<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://www.vetsurgeon.org/utility/feedstylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Help with GDPR Staff contracts</title><link>https://www.vetsurgeon.org/f/non-clinical-questions/27022/help-with-gdpr-staff-contracts</link><description> Hi, 
 I read a few weeks ago that someone has updated their staff contracts to include a GDPR clause, but can&amp;#39;t find it now. Can some kind soul please send me a generic text they have used to append their staff contracts. 
 Thanks </description><dc:language>en-US</dc:language><generator>Telligent Community 10</generator><item><title>RE: Help with GDPR Staff contracts</title><link>https://www.vetsurgeon.org/thread/197560?ContentTypeID=1</link><pubDate>Wed, 23 May 2018 18:07:06 GMT</pubDate><guid isPermaLink="false">146601cc-3922-4be7-9974-7e1d4e45a66b:71da14d5-6808-4379-a84f-a56a3a9c1f0f</guid><dc:creator>Peter Faulkner</dc:creator><description>&lt;p&gt;Thanks Martin, that&amp;#39;s great.&lt;/p&gt;
&lt;p&gt;Its amazing how much is involved in all this.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Help with GDPR Staff contracts</title><link>https://www.vetsurgeon.org/thread/197549?ContentTypeID=1</link><pubDate>Wed, 23 May 2018 12:15:22 GMT</pubDate><guid isPermaLink="false">146601cc-3922-4be7-9974-7e1d4e45a66b:4849fc63-a9cb-4427-8203-222e03ef7a39</guid><dc:creator>Martin Atkinson</dc:creator><description>&lt;p&gt;I don&amp;#39;t know if it was me but my contracts already had a confidentiality clause:&lt;/p&gt;
&lt;p&gt;c) In no way divulge or make public any confidential records, accounts, information, transactions or details of the employer relating to the business except to a person having the legal authority to require such disclosure. This would normally mean a subpoena from a court of law.&lt;/p&gt;
&lt;p&gt;Here is a copy of the record of GDPR training they undertook, which they have signed and is kept as an annex to the contracts, I hope this will suffice but would be interested if anyone has anything they think is better:&lt;/p&gt;
&lt;p align="center"&gt;&lt;span style="text-decoration:underline;font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;Record of confidentiality and data protection training&lt;/span&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;Current staff members underwent confidentiality and data protection training on (date) and were made aware of the following:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;The PMS is password protected with their personal password which should be updated regularly and workstations should be logged off between sessions of use and when left unattended in public areas.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;A data audit was carried out to identify what information the practice collects, where it is held and the legal basis for holding that information.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;Paper files which include credit card receipts, client registration and consent forms are to be stored securely and not left in places with public access such as the reception desk and are subject to an agreed retention period.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;What constitutes personal information under GDPR or anything that could be used to identify an individual, but we do not request or store sensitive or special category personal information.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;During telephone calls staff must ensure that they cannot be overheard by members of the public if they are using information which could identify the caller.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;The data information controller should be identified if a breach of data security is identified.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;Personal information should be accurate and up to date. This is achieved by asking clients if their details have changed and/or by requesting them to complete an information update sheet on a regular basis.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;Clients must be asked if they wish to continue to receive information which uses their personal data such as appointment reminders, given the choice to opt in and their preference recorded in the client file with the date.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;A data protection policy has been formulated and instructed in accordance with this training.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;Sensitive information should not be included in emails.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;Staff should not use personal devices such as mobile phones, laptops or tablets to access the PMS without using two-factor authentication and these and removable data storage such as USB sticks should encrypted to prevent access to data if lost or stolen.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;Staff have been trained on how to recognise, report and handle a subject access request or a request to see information held on an individual.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;We the undersigned confirm that we have received relevant confidentiality&lt;/span&gt; and data protection training as recorded and on the date indicated above:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:&amp;#39;andale mono&amp;#39;, times;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>