This is a new service. To help us improve it, give your feedback by email.

Your privacy on the NHS Digital Weight Management Programme Public Self-Referral Site

Our privacy policy

NHS Midlands and Lancashire Commissioning Support Unit (We, Our, Us and all similar references) are committed to protecting and respecting your privacy.

This policy sets out the basis on which any personal data We collect from you, or that you provide to Us, will be processed by us. Please read the following carefully to understand how we look after your personal data when you access our Hub and tell you about your privacy rights and how the law protects you.

We are NHS Midlands and Lancashire Commissioning Support Unit. Our registered address is  Heron House, Midlands and Lancashire CSU HQ, 120 Grove Road, Stoke on Trent, ST4 4LX.

You can contact us by post at the above address (Attention to Digital Innovation Unit) or by email at mlcsu.digitalinnovations@nhs.net

Any enquiries about our use of your personal data should be addressed to our Data Protection Officer using the above address or email mlcsu.ig@nhs.net

What data do we collect?

"Please note that if you access our service using your NHS login details, the identity verification services are managed by NHS England. NHS England is the controller for any personal information you provided to NHS England to get an NHS login account and verify your identity, and uses that personal information solely for that single purpose. For this personal information, our role is a “processor” only and we must act under the instructions provided by NHS England (as the “controller”) when verifying your identity. To see NHS England’s Privacy Notice and Terms and Conditions, please click here. This restriction does not apply to the personal information you provide to us separately."

When you register with the NHS Digital Weight Management Programme Public Self-Referral Site (Referral Hub), we receive the following information from NHS Login for care purposes

  • Your NHS Number
  • Your GP Practice Details
  • NHS Number
  • Date of Birth
  • Surname
  • First Name
  • Identity Verification Level 5*
  • Email
  • Mobile Number

* Identity verification level 5 indicates that NHS login has verified your Email, mobile phone number, NHS number and GP practice details.

As an integral part of your application process, NHS Login will seek your consent to share above information with NHS Digital Weight Management Programme. If you decline your consent, you will not be able to register with NHS Digital Weight management Programme.

When you access the Referral Hub, you  are  the data subject  who  supplies the further personal information necessary, beyond the information provided to us from NHS Login, for your use of the system. This personal information is:

  • Height
  • Weight
  • Date of weight measurement
  • Ethnicity
  • Date of Birth
  • Bariatric surgery in the last two years **
  • Active eating disorder **
  • Pregnancy **
  • Post Code
  • Address
  • Landline Number (Optional)
  • Diabetes Type 1 and/or take regular medication
  • Diabetes Type 2 and/or take regular medication
  • Hypertension / High Blood Pressure and/or take regular medication
  • Arthritis of the knee
  • Arthritis of the hip
  • Physical conditions lasting or expected to last 12 months or more
  • Learning Disability

** If you answer “Yes” you are not eligible for the programme.

In addition, we will also seek your permission from which you may optout:

  • Take part in future NHS England surveys
  • Share your weight management programme completion information with your GP

The following information (passed through to us by NHS Login) can be changed by you within the Referral Hub, however it is important to be aware that these changes will not be reflected within NHS Login and that these changes will only feature/appear within the Referral Hub:

  • Last Name
  • First Name
  • Email
  • Mobile Number

How we use your Personal Data

We will use your personal data only when the law allows us to. Most commonly, we will use your personal data in the following ways:

  • To enable you, as a user, to access the Hub and to select your chosen Weight Management Provider.
  • To enable your chosen Provider to know basic information about you as a client of their service and to enable them to contact you.
  • To enable NHSE/I to contact you, if you so choose, to take part in future evaluations.

What do we do with your information?

Your information is securely stored in our database. The data collected by the system is available to your chosen Provider for them to contact you to commence your programme. We will not share your data with any non-related third parties. Your data may be sent or stored outside of the UK. Nor will we use the information to make any automated decisions that might affect you.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our App; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

If NHS Midlands and Lancashire CSU (MLCSU) or its assets are acquired by a third party or transferred to a third-party personal data held by it about its registered users will be one of the transferred assets.

MLCSU will comply with any legal obligation to share personal data, or to protect the rights, property, or safety of MLCSU, our registered users and customers. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction and to aid the prevention of cybercrime.

We may use cookies or browser storage to temporarily store information on your device. This information will be used to secure your login session, remember the application state, and to cache data when the device is without an Internet connection.

Data Retention

We will only retain your personal data for as long as is reasonably necessary to fulfil the purposes for which we collected it, including satisfying any legal, regulatory, accounting or reporting requirements.

Your rights

Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

  • if you want us to establish the data's accuracy
  • where our use of the data is unlawful but you do not want us to erase it
  • where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims
  • you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

Changes to Privacy Policy

We aim to keep our privacy policy under regular review. This version was last updated in January 2022.

Any changes We may make to our privacy policy in the future will be posted on this page. The new terms may be displayed on-screen and you will be required to read and accept them to continue your use of the Public Self-Referral Site.

Your right to complain

If you have a complaint about our use of your information, you can contact the Information Commissioner's Office via their website at www.ico.org/concerns or write to them at:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

I have read the Privacy Notice above, and I consent MLCSU holding my personal data for NHS Digital Weight Management Programme Referral Hub processing purposes and share them with your chosen Weight Management Provider.

Page last reviewed: 05 April 2023