List of active policies
| Name | Type | User consent |
|---|---|---|
| Privacy Policy | Privacy policy | All users |
| Cookies Policy | Site policy | All users |
Summary
Privacy Policy
Full policy

Version 2.2, October 2021
Galway Clinic
Privacy Notice for Employees, Medical
Consultants & Independent Practitioners
1. Introduction
The Galway Clinic (GC) is committed to protecting all personal data which we collect from our employees, medical consultants and independent practitioners during the course of their contract of
employment or contract for service at GC.
This Notice sets out how we intend to capture, use and protect all personal data which GC collects and
stores during the course a contract of employment or contract for service at GC. We also want you to
be clear as to what rights you can invoke in respect to your information, as an employee or contractor
of GC.
In this regard, it is important that you read this Privacy Notice and understand our use of your personal
data.
Please note that this policy may be updated from time-to-time to reflect a changing environment, as
required. The most recent version of this document can be found on the Galway Clinic intranet.
1.1 Company Information
References to “GC”, “us”, “our” and “we” refer to Galway Clinic Doughiska Limited, and any associated
companies from time to time. More information about GC can be found at www.galwayclinic.com.
1.2 Legislation
All personal data we gather will be Processed in accordance with all applicable data protection laws
and principles, including the EU General Data Protection Regulation 2018 and the Data Protection Act
2018.
Version 2.2, October 2021
1.3 Queries and Complaints
If you require further information about the way your personal data will be used, or if you are unhappy
with the way we have handled your personal data, and wish to contact us please submit your concerns
to: DPO@galwayclinic.com
The DPO@galwayclinic.com mailbox is managed by the Galway Clinic DPO function and all
correspondence received will be addressed accordingly, including oversight from the designated
Galway Clinic Data Protection Officer.
You have the right to lodge a complaint with the Office of the Data Protection Commissioner. To contact
the Office of the Data Protection Commissioner, please use the following details:
Data Protection Commissioner
DATA PROTECTION COMMISSION
21 FITZWILLIAM SQUARE SOUTH
DUBLIN 2
D02 RD28
IRELAND
Telephone: +353 (0)761 104 800
Telephone: +353 (0)57 868 4800
Web: https://forms.dataprotection.ie/contact
Please note that we will take all appropriate steps to keep your personal data safe. In the unlikely event
that we have a security breach, we will notify you without undue delay regarding the circumstances of
the incident in accordance with our legal obligations.
Version 2.2, October 2021
2. How do we collect information?
We collect personal data from all employees, medical consultants and independent practitioners in
order to keep records of employment as required by employment law, and to facilitate the operation of
the Clinic. This data is collected from you when you initially apply for a position at GC, and is then
collected throughout the term of your employment here.
Most information will be collected directly from you, your manager, or by a member of the human
resources or finance departments.
In the case of job applications made through external agencies, we will initially collect data from the
relevant agency.
During the recruitment process, we may contact references or stated previous workplaces, to verify the
information provided.
Version 2.2, October 2021
3. What do we use information for?
We use your personal information so that we can provide you with employment and employment-related
services.
However, more specifically, we may use the personal data we gather for any or all the following
purposes:
Process Description Lawful Basis for Processing
under GDPR
Recruitment During the recruitment process
we obtain your personal profile
and work experience details
through online forms, CVs
submitted, references, external
agencies and any details
provided in cover letters.
This data is then used by GC to
assess your suitability for the
role being applied for
throughout the recruitment
process. This may include
sharing your details with
relevant parties as required for
the recruitment process.
This may include checks with
past employers or references.
The use of the data is
necessary to take steps at the
request of the prospectiveemployee,
medical consultant
or independent practitioner
prior to entering a contract.
Employment Permits and
Visas
GC is required by law to
complete and maintain
employment permit and visa
documentation during the
recruitment process, and for the
employment of some GC
employees, medical consultants
or independent practitioners.
The use of the data is
necessary to take steps at the
request of the prospectiveemployee,
medical consultant
or independent practitioner
prior to entering a contract.
The use of the data is
necessary for the performance
of a contract to which the
employee is party.
Primary Source Verification of
Qualifications and
Registrations
During the recruitment process,
and for the employment of some
GC employees, we may
conduct primary source
verification in relation to
qualification and registration.
