In connection with our examination, diagnostics and treatment of you as a patient, CPH Privathospital collects and processes a range of personal data about you. In this privacy policy you can read how CPH Privathospital processes, uses and discloses your personal data.

Last updated 19 August 2020

Types of information

CPH Privathospital collects and processes the following types of personal data about you (to the extent relevant for you specifically):

Ordinary categories of personal data:

  • Name, address, e-mail address if applicable, telephone number, civil registration number, gender, family relationships and social relationships, employment relationships and education.

Special categories of personal data (“sensitive personal data”):

  • Health data (e.g. medical records, test results, tests, X-ray images, scan results etc.), sexual matters, race or ethnic origin and religious matters.

Purpose

We process your personal data for the following purposes:

  • Our examination, diagnostics and treatment of you
  • Preparation of medical certificates
  • Preparation of certificates for use by authorities, insurance companies etc.
  • Communication with or referral to other healthcare professionals, doctors, hospitals or hospital laboratories
  • Medication prescriptions, including issuing of prescriptions
  • Reporting to clinical quality databases
  • Reporting of laboratory samples to hospital laboratories
  • Billing purposes
  • Complying with our obligations under applicable legislation, including the EU General Data Protection Regulation, the Data Protection Act and other relevant health legislation, e.g.
    • Documentation obligation
    • Compliance with basic principles for processing personal data and legal basis for the processing
    • Implementation and maintenance of technical and organisational security measures, including but not limited to preventing unauthorised access to systems and information, preventing the receipt or distribution of malicious code, stopping denial-of-service attacks and damage to computer systems and electronic communication systems
    • Investigation of suspected or known security breaches and reporting to individuals and authorities
    • Handling enquiries and complaints from data subjects and others
    • Handling inspections and enquiries from supervisory authorities
    • Handling disputes with data subjects and third parties.
    • Statistical surveys and scientific research

Voluntary provision

When we collect personal data directly from you, you provide the personal data voluntarily. You are not obliged to provide this personal data to us. The consequence of not providing us with the personal data will be that we cannot fulfil the purposes stated above, including that in some cases we cannot examine, diagnose or treat you.

Sources

In some cases we collect personal data about you from other healthcare professionals, for example hospitals, referring doctors or by accessing electronic medical record systems. We process the received information in accordance with this privacy policy.

Disclosure of personal data

To the extent necessary for the specific examination, diagnosis or treatment of you, your personal data will be disclosed and shared with the following recipients:

  • Information is disclosed to other healthcare professionals if it is necessary for a current course of treatment
  • Information is disclosed to other authorities, clinical quality databases, the Danish Vaccination Register, the Danish Patient Safety Authority, the Shared Medication Record, the Police, Social authorities, the Danish Working Environment Authority to the extent that there is an obligation to do so under applicable legislation.
  • As a patient you have access to your own information (self-access)
  • When referring patients, information is disclosed to the healthcare professionals to whom the referral is sent.
  • When submitting laboratory samples, the samples are disclosed to hospital laboratories
  • When reporting information in connection with billing for patient treatment, information is passed on to the regional billing offices
  • When issuing prescriptions, information is passed on to the country’s pharmacies and the Danish Medicines Agency via the prescription server
  • When reporting to clinical quality databases
  • When passing on discharge summaries, information is passed on to the referring doctor and in certain cases the referring hospital
  • In other cases, information is passed on to relatives or insurance companies
  • The information is never transferred to third countries (outside the EU).

Legal basis for processing and disclosure of personal data

The legal basis for collecting, processing and disclosing your personal data is:

