1. Introduction
Medmark respects your privacy. We handle personal data fairly, lawfully and transparently, and we use it only for clear and legitimate purposes.
This notice tells you what personal data we may collect, where it comes from, why we use it, who may receive it, how long we keep it and what rights you have. “Personal data” means information relating to an identified or identifiable person. Health information is “special category” personal data and receives additional protection under the GDPR.
2. Who we are
Medmark Occupational Healthcare Limited (“Medmark”, “we”, “us” or “our”) provides occupational health and related medical services to public- and private-sector organisations throughout Ireland.
Data Protection Officer Medmark Occupational Healthcare Limited 69 Lower Baggot Street Baggot Street Bridge Dublin 2 D02 HW52 Ireland
Email: dataprotectionofficer@medmark.ie Telephone: 01 676 1493 Website: www.medmark.ie
3. Scope of this notice
This notice applies when you:
- visit or interact with our website;
- contact us about our services or make an enquiry;
- are referred to Medmark by an employer or another organisation;
- attend an occupational health appointment, assessment, screening or vaccination service;
- use a Medmark portal, form or other digital service;
- communicate with our clinicians or administrative teams; or
- are otherwise involved in delivering or receiving our services, including as a client contact, supplier contact or healthcare professional.
Separate privacy information may be provided for a particular service, event, portal, recruitment process or employment relationship. If it conflicts with this general notice, the more specific notice applies to that processing.
4. When Medmark is a controller or processor
Medmark’s data protection role depends on the particular service and the reason the information is being processed. The role is determined by the actual processing activity and not simply by the description used in a contract.
Occupational health services
Where an employer or other organisation refers an individual to Medmark for an occupational health assessment, the referring organisation will generally be the controller for:
- deciding why the referral is required;
- determining the questions to be addressed;
- providing employment and referral information to Medmark; and
- deciding how the occupational health report will be used within the employment relationship.
Medmark may act as a processor for certain administrative activities undertaken solely on the client’s documented instructions, such as arranging appointments or delivering an agreed service.
However, Medmark will generally act as an independent controller where it determines how personal data must be processed to meet its clinical, professional, regulatory and legal responsibilities. This includes maintaining clinical records, making independent clinical decisions, ensuring patient safety, managing clinical quality, handling complaints and rights requests relating to Medmark-controlled records, and establishing, exercising or defending legal claims.
The occupational health report provided to an employer is normally limited to relevant and proportionate information, such as fitness for work, functional effects, workplace adjustments and review recommendations. The employer does not normally receive the individual’s full Medmark clinical record.
Wellness, screening and vaccination services
Where Medmark provides an individual wellness, screening or vaccination service and the clinical results are provided directly to the individual, Medmark will generally act as the controller for the health information and clinical records created through that service.
A client organisation may separately be a controller for limited information used to organise or fund the service, such as eligibility, appointment administration or attendance information. The client will not receive individual clinical findings unless this has been clearly explained and there is a lawful basis for doing so.
Other Processing
Medmark acts as a controller when operating its website, responding to general enquiries, managing its business, staff, suppliers and systems, protecting its services, and meeting its own legal and regulatory obligations.
In some arrangements, Medmark and another organisation may act as separate controllers or, where they jointly determine the purposes and essential means of processing, as joint controllers. Where necessary, we will provide more specific privacy information explaining the relevant arrangement.
5. Personal data we collect
| Category | Examples |
|---|---|
| Identity and contact | Name, title, date of birth, address, email address, telephone number, signature and identity-verification information. |
| Employment and referral | Employer, role, department, employee or reference number, work history, job demands, attendance information, reason for referral and questions asked by the referring organisation. |
| Health and clinical | Medical and occupational history, symptoms, diagnoses, medication, disability information, examination findings, test results, vaccination information, clinical correspondence, fitness opinions, recommendations and clinical notes. |
| Appointment and service | Booking details, attendance, communications, consent and preference records, service history, accessibility or support requirements. |
| Reports and correspondence | Occupational health reports, certificates, referral documents, complaints, queries, rights requests and communications with you, the client and relevant professionals. |
| Technical and website | IP address, device and browser data, security logs, cookie identifiers, pages viewed and information submitted through online forms. |
| Business administration | Client and supplier contacts, contracts, invoices, payment status, audit trails, quality, risk and incident records. |
| Other protected information | Where relevant and lawful, information about racial or ethnic origin, religious beliefs, trade union membership, sex life or sexual orientation, genetics or biometrics, or criminal allegations and offences. |
We aim to collect only information that is relevant and necessary. Please do not send clinical information through a general website enquiry form unless the form specifically asks for it and is intended for that purpose.
6. How we obtain personal data
We may obtain personal data:
- directly from you, including during an appointment, by telephone, email, post, form, portal or website;
- from your employer, prospective employer or another referring organisation;
- from an occupational health, medical or nursing professional;
- from your GP, consultant or another treating professional, normally with your knowledge and where any required permission has been obtained;
- from laboratories, imaging providers, vaccination providers or other clinical service partners;
- from service providers that support our systems and operations;
- from records created while we deliver the service; and
- from publicly available or official sources where lawful and relevant.
