Privacy Notice
As a data controller, Northamptonshire Healthcare NHS Foundation Trust (NHFT) process both personal data and special category personal data (sensitive).
Northamptonshire Healthcare NHS Foundation Trust,
St Mary's Hospital
London Road
NN15 7PW
Tel 03000 274 000
Our Data Protection Registration number is Z6769102.
We have an obligation to ensure compliance with the terms of the UK General Data Protection Regulations, Data Protection Act 2018 and Freedom of Information Act 2000.
Why do we collect and store personal data?
We process personal data to enable us to provide healthcare services for patients, data matching under the national fraud initiative; research; supporting and managing our employees, maintaining our accounts and records and the use of CCTV systems for crime prevention.
The Trust has a duty to:
- Process data lawfully, fairly and in an open manner
- Only use data for a specific defined purpose
- Only gather and record data that is relevant and limited to the defined purpose
- Take every reasonable step to ensure data is kept accurately
- Only hold data in an identifiable form for the minimum period necessary
- Hold data securely and prevent any unlawful processing
The Types of Information that we may collect and use include the following:
- personal details
- family details
- education, training and employment details
- financial details
- goods and services
- lifestyle and social circumstances
- visual images, personal appearance and behaviour,
- details held in the patients record
- responses to surveys
What is the Legal Basis for processing data?
Under the terms of the UK General Data Protection Regulations, we are required to notify you of the legal basis for processing the data we handle.
Personal data provided to the Trust for the purpose of healthcare delivery, management and treatment:
6(1)(e)Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
Special Category Personal Data provided to the Trust for the purpose of healthcare delivery, management and treatment:
9(2)(h) Necessary for the reasons of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional
To manage our contractual obligations for the services we have been commissioned to deliver:
- Ensure that money is used properly to pay for the services it provides
- Investigate complaints, legal claims or important incidents
- Make sure that services offered give value for money
- Make sure services are planned to meet patients' needs in the future
- Review the care given to make sure it is of the highest possible standard
To improve the efficiency of healthcare services
Schedule 1 Part 2 of the Data Protection Act 2018, provides the basis in UK law for the processing of criminal offence data that is gathered by the Trust for healthcare management purposes.
Staff Data
If we are your employer we process your data to enable us to undertake our responsibilities under law.
Personal data provided by staff members for the purpose of employment:
6(1)(f) Necessary for the purposes of legitimate interests
Special category data provided by staff members for the purpose of employment:
This data is required to manage the operation of the organisation and to ensure compliance with the terms and conditions outlined in your contract, as part of your employment.
9(2)(b) necessary for the carrying out of obligations under employment, social security or social protection law, or a collective agreement;
Data that is processed by RL Datix via the Allocate system is processed outside of the UK. This transfer is conducted using the Information Commissioners Office International Data Transfer Agreement to meet legal requirements.
System Monitoring
We will adhere to the Information Commissioners Office guidance in relation to the monitoring of staff activity within electronic systems, for more information please see below:
National Fraud Initiative:
The Trust has a duty to protect the public funds it administers and as such participates in the National Fraud Initiative. This is an electronic data matching exercise conducted by the Cabinet Office, carried out with statutory authority under Part 6 of the Local Audit and Accountability Act 2014. It does not require the consent of employees.
6(1)(e)Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
For more information see the link below:
Staff Occupational Health Data
Special category data gathered by the Trust in relation to employee health is processed for the reasons of preventative or occupational medicine and for assessment of working capacity.
Special Category Personal Data provided to the Trust for the purpose of healthcare delivery, management and treatment:
9(2)(h) Necessary for the reasons of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional
Staff Vaccinations
NHS England are leading on the use of vaccination data to support national planning and response. The relevant national data has been made available to the Trust to assist with the monitoring of the vaccine rollout for Trust staff. Staff vaccination status will be shared in accordance with Regulation 3 of the Health Service Regulations 2002 to assist in meeting national requirements as part of the NHS response plan to vaccinations for staff. Staff may be asked for additional personal data to ensure that data quality requirements are met.