  • For the purposes of ordinary patient treatment, ordinary personal data is collected, processed and disclosed pursuant to Article 6(1)(c) and (d) of the Data Protection Regulation, while sensitive personal data is collected, processed and disclosed pursuant to Article 9(2)(c) and (h) of the Data Protection Regulation.
  • In addition, we are obliged to process a number of personal data about you in connection with ordinary patient treatment pursuant to Chapter 6 of the Authorisation Act, the Executive Order on Health Professionals’ Medical Records (the Medical Records Order), in particular sections 5–10, and Chapter 9 of the Health Act.
  • Health information for the purpose of further treatment when referring patients is disclosed in accordance with the rules in the Agreement on Specialist Medical Services, sections 20–23, and the Health Act.
  • Reporting of laboratory tests to hospital laboratories takes place in accordance with the rules in the Danish Health Authority’s guidance on the handling of paraclinical examinations pursuant to the Authorisation Act.
  • Information for the purpose of billing for patient treatment is sent once a month to the region’s billing office in accordance with the rules in the Agreement on Specialist Medical Services, section 49, and the Health Act.
  • Medicine prescriptions on prescriptions are sent via the IT service prescription server in accordance with the rules in Chapter 42 of the Health Act and the Executive Order on Prescriptions and Dose Dispensing of Medicines, in particular Chapter 3.
  • Clinical patient data is disclosed to clinical quality databases in accordance with the rules in sections 195–196 of the Health Act and the Executive Order on Reporting of Information to Clinical Quality Databases, etc. Data may also be disclosed on the basis of specific consent from you as a patient.
  • Discharge summaries, which are a brief summary of the patient’s medical history and course of treatment, are sent to the referring doctor and in some cases to the referring hospital in accordance with the rules in Chapter 9 of the Health Act.
  • Your personal data is only disclosed to insurance companies with your prior consent, cf. Article 6(1)(a) and 9(2)(a) of the Data Protection Regulation.
  • Your personal data will only be disclosed to your relatives with your prior consent in accordance with the rules in section 43 of the Health Act.
  • In the case of deceased patients, certain personal data may be disclosed to the deceased’s closest relatives, the deceased’s general practitioner and the doctor who had the deceased in treatment in accordance with the rules in section 45 of the Health Act.

Withdrawal of consent

If the processing of your personal data is based on consent, you have the right to withdraw your consent. If you withdraw your consent, it does not affect the processing prior to the withdrawal of consent, including any disclosure based on consent.

Use of data processors

Your personal data are processed and stored by our data processors, who store them on our behalf and according to our instructions. Our data processors are currently

  • SAC-IT Frydenlundsvej 30, Bygning B

Retention period

We retain personal data about you for as long as we need to fulfil the purposes stated above. However, in accordance with the medical records regulations, we are obliged to retain these for a minimum of 10 years after the last entry in the medical record. There may be cases where we are required to retain your personal data for a longer period, for example in connection with a complaint or compensation case, in which case the data will be retained until the case is finally concluded.

Your rights

You have – subject to the limitations of the law – certain rights, including the right of access to personal data, the right to have incorrect data corrected, the right to have data deleted, the right to have data restricted, the right to data portability, the right to object to the processing of personal data, including with regard to automated individual decision-making (“profiling”).

You also have the right to lodge a complaint with a competent supervisory authority, including the Danish Data Protection Agency.

If you apply for a job at CPH Privathospital?

If you apply for a job with us, the following personal data is processed:

  • General information: Name, address details, email, telephone numbers
  • CV and application
  • Date of birth
  • Photograph if applicable
  • Information about any criminal record

The purpose of the processing is to offer a smooth recruitment procedure where data security is paramount. Applications are deleted immediately after the recruitment process has ended, unless you wish us to retain your information for longer. Consent is always obtained for this. You can always contact us if you wish to have your personal data deleted earlier.

Your personal data is never passed on to others.

If you are employed at CPH Privathospital

We process the following personal data:

  • General information: Name, address details, email, telephone numbers
  • CV and application
  • CPR number (Danish civil registration number)
  • Photograph if applicable – consent is always obtained for this

Cf. the Data Protection Act section 12.

CPH Privathospital is the data controller for its own processing of payroll and personnel information about employees at the company.

If you apply for a job at CPH Privathospital

If you apply for a job with us, the following personal data is processed:

  • General information: Name, address details, email, telephone numbers
  • CV and application
  • Date of birth
  • Photograph if applicable
  • Information about any criminal record

The purpose of the treatment is to offer a smooth recruitment procedure where data security is paramount. Applications are deleted immediately after the recruitment process has ended, unless you wish us to retain your information for longer. Consent is always obtained for this. You can always contact us if you wish your personal data to be deleted earlier.

Your personal data will never be passed on to others.

If you are employed at CPH Privathospital

We process the following personal data:

  • General information: Name, address details, e-mail, telephone numbers
  • CV and application
  • CPR number
  • Possible photograph – consent is always obtained for this

Cf. the Data Protection Act §12.

CPH Privathospital is the data controller for its own processing of payroll and personnel information about employees at the company.

Your rights

  • You have the right to access which personal data we process about you
  • You have the right to have the personal data we have registered about you corrected and updated
  • You have the right to have the personal data we have registered about you deleted. If you wish to have your personal data deleted, we will delete all information that we are not required by law to retain.
  • If the processing of personal data is based on your consent, you can at any time withdraw this consent in whole or in part
Questions?
If you have questions about our processing of your personal data or need clarification of your rights, you can contact us:

CPH Privathospital
Rådhustorvet 4
3520 Farum
Mail: job@cph-privathospital.dk

Contact details for DPO
E-mail: dpo@cph-privathospital.dk 

Security

We protect your personal data and have adopted internal rules on information security, which contain measures that protect your personal data against unauthorised disclosure and against unauthorised persons gaining access to or knowledge of them.