Where we receive your data from someone else, the categories commonly include identity and contact details, employment and referral information, relevant health information, appointment details and the questions the referring organisation wants addressed. Article 14 GDPR requires this source information unless an exemption applies.
7. Why we use personal data and our legal bases
When Medmark is a controller, we must have a lawful basis under Article 6 GDPR. Because occupational health work frequently involves health data, we must also satisfy a condition under Article 9 GDPR. The basis depends on the service, the facts and the public- or private-sector context.
| Purpose | Plain-English legal basis |
|---|---|
| Arrange and deliver services | Contract steps or performance of a contract (Article 6(1)(b)); compliance with a legal obligation (Article 6(1)(c)); or legitimate interests in delivering and administering occupational health services (Article 6(1)(f)). For health data: occupational medicine, assessment of working capacity, medical diagnosis, health care or management of health systems and services, subject to professional secrecy (Article 9(2)(h)). |
| Assess fitness and provide occupational health advice | Legal obligation (Article 6(1)(c)) or legitimate interests (Article 6(1)(f)), depending on the referral and applicable law. For health data: employment and social protection obligations or rights (Article 9(2)(b)) and/or occupational medicine and working-capacity assessment (Article 9(2)(h)). |
| Maintain clinical records and ensure quality and safety | Legal obligation (Article 6(1)(c)) and legitimate interests in safe, accountable clinical practice (Article 6(1)(f)). For health data: health care and occupational medicine (Article 9(2)(h)); in limited cases, public interest in public health (Article 9(2)(i)). |
| Communicate reports and recommendations | Legal obligation (Article 6(1)(c)), contract (Article 6(1)(b)) or legitimate interests (Article 6(1)(f)). For health data: employment and social protection law (Article 9(2)(b)) and/or occupational medicine and working-capacity assessment (Article 9(2)(h)). Only relevant and proportionate information is communicated. |
| Respond to enquiries and manage client relationships | Steps at your request or contract (Article 6(1)(b)) and legitimate interests in responding, managing services and keeping business records (Article 6(1)(f)). |
| Meet legal, regulatory and professional duties | Compliance with legal obligations (Article 6(1)(c)). For special category data: the relevant Article 9 condition, commonly Article 9(2)(b), (f), (h) or (i), together with applicable Irish law. |
| Handle complaints, incidents and legal claims | Legal obligation (Article 6(1)(c)) or legitimate interests in investigating, protecting rights and managing risk (Article 6(1)(f)). For special category data: establishment, exercise or defence of legal claims (Article 9(2)(f)) or, where relevant, Article 9(2)(h). |
| Protect systems and prevent misuse | Legitimate interests in security, fraud prevention, service continuity and audit (Article 6(1)(f)); legal obligation where applicable (Article 6(1)(c)). |
| Use optional cookies or send consent-based communications | Consent (Article 6(1)(a)). You may withdraw consent at any time. Where permitted by Irish electronic communications law, limited business communications may rely on legitimate interests (Article 6(1)(f)) with an opt-out. |
| Protect life in an emergency | Vital interests (Article 6(1)(d)); for health data, vital interests where the person is physically or legally incapable of consenting (Article 9(2)(c)). This basis is used only in exceptional circumstances. |
Consent
We do not normally rely on consent as the legal basis for core occupational health processing where another basis applies. Clinical consent to an examination, procedure or release of particular information is distinct from GDPR consent. Where GDPR consent is the basis, it is voluntary and may be withdrawn without affecting processing already carried out lawfully.
Legitimate interests
Where we rely on legitimate interests, we consider the purpose, necessity and impact on individuals. Our interests may include providing and improving safe services, administering our organisation, protecting systems, maintaining audit trails, resolving disputes and communicating with professional or client contacts. We do not rely on legitimate interests where your rights and freedoms override those interests.
Is providing information required?
Some information is needed to arrange or safely deliver a service, answer the referral question, meet legal or professional duties, or enter into or perform a contract. If you do not provide it, we may be unable to complete an assessment, provide a reliable opinion or deliver the requested service. We will explain any material consequence at the time. You are not required to provide information for optional marketing or non-essential cookies.
Automated decisions
Medmark does not ordinarily make decisions producing legal or similarly significant effects about individuals solely by automated means. If that changes for a service, we will provide specific information about the logic involved, likely consequences and safeguards, including any right to human review (Article 22 GDPR).
9. International transfers
We aim to store and process personal data within Ireland or the European Economic Area (“EEA”). Some service providers or their support teams may process data outside the EEA. Before such a transfer, we use a lawful transfer mechanism and assess the protection available.
Safeguards may include an adequacy decision under Article 45 GDPR, the European Commission’s Standard Contractual Clauses under Article 46, supplementary technical and organisational measures, or another lawful derogation used only where appropriate. You may contact our Data Protection Officer for information about the relevant safeguard and, where available, a copy of it.
