Privacy Notice for applicants

< Back to policies & procedures

What is this?

We are required by law to provide you with information on how we use your data as a person applying for a role at our practice. This notice was last updated October 2025.

Who are we?

We are Swiss Cottage Surgery. We provide medical services to patients as part of the NHS.

Address: 2 Winchester Mews, Swiss Cottage, London, NW3 3NP Telephone: 020 7722 2772

Data Protection Officer

The practice is required by law to have a Data Protection Officer. The contact details are:

  • Name: Steve Durbin
  • Email: Dpo.Ncl@nhs.net
  • Address: Please use the practice address above, marking “For the attention of the Data Protection Officer

Note that the DPO covers a number of practices, to ensure your request is dealt with effectively, please include the name of the practice in any email correspondence.

Purposes of Processing, Legal Basis, Types of Data

We process your data to enable us to carry out the recruitment function and, should you be successful, to then enrol you as an employee or volunteer to us.

The data we collect includes:

  • your name, address and contact details, including your email address and telephone number
  • details of your qualifications, employment history, skills and experience
  • information on any unspent criminal convictions
  • information on your gender, ethnicity, sexual orientation and religion to support equal opportunities monitoring
  • information about your entitlement to work in the UK
  • employment references from past employers
  • whether or not you have a disability for which the organisation needs to make reasonable adjustments during this process and,
  • if an offer is made, bank details for payment purposes, legally required data for taxation, vaccination status and occupational health information

The legal basis for the overall purpose is provided UK GDPR Article 6 1(e) – the public interest of ensuring that we can carry out our official task.

Some of the data we need to do this is legally mandated – for example, evidence of right to work, checks on your professional qualifications. In this case UK GDPR Article 6 1(c) would apply.

If you are successful and ask us to take your engagement forward, UK GDPR Article 6 1(b) would also apply – steps necessary to enter into a contract.

We need certain special category data to assess and engage you, some of which is mandated such as Disclosure and Barring Service (DBS) checks. For these UK GDPR Article 9 2(b) is the legal basis – employment and social protection law. We may also need certain medical data e.g. vaccination status; these are covered by UK GDPR Article 9 2(h) – occupational medicine, provision of health care.

Recipients of Your Data

Your data is not shared outside of our organisation except as necessary for review of your qualifications, reference and DBS checks.

Transfers to Other Countries

We do not store or transmit your data outside of the UK for recruitment purposes.

We do not sell your data.

How Long Will You Keep My Data?

If you are unsuccessful in your application, we will keep your records for six months after the end of the application process in order to process potential objections or appeals.

If you are successful, most data is added to your staff record and then kept until your 75th birthday.

Full details of how long different types of data are held can be found in the NHS Records Management Code of Practice.

Your Rights

You have the right to:

  • Receive a copy of your data (Subject Access Request)
  • Have your data corrected, erased or restrict processing
  • Complain to our Data Protection Officer or the supervisory authority (the Information Commissioner) about our use or handling of your data

If you wish to exercise your rights, please contact the practice in the first instance - details above. You can also contact the Data Protection Officer if you prefer – details are again given above, or you can contact the Information Commissioner (ICO) – details via their website.

Note that some parts of the application record are specifically excluded from the subject access right – in particular, employment references.

Provision of Data

It is not generally a legal requirement for you to provide us with data – however if you do not do so we may be unable to process your application.

Automated Decision Making

No decisions on recruitment are taken without human intervention.