Student Data
Student Information Privacy Notice
The Trust is the Data Controller for your personal information and is subject to the General Data Protection Regulation (GDPR).
The Trust works with partner academic organisations to support and mentor students and apprentices during their placements. Student and apprentice information is processed in accordance with the individual learning agreements in place with the academic institution.
This privacy notice explains how the Trust uses and shares your personal data and outlines your rights in relation to the personal data we hold.
What information are you collecting?
The Trust may obtain, hold and process data of applicants and students including personal data and special category data.
Personal data and special category data held by the Trust relating to students is obtained directly from the student or applicant.
Why are you collecting my data?
The Trust holds the personal data and special category data of its applicants and students to facilitate support and mentoring of individuals and to ensure compliance with the terms and conditions outlined via contract or learning agreement.
Only information required for these purposes is obtained and processed for operational purposes, and without it the Trust may not be able to provide its services to you or meet its statutory obligations.
Personal data provided by students for the purpose of employment:
6(1)(e) whereby processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller (Northamptonshire Healthcare).
Special Category Personal Data provided to the Trust for the purpose of healthcare delivery, management and treatment:
9(2)(b) necessary for the carrying out of obligations under employment, social security or social protection law, or a collective agreement;
Additional Information on the e-leaning toolkits used and their Privacy Polices can be accessed via links below.
Training Tracker Privacy Policy link:
Highfield e-learning Privacy Policy link:
Data held by the Trust may be audited to ensure that quality standards are being met this is in line with the purpose of healthcare, delivery, and management. Personally, identifiable data is kept to a minimum when audits are undertaken. Data collected to evidence audits undertaken are always anonymised.
Personal data provided by individuals that is used for audit.
6(1)(e)Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
Special Category Personal Data provided to the Trust for the purpose of healthcare delivery, management and treatment:
9(2)(h) Necessary for the reasons of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional
Body Worn Cameras
Body worn camera technology will be used within inpatient areas at Berrywood and St Mary's hospital. The initiative is specifically being implemented for security and safety purposes; not for clinical observation.
Personal data gathered by Body Worn Cameras:
6(1)(e) whereby processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller (Northamptonshire Healthcare)
Special Category Personal Data gathered by Body Worn Cameras:
9(2)(g) processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;
Trust Membership and Involvees
As Members or Involvees of the trust you will likely receive information that may be of interest as a patient, carer or member of the community that we serve. In common with all other NHS foundation trusts we have a statutory duty to engage with our communities and encourage new Members and Involvees of the Trust. Member data is stored in conjunction with Civica who act on behalf of the Trust.
Personal data provided by Members or Involvees for the purpose of engaging with communities:
6(1)(e) whereby processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller (Northamptonshire Healthcare).
Special Category data provided by Members
9(2)(g) processing is necessary for reasons of substantial public interest on the basis of UK law.
Equality and Diversity Data
As a Trust we have a duty to eliminate unlawful discrimination, harassment or victimisation, to advance equality of opportunity and to foster good relations. All public bodies must treat people from different groups fairly and equally. Data on equality and diversity is captured in accordance with the Equality Act 2010.
Special Category Personal Data provided to the Trust for the purpose of compliance with Equality legislation :
9(2)(b) necessary for the carrying out of obligations under employment, social security or social protection law, or a collective agreement.
Mental Health Act Data
Most people who receive treatment in hospitals or psychiatric units for mental health conditions are there voluntarily and have the same rights as people receiving treatment for physical illnesses. However, a small number of patients may need to be compulsorily detained under a section of the Mental Health Act 1983.
Special Category Personal Data provided to the Trust for the purpose of healthcare delivery, management and treatment:
9(2)(b) necessary for the carrying out of obligations under employment, social security or social protection law, or a collective agreement.
9(2)(c) Necessary to protect the vital interests of a data subject who is physically or legally incapable of giving consent
9(2)(h) Necessary for the reasons of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional
Use of Photographs
Photographs where an individual can be clearly identified will only be used as part of promotional materials and website where explicit consent has been given by the individual.
Personal data for the purpose of promoting the work of the Trust:
6(1)(a)Consent of the data subject
Recovery College
Recovery College NHFT supports individuals with experience of mental health difficulties to live the life they want to lead and become experts in their own self-care. The college supports individuals through courses designed to contribute towards wellbeing.
Data captured during enrolment is required to manage this service and to provide you details of available courses and resources.
Personal data provided by individuals for the purpose of enrolment:
6(1)(e)Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
Special Category Personal Data provided to the Trust for the purpose of healthcare delivery, management and treatment:
9(2)(b) necessary for the carrying out of obligations under employment, social security or social protection law, or a collective agreement;
Data is gathered for research with the same controls as for the collection and processing of data for healthcare purposes. Consent will be sought for participation in research trials under the common law duty of confidentiality.
Personal data provided by individuals for the purpose of research:
6(1)(e)Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
Special Category Personal Data provided to the Trust for the purpose of healthcare delivery, management and treatment:
9(2)(h) Necessary for the reasons of preventative or occupational medicine, for assessing the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services on the basis of Union or Member State law or a contract with a health professional
CAMHS Crisis Cafe
The Trust is partnered with the REACH Collaborative and ST Andrew's Hospital to provide health services at our Crisis Cafe sites. Data is shared between the partner organisation for the purpose of providing support to users of the cafe. The legal basis for processing this data is the same as the Healthcare purpose stated above.
Patient Feedback
The Trust works with IQVIA as a Third Party to support us to capture patient feedback. Service users who have not dissented to take part will receive a text message asking them to provide feedback on their experience. If you are concerned or wish to opt out of providing feedback please raise with your care team.
Patient Stories
Patient stories are gathered as part of the reflective practice of the Trust and are voluntarily provided by patients who want to contribute feedback and give their consent to do so.
- 6(1)(a) & 9(2)(a) Consent of the data subject, is the lawful basis used to process this data.
Statutory inquiries are held under the Inquiries Act 2005 which provides public inquiries certain powers in the furtherance of its obligations.
Section 21 of the Inquiries Act 2005 gives an inquiry the power to compel relevant evidence from the Trust, this may include records that contain personal data. This data is necessary to enable the inquiry to carry out their work, which is a task carried out in the public interest and in the exercise of a statutory function. The Trust has a duty to comply with requests for data and consent is not needed from data subjects for this processing purpose.
6(1)(c) Legal obligation: the processing is necessary for to comply with the law (not including contractual obligations).
Data sharing with partner organisations
We hold a list of the information sharing agreements we currently have in place with our partner organisations. As part of the Northamptonshire Health and Care partnership we work with other health and public sector organisations for the delivery of direct care services. An example of working with other organisations for direct patient care is supporting the management of Musculoskeletal Care within the county through triaging referrals made via GP surgeries.
Northamptonshire Care Record
Local providers of health and social care have a duty to keep complete, accurate and up-to-date information about your care to ensure you can receive the best possible treatment and support.
However, when these records need to be shared between different organisations this has previously had to be done via traditional methods such as secure post, fax or email, which can be slow and sometimes unreliable.
All this is about to change in Northamptonshire as we work to introduce a new process joining up your care records digitally so any professional who's directly involved in your care can instantly access the information they need to support you. We're calling this the Northamptonshire Care Record (NCR).
By modernising the way GPs, hospital specialists, nurses, social workers, psychologists, health visitors and other professionals access your records, we're making it much quicker and easier for you to get the best possible care.
All information held in the Northamptonshire Care Record is completely secure and can only be seen by those who are directly involved in your care. Northamptonshire Healthcare NHS Foundation Trust will be providing information to support health and care partners in the County to treat you safely.
For more information or if you have any queries please see the dedicated Northamptonshire Care Record website at Northamptonshire Care Record | Integrated Care Northamptonshire (
National Surveys
Your personal data may be used for the purposes of the NHS Patient Survey Programme, and this may include passing data to a CQC approved contractor. The anonymised reports produced by the survey programmes are used to help make service improvements.
The processing basis for the Trust to use your information for the NHS Patient Survey Programme is set out in Article 6(1)(e) of the General Data Protection Regulations which allows data to be processed where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller .
There is a Duty of Care to report safeguarding concerns to partner organisations to support an individual's welfare. There is useful information on the Trust's Safeguarding Page on the importance of safeguarding for Adults and Children and how staff are supported to act in the best interests of the individual.
Supporting families
We are committed to supporting the health and wellbeing of families. This means to protect you and your child we may need to share information with other agencies such as social services or the police.
Public security
Data may be shared with the Police or other national security agencies where it is necessary and proportionate to support the prevention, investigation and detection of crime.
Data may be provided to the Trust by partner agencies to support the management of patients with Tuberculosis or suspected Tuberculosis.
Infection Control
Data may be provided to the Trust by partner agencies to support the management of public health.
Integrated Care Across Northamptonshire
NHFT is part of Northamptonshire Health and Care Partnership. As part of this NHFT have committed to the Integrated Care Across Northamptonshire (iCAN) five-year transformation programme, to deliver change to services across the whole spectrum of health and care in Northamptonshire.
The programme will address the four priority areas of:
mental health,
children and young people,
elective care,
ICAN (integrated care across Northamptonshire)
The transform of care and outcomes aims to ensure best use is made of all resources i.e. staff, buildings and funding, and of the wider support within the community. It aims to join up services in a way that makes it easier for professionals and residents to navigate as an integrated care system and grow as the programme progresses. The transformation will directly affect service users, front line teams and clinicians and to make this happen, it needs to be designed with them and tested in real life.
To facilitate this project work including carrying out system-wide diagnostics using data analysis, data is required to be shared with NHS Northamptonshire Clinical Commissioning Group & Newton Europe Limited.
The information gained will help the health and care organisations across Northamptonshire to see the key opportunities to improve outcomes for care. iCAN will also help organisations across Northamptonshire to understand the scale of the change needed and how ready they are to embed change.
Is my data transferred overseas?
Your personal data may be transferred outside of the UK, for example, if the Trust uses a cloud service that has servers in another country. A Data Protection Impact Assessment will have been completed to ensure that data is held securely and within the requirements of the law.
If your data is transferred overseas there will be a contract in place, and a Data Processing Agreement that ensures responsibility for safeguarding data.
Is my data handled using automated decision processes?
The Trust does not currently use automated decision processes this privacy notice will be regularly reviewed and updated as necessary.
How do we store and safeguard your data?
We may introduce new processes or technologies that capture and store personal data e.g. biometric scanners, body worn video cameras etc. The Trust considers privacy at the initial design stages and throughout the complete development process by invoking the Data Protection Impact Assessment and Change Management Processes; thus ensuring the appropriate technical and organisational measures are in place to safeguard individual's rights and adherence to UK-GDPR/DPA 18.
We keep your information in accordance with timescales set out in the Records Management Code of Practice for Health and Social Care. Personal data that does not have a national retention schedule in the Code of Practice is managed for as long as is necessary to fulfil the purpose of obtaining it or if we are required to keep it by law. A link to this document can be found below:
NHSX_Records_Management_CoP_V7.pdf (
Patient Led Sharing
Across a number of NHFT services a secure computer system is used called SystmOne to hold medical records.
SystmOne is also used in Northamptonshire, by most GPs as well as the out of hours GP service. For those services that use SystmOne, since October 2013 you have been able to decide which NHS services can view your record, with the aim of providing you with control and reassurance regarding how your secure medical records are used.
With your permission, clinicians using SystmOne are able to share your medical record easily and safely with the other healthcare services involved in your care. This will mean that when you attend any service using SystmOne they will be able to view your NHFT medical record so that the clinicians who see you have all the information they need to enable them to provide the best possible health care for you.
Why is this necessary and how does it work?
Patient Led Record Sharing puts YOU in control of your NHFT medical record - you will be asked whether you wish to share your information with other health care services, like your GP and the benefits and any risks of your decision will be fully explained to you.