We have established procedures for granting access rights to those of our employees who process your personal data. We control this through logging and supervision. To avoid data loss, we perform regular backups. We also protect the confidentiality and authenticity of your data using encryption.
In the event of a security breach that results in a high risk to you, for example of discrimination, identity theft, financial loss, loss of reputation or other significant disadvantage, we will notify you of the security breach as quickly as possible.

Deadlines for deletion and retention of personal data

All patient information that we record at CPH Privathospital is retained in accordance with the “Executive Order on Patient Records of Authorised Healthcare Professionals”. Pursuant to the Executive Order on the Limitation of Claims (the Limitation Act) §3, subsection 3.1, patient records must not be deleted. CPH Privathospital must at all times be able to produce documentation for examinations and treatments performed in the event of patient complaints.

We retain relevant personal data, such as employment contracts, time/holiday/absence records etc., for up to 5 years after termination of employment.

The reason for retaining employment contracts, time/holiday/absence records and other documents for 5 years after termination of employment is that if a case arises concerning a legal claim or similar from an employee or a former employee, CPH Privathospital must be able to meet the dispute. CPH Privathospital must be able to meet cases until they become time-barred pursuant to the Limitation Act § 4.

If there is to be a deviation from the data deletion 5 years after termination of employment, for example in the case of a pending employment law case, approval from the management is required for the deletion not to be carried out.

All other personal data is deleted or anonymised when it is no longer relevant for the purpose for which it was collected.

Complaints authority

You have the option to complain about our processing of your personal data to the Danish Data Protection Agency.

See contact details and more about the right to complain here: www.datatilsynet.dk

You can also contact us at job@cph-privathospital.dk

Contact

If you have questions regarding the processing of your personal data or the exercise of your rights, you are welcome to contact us on tel. 7021 8000 or dpo@cph-privathospital.dkz

  • You have the right to access the personal data we process about you
  • You have the right to have the personal data we have registered about you corrected and updated
  • You have the right to have the personal data we have registered about you deleted. If you wish to have your personal data deleted, we will delete all information that we are not required by law to retain.
  • If the processing of personal data is based on your consent, you may at any time withdraw this consent in whole or in part

If you have questions about our processing of your personal data or need clarification of your rights, you can contact us:

CPH Privathospital
Rådhustorvet 4
3520 Farum
Mail: job@cph-privathospital.dk

Contact details for DPO

E-mail: dpo@cph-privathospital.dk 

Security

We protect your personal data and have adopted internal information security policies that include measures to protect your personal data against unauthorised disclosure and against unauthorised access or knowledge of them.

We have established procedures for granting access rights to those of our employees who process your personal data. We monitor this through logging and supervision. To prevent data loss, we perform regular backups. We also protect the confidentiality and authenticity of your data using encryption.
In the event of a security breach that results in a high risk to you, such as discrimination, identity theft, financial loss, loss of reputation or other significant disadvantage, we will notify you of the security breach as quickly as possible.

Deadlines for deletion and retention of personal data

All patient information that we record at CPH Privathospital is retained in accordance with the “Executive Order on Patient Records of Authorised Healthcare Professionals”. Pursuant to the Executive Order on the Limitation of Claims (Limitation Act) §3, subsection 3.1, patient records must not be deleted. CPH Privathospital must at all times be able to produce documentation for examinations and treatment performed in the event of patient complaints.

We retain relevant personal data, such as employment contracts, time/holiday/absence records, etc., for up to 5 years after termination of employment.

The reason for storing employment contracts, time/holiday/absence registrations and other documents for 5 years after termination is that if a case arises concerning a legal claim or similar from an employee or a former employee, CPH Privathospital must be able to address the dispute. CPH Privathospital must be able to address cases until they are statute-barred pursuant to the Limitation Act section 4.

If there is to be a deviation from the data deletion 5 years after termination, for example in the case of a pending employment law case, it requires approval from the management that the deletion is not carried out.

All other personal data are deleted or anonymised when they are no longer relevant for the purpose for which they were collected.

Complaints authority

You have the option to lodge a complaint about our processing of your personal data with the Danish Data Protection Agency.

See contact details and more about the right to complain here: www.datatilsynet.dk

You can also contact us at job@cph-privathospital.dk

Contact

If you have questions regarding the processing of your personal data or the exercise of your rights, you are welcome to contact us on tel. 7021 8000 or dpo@cph-privathospital.dk