Personal Data Protection Policy
1. Who is responsible for processing your personal data
The controller responsible for processing your personal data is Internacionalni medicinski centar PRIORA, Ulica Kralja Tomislava 153, 31431 Čepin, Croatia, OIB 28948012246, telephone +385 31 227 400, email address [email protected], website www.priora.eu.
This Privacy Policy explains which personal data we collect about you, why and on what legal basis we process it, how long we retain it, who may have access to it, and what rights you have.
This Privacy Policy applies to patients and, as described in Section 4.5, to other individuals whose personal data we process in connection with the provision of healthcare services. The processing of data relating to our employees, job applicants and business partners is governed by separate privacy notices.
2. Data Protection Officer
We have appointed a Data Protection Officer (DPO), whom you may contact with any questions regarding the processing of your personal data and the exercise of your rights.
You can contact the Data Protection Officer by email at [email protected] or by post at Internacionalni medicinski centar PRIORA, Ulica Kralja Tomislava 153, 31431 Čepin, Croatia, marked for the attention of the Data Protection Officer.
3. How we process your health data
Health data constitute a special category of personal data and their processing is generally prohibited. The General Data Protection Regulation (GDPR) provides for certain exceptions. For a healthcare institution, the relevant exception is Article 9(2)(h), under which processing is permitted where necessary for medical diagnosis and the provision of healthcare or treatment. This exception applies subject to the conditions set out in Article 9(3), namely that the data are processed by persons who are subject to an obligation of professional secrecy.
All our healthcare professionals, as well as all other employees who may have access to information concerning your health in the course of their duties, are required to treat such information as confidential and as subject to professional secrecy, in accordance with the Croatian Health Care Act and the Croatian Medical Practice Act.
As a rule, we do not process your health data based on consent. It is therefore important to distinguish between consent and the agreement or informed consent that you sign before a medical procedure. The consents you sign before individual diagnostic or therapeutic procedures, such as consent to hospitalization or an X-ray examination, are required under the Croatian Patients’ Rights Protection Act and represent your informed consent to the relevant medical procedure. They do not constitute consent to the processing of personal data under the GDPR. Accordingly, withdrawing such consent does not result in the deletion of medical records that we are legally required to create and retain.
We use consent as a legal basis only for the processing activities described in Section 4.3, namely processing activities that are not necessary for the provision of healthcare and which you may choose to participate in.
4. Purposes and legal bases for processing
We have divided our processing activities into five groups according to the purpose for which they are carried out. Within each group, the legal basis for each processing purpose is specified.
4.1 Provision of healthcare
This is the primary reason why we process your personal data and covers the entire process, from your initial contact with us through to the issuance of documentation following completion of your treatment.
When you contact us to arrange an appointment, we process your first and last name, telephone number and, if provided, your email address. We use your telephone number to arrange and confirm appointments and to send appointment reminders, while your email address is used to arrange appointments and deliver medical reports. During communications, we verify your identity to ensure that we are speaking with you, as the information concerned is subject to professional confidentiality.
For examination, diagnosis and treatment, we process your identification and contact details, including your first and last name, personal identification number, date and place of birth, sex, nationality, permanent or temporary address, telephone number and email address, as well as information concerning your health. Health data include your medical history, information on previous treatment and medication, examination results, diagnostic images and scans, diagnosis, treatment plan and course of treatment, therapies administered, information concerning procedures performed, and your signed consents and statements relating to individual procedures.
If you are admitted for inpatient treatment, we also process information concerning your admission and discharge, nursing documentation and clinical course, the discharge summary, and any information required to issue a certificate of hospitalization. If you designate a person who may be informed about your admission and health condition, we process that person’s name and contact details. We also record individuals to whom you have expressly prohibited the disclosure of such information. If you intend to leave the institution against medical advice, your written statement is included in your medical records. If the patient is a minor or legally incapacitated, we also process the personal data of their legal representative or guardian.
We maintain medical records in electronic form, together with related paper documentation where the patient’s signature is required for validity. You have the right to access your complete medical records relating to the diagnosis and treatment of your condition and the right to request a copy at your own expense. In the event of your death, the right of access belongs to the persons specified by the Croatian Patients’ Rights Protection Act, unless you expressly prohibited such access during your lifetime.
Upon your request, we also issue certificates confirming facts contained in your medical records. Such certificates contain your identification details and information concerning the period and type of healthcare service provided. The certificate is provided directly to you and is not disclosed to third parties unless you request this or we are legally required to do so.