10. Retention
We keep personal data no longer than necessary. The period varies according to the record, service and Medmark’s role. We apply a documented retention schedule and review records for secure deletion or anonymisation when the applicable period ends.
| Record type | How the retention period is determined |
|---|---|
| Occupational health and clinical records | The nature of the service and clinical record; continuity of care; the age of the individual; professional and clinical guidance; applicable limitation periods; employment, health and safety and other legal duties; contractual requirements where lawful; and the need to establish, exercise or defend legal claims. |
| Referral reports and service administration | The duration of the service or client relationship, audit and quality requirements, contractual commitments, limitation periods and any continuing complaint, investigation or claim. |
| Website enquiries and general correspondence | The time needed to respond and follow up, then a limited period for service, audit, security or legal purposes. |
| Cookie and technical data | The lifetime stated in the cookie information or the shorter period needed for security, troubleshooting and analytics. |
| Rights requests, complaints and incidents | The time needed to manage the matter and demonstrate compliance, taking account of limitation periods, regulatory expectations and any continuing proceedings. |
| Financial and corporate records | The period required by Irish tax, accounting, company and other applicable law. |
A specific period may be stated in a service notice, client arrangement or record-retention schedule. If you want to know the period that applies to a particular record, contact our Data Protection Officer.
11. Security
We use proportionate technical and organisational measures designed to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include:
- role-based access and least-privilege controls;
- authentication, encryption and secure transfer methods where appropriate;
- logging, monitoring, backup, resilience and recovery arrangements;
- confidentiality duties, staff training and clinical governance;
- supplier due diligence and data-processing agreements;
- physical security and secure disposal; and
- incident response, risk assessment and periodic review.
No system can be guaranteed completely secure. If a personal data breach occurs, we assess it promptly and notify the Data Protection Commission and affected individuals where the GDPR requires this.
12. Your rights
Depending on the circumstances and subject to legal restrictions, you may have the following rights:
| Right | What it means |
|---|---|
| Access - Article 15 | Ask whether we process your personal data and obtain a copy, together with supporting information. |
| Rectification - Article 16 | Ask us to correct inaccurate personal data or complete information that is incomplete. A clinical opinion is not inaccurate merely because you disagree with it, but your view may be recorded where appropriate. |
| Erasure - Article 17 | Ask us to delete personal data in certain circumstances. This is not absolute; clinical, legal or public-interest duties may require continued retention. |
| Restriction - Article 18 | Ask us to limit how data is used while an issue is considered, in specified circumstances. |
| Notification - Article 19 | Where applicable, require us to tell recipients about rectification, erasure or restriction. |
| Portability - Article 20 | Receive certain data you provided in a structured, commonly used and machine-readable format, or have it sent to another controller, where processing is automated and based on consent or contract. |
| Object - Article 21 | Object to processing based on legitimate interests or a public task. You have an absolute right to object to direct marketing. |
| Automated decisions - Article 22 | Not be subject to a solely automated decision with legal or similarly significant effects, except where law permits it and safeguards apply. |
| Withdraw consent | Withdraw consent at any time where consent is the basis. Withdrawal does not affect earlier lawful processing. |
| Complain - Article 77 | Lodge a complaint with the Data Protection Commission. |
How to exercise a right
Contact our Data Protection Officer using the details in section 14. Please describe your request and the information or service concerned. We may ask for proportionate information to verify your identity and locate the relevant records. We do not normally charge a fee. We generally respond within one month, although the GDPR permits an extension of up to two further months for complex or numerous requests; if so, we will tell you within the first month.
Rights can be limited by the GDPR or Irish law, including where disclosure would adversely affect another person’s rights or where data must be retained for legal or clinical reasons. If we cannot fully comply, we will explain why and tell you about available complaint and judicial-remedy rights.
Where Medmark acts only as a processor, the relevant client controller is responsible for deciding the request. You may contact either organisation; Medmark will assist and route the request appropriately.
14. Contacting us
For questions, concerns, rights requests or information about safeguards and retention, contact:
Please avoid sending unnecessary medical information by ordinary email. We will tell you if a secure method is appropriate.
15. Complaints to the Data Protection Commission
We encourage you to contact us first so we can try to resolve your concern. You also have the right under Article 77 GDPR to lodge a complaint with the Irish Data Protection Commission (“DPC”), in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement.
Data Protection Commission 6 Pembroke Row Dublin 2 D02 X963 Ireland Website: www.dataprotection.ie (opens in a new tab) Email: info@dataprotection.ie Telephone: 01 765 0100 or 1800 437 737
The DPC’s online contact form is generally the most effective route for a query or complaint. The DPC recommends that individuals first raise the concern with the organisation and retain the relevant correspondence.
16. Changes to this notice
We keep this notice under review and may update it to reflect changes in our services, technology, legal obligations or regulatory guidance. The current version will be published on our website with the “last updated” date. Where a change materially affects how we use personal data, we will take reasonable steps to bring it to the attention of affected individuals and seek consent if required.
