and/or equipment.

Legitimate interests

This may be in circumstances to:

Support business functions, eg raising system level tickets, arranging access to system, take photos of service users to publish on twitter and interests’ websites, for general website enquiries, store next of kin data in the event of a medical emergency record of CCTV.

Your rights

We have a duty to provide you with rights of access to your data when requested.

Under the Data Protection Legislation, patients have the right to obtain a copy of their personal records held by us; this is called a Subject Access Request (SAR). 

To obtain a copy of your medical records, please submit your request to the CSH Surrey Subject Access Request Team.

Address: CSH Surrey SAR Team, 4th Floor, Dukes Court, Woking, Surrey, GU21 5BH


You will need to provide your information (e.g. full name, address, date of birth, Hospital/NHS number) and forms of identification. If you wish for another person to process your request on your behalf they will need to obtain your written permission to do so before we can provide copies of medical records. This ensures we are providing confidential information to authorised persons(s).

An individual may choose to nominate a representative (such as a solicitor or relative) to make a request on their behalf, however when this happens the request must be explicitly authorised by the person (e.g.  evidenced by a signed letter of consent).

Those who hold Lasting Power of Attorney for Health and Welfare for an individual can apply for that individual’s records.

Further guidance and assistance can be obtained from the Subject Access Request Team.

Under Data Protection legislation, you have a right to:

Be informed

Be informed about the collection and use of your personal data. This communication is achieved through this privacy policy.

Object and restrict

The legislation gives individuals the right to object to the processing of their personal data in some circumstances. This will depend on the legal basis (as described above) for processing your information. In order to formally object, you will need to do so verbally or in writing to

Request the restriction of your personal data, however this will only applies when/if you contest the accuracy of the personal data, the data has been unlawfully processed and/if you oppose erasure and requests. You can make a request for restriction verbally or in writing to

Rectification and erasure

Have inaccurate personal data rectified or completed if it is incomplete.

The legislation states that ‘personal data is inaccurate if it is incorrect or misleading as to any matter of fact.’ You can make a request for rectification verbally or in writing to


When you are providing consent for the purpose of processing your personal data and activity, you will always have the freely given right to actively accept and withdraw.

CSH Surrey manages consent when processing data in the following ways:

Regularly reviewing consents to check that the relationship with the individual and the purpose for processing information has not changed. By having appropriate processes in place to refresh consent at appropriate intervals, including any parental consents. Acting on withdrawals of consent as soon as reasonably possible. 

National Data Opt Out

Whenever you use a health or care service, such as attending Accident & Emergency or using community care services, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.

The information collected about you when you use these services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:

improving the quality and standards of care provided
research into the development of new treatments
preventing illness and diseases
monitoring safety
planning services

This may only take place when there is a clear legal basis to use this information. All these uses help to provide better health and care for you, your family and future generations. Confidential patient information about your health and care is only used like this where allowed by law.

Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn’t needed.

You have a choice about whether you want your confidential patient information to be used in this way. If you are happy with this use of information you do not need to do anything. If you do choose to opt out your confidential patient information will still be used to support your individual care.

To find out more or to register your choice to opt out, please visit   On this web page you will:

  • See what is meant by confidential patient information
  • Find examples of when confidential patient information is used for individual care and examples of when it is used for purposes beyond individual care
  • Find out more about the benefits of sharing data
  • Understand more about who uses the data
  • Find out how your data is protected
  • Be able to access the system to view, set or change your opt-out setting
  • Find the contact telephone number if you want to know any more or to set/change your opt-out by phone
  • See the situations where the opt-out will not apply

You can also find out more about how patient information is used at:  (which covers health and care research); and (which covers how and why patient information is used, the safeguards and how decisions are made)

You can change your mind about your choice at any time.

Data being used or shared for purposes beyond individual care does not include your data being shared with insurance companies or used for marketing purposes and data would only be used in this way with your specific agreement.

Health and care organisations have to put systems and processes in place so they can be compliant with the national data opt-out and apply your choice to any confidential patient information they use or share for purposes beyond your individual care.

How long will we hold your information?

Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for the specific purposes. All NHS patient records are kept in line with the NHS Records Management Code of Practice 2021 and the Retention Schedule.

CSH Surrey will regularly review the length of time we keep your personal data and securely delete information that is no longer needed for the purposes it was originally intended. This process will enable clear and accurate data, keeping it up to date, available and confidential.

How we share your information

In circumstances where we need to share your personal data; we will always ensure this is conducted lawfully and account the justifications for doing so.

When data sharing external to our organisation, CSH Surrey will always assess the potential benefits and risks to you and others, we will weigh the proportionality for the purpose and what we are trying achieve by this activity. We will also consider if the objective be achieved without sharing personal data and have measures to ensure adequate security is in place to protect the data when sharing this.

International transfer of your personal data

CSH Surrey does not transport, store or share personal data outside of the European Economic area.

Links to other publiciations - websites

This privacy notice does not cover the links within this site linking to other websites. We encourage you to read the privacy statements on the other websites you visit.

Cookie Policy

Cookies allow a website to recognise a user’s device and respond to them as an individual. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.

What cookies we use and how we use them

Business Critical Cookies

_ga, _gat, _gat_cqc_tracker and _gid

These cookies allow CSH Surrey to count visits and traffic sources to measure and improve the performance of its website. They help us to know which pages are the most and least popular and see how visitors move around our site. All information these cookies collect is aggregated and therefore anonymous. We use the Google Analytics service for this purpose. We also use a cookie for the cookie bar to remember you have accepted cookies: CP_allowcookies

Essential Cookies


These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by visitors which amount to a request for services, such as logging in or filling in forms. Visitors can set their browser to block or alert them about these cookies; however, some parts of the site will not then work. These cookies do not store any personally identifiable information.

​You can choose to accept or decline cookies although this may prevent you from taking full advantage of the website.


If you have any comments, queries or complaints about this Privacy Notice or the processing of your personal information please address these to: Data Protection Officer, Central Surrey Health, 4th floor, Dukes Court, Woking, GU21 5BH


Alternatively, you are entitled to get in touch with the Information Commissioner’s Office (ICO). The Information Commissioner’s Office enforces and oversees the Data Protection Regulations. To find out more about the information rights in the public interest, further details can be found at: