
Last updated: 4 August 2026
Our Commitment to UK GDPR & Data Protection
Protecting confidential information is one of Alex C&C Healthcare Ltd's highest priorities and forms an essential part of delivering safe, compassionate, person-centred care, professional training, recruitment services and organisational governance.

Privacy, confidentiality and information security are embedded throughout every aspect of the organisation.
Legal Responsibilities for GDPR & Data Protection
Alex C&C Healthcare Ltd complies with applicable UK legislation and recognised standards, which guide how information is collected, used, stored, shared, retained and securely destroyed.
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Common Law Duty of Confidentiality
- Human Rights Act 1998 (where privacy rights apply)
- Health and Social Care legislation relating to confidential information
- NHS Information Governance principles where applicable

Alex C&C Healthcare Ltd maintains compliance with the NHS Data Security and Protection Toolkit (DSPT), the NHS's recognised framework for information governance and cyber security. DSPT compliance demonstrates our commitment to protecting confidential information, maintaining secure digital systems, managing cyber security risks, and meeting NHS expectations for organisations delivering health and social care. Maintaining this compliance reflects our ongoing commitment to protecting the information entrusted to us by clients, families, commissioners, NHS partners, and employees.
%20C6J8%20DSPT%20standards%20exceeded%20certificate.jpg)

UK GDPR Compliance
Strict adherence to the General Data Protection Regulation.

Secure Digital Records
Encrypted management of all digital health and care records.
Our Information Governance Standards
These standards help ensure information remains protected throughout its lifecycle, supporting our commitment to UK GDPR and NHS information security frameworks.

Data Protection Act 2018
Full alignment with contemporary UK data legislation and rights.

Role-Based Access
Strict controls ensuring information is shared on a need-to-know basis.

Secure Info Sharing
Lawful and encrypted protocols for professional clinical information sharing.

NHS DSPT Compliance
Maintaining the highest NHS data security toolkit standards.

IG Training
Comprehensive mandatory training for all staff members across the organization.

Continuous Monitoring
Continuous auditing of our data protection and governance procedures.

Confidentiality & Governance
Information governance principles fully embedded in clinical care.

Cyber Security Aware
Ongoing education to mitigate digital risks and protect confidential care data.
Keeping Information Secure
Alex C&C Healthcare Ltd protects information through robust organisational, physical and technical security measures. These help protect information from accidental loss, unauthorised access, misuse, disclosure, alteration or cyber threats.
- Secure electronic systems and password-protected devices
- Role-based access controls and confidentiality agreements
- Secure record storage and disposal of confidential records
- Staff IG training and cyber security awareness
- Routine security monitoring and NHS DSPT compliance
- Regular review of information governance procedures
Your Rights
Under the UK General Data Protection Regulation (UK GDPR), individuals have several rights regarding their personal information. Alex C&C Healthcare Ltd is dedicated to ensuring you can exercise these rights freely and transparently. Note that some rights may be limited where legislative recording requirements apply.
Right to be Informed
You have the right to be informed about the collection and use of your personal data, provided through clear privacy notices.
Right of Access
You have the right to access your personal data and supplementary information, enabling you to verify the lawfulness of processing.
Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to have it rectified in a timely manner.
Right to Erasure
Also known as ‘the right to be forgotten’, you can request deletion of data when there is no compelling reason to continue its processing.
Restrict Processing
You have the right to block or suppress the processing of your personal data in certain circumstances.
Right to Object
You have the right to object to processing based on legitimate interests or direct marketing.
Data Portability
You have the right to obtain and reuse your personal data for your own purposes across different services.
Automated Actions
You have rights in relation to automated decision making and profiling, ensuring human intervention when appropriate.