What information must I provide to data subjects? (Fair processing notices) #GDPR

Where the personal data is provided by the data subject, for example, when a prescription is presented to a pharmacy in hard copy or following nomination of that pharmacy, the following information must be provided to the data subject, the patient:

  1. The name and address of the data controller, the pharmacy company;
  2. The contact details of the Data Protection Officer (DPO)
  3. the purposes for which the personal data is processed and the legal basis for this;
  4. The recipients or categories of the recipients of the personal data, if any;
  5. Any relevant information about transfers to a third country or international organization
  6. The period or criteria that will determine, how long the personal data is stored;
  7. The relevant rights the data subject has in this case;
  8. If the processing is based on consent, the right to withdraw that consent at any time;
  9. The right to lodge a complaint with the supervisory authority, the Information Commissioners Office;
  10. If the provision of personal data is a statutory requirement, the possible consequences of failure to provide it;
  11. Relevant information on automated decision-making; and,
  12. Any processing of the information subsequently for a different purpose.

 You do not need to provide this information if it has been provided to the data subject already.

View our GDPR page for more information