Medmark Privacy
Medmark

Privacy Policy

Our Commitment to Your Privacy

Learn how we protect your personal information

Medmark Occupational Healthcare Limited

PRIVACY NOTICE

Last updated: 31 July 2026

Applies in Ireland under Regulation (EU) 2016/679 (the “GDPR”) and the Data Protection Act 2018.

Contents

1. Introduction

Medmark respects your privacy. We handle personal data fairly, lawfully and transparently, and we use it only for clear and legitimate purposes.

This notice tells you what personal data we may collect, where it comes from, why we use it, who may receive it, how long we keep it and what rights you have. “Personal data” means information relating to an identified or identifiable person. Health information is “special category” personal data and receives additional protection under the GDPR.

2. Who we are

Medmark Occupational Healthcare Limited (“Medmark”, “we”, “us” or “our”) provides occupational health and related medical services to public- and private-sector organisations throughout Ireland.

Data Protection Officer Medmark Occupational Healthcare Limited 69 Lower Baggot Street Baggot Street Bridge Dublin 2 D02 HW52 Ireland

Email: dataprotectionofficer@medmark.ie Telephone: 01 676 1493 Website: www.medmark.ie

3. Scope of this notice

This notice applies when you:

  • visit or interact with our website;
  • contact us about our services or make an enquiry;
  • are referred to Medmark by an employer or another organisation;
  • attend an occupational health appointment, assessment, screening or vaccination service;
  • use a Medmark portal, form or other digital service;
  • communicate with our clinicians or administrative teams; or
  • are otherwise involved in delivering or receiving our services, including as a client contact, supplier contact or healthcare professional.

Separate privacy information may be provided for a particular service, event, portal, recruitment process or employment relationship. If it conflicts with this general notice, the more specific notice applies to that processing.

4. When Medmark is a controller or processor

Medmark’s data protection role depends on the particular service and the reason the information is being processed. The role is determined by the actual processing activity and not simply by the description used in a contract.

Occupational health services

Where an employer or other organisation refers an individual to Medmark for an occupational health assessment, the referring organisation will generally be the controller for:

  • deciding why the referral is required;
  • determining the questions to be addressed;
  • providing employment and referral information to Medmark; and
  • deciding how the occupational health report will be used within the employment relationship.

Medmark may act as a processor for certain administrative activities undertaken solely on the client’s documented instructions, such as arranging appointments or delivering an agreed service.

However, Medmark will generally act as an independent controller where it determines how personal data must be processed to meet its clinical, professional, regulatory and legal responsibilities. This includes maintaining clinical records, making independent clinical decisions, ensuring patient safety, managing clinical quality, handling complaints and rights requests relating to Medmark-controlled records, and establishing, exercising or defending legal claims.

The occupational health report provided to an employer is normally limited to relevant and proportionate information, such as fitness for work, functional effects, workplace adjustments and review recommendations. The employer does not normally receive the individual’s full Medmark clinical record.

Wellness, screening and vaccination services

Where Medmark provides an individual wellness, screening or vaccination service and the clinical results are provided directly to the individual, Medmark will generally act as the controller for the health information and clinical records created through that service.

A client organisation may separately be a controller for limited information used to organise or fund the service, such as eligibility, appointment administration or attendance information. The client will not receive individual clinical findings unless this has been clearly explained and there is a lawful basis for doing so.

Other Processing

Medmark acts as a controller when operating its website, responding to general enquiries, managing its business, staff, suppliers and systems, protecting its services, and meeting its own legal and regulatory obligations.

In some arrangements, Medmark and another organisation may act as separate controllers or, where they jointly determine the purposes and essential means of processing, as joint controllers. Where necessary, we will provide more specific privacy information explaining the relevant arrangement.