Sharing your medical record will improve communication about your care between healthcare professionals - it is important that you give your consent to this sharing, to ensure that your clinicians have all the information they require to offer you the best possible care.
Patient led record sharing enables high quality, joined up care across the different NHS services.
This sharing was designed to align SystmOne with the NHS care record guarantee. This guarantee states that patients should be able to control which services, (that are caring for them) are able to see information held on their record.
All staff members are trained in confidentiality and information governance. If you decide to share your record you can be sure that healthcare professionals will always treat your health record with the greatest care and discretion.
Will all my medical record be shared?
If you do not wish another service to see particular items in your medical record, please discuss this with your GP or healthcare professional. You can request for individual entries in your patient record to be marked as 'Private'. These will not be visible at any NHS care service other than the one that recorded the information.
Can I opt out of processing?
Article 21 of the UK GDPR gives you the right to object to processing of personal data about you on grounds relating to your particular situation. The right is not absolute and will only apply in specific circumstances. We may continue to use the data if we can demonstrate compelling legitimate grounds. If you wish to request an objection to processing, please write to the information governance team using the following address
If you wish to opt out of sharing your information with other healthcare settings please discuss with your healthcare team at your next appointment. They can discuss with you the impact to your individual health care.
Where consent has been identified as the basis for processing your data, please contact the service as instructed on the relevant consent form to withdraw your consent. Otherwise, please email
If you wish to opt out of having your information used for the purpose of national surveys detailed in the section of the privacy notice called Other ways data may be shared , please complete the form below:
National Opt-Out
Northamptonshire Healthcare NHS Foundation Trust is one of many organisations working in the health and care system to improve care for patients and the public.
Whenever you use a health or care service, such as attending Accident & Emergency or using Community Care services, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.
The information collected about you when you use these services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:
improving the quality and standards of care provided
research into the development of new treatments
preventing illness and diseases
monitoring safety
planning services
This may only take place when there is a clear legal basis to use this information. All these uses help to provide better health and care for you, your family and future generations. Confidential patient information about your health and care is only used like this where allowed by law.
Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn't needed.
You have a choice about whether you want your confidential patient information to be used in this way. If you are happy with this use of information you do not need to do anything. If you do choose to opt out your confidential patient information will still be used to support your individual care.
To find out more or to register your choice to opt out, please visit On this web page you will:
- See what is meant by confidential patient information
- Find examples of when confidential patient information is used for individual care and examples of when it is used for purposes beyond individual care
- Find out more about the benefits of sharing data
- Understand more about who uses the data
- Find out how your data is protected
- Be able to access the system to view, set or change your opt-out setting
- Find the contact telephone number if you want to know any more or to set/change your opt-out by phone
- See the situations where the opt-out will not apply
You can also find out more about how patient information is used at: covers health and care research); and (which covers how and why patient information is used, the safeguards and how decisions are made)
You can change your mind about your choice at any time.
Please note the National Data Opt-Out does not apply to data collected by the National Confidential Inquiry into Suicide and Safety in Mental Health (NCISH). This means that information about patients and care can be collected by NCISH even where people have chosen not to have their health data shared for reasons beyond treatment and care.
Northamptonshire Health Care NHS Foundation Trust is compliant with the national data opt-out policy.
How do I make a request for Information or make a complaint?
If you wish to ask the Trust about a data protection issue, request information on data we process, request a copy of your data, make a request for data to be erased, rectified or you have concerns about the processing of your personal data by us you may contact our Information Governance Team at:
Information Governance Team
Information Governance Team Office,
1st Floor,
RCI Building,
Kettering Venture Park,
NN15 6EY
Telephone: 0300 0111133
If you wish to contact our Data Protection Officer directly then please use the details below:
Sarah Ratcliffe
Data Protection Officer
Information Governance Team Office,
1st Floor,
Haylock House,
Kettering Venture Park,
NN15 6EY
The data protection function is further supported by the Caldicott Guardian - Itai Matumbike and Senior Information Risk Owner - David Maher
If you wish to make a complaint then please contact the relevant team below:
You can call the patient advice and liaison service PALS free on 0800 917 8504 9am-4pm
You can call our complaints department free on 0800 917 7206, 9am-4pm
You can e-mail PALS or the complaints team at
Care will not be adversely affected by any comments or complaints you make.
