notification Created with Sketch. CORONAVIRUS: We are still taking precautions to keep you safe Coronavirus (Respiratory infections) Update

Privacy Policy

Privacy Notice

King Edward VII’s Hospital is committed to protecting your privacy and meeting the requirements of data protection legislation. This privacy notice explains:

  • what personal data we collect about you;
  • why we collect that personal data;
  • who we share your personal data with;
  • why we might contact you and how you can change that;
  • how long we retain your personal data;
  • how we keep your personal data secure; and
  • what rights you have in relation to your personal data.

When we talk about “personal data” in this notice, we mean any information which could be used to identify you, either directly or indirectly when combined with any other information we may hold about you.

In this privacy notice, when we refer to “we”, “us” or “our”, we mean King Edward VII’s Hospital, 5-10 Beaumont Street, London W1G 6AA. We are the data controller under the Information Commissioner’s Office registration number Z4817679

If you need to contact us about this privacy notice or further details on how we use your personal information please contact the Data Protection Officer

By Post:

Data Protection Officer
Medical Records Department
King Edward VII’s Hospital
5-10 Beaumont Street

By email:  Data Protection Officer at

This privacy policy does not cover the links within our websites linking to other websites. We encourage you to read the privacy statements on the other websites you visit.

Personal data collected by King Edward VII’s Hospital

The doctors, nurses and team of healthcare professionals caring for you keep records about your health and any treatment and care you receive from us. These records help to ensure that you receive the best possible care.

They may be written down in paper records or held on computer. These records may include:

  • Basic details about you such as name, address, date of birth, next of kin, etc.
  • Contact we have had with you such as appointments or clinic visits
  • Notes and reports about your health, treatment and care
  • Results of x-rays, scans and laboratory tests
  • Relevant information from people who care for you and know you well such as health professionals and relatives

It is essential that your details which we hold are accurate and up to date. Always check that your personal details are correct when you visit us and please inform us of any changes as soon as possible.

Reasons for collecting that personal data

Your records are used to direct, manage and deliver the care you receive to ensure that:

  • The doctors, nurses and other healthcare professionals involved in your care have accurate and up to date information to assess your health and decide on the most appropriate care for you
  • Healthcare professionals have the information they need to be able to assess and improve the quality and type of care you receive
  • Your concerns can be properly investigated if a complaint or any concerns are raised
  • Appropriate information is available if you see another doctor, or are referred to a specialist or another part of the healthcare system to ensure you receive continuity of care

Your information will also be used to help us manage and protect the health of the public by being used to:

  • Review the care we provide to ensure it is of the highest standard and quality
  • Ensure our services can meet patient needs in the future
  • Investigate patient queries,  incidents, complaints and legal claims
  • Ensure the hospital/clinic receives payment for the care you receive
  • Prepare statistics on our performance
  • Audit our accounts and services
  • Undertaking health research and development (with your explicit consent – you may choose whether or not to be involved)
  • Helping to train and educate healthcare professionals

We have a number of lawful bases for using this information under data protection legislation:

  • In some cases it will be necessary for us to use information in order to fulfil our contract with you to provide you with healthcare services, such as using your health data for the purposes of diagnosis and assessment by a healthcare professional.
  • In exceptional circumstances, we may be required to use your information in order to protect your vital interests or those of another person for example, in the case of an epidemic or extreme event.
  • We may also need to use your information for the purposes of establishing, exercising or defending our legal rights, for example in the event of a complaint.
  • Where we do not have a contractual or legal obligation to handle your data in a particular way or your explicit consent to use your information for a specific purpose, we have a legitimate interest to conduct general business processes and improve our services. When relying on our legitimate interests we conduct an assessment to ensure that this use of your data is fair, proportionate and in no way detrimental.

Who we share your personal data with

Everyone working within healthcare has a legal duty to keep information about you confidential. Similarly, anyone who receives information from us has a legal duty to keep it confidential.

We will share information with your private consultant and the following main partner organisations:

  • Your General Practitioner (GP)
  • Private insurers that are involved in your care
  • NHS Trusts and hospitals that are involved in your care
  • Ambulance Services
  • PHIN (Private Healthcare Information Network) who are the government’s recognised body for processing private patient’s data

You may be receiving care from other people as well as us, for example Social Care Services or District Nursing Services. We may need to share some information about you with them so we can all work together for your benefit if they have a genuine need for it or we have your permission. Therefore, we may also share your information, subject to strict agreement about how it will be used, with:

  • Social Care Services
  • Local Authorities
  • Voluntary and private sector providers working with us

We will not disclose your information to any other third parties without your permission unless there are exceptional circumstances, such as if the health and safety of others is at risk or if the law requires us to pass on information.

You have the right to restrict how and with whom we share the personal information in your records that identifies you. This must be noted explicitly within your records in order that all healthcare professionals and staff treating and involved with you are aware of your decision. By choosing this option, you should be mindful that it may make the provision of treatment or care more difficult or unavailable. You can also change your mind at any time about a disclosure decision.

Information we collect when you visit our website or use our online services

Activities that may result in collection of personal information

  • visits to our websites
  • enquiries about our products or services
  • information contained in enquiry or booking forms, including through our ‘make an enquiry’ or ‘Live Support’ sections of our websites
  • information you provide in surveys or in feedback
  • transactions you carry out on our websites
  • online payments
  • referrals from GPs

If you call our helpline or contact our live support, these telephone calls or live chats may be recorded and retained for a limited period for training and monitoring purposes and to help improve our services. Telephone calls to and from hospitals are never recorded.

Personal identifiers from your browsing activity

  • Requests by your web browser to our servers for web pages and other content on our website are recorded.
  • We record information such as your geographical location, your Internet service provider and your IP address. We also record information about the software you are using to browse our website, such as the type of computer or device and the screen resolution.
  • We use this information in aggregate to assess the popularity of the webpages on our website and how we perform in providing content to you.
  • If combined with other information we know about you from previous visits, the data possibly could be used to identify you personally, even if you are not signed in to our website.

Fundraising Marketing

We rely on different legal reasons depending on the circumstances to let you know about fundraising campaigns that we are undertaking.

We would like to provide you with choices regarding certain personal data uses, in particular, we will always seek your express opt-in consent before we send any fundraising marketing communications to you by email. If you choose to opt-in to such communications, or if you have directly requested this type of communication from us, we will send you emails from time to time to let you know about fundraising that we are undertaking.

We also use your address details to send you marketing information by post telling you about fundraising campaigns that we think may be of interest to you where this is in our legitimate interests and it does not materially impact your rights, freedom or interests. We do not seek your consent to send postal fundraising marketing communications.

You can ask us to stop sending you marketing communications by email or by post at any time, by following the opt-out information provided on the communications which are sent to you, or by contacting us at any time at

Prospect Research for Fundraising

We undertake prospect research for the purpose of researching and profiling individuals and organisations, so that we can assess how we should engage with specific audiences and tailor communications and engagement strategies more effectively and appropriately. These activities help us make informed decisions about fundraising strategy and ensure we are raising funds in the most effective manner possible. As such, we may use personal information we hold on you and augment this with information collected from publicly available information sources, to carry out research to determine whether you would be interested in hearing more about us and/or being involved with our charitable work.

Further information that may be collected can include financial, business, philanthropic, networks, biographical and demographic information sourced from publicly available data, such as Companies House (or other business-related resources), the Charity Commission (or other charity-related resources), company websites, LinkedIn profiles and press sources. This work may be undertaken by us directly, but on occasion may be performed by trusted third-party suppliers, wherein your name, employment and postcode may be shared with them to assist us in identifying potential supporters who may have the capacity to provide significant support to the organisation. All information is processed securely and in line with other data collection processes.

Prospect research involves the processing of personal information provided by individuals that have engaged with King Edward VII Hospital, such as contact information, gift history, and types of fundraising activity previously participated in. This helps us to establish the appropriate fundraising and engagement strategies to ensure we are utilising our internal resources effectively. We have assessed it is in our legitimate interests to process your information in this manner, allowing us to direct more tailored communications to qualified supporters, so that we can maximise the opportunities for potential philanthropic support.

On occasion, names and contact details of potential supporters may be suggested by existing supporters when it is deemed likely that an individual may be open to being approached to support the organisation. When this happens, we will contact you as soon as is practicable to let you know we are processing your data in this way. This information will be processed in accordance to King Edward VII’s Hospital Data Protection policy retention schedule.

Should you have any objections to how we process your data you have the right to withdraw your consent at any time by contacting us at


Cookies are small text files that are placed on your computer’s hard drive by your web browser when you visit any website. They allow information gathered on one web page to be stored until it is needed for use on another, allowing a website to provide you with a personalised experience and the website owner with statistics about how you use the website so that it can be improved.

Some cookies may last for a defined period of time, such as one day or until you close your browser. Others last indefinitely. Your web browser should allow you to delete any you choose. It also should allow you to prevent or limit their use.

Our website uses cookies. They are placed by software that operates on our servers, and by software operated by third parties whose services we use.

When you first visit our website, we ask you whether you wish us to use cookies. If you choose not to accept them, we shall not use them for your visit except to record that you have not consented to their use for any other purpose.

If you choose not to use cookies or you prevent their use through your browser settings, you will not be able to use all the functionality of our website.

We use cookies in the following ways:

  • to track how you use our website
  • to record whether you have seen specific messages we display on our website
  • to keep you signed in our site
  • to record your answers to surveys and questionnaires on our site while you complete them
  • to record the conversation thread during a live chat with our support team

Receiving communications from King Edward VII’s Hospital and updating your preferences

When attending our facilities for an outpatient appointment or a procedure you may be asked to confirm that we have an accurate email address, contact number and/or mobile telephone number for you. This can be used to provide appointment details via email, SMS text messages and telephone calls to advise you of appointment times, with your consent.

We may also contact you about goods and services which we think may be of interest to you where you have consented to us using your information in this way.

You can update your communications preferences at any time by informing a member of staff or by contacting the Data Protection Officer. Please contact the Data Protection Officer by post at our address above or by emailing the Data Protection Officer at

Retention of personal data

We retain personal data for no longer than required and in line with King Edward VII’s Hospital Data Protection policy retention schedule. This is based on statutory requirements and legal obligations, as well as our business requirements.

Security of personal data

We take our duty to protect your personal information and confidentiality very seriously and we are committed to taking all reasonable measures to ensure the confidentiality and security of personal data for which we are responsible, whether computerised or on paper. Where we have a need to transfer data outside of the European Economic Area (EEA) we do so with appropriate safeguards in place.

Personal data and your rights

Data protection legislation gives you the right to:

  • Correct any data we hold about you that is not correct (Rectification)
  • Request that we delete your personal data (Erasure)
  • Block or suppress the further processing of your personal data in certain circumstances (Restriction)
  • Request access to personal data that we hold about you (Subject Access)
  • In some circumstances, receive the personal data which you have provided to us, in a structured, commonly used and machine-readable format and have this transmitted to another data controller (Data Portability)
  • Withdraw consent where this is the legal basis for us processing your information
  • Object to processing where King Edward VII’s Hospital is relying on its legitimate interests as the legal ground for processing
  • Not be subject to automatic decisions (i.e. decisions that are made about you by computer alone) that have a legal or other significant effect on you.

Please contact the Data Protection Officer using the details above if you wish to exercise your rights in relation to personal data using the contact information below. Our policy is to verify the authenticity of all requests made, and requests may be refused if we are unable to verify the identity of the requester.

If you have concerns about the way we have handled your personal data please contact the Data Protection Officer in the first instance.

By Post:

Data Protection Officer
Medical Records Department
King Edward VII’s Hospital
5-10 Beaumont Street

By email:  Data Protection Officer at

If you remain unsatisfied you can contact the Information Commissioner’s Office (ICO) on 0303 123 1113, by emailing  or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Page updated: 21/02/23