The use of the data is
necessary to take steps at the
request of the prospectiveemployee,
medical consultant
or independent practitioner
prior to entering a contract.
Version 2.2, October 2021
Process Description Lawful Basis for Processing
under GDPR
This may include the completion
of checks with higher education
bodies, training institutions and
professional bodies.
The use of the data is
necessary for the performance
of a contract to which the
employee, medical consultant
or independent practitioner is
party.
Occupational Health GC periodically complete a
review of existing and
prospective GC employees,
medical consultants or
independent practitioners to
establish their fitness to work.
The use of the data is
necessary to take steps at the
request of the prospectiveemployee,
medical consultant
or independent practitioner
prior to entering a contract.
The use of the data is
necessary for the performance
of a contract to which the
employee, medical consultant
or independent practitioner is
party.
PCR (polymerase chain
reaction) Covid-19 testing
Mandatory PCR Covid-19
testing for all unvaccinated staff
to prevent the spread of Covid-
19 at the Clinic.
The use of the data is
necessary for the purposes of
the Clinic’s legal obligation to
comply with the Health and
Welfare at Work Act, 2005. The
Clinic is obligated to identify
hazards in the workplace and
take steps to mitigate these
risks; such as preventing the
spread of Covid-19 within the
Clinic.
The use of the data is
necessary to take steps at the
request of the prospectiveemployee,
medical consultant
or independent practitioner
prior to entering a contract.
Garda Vetting GC is required by law to
complete Garda vetting on all
employees, medical consultants
or independent practitioners.
The use of the data is
necessary to take steps at the
request of the prospectiveemployee,
medical consultant
or independent practitioner
prior to entering a contract.
Payroll Once employed, we provide the
payroll team with your details in
The use of the data is
necessary for the performance
Version 2.2, October 2021
Process Description Lawful Basis for Processing
under GDPR
order for GC to process your
salary payments each month.
This includes the administration
of employee benefits such as
pension, health insurance and
credit union savings.
of a contract to which the
employee is party.
Employee ID Cards Once employed, we shall issue
you with an official ID card.
The use of the data is in our
legitimate interests as your
employer.
TMS Once employed, you will be set
up on our TMS system which
will capture your data to allow
you to clock in and out
.
The use of the data is in our
legitimate interests as your
employer.
Assessing Training Needs Employee skills, experience and
performance data may be used
by GC in order for the Clinic to
assess employee training
needs.
The use of the data is in our
legitimate interests as your
employer.
Internal Reporting Employee performance and
sick-leave information may be
used for internal reporting
purposes.
The use of the data is in our
legitimate interests as your
employer.
Scheduling Leave Employee availability data
including leave requests is used
across GC to schedule rosters
and assess leave days used by
employees.
The use of the data is in our
legitimate interests as your
employer.
Radiation Protection Some employees working in
areas that encounter radiation
must wear radiation dosage
badges. Personal data (i.e.
name and date of birth) of
relevant employees is sent to
external organisations (both EU
and US) for radiation
monitoring.
The use of the data is
necessary for the performance
of a contract to which the
employee is party.
GC Newsletter Once employed, GC may use
your data for inclusion in our
monthly HR newsletter and in
The use of the data is in our
legitimate interests as your
employer.
Version 2.2, October 2021
Process Description Lawful Basis for Processing
under GDPR
the circulation of similar content
using the GC employee app.
When an Employee is also a
Patient
When an employee requires
treatment at GC we will treat
their data as we would a
patient’s data. This will be
achieved using the additional
controls provided by Meditech
using the VIP file status.
The use of the data is in
relation to the provision of
health care.
Employment Termination On termination of employment,
the termination of employment
is recorded.
The use of the data is in our
legitimate interests as an
employer.
Issuing References On request, we issue
employment references to other
entities.
This process begins on receipt
of your consent.
Wi-Fi We provide a free Wi-Fi service
for employees, medical
consultants & Independent
practitioners and public use but
we do not collect any personal
data when providing this service
This process does not require a
lawful basis as no personal
data is captured.
We may also process your data for other purposes in line with our data protection policies:
Data Protection Policy, GDPR – which is available on QPulse
Version 2.2, October 2021
4. Who do we share information with?
There are various circumstances where we may share personal data with third parties.
Generally, this includes your representatives and our representatives, and some pre-advised
third parties.