If you are not content with the outcome of your complaint, you may apply directly to the Information Commissioner for a decision. Generally, the Information Commissioner cannot make a decision unless you have exhausted the complaints procedure provided by the Trust. The Information Commissioner can be contacted at:
The Information Commissioner's Office
Wycliffe House
Water Lane
How do I make a request for information relating to someone who has died?
Access to the health records of deceased patients is covered by The Access to Health Records Act AHRA) 1990
The Act provides certain individuals with a right of access to the health records of a deceased individual. These individuals are defined under Section 3(1)(f) of that Act as, 'the patient's personal representative and any person who may have a claim arising out of the patient's death'. A personal representative is the executor or administrator of the deceased person's estate.
There is no statutory right of access to records of deceased patients which fall outside of the time period covered by the Act and Northamptonshire Healthcare NHS Foundation Trust is unable to process requests for records of Deceased Patients where the date of death is prior to 1st November 1991.
The Trust will consider requests for access where a patient has died after 1st November 1991; these requests will be considered on a case by case basis.
Information Governance Team
Information Governance Team Office,
1st Floor,
Haylock House,
Kettering Venture Park,
NN15 6EY
Is this Privacy Notice regularly reviewed?
We keep our privacy notice under regular review. This privacy notice was last updated on: 20/05/2024
Children's privacy notice
This page is our Privacy Notice. A Privacy Notice tells you how we use information about you, so you know what happens with it when people give it to us.
Who are we?
We are Northamptonshire Healthcare NHS Foundation Trust, and we offer lots of services to people who live in Northamptonshire. We provide care for people who need it and help them to be healthy, comfortable and happy.
Personal data? What's that?
Anything that can identify you is your personal data. You might know this could be things like your name or a photo of you, but it is also things like your email address or your online usernames.
There are some types of data we have to be extra careful with. These are known as special category data. This could be something like an illness you have, or what religion you are.
Sometimes we have to use data about crimes and breaking the law.
Why do you need my personal data?
The main reason we need to use your personal data is to know who you are if you are receiving help from us to be healthy, comfortable and happy.
If we don't have information about you, it could mean you miss out on the things we can help you with.
Sometimes we need to tell you more about what we're doing with information about you. You can see some of these on this page.
So, can you use my personal data for anything?
Just because we have information about you, it doesn't mean we can do what we want with it - we have to follow lots of rules.
Sometimes we have to ask you if we can use it, and if you say no then we can't. There are times when there are more rules that say we must use information about you to do our work, and we can do this without asking you first.
There are different rules for your name and address and about health and wellbeing. If we are using any of your data, we make sure we are following all the rules.
Can anyone else see my personal data?
Sometimes to do our work we have to share information about you, or other people might share it with us. We're very careful about how we do this, meaning there are even more rules.
We might need to share your data with your school, doctor or family if they are helping you, or with the police or ambulance service.
We keep a lot of data on a system we call SystmOne. There are times we let other people who are involved in your care use SystmOne to make sharing easier, but we always make sure that they know all our rules first, so only people who are helping you will look at your data.
There are times we might need to ask for help doing our work, and someone else will use your data for us. This could mean your personal data might go around the world, but don't worry - we'll make sure it's safe.
Do you keep my personal data forever?
We only keep your personal data for as long as we need it and sometimes this might be for years. This is because we have to follow rules about how long we can keep your personal data.
Do I have a say in what happens to my personal data?
Yes, you do. You have what we call 'rights' when we use information about you. One of these is the right to know what we do with it. That's what this page is for.
You can ask us to tell you what personal data we have about you or ask us if we can stop using it or delete it. If your personal data is wrong, you can tell us, and we will fix it.
Who makes sure you follow all the rules?