The legal basis for all of the above is Article 6(1)(c) GDPR, as processing is necessary for compliance with our legal obligations under the Croatian Health Care Act, the Croatian Patients’ Rights Protection Act, the Croatian Medical Practice Act and the Croatian Health Data and Information Act, as well as Article 6(1)(b) GDPR insofar as processing is necessary for the performance of a healthcare services agreement or is carried out at your request. For health data, the relevant exception is Article 9(2)(h) in conjunction with Article 9(3) GDPR.
In emergencies where you are unable to express your wishes and failure to take action would endanger your life or health, processing is based on Article 6(1)(d) and Article 9(2)(c) GDPR, namely the protection of your vital interests.
4.2 Compliance with legal obligations towards competent authorities
We process certain personal data because we are legally required to do so, irrespective of your treatment.
If you are not a Croatian citizen, and to the extent required by applicable immigration legislation, we process information from your travel document or identity card, visa information, date and place of entry into the Republic of Croatia, expiry date of your residence permit, and your previous accommodation, temporary residence or permanent address in the Republic of Croatia. We copy this information from the document you present to us for inspection and submit it to the Ministry of the Interior using the prescribed form for the purpose of registering your stay.
Where required by law, we notify the competent epidemiological service and other competent health authorities.
For the purpose of collecting payment for healthcare services and fulfilling our tax and accounting obligations, we process your first and last name, address, personal identification number, information about the service provided, amount charged and payment details, including information relating to the bank account or other means of payment used to pay for the service. If an insurance policy covers the service, we provide the information required for billing to the insurance company with which you are insured.
The legal basis is Article 6(1)(c) GDPR, together with Article 6(1)(b) GDPR insofar as payment constitutes performance of our agreement with you. Where health data are processed in this context, the exception under Article 9(2)(h) GDPR applies.
4.3 Processing carried out only with your consent
The following processing activities are not necessary for your treatment and are carried out only if you choose to participate. You may withdraw your consent at any time without giving a reason. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Refusing or withdrawing consent has no consequences for the healthcare services we provide to you.
The legal basis for all processing activities in this category is your consent under Article 6(1)(a) GDPR and, where your health data are concerned, your explicit consent under Article 9(2)(a) GDPR.
Participation in scientific research. Within our institution, the Scientific Research Unit conducts clinical trials in cooperation with sponsors, as well as our own retrospective and prospective research. For each research project in which you participate, we obtain your written, dated and signed informed consent, as required by the Croatian Patients’ Rights Protection Act. Research only begins after approval by the competent ethics committee. Before giving your consent, you will receive clear and understandable information about the nature, importance, consequences and risks of the research.
In clinical trials conducted in cooperation with a sponsor, each participant is assigned a unique code, and the sponsor receives only data identified by that code. The sponsor does not have access to your name or other information that could directly identify you, while the key linking your identity to the code remains with us. Paper research documentation is stored in a locked area of the Scientific Research Unit. In contrast, electronic documentation is stored separately, with access restricted to members of the research team and persons authorized by the principal investigator. Student research uses only data from which identifying information has been removed, and students are subject to confidentiality obligations.
After withdrawal of your consent, we stop collecting new data about you for research purposes. Data collected up to that point may nevertheless be retained to the extent necessary to ensure the integrity, reliability and verifiability of the research already conducted.
Testing following a needlestick or other exposure incident. If, during the provision of healthcare, an incident occurs in which one of our employees is exposed to your blood or other bodily material, we may ask you to consent to testing for blood-borne diseases. We process your identification data, information concerning the incident, and the test results. The results are communicated to the physician responsible for determining appropriate protective measures for the exposed employee, and the competent epidemiological service is notified of the incident where required by law.
Information about our services. If you subscribe to receive information through our website, we process the email address you provide. Our mailing list is created solely from such subscriptions and is not linked to your medical records. For direct marketing by email, prior consent is also required under the Croatian Electronic Communications Act. You may withdraw your consent at any time by using the unsubscribe link included in each message or by contacting us at [email protected].
4.4 Processing based on our legitimate interests
The legal basis for the processing activities in this category is Article 6(1)(f) GDPR. You may object to any of these processing activities in the manner described in Section 10.
