Data Protection

GDPR & Data Protection

How Kimberworth Pharmacy handles your personal data in compliance with UK GDPR and data protection law.

Home / GDPR & Data Protection
Last updated: May 2026

Kimberworth Pharmacy is fully committed to compliance with the General Data Protection Regulation (GDPR) and all applicable data protection laws in the United Kingdom. This page outlines how we handle personal data, your rights as a data subject, and how to exercise those rights.

1. Our Data Protection Commitment

Who We Are

Kimberworth Pharmacy is a registered pharmacy operating at Langdon Road, Rotherham, S61 3QH. We are the Data Controller for personal data we process through our website and pharmacy services.

Our Principles

We process personal data in accordance with the following GDPR principles:

  • Lawfulness: We only collect and process data where we have a legal basis to do so.
  • Fairness & Transparency: We are clear about what data we collect and why.
  • Purpose Limitation: Data is used only for the purpose stated at the point of collection.
  • Data Minimisation: We only collect data that is necessary for the purpose.
  • Accuracy: We take steps to keep data accurate and up-to-date.
  • Storage Limitation: Data is kept only as long as needed.
  • Integrity & Confidentiality: Data is kept secure and protected at all times.

3. Types of Data We Process

Patient Health Data

We process health data to provide pharmacy services, including prescription information and medication history, allergy and adverse reaction records, consultation notes, and NHS and private health records.

Website Data

When you visit our website, we may collect your name, email address, and contact details; any messages or enquiries you submit; IP address and browsing information via cookies; and device and browser information.

Special Category Data

Health data is treated as special category data under GDPR Article 9. We process this only where you have given explicit consent or where we have a lawful basis such as the provision of health services.

4. Your GDPR Rights

Under UK GDPR, you have the following rights regarding your personal data:

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Ask us to correct inaccurate or incomplete data.

Right to Erasure

Request deletion of your data under certain circumstances.

Right to Restrict

Ask us to limit how we use your data in certain situations.

Data Portability

Receive your data in a structured format to transfer to another organisation.

Right to Object

Object to certain types of processing, including marketing.

Automated Decisions

Rights in relation to decisions made solely by automated processing.

Withdraw Consent

Withdraw any consent you have given at any time.

5. How to Exercise Your Rights

Subject Access Requests (SAR)

To request a copy of your personal data, please submit a Subject Access Request. We will respond within 30 calendar days. In most cases, this is free of charge, though we may charge a reasonable fee for repeat or excessive requests.

Other Requests

To exercise any other right, please contact us in writing with your request and evidence of your identity. We will respond within 30 days. Please send requests to:

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected:

Data Type Retention Period
Prescription Records Typically 2 years from last transaction (subject to NHS requirements)
Consultation Notes Retained per pharmacy and health service regulations
Website Enquiries A reasonable period to respond, then deleted unless you consent otherwise
Cookies Per your browser settings and our cookie policy

7. Data Sharing & Third Parties

We may share your personal data with the following types of organisations:

  • NHS Services: Doctors, hospitals, and healthcare providers for continuity of care.
  • Regulatory Bodies: The pharmacy regulator (GPhC) and health authorities.
  • Payment Processors: For processing payments securely.
  • Website Hosts: To store and maintain our website.
  • Legal Requirements: When required by law or court order.

We never sell your data to third parties. Any third parties who process data on our behalf are contractually obligated to protect it.

8. Data Security

We take data security seriously and employ appropriate technical and organisational measures:

Secure password protection and access controls
Encryption of data in transit and at rest
Regular security assessments and testing
Staff training on data protection
Physical security of premises and records
Incident response procedures

9. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify affected individuals within 72 hours where there is high risk to their rights and freedoms.
  • Notify the Information Commissioner's Office (ICO) where legally required.
  • Provide details of the nature of the breach and steps taken to mitigate harm.
  • Make reasonable efforts to assist you in protecting your information.

10. International Transfers

We operate within the UK and do not routinely transfer personal data outside the UK/EEA. If any transfer is necessary, we ensure appropriate safeguards are in place in accordance with GDPR Chapter V.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

11. Data Protection Contact

If you have questions about this GDPR policy or wish to exercise your data rights, please contact us directly and we will respond as quickly as possible.