5. Personal data we collect

CategoryExamples
Identity and contactName, title, date of birth, address, email address, telephone number, signature and identity-verification information.
Employment and referralEmployer, role, department, employee or reference number, work history, job demands, attendance information, reason for referral and questions asked by the referring organisation.
Health and clinicalMedical and occupational history, symptoms, diagnoses, medication, disability information, examination findings, test results, vaccination information, clinical correspondence, fitness opinions, recommendations and clinical notes.
Appointment and serviceBooking details, attendance, communications, consent and preference records, service history, accessibility or support requirements.
Reports and correspondenceOccupational health reports, certificates, referral documents, complaints, queries, rights requests and communications with you, the client and relevant professionals.
Technical and websiteIP address, device and browser data, security logs, cookie identifiers, pages viewed and information submitted through online forms.
Business administrationClient and supplier contacts, contracts, invoices, payment status, audit trails, quality, risk and incident records.
Other protected informationWhere relevant and lawful, information about racial or ethnic origin, religious beliefs, trade union membership, sex life or sexual orientation, genetics or biometrics, or criminal allegations and offences.

We aim to collect only information that is relevant and necessary. Please do not send clinical information through a general website enquiry form unless the form specifically asks for it and is intended for that purpose.

6. How we obtain personal data

We may obtain personal data:

  • directly from you, including during an appointment, by telephone, email, post, form, portal or website;
  • from your employer, prospective employer or another referring organisation;
  • from an occupational health, medical or nursing professional;
  • from your GP, consultant or another treating professional, normally with your knowledge and where any required permission has been obtained;
  • from laboratories, imaging providers, vaccination providers or other clinical service partners;
  • from service providers that support our systems and operations;
  • from records created while we deliver the service; and
  • from publicly available or official sources where lawful and relevant.

Where we receive your data from someone else, the categories commonly include identity and contact details, employment and referral information, relevant health information, appointment details and the questions the referring organisation wants addressed. Article 14 GDPR requires this source information unless an exemption applies.

8. Sharing personal data

We disclose personal data only where it is necessary, proportionate and lawful. Depending on the service, recipients may include:

  • the referring employer or client organisation, usually through a focused occupational health report rather than the full clinical record;
  • healthcare professionals involved in your care or assessment;
  • laboratories, diagnostic, imaging, vaccination and other clinical providers;
  • secure hosting, communications, appointment, portal, IT support, records-management and cybersecurity providers;
  • professional advisers, insurers, auditors and accreditation or quality-assurance bodies, subject to appropriate confidentiality;
  • public authorities, regulators, courts, tribunals, law enforcement or emergency services where disclosure is required or permitted by law; and
  • a purchaser, successor or adviser involved in a genuine business reorganisation, subject to appropriate safeguards.

Service providers acting as processors are bound by contracts requiring confidentiality, security, assistance with rights and deletion or return of data. We do not sell personal data.

9. International transfers

We aim to store and process personal data within Ireland or the European Economic Area (“EEA”). Some service providers or their support teams may process data outside the EEA. Before such a transfer, we use a lawful transfer mechanism and assess the protection available.

Safeguards may include an adequacy decision under Article 45 GDPR, the European Commission’s Standard Contractual Clauses under Article 46, supplementary technical and organisational measures, or another lawful derogation used only where appropriate. You may contact our Data Protection Officer for information about the relevant safeguard and, where available, a copy of it.

10. Retention

We keep personal data no longer than necessary. The period varies according to the record, service and Medmark’s role. We apply a documented retention schedule and review records for secure deletion or anonymisation when the applicable period ends.

Record typeHow the retention period is determined
Occupational health and clinical recordsThe nature of the service and clinical record; continuity of care; the age of the individual; professional and clinical guidance; applicable limitation periods; employment, health and safety and other legal duties; contractual requirements where lawful; and the need to establish, exercise or defend legal claims.
Referral reports and service administrationThe duration of the service or client relationship, audit and quality requirements, contractual commitments, limitation periods and any continuing complaint, investigation or claim.
Website enquiries and general correspondenceThe time needed to respond and follow up, then a limited period for service, audit, security or legal purposes.
Cookie and technical dataThe lifetime stated in the cookie information or the shorter period needed for security, troubleshooting and analytics.
Rights requests, complaints and incidentsThe time needed to manage the matter and demonstrate compliance, taking account of limitation periods, regulatory expectations and any continuing proceedings.
Financial and corporate recordsThe period required by Irish tax, accounting, company and other applicable law.

A specific period may be stated in a service notice, client arrangement or record-retention schedule. If you want to know the period that applies to a particular record, contact our Data Protection Officer.

