DATA PROTECTION & GDPR COMPLIANCE
MyCare Malta – Data Protection & GDPR Compliance
Effective Date: [Insert Date]
Last Updated: [Insert Date]
At MyCare Malta, we are committed to protecting personal data and ensuring compliance with the General Data Protection Regulation (GDPR) and Maltese data protection laws. This page outlines how we safeguard personal information, user rights under GDPR, and our data handling practices.
1. Our Commitment to Data Protection
We take privacy and security seriously and have implemented robust technical, administrative, and legal safeguards to ensure that personal data is processed lawfully, transparently, and securely.
MyCare Malta acts as a Data Controller for personal data collected through our platform and as a Data Processor when handling information on behalf of healthcare professionals and businesses.
2. Legal Basis for Data Processing
Under GDPR, we process personal data based on the following legal grounds:
✅ Consent – Users explicitly agree to data collection for specific purposes, such as booking appointments or receiving marketing communications.
✅ Contractual Obligation – Data is processed when necessary to provide services, such as appointment scheduling, telemedicine, and recruitment.
✅ Legal Compliance – We process data to comply with regulatory and legal obligations.
✅ Legitimate Interest – When processing is required for business operations while ensuring user rights are protected.
3. How We Protect Your Data
We implement industry-standard security measures to prevent unauthorised access, loss, or misuse of personal data, including:
🔒 Encryption – Sensitive data is encrypted to protect confidentiality.
📑 Access Control – Restricted access to personal data, ensuring only authorised personnel can handle it.
🛡️ Regular Security Audits – Ongoing system monitoring, vulnerability assessments, and security updates.
🖥️ Data Minimisation – We collect and retain only the necessary data required for service delivery.
4. User Rights Under GDPR
As a MyCare Malta user, you have the following rights under GDPR:
✅ Right to Access – Request a copy of the personal data we store about you.
✅ Right to Rectification – Correct inaccurate or incomplete personal data.
✅ Right to Erasure (‘Right to be Forgotten’) – Request deletion of your personal data under certain conditions.
✅ Right to Restrict Processing – Limit how your data is used in specific circumstances.
✅ Right to Data Portability – Obtain your personal data in a structured format for transfer to another service provider.
✅ Right to Object – Opt out of data processing for direct marketing or other purposes.
✅ Right to Withdraw Consent – Revoke consent at any time when data processing is based on consent.
✅ Right to Lodge a Complaint – File a complaint with the Maltese Information and Data Protection Commissioner (IDPC) if you believe your data rights have been violated.
To exercise these rights, please contact us at [Insert Contact Email].
5. Data Retention Policy
We retain personal data only for as long as necessary to:
- Fulfil service commitments (e.g., appointment records, order history, recruitment details)
- Comply with legal obligations (e.g., financial records, regulatory compliance)
- Resolve disputes and enforce agreements
When data is no longer required, we securely delete or anonymise it.
6. Data Sharing & Third Parties
We do not sell personal data. However, we may share information with:
- Healthcare Professionals & Businesses – When users book appointments, purchase services, or engage with providers.
- Regulatory Authorities – If required for legal or compliance purposes.
- Third-Party Service Providers – Such as payment processors, hosting providers, and analytics tools, all of whom are contractually bound to protect data confidentiality.
All third parties must adhere to GDPR requirements and MyCare Malta’s strict privacy policies.
7. International Data Transfers
If we transfer data outside the European Economic Area (EEA), we ensure that:
- The recipient country has adequate data protection laws.
- We implement Standard Contractual Clauses (SCCs) to safeguard data security.
- Users are informed and have the right to object to such transfers.
8. Data Breach Policy
In the unlikely event of a data breach, MyCare Malta will:
- Investigate and assess the scope of the breach.
- Notify affected users within 72 hours if their data is at risk.
- Report the breach to the Maltese Information and Data Protection Commissioner (IDPC) if legally required.
- Implement corrective measures to prevent future breaches.
9. Updates to Our Data Protection Policy
We may update this policy periodically to reflect regulatory changes or improvements in data protection practices. Users will be notified of major changes via email or platform notifications.
10. Contact Us
For any questions or concerns regarding data protection and GDPR compliance, please contact us at:
📧 [Insert Contact Email]
📞 [Insert Contact Phone Number]
📍 [Insert Physical Address]
If you believe we have not addressed your concerns adequately, you may contact the Maltese Information and Data Protection Commissioner (IDPC) for further assistance.
📢 MyCare Malta is dedicated to upholding the highest standards of data protection and privacy. By using our platform, you acknowledge your rights under GDPR and our commitment to safeguarding your personal information.