Data Protection Policy
Company Name: Ben Williams trading as Ben Williams Health Data Solutions
Date of Implementation: 01 June 2026
Last Reviewed: 01 June 2026
Data Protection Officer (DPO) / Lead: Ben Williams
1. Introduction & purpose
As a self-employed data analyst operating within the health sector, I acknowledge that I handle highly sensitive personal data, categorized as Special Category Data under data protection law (such as clinical records, patient demographics, or structured health codes).
The purpose of this policy is to outline how I collect, process, store, and destroy personal data securely, ensuring full compliance with the UK GDPR and the Data Protection Act 2018.
2. Core Data Protection Principles
I commit to managing all data in accordance with the seven core principles of data protection:
- Lawfulness, fairness, and transparency: Data is processed legally and transparently under clear contract terms with my clients.
- Purpose limitation: Data is only analyzed for the specific scope of work agreed upon with the client.
- Data minimization: I will only request or extract the minimum amount of patient/health data necessary to complete the analysis.
- Accuracy: I will ensure data cleaning and transformation processes maintain the integrity and accuracy of the original dataset.
- Storage limitation: Data will not be kept longer than necessary for the completion of the project and will be deleted according to client agreements.
- Integrity and confidentiality (Security): I implement robust technical safeguards to protect data from unauthorized access or accidental loss.
- Accountability: I maintain documentation of my processing activities and data protection measures.
3. Types of Data Processed
In my capacity as a health data analyst, I may process:
- Pseudonymized / Anonymized Data: Wherever possible, I insist that clients provide datasets where direct identifiers (names, specific addresses, NHS numbers) have been removed or masked.
- Special Category Health Data: Structured clinical codes (e.g., ICD-10, SNOMED CT), diagnostic text, clinical outcomes, or demographic details.
- Administrative Client Data: Contact information and billing details of the organizations hiring my services.
4. Technical and Organizational Security Measures
Because I operate as an independent professional, I maintain direct control over my technical environment. I enforce the following security protocols:
- Encryption: All devices used for data analysis (desktops, laptops, external drives) utilize full-disk encryption (i.e., BitLocker). Any data in transit is shared via secure, encrypted channels (e.g., SFTP, end-to-end encrypted cloud storage).
- Access Control: Strong, unique passwords combined with Multi-Factor Authentication (MFA) are mandated across all professional accounts, email, and cloud platforms.
- Data Isolation: Client health data is never mixed with personal files. It is kept in isolated, dedicated local directories or dedicated secure client environments.
- Local Processing: I do not store patient-level datasets on public or unencrypted cloud services unless explicitly provided through a secure client-managed tenant.
- Software Security: Anti-malware and firewalls are kept active at all times. Operating systems and analysis tools (e.g., R, Python libraries, SQL environments) are updated immediately when security patches are released.
5. Data Retention and Destruction
- Upon final delivery and client sign-off of an analytical report or model, I will retain the underlying raw dataset for no longer than 180 days to handle follow-up queries, unless a different timeline is contractually mandated by the client.
- When deleting data, I utilize secure digital shredding or formatting methods to ensure data cannot be recovered. Physical notes containing sensitive project details are cross-cut shredded.
6. Breach Notification Procedure
In the unlikely event of a data breach (e.g., theft of a device, malware infection, accidental data exposure):
- Containment: I will immediately isolate the affected device or account to stop further exposure.
- Assessment: Evaluate the risk to individuals’ privacy.
- Client Notification: Because I typically act as a Data Processor for health sector clients, I will notify the respective client (the Data Controller) immediately—and no later than 24 hours after discovering the breach.
- Regulatory Notification: If required by law or contract, I will assist the client in reporting the breach to the Information Commissioner’s Office (ICO) within 72 hours.