11. Security

We use proportionate technical and organisational measures designed to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include:

  • role-based access and least-privilege controls;
  • authentication, encryption and secure transfer methods where appropriate;
  • logging, monitoring, backup, resilience and recovery arrangements;
  • confidentiality duties, staff training and clinical governance;
  • supplier due diligence and data-processing agreements;
  • physical security and secure disposal; and
  • incident response, risk assessment and periodic review.

No system can be guaranteed completely secure. If a personal data breach occurs, we assess it promptly and notify the Data Protection Commission and affected individuals where the GDPR requires this.

12. Your rights

Depending on the circumstances and subject to legal restrictions, you may have the following rights:

RightWhat it means
Access - Article 15Ask whether we process your personal data and obtain a copy, together with supporting information.
Rectification - Article 16Ask us to correct inaccurate personal data or complete information that is incomplete. A clinical opinion is not inaccurate merely because you disagree with it, but your view may be recorded where appropriate.
Erasure - Article 17Ask us to delete personal data in certain circumstances. This is not absolute; clinical, legal or public-interest duties may require continued retention.
Restriction - Article 18Ask us to limit how data is used while an issue is considered, in specified circumstances.
Notification - Article 19Where applicable, require us to tell recipients about rectification, erasure or restriction.
Portability - Article 20Receive certain data you provided in a structured, commonly used and machine-readable format, or have it sent to another controller, where processing is automated and based on consent or contract.
Object - Article 21Object to processing based on legitimate interests or a public task. You have an absolute right to object to direct marketing.
Automated decisions - Article 22Not be subject to a solely automated decision with legal or similarly significant effects, except where law permits it and safeguards apply.
Withdraw consentWithdraw consent at any time where consent is the basis. Withdrawal does not affect earlier lawful processing.
Complain - Article 77Lodge a complaint with the Data Protection Commission.

How to exercise a right

Contact our Data Protection Officer using the details in section 14. Please describe your request and the information or service concerned. We may ask for proportionate information to verify your identity and locate the relevant records. We do not normally charge a fee. We generally respond within one month, although the GDPR permits an extension of up to two further months for complex or numerous requests; if so, we will tell you within the first month.

Rights can be limited by the GDPR or Irish law, including where disclosure would adversely affect another person’s rights or where data must be retained for legal or clinical reasons. If we cannot fully comply, we will explain why and tell you about available complaint and judicial-remedy rights.

Where Medmark acts only as a processor, the relevant client controller is responsible for deciding the request. You may contact either organisation; Medmark will assist and route the request appropriately.

13. Cookies and similar technologies

Our website may use cookies and similar technologies. Cookies that are strictly necessary for security, navigation or requested functionality may be placed without consent. Optional analytics, preference or advertising technologies are used only where a valid consent or another lawful exemption applies.

The website’s cookie notice and consent tool provide current details of each cookie or technology, its provider, purpose and duration, and allow you to accept, reject or change optional choices. Withdrawing consent does not affect the lawfulness of earlier processing. Browser controls may also block or delete cookies, although this can affect website functions.

14. Contacting us

For questions, concerns, rights requests or information about safeguards and retention, contact:

Please avoid sending unnecessary medical information by ordinary email. We will tell you if a secure method is appropriate.

15. Complaints to the Data Protection Commission

We encourage you to contact us first so we can try to resolve your concern. You also have the right under Article 77 GDPR to lodge a complaint with the Irish Data Protection Commission (“DPC”), in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement.

Data Protection Commission 6 Pembroke Row Dublin 2 D02 X963 Ireland Website: www.dataprotection.ie (opens in a new tab) Email: info@dataprotection.ie Telephone: 01 765 0100 or 1800 437 737

The DPC’s online contact form is generally the most effective route for a query or complaint. The DPC recommends that individuals first raise the concern with the organisation and retain the relevant correspondence.

16. Changes to this notice

We keep this notice under review and may update it to reflect changes in our services, technology, legal obligations or regulatory guidance. The current version will be published on our website with the “last updated” date. Where a change materially affects how we use personal data, we will take reasonable steps to bring it to the attention of affected individuals and seek consent if required.

Medmark Icon

Contact Us

Contact your nearest clinic

Choose your nearest Medmark clinic below and contact us directly by phone or email.