We may from time to time disclose your information to the following categories of recipients:
Any party which you have given us permission to speak with (family, friends or
otherwise)
Health insurance providers
Pension administrators
Translation service providers
Radiation monitoring service providers
Legal representatives, if necessary
Statutory bodies as required by EU and Irish law
Entities within the Group
Third party investigators as part of the GC Disciplinary and Grievance process
We take steps to ensure that any third-party partners who handle your information comply with
data protection legislation and protect your information just as we do. We only disclose
personal information that is necessary for them to provide the service that they are undertaking
on our behalf. We will aim to anonymise your information or use aggregated non-specific data
sets where possible.
Where we transfer your personal data outside of the EEA to our suppliers, we will ensure that
appropriate safeguards are in place to protect your personal data.
Version 2.2, October 2021
5. What type of information is collected?
As a healthcare providerand employer, we need to collect many categories of personal data
about our employees, medical consultants and independent practitioners much of which is
highly sensitive in nature.
While the type of personal data may change occasionally, we believe it is important you are
aware of the types of personal data we gather and use. The following table is a non-exhaustive
list and provides an indication of the categories and types of personal data we use to perform
our duties.
Please note that information listed under one category may be used for the performance of a
task or in relation to activities under another heading or as outlined under Section 3.
Reason Type of Data Collected
Recruitment Information Provided on CV, Garda Vetting, Occupational Health Data,
Verifications of Experience and Qualifications Provided, Interview Notes
Employment Facilitation Contact Details, Date of Birth, Bank Details, Hours Worked, Sickness
Details when Absent, Training Needs, Performance Reviews
During Medical Diagnosis
/ Treatment
Medical data relating to treatment
Quality Improvement Employee Feedback, Formal Enquiries Made
Clinic Security CCTV footage
Version 2.2, October 2021
6. How long do we retain information?
How long we keep data is primarily determined by how long it is required for the stated
purpose, for time periods set out by legislation or the period required to defend ourselves
against legal action.
Employees, medical consultants, and independent practitioners, information such as your
employee file is retained for the duration of the employment contract plus 8 years after the
contract’s termination. Details of any data that is retained outside of this retention period can
be found in our retention policy.
Where we wish to retain personal data beyond the above periods we will either:
Anonymise the information so that it is no longer possible to determine who the data
relates to.
Have justification for doing so (e.g. legal claims, pensions).
Please feel free to contact us if you would like more information about GC data retention
periods.
Version 2.2, October 2021
7. What are your rights?
You have a number of rights when it comes to your personal data. On receipt of a valid request
to invoke one your rights, we will do our best to adhere to your request as promptly as
reasonably possible, however, restrictions may apply in certain situations.
Right of Access
You have a right to know what personal data we hold on you, why we hold the data, and how
we are using the data.
When submitting your request, please provide us with information to help us verify your identity
i.e. name, date of birth, proof of address, telephone numberand as much detail as possible to
help us identify the information you wish to access (i.e. date range, subject of the request).
Right to Rectification
You have a right to request that the personal data held in relation to you is up to date and
accurate.
Where information is inaccurate or incomplete, we encourage you to contact us to have this
information rectified. Upon receipt of your request, we will ensure that the personal data is
rectified and as up to date as is reasonably possible.
Right to be Erasure
You have the right to seek the erasure of personal data relating to you in the following
circumstances:
The personal data is no longer required for the purposes for which is was obtained.
Where the use of the data is only lawful on the basis of consent, you withdraw
consent to the processing and no other lawful basis exists.
The personal data is being used unlawfully.
You object to the use of your personal data and there are no overriding legitimate
grounds for the use of the data
Your personal data requires deletion in line with legal requirements.
However, we will be unable to fulfil an erasure request if the personal data is required for
execution of an employee’s, medical consultants or independent practitioner’s active
employment contract.
Please be aware that in certain circumstances we may need to retain some information to
ensure your preferences are respected in the completion of our duties. For example, we
cannot erase all information about you where you have also asked us not to send you future
communications. Otherwise, your preference not to receive communications from us would be
erased.
Version 2.2, October 2021
Right to Restriction
You have the right to restrict the extent for which your personal data is being used by us in
circumstances where:
You believe the personal data is not accurate (restriction period will exist until we
update your information).