We have someone called our Data Protection Officer, and their job is to protect your data. This means they make sure we are following all the rules, and your data is safe. If they see something wrong, they tell us how we can fix it.
Because of how important it is to keep your data safe, and to follow all the rules, you can email or write a letter to our Data Protection Officer if you are worried about what we do:
Data Protection Officer
Information Governance Team
Northamptonshire Healthcare NHS Foundation Trust
Haylock House
Kettering Venture Park
NN15 6EY
Or email:
There is a business whose job it is to make sure we follow the rules and can speak to us if we do things wrong.
You can also email or write to them:
Information Commissioner's Office
Wycliffe House
Water Lane
Or look online at
Conditions of use of this site
Use of this site
Northamptonshire Healthcare NHS Foundation Trust provides this website for personal use. In using this website, the user agrees to use this site for lawful purposes only and in a manner that does not infringe the rights, or restrict or inhibit the use of this site by any third party.
Information collected through this website is for the sole use of Northamptonshire Healthcare NHS Foundation Trust.
Northamptonshire Healthcare NHS Foundation Trust cannot guarantee uninterrupted access to this website or the sites to which it links, and accepts no responsibility for any damages arising from the loss of use of this information.
This website is intended simply to provide helpful advice and information about Northamptonshire Healthcare NHS Foundation Trust and the services we provide.
The Trust has taken every care in the preparation of the content of this website. Northamptonshire Healthcare NHS Foundation Trust is not liable for any loss or damage arising from the use of this site or the information contained in it.
Northamptonshire Healthcare NHS Foundation Trust is not responsible for the availability of access to and links from this site, or for the content on linked sites. The Trust is not responsible for any transmission received from any linked site. Links are provided solely to assist visitors to Northamptonshire Healthcare NHS Foundation Trust’s website and the inclusion of a link does not imply that the Trust endorses or has approved the linked site. Equally, the lack of a link does not imply lack of endorsement.
Unless otherwise indicated, Northamptonshire Healthcare NHS Foundation Trust retains the copyright to information featured on this website.
The names and logos identifying Northamptonshire Healthcare NHS Foundation Trust are proprietary marks of the NHS. Copying our logos and any other third party logo via this website is not permitted without approval of the relevant copyright owner.
Re-use of information
You may re-use the information on this website free of charge in any format. Re-use includes copying, issuing copies to the public, publishing, broadcasting and translating into other languages. It also covers non-commercial research and study. Re-use is subject to the following conditions:
- Use of material should include an acknowledgement of the source
- Reproduction of material should be accurate and should not mislead
- Information should not be used for the principal purpose of advertising or promoting a particular product or service or for commercial gain.
If you have any questions about reusing information please email
Northamptonshire Healthcare NHS Foundation Trust may at any time amend and update this website.
Cookies are small files placed on your computer by websites you visit. You can read all about common things cookies are used for on the Your Online Choices website and the About Cookies website.
You can view all key public information on our website without needing to use cookies, but some parts of it (usually third party software like YouTube or Twitter) may not display properly without them.
Your cookie choice
It is your choice whether or not you want websites to put cookies on your computer. You can manage your choices in your web browser on any device, and AboutCookies offers a guide to managing your cookies on all modern browsers.
It’s important to remember that if you choose to disable all cookies all the time, some websites or website functions (particularly ones that require logins or passwords) may not work.
Withdrawing consent to use of cookies
If you decide at any time you don’t want cookies anymore, you can clear the cache in your web browser to delete any cookies that are there. You can then disable cookies and no more will be stored unless you decide to enable them again.
Our cookies do not provide us with any private or personally identifiable information about you. All data that is gathered is anonymous.
Our cookies
VerseOne CMS Cookies
This website is bulit on the VerseOne CMS By default, VerseOne CMS uses only one essential cookie, which is called JSESSIONID: this cookie is destroyed at the end of a user's session, i.e. when a user logs out and leaves the site, or after 20 minutes of inactivity on the site.
VerseOne CMS does not track users across sites, and JSESSIONID does not enable any functionality except the three items listed above.