Video surveillance. We use a video surveillance system to protect people and property and to monitor access to and exit from our premises, thereby reducing the risk of burglary, theft and violence affecting patients, employees and property. Video surveillance covers the building’s entrance and exit areas, including the entrance lobby, as well as corridors and other areas of the institution. Areas intended for rest, personal hygiene and changing, as well as surrounding public areas, are not subject to video surveillance. Areas under surveillance are clearly marked with notices visible upon entering. Access to recordings is restricted to authorized persons and specifically designated individuals. Every access to recordings is logged, including the time and location of access and the identity of the person accessing the recording. In addition to the GDPR, video surveillance is governed by the Croatian Act on the Implementation of the General Data Protection Regulation.
Recording of telephone calls. Telephone calls with our institution are recorded. We inform you of this at the beginning of the call via an automated message for incoming calls and verbally for outgoing calls. Recordings are used to monitor the quality of communication with patients and to establish what was agreed during the telephone conversation. We process your telephone number, the date and time of the call, and the content of the conversation.
Handling written complaints and compliments. If you submit a written complaint or compliment, we process your first and last name and contact details, the content of your submission, information concerning the patient to whom the submission relates if you are submitting it on their behalf, and the names of our employees mentioned in the submission. We process this information to investigate the matters raised, respond to the person submitting the complaint or compliment, and take measures to improve the quality of our services. The information remains within the institution unless the matter proceeds to a competent authority. To the extent that handling a patient’s complaint is required by the Croatian Patients’ Rights Protection Act, processing is also based on Article 6(1)(c) GDPR. Where health data are included in the submission, the relevant exception is Article 9(2)(h) GDPR, or Article 9(2)(f) GDPR, where the data are necessary for the establishment, exercise, or defense of legal claims.
4.5 Individuals who are not patients
In addition to patients’ data, we also process personal data relating to certain other individuals. Such individuals are independent data subjects and have all the rights described in Section 10, regardless of their relationship with the patient.
If a parent, guardian, or another person stays with a patient as an accompanying person, we process that person’s first and last name, identification, contact details, and information regarding the period of their stay for the purpose of issuing a certificate of accommodation. If the accompanying person is not a Croatian citizen, their data are also processed and provided to the Ministry of the Interior as described in Section 4.2.
For a person designated by the patient as someone who may be informed about the patient’s admission and health condition, we process their name and contact details solely to provide such information.
For our employees who are mentioned in a written complaint, we process their data to the extent necessary to investigate the allegations and handle the submission.
Individuals entering our premises are subject to the video surveillance system described in Section 4.4.
The legal basis is Article 6(1)(c) GDPR for processing required by law, Article 6(1)(b) GDPR for issuing certificates requested by the individual, and Article 6(1)(f) GDPR for the processing activities described in Section 4.4.
5. Who within our institution has access to your data
Access to your personal data is restricted to our employees who need access to perform their duties and only to the extent required for those duties.
Healthcare professionals involved in your diagnosis and treatment have access to your medical records to the extent necessary to provide healthcare. Access within our information systems is role-based, meaning that employees in one department do not automatically have access to records created by another department. In contrast, non-healthcare staff do not have access to the contents of medical records.
Administrative staff have access to your identification and contact details, as well as information required for appointments, admission, discharge, and billing.
All such employees are subject to professional secrecy and confidentiality obligations.
6. Whom we disclose your data to
We disclose your personal data to public authorities and other parties that process such data independently and based on their own statutory powers, but only where there is a legal basis for doing so or where you have requested such disclosure.
These recipients include the Ministry of the Interior in connection with the registration of foreign nationals’ stays; the ministry responsible for health and competent inspection authorities, as well as relevant professional chambers, in connection with the supervision of healthcare activities; competent public health authorities where reporting is required by law; the Tax Administration and Ministry of Finance in connection with tax obligations; courts and the State Attorney’s Office within their statutory powers; insurance companies where healthcare services are billed under an insurance policy; and other healthcare providers to whom we refer you or who are involved in your treatment, with your knowledge.
7. Data processors
For certain technical and support services, we use external service providers that process personal data solely on our behalf and in accordance with our instructions. These include the provider and maintainer of our hospital information system, including cloud-based data hosting; providers of telecommunications services; providers of technical security and video surveillance services; accounting service providers; and providers of information and communication technology services.
We enter into a data processing agreement with each processor that contains the elements required under Article 28(3) GDPR, including confidentiality obligations, requirements to implement appropriate security measures, and restrictions on the engagement of sub-processors.
We maintain a separate, regularly updated register of our data processors. You may request information from the Data Protection Officer regarding which processor processes your data for a particular purpose.
8. Transfers of data outside the European Economic Area
As a rule, we process your personal data within the European Economic Area.
