ICG Medical Group ("ICG Medical", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your data, and outlines your rights under global data protection laws. It applies across all ICG Medical brands and global operations, including:
United Kingdom – Republic of Ireland – United States – Canada – Mexico – South Africa – India – China – Japan – Australia – Philippines
This policy applies to all individuals engaging with us as candidates, clients, suppliers, website or app users. For region-specific rules and obligations, refer to the Regional Attestations Framework in the appendices.
1 – Who We Are
ICG Medical Group is a global provider of healthcare workforce solutions. While each of our brands may act as a data controller, this group-level policy governs the overarching data protection standards applied across all group entities.
Postal Address:
Suite 1, Wrest Park Business Centre Capability House, Wrest Park, Silsoe Bedfordshire, MK45 4HR United Kingdom
2 – Scope of This Policy
This Privacy Policy applies when you:
Visit our websites or use our applications
Apply for or register interest in roles
Communicate with us via email, phone or in person
Are referred to us by a third party (with your permission)
Engage with us as a supplier, contractor or client
This policy does not apply to third-party services or platforms linked to our websites or applications.
3 – Types of Data We Collect
Depending on your interaction, we may collect:
Identity & Contact Data
Name, address, email, phone number
Professional Data
CV, qualifications, references, employment history
Compliance Data
Identity checks, background screening, licences, health records
Account Data
Usernames, passwords, log data
Financial Data
Payment information, tax references
Behavioural & Technical Data
Device information, IP, usage data
Sensitive Data
Health or criminal background (where required and legally justified)
4 – How We Collect Your Data
Directly from You
Via applications, forms, surveys, or direct contact
Automatically
Using cookies or analytics tools on websites and apps
Post: Suite 1, Wrest Park Business Centre, Capability House, Wrest Park, Silsoe, Bedfordshire, MK45 4HR, United Kingdom
Regional Compliance Appendices
Appendix A – Asia-Pacific Compliance
This appendix outlines the additional obligations, safeguards, and operational controls applicable to personal data processed or transferred in or from the Asia-Pacific region, specifically: China, Japan, Australia, and India.
China – Personal Information Protection Law (PIPL) Compliance
Compliance Audits: Formal compliance audits every two years for processing over 10 million individuals
Cross-Border Data Transfer Mechanisms: Security Assessment, Standard Contracts, or Certification requirements
Localisation and Data Mapping: Classification and inventory of all personal data collected within China
Japan – Act on the Protection of Personal Information (APPI) Amendments (2025)
AI Training: Personal data may be used for AI model training with pseudonymisation and opt-out options
Biometric and Children's Data: Enhanced protections with explicit opt-in consent
Breach Notification: 30-60 days for certified entities, 5 days for non-certified
Australia – Privacy Act Reforms (Effective June 2025)
Statutory Tort: Privacy Impact Assessment register for high-risk activities
Strengthened Consent: Freely given, informed, specific, and unambiguous consent requirements
Penalty Framework: Up to AU$50 million or 30% of adjusted turnover penalties
India – Digital Personal Data Protection Act (DPDP 2023)
Consent Requirements: Free, informed, specific, clear, and withdrawable consent
Consent Manager Integration: Interoperability with authorised Consent Manager Platforms
Data Protection Board: Compliance with penalties up to INR 250 crore
Appendix B – European and UK Compliance
This appendix outlines compliance with EU GDPR, UK GDPR, and UK Data Protection Act 2018 - forming the baseline of our global data protection model.
Key Compliance Areas:
Lawful Basis: All processing meets Article 6 requirements with additional Article 9 conditions for special category data
Data Subject Rights: Full suite of rights under Articles 12-22 processed within one calendar month
Record of Processing Activities (ROPA): Group-wide ROPA updated quarterly
Data Protection Impact Assessments: Conducted for high-risk processing activities
International Transfers: Adequacy decisions, SCCs, BCRs, or Article 49 derogations
Appendix C – Americas Compliance
Compliance approach across the United States, Canada, and Mexico with tailored safeguards for each region.
United States – Multi-State Privacy Laws
Core Principles: Data minimisation, transparency, opt-out rights for sale/sharing and profiling
California CPRA: Enhanced protections for Sensitive Personal Information including neural data
Vendor Compliance: Data Processing Agreements with prohibition of secondary use
Canada – PIPEDA and Bill C-27 (CPPA)
Consent Framework: Express or implied consent with clear purpose disclosures
Algorithmic Accountability: Right to explanation and opt-out for automated decisions
Data Classification: Distinction between anonymised and de-identified data
Mexico – LFPDPPP
ARCO Rights: Access, Rectification, Cancellation, Opposition within specified timeframes
Purpose Specification: Processing limited to employment, regulatory, and service delivery purposes
Objection Rights: Form 1 process for objections with balancing test documentation
Cross-border Transfers: Equivalent protection requirements with Transfer Assessment Files
Security Safeguards: Administrative, technical, and physical protections with breach notification
Information Officer: Appointed IO for compliance promotion and regulatory liaison
Note: This privacy policy is effective as of the date of publication and may be updated periodically to reflect changes in our practices or applicable laws. Please check this page regularly for updates.