JSESSIONID is an essential cookie — it is absolutely required for the operation of the solution and for the protection of users' data and security. For this reason, it cannot be switched off and users cannot opt out.
VerseOne CMS also uses VOPECRA, a long-term non-tracking cookie that is only placed on the user's browser if the user accepts cookies: VOPECRA is the cookie that remembers that the user has accepted cookies.
JSESSIONID | Session | Essential cookie for software functionality including session management for authentication, form submission validation, load-balancer configuration. Secured and does not track across websites (domain-specific). | 44B |
VOPECRA | 'Permanent' (multi-year duration) | Remembers that a user has accepted cookies from a specific VerseOne CMS-powered website, enabling cookies from GA and Code Droplets (where configured). Secured and does not track across websites (domain-specific). | 8B |
AboutCookies offers a guide to managing your cookies on all modern browsers.
Read more about VerseOne CMS and cookies here.
Additional Cookies
In addition, also uses four other cookies to help us understand who is using our website as well as help us effectively promote our services through social media channels.
Google analytics | Three of the cookies are Google Analytics cookies, which allows us to understand how people are using our site and make improvements to it - they do not record any personal identifiable information. Read more on how Google protects your privacy. |
Facebook Pixel |
This pixel was removed from our site in June 2023. |
In addition, one other cookie appears on some pages wheres a video has been embeded from YouTube. (YouTube) | YouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data |
Trust usage of social media
Northamptonshire Healthcare NHS Foundation Trust (NHFT) uses social media platforms to share information about the Trust and our work with service users, carers and members of the public as well as other organisations and professionals such as journalists.
We typically use our social media accounts in three ways:
- Share service updates including new service information, developments and urgent changes to advertised services e.g. clinic closures or change of hours
- Share relevant campaign information such as campaigns to destigmatise mental health and to share public health information.
- Showcase individuals and teams working in the Trust, with a focus on celebration of the difference they make as well as sharing learning
NHFT will often share relevant information from others through its social media accounts. Sharing of other social media users’ content should not necessarily been seen as NHFT endorsing the information or the views of that organisation or individual, unless expressly stated.
In keeping with the Trust’s legal duties and our responsibilities as a public sector body within the NHS, NHFT will not discuss individual patient cases including concerns and complaints on our social media channels. If you need to discuss your care with the Trust, you are advised to contact the team responsible for your care. As an organisation committed to learning and continuous improvement, we welcome and value feedback about your care. If you wish to pass on a compliment or raise a concern or complaint, please contact the PALS team or Complaints team.
NHFT reserves the right to block individual access to our social media channels in the event that it is not being used appropriately. Any such decision to block access will be carefully considered and will be kept under review. Reasons for blocking an individual might include for example, if the individual:
- shares confidential patient information,
- shares information that poses a risk to the safety of patients or the public,
- posts information that could reasonably be considered to be threatening, abusive or insulting,
- behaves in a manner that could reasonably be considered to be aggressive or violent,
- behaves in a manner that could reasonably be considered to constitute trolling or harassment;
- behaves in a manner that is repetitive, rude, inappropriate or unwanted by the recipient (notwithstanding that such may not amount to a criminal offence or actionable civil wrong);
- acts in a manner that could reasonably be considered to be detrimental to, or contrary to the interests of, the Trust or its partners.
NHFT may also restrict access where an individual has been advised about specific ways to contact the Trust for example, to raise concerns, and continues to contact the Trust inappropriately via social media.
Access to service information for any individual who is blocked from the Trust’s social media channels will continue to be available through NHFT’s website
The Trust is aware that some members of NHFT staff use social media channels in a personal capacity, which identify their professional roles. While they might identify their role, these personal social media accounts are not affiliated with NHFT - any views shared by individuals via their personal social media accounts are their own. Individuals have full control of their own personal social media accounts and are free to make their own decisions about who to follow and who to restrict from accessing their accounts.
NHFT’s social media accounts are monitored during office hours: 09:00–17:00, Monday – Friday, excluding public holidays.