The processing of the personal data is unlawful but you wish to restrict the use of the
data rather than erase it.
Where the personal data is no longer required by us but you require the retention of
the data for the establishment, exercise, or defence of a legal claim.
You have a pending objection to the future use of your personal data.
When the use of your data has been restricted, your personal data will only be further used:
with your consent; for the establishment, exercise or defence of legal claims; for the protection
of the rights of other people; or for reasons important to public interest.
We will contact you to confirm where the request for restriction is fulfilled and will only lift the
restriction after we have informed you that we are doing so.
Right to Data Portability
You have the right to the provision of all personal data that you have provided to GC in relation
to you in a structured, commonly used and machine-readable format where:
The lawfulness of the use of your personal data by us is reliant on the basis a contract.
The lawfulness of the use of your personal data by us is reliant on the provision of your
consent.
The data is being utilised by fully automated means.
You may also request that we send this personal data to another legal entity where technically
feasible.
We will refuse such a request if the data being requested may adversely affect the rights and
freedoms of others.
Right to Object
You have the right to object to the further use of your personal data where:
The lawfulness of the use of your personal data by us is reliant on the basis of our
legitimate interests.
Where the data is non-sensitive, and being used for reasons in the public interest.
Where the data is being used for direct marketing purposes.
If you wish to object to the use of your data, please contact us with your request. We will then
stop using the data of personal data unless it is required for legal proceedings.
Version 2.2, October 2021
Right not to be subject to Automated Decision Making, including Profiling
You have a right not to be subject to a decision based solely on automated processing or
profiling, where such decisions would have a legal effect or significant impact on you.
Where we (or one of our third-party processors) use profiling, which produces legal effects for
you or otherwise significantly affects you, you will have the right to object to such processing.
Where do I send requests?
Please send all your requests to DPO@Galwayclinic.ie with as much detail as possible
regarding your requirements to allow us to deal with your request efficiently. To answer your
request, we may ask you to provide identification for verification purposes.
How long will a request take to complete?
Upon receipt of a request, we will have 30 days to provide a response, with an extension of
two further months if required. If we require more time to deal with your request, we will notify
you of the delay, and the factors responsible for the delay, within 30 days of the receipt of your
request. If we refuse your request, we will notify you within 30 days of the receipt of your
request accompanied by the reason for refusal.
You are entitled to contact the Office of the Data Protection Commissioner if we refuse your
request.
How much does it cost to submit a request?
We will not charge a fee for any requests, provided we do not consider them to be unjustified
or excessive. If we do consider requests to be unjustified or excessive, we may charge a
reasonable fee (also applicable for multiple copies) or refuse the request.
Summary
Cookies Policy
Full policy
WHAT IS A COOKIE?
Cookies are text files containing small amounts of information which are downloaded to your device when you visit a Site. Cookies are then sent back to the originating Site on each subsequent visit, or to another Site that recognises that cookie. Cookies are useful because they allow a Site to recognise a user’s device. You can find more information about cookies at:
Cookies and Local Storage are standardised ways for a website to store a small text file in your browser, and FESSLearning.ie uses cookies to make the experience of using the site easier for you.
WHICH COOKIES ARE BEING USED IN THIS SITE?
We use only use first party cookies which fall into the ‘strictly necessary’ category. Your consent is not required for us to use this type of cookie.
FESSLearning.ie uses Session Cookies to distinguish you from other users of the website. These cookies are necessary for the elearning platform to work for you. They provide you with seamless access as you move from one area of the site to another based on your session login. Once your session ends these cookies forget about you.
Strictly necessary cookies are essential in order to enable you to move around the Site and use its features and/or services. Without these absolutely necessary cookies, the Site will not perform as smoothly for you as we would like it to and we may not be able to provide the Site with certain services or features. Under the GDPR, your consent for the use of such cookies is not required. This is the only type of cookie used on this website.
Cookie Name | Description | Expiry Date | 1st party or 3rd party |
MoodlesessionXXXXXXX | To enable front page viewing and maintain the user login from page to page | 24 hours | 1st |
Our elearning platform also uses Local Storage to keep track of the progress you have made within each course. They will remain in your web browser after you have logged off, and allow you to continue a learning programme at the point you previously ended it next time you log on.
You may delete cookies or other storage from your browser at any time you like by visiting your web browser settings.