If a service provider processing data on our behalf processes such data outside the European Economic Area or uses infrastructure located outside the EEA, we carry out such transfers only with appropriate safeguards in accordance with Chapter V of the GDPR, generally using standard contractual clauses approved by the European Commission. You may request information from the Data Protection Officer as to whether such a transfer concerns your data and which safeguards we apply.
9. How long we retain your data
We retain data relating to outpatient treatment for ten years after completion of treatment, as required by the Croatian Medical Practice Act. After this period, the documentation is handled in accordance with the applicable rules governing the retention of documentation and archival records.
For other healthcare and medical documentation, including records relating to inpatient treatment and procedures performed, retention periods are determined by a specific records retention schedule adopted with the approval of the competent state archive in accordance with the regulations governing archival records and archives, together with the applicable legislation governing health data and information.
Your consents and statements included in your medical records are retained for the same period as the documentation to which they relate.
Invoices and accounting records are retained for at least eleven years, calculated from the last day of the financial year to which they relate, as required by the Croatian Accounting Act.
Data collected to fulfill foreign nationals’ residence registration requirements are retained in accordance with the retention periods prescribed by the applicable legislation governing the stay of foreign nationals in the Republic of Croatia.
Video surveillance recordings are retained for thirty days and are then permanently deleted. Exceptionally, recordings that constitute evidence in judicial, administrative, arbitration or other equivalent proceedings are retained until the conclusion of such proceedings. Telephone recordings are retained only for as long as necessary for the purposes described in Section 4.4.
Written complaints and compliments, together with documentation relating to their handling, are retained until the relevant matter has been resolved and thereafter for the period during which legal claims may be brought under the applicable civil law provisions.
The clinical trial master file is retained for at least twenty-five years after completion of the trial, as required by Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use. Participants’ medical records are retained for the periods generally applicable to medical records. In contrast, data collected for other research projects are retained until the expiry of the period specified in the research protocol approved by the competent ethics committee.
Your email address used to receive information about our services is retained until you withdraw your consent.
Once the applicable retention periods have expired, we delete or permanently destroy the data unless it is subject to ongoing proceedings before a competent authority, in which case it is retained until the proceedings are finally concluded.
10. Your rights
You have the right to request access to your personal data, as well as its rectification, erasure or restriction of processing. You also have the right to data portability in relation to data processed based on your consent or a contract, where the processing is carried out by automated means.
You have the right to object at any time to processing based on our legitimate interests, namely all processing activities described in Section 4.4. You may submit your objection to us. Once we receive your objection, we will stop processing your data for that purpose unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defense of legal claims.
Where processing is based on your consent, namely for the processing activities described in Section 4.3, you may withdraw your consent at any time without giving a reason. Withdrawal of consent does not affect the lawfulness of processing carried out based on your consent before it was withdrawn.
Your rights are not absolute. Where we are legally required to process and retain your data, such as medical records and accounting documents, we cannot comply with a request to erase it. At the same time, the statutory retention obligation remains in force. This follows from Article 17(3) GDPR and is also consistent with the position of the Croatian Personal Data Protection Agency.
You may submit a request to exercise your rights by email to [email protected] or by post to our address, marked for the attention of the Data Protection Officer. To protect your data, we will verify your identity before acting on your request. We will respond without undue delay and, in any event, within one month of receiving your request. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receiving your request.
The objection described in the second paragraph of this section should be distinguished from a complaint lodged with the supervisory authority. An objection is a right you exercise against us, the data controller, and you submit it directly to us.
If you believe that we are processing your personal data in breach of data protection legislation, you have the right to lodge a complaint with the supervisory authority, regardless of whether you have previously contacted us. The supervisory authority in the Republic of Croatia is the Croatian Personal Data Protection Agency (AZOP), Ulica Metela Ožegovića 16, Zagreb, email: [email protected], website: www.azop.hr. You also have the right to an effective judicial remedy.
11. Security of your data
We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful access, alteration, disclosure, loss or destruction.
These measures include role-based access controls and the principle of least privilege; logging of data access within our information systems; physical protection of premises and paper documentation; confidentiality obligations for all persons with access to data; and contractual arrangements with all external service providers that process data on our behalf.
12. Cookies
The processing of personal data through cookies on our website is governed by a separate Cookie Policy available on our website. It specifies the cookies we use, their purposes and retention periods, and how you can manage your preferences and withdraw any consent you have given.
13. Changes to this Privacy Policy
We periodically update this Privacy Policy to reflect changes in our operations and applicable legislation. The current version is always published on our website.