Schedule a Free ConsultationContact Us

Privacy Policy

ICG Medical Group ("ICG Medical", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your data, and outlines your rights under global data protection laws. It applies across all ICG Medical brands and global operations, including:

United Kingdom – Republic of Ireland – United States – Canada – Mexico – South Africa – India – China – Japan – Australia – Philippines

This policy applies to all individuals engaging with us as candidates, clients, suppliers, website or app users. For region-specific rules and obligations, refer to the Regional Attestations Framework in the appendices.

1 – Who We Are

ICG Medical Group is a global provider of healthcare workforce solutions. While each of our brands may act as a data controller, this group-level policy governs the overarching data protection standards applied across all group entities.

Postal Address:

Suite 1, Wrest Park Business Centre
Capability House, Wrest Park, Silsoe
Bedfordshire, MK45 4HR
United Kingdom

2 – Scope of This Policy

This Privacy Policy applies when you:

  • Visit our websites or use our applications
  • Apply for or register interest in roles
  • Communicate with us via email, phone or in person
  • Are referred to us by a third party (with your permission)
  • Engage with us as a supplier, contractor or client

This policy does not apply to third-party services or platforms linked to our websites or applications.

3 – Types of Data We Collect

Depending on your interaction, we may collect:

Identity & Contact Data

Name, address, email, phone number

Professional Data

CV, qualifications, references, employment history

Compliance Data

Identity checks, background screening, licences, health records

Account Data

Usernames, passwords, log data

Financial Data

Payment information, tax references

Behavioural & Technical Data

Device information, IP, usage data

Sensitive Data

Health or criminal background (where required and legally justified)

4 – How We Collect Your Data

Directly from You

Via applications, forms, surveys, or direct contact

Automatically

Using cookies or analytics tools on websites and apps

Third Parties

Background screening services, referees, regulatory bodies

Referral

By others, with your prior consent

5 – Cookies and Tracking

We use cookies to:

  • Enable site functionality
  • Analyse usage behaviour
  • Customise user experience
  • Deliver targeted advertising

You may manage or disable cookies in your browser or using our cookie preference tool. See our full Cookie Policy for details.

6 – Lawful Use of Your Data

We use your personal data only when permitted by law. The lawful bases include:

PurposeData TypesLegal Basis
User verification and onboardingIdentity, ComplianceContract
Regulatory and credential checksComplianceLegal obligationLegitimate interest
Contract management and paymentFinancial, ContactContractLegal obligation
Analytics and service improvementTechnical, UsageLegitimate interest
Marketing and communicationsContactConsentLegitimate interest
Legal reporting or fraud preventionAnyLegal obligationVital interestLegitimate interest

You may withdraw consent at any time.

7 – Sharing Your Data

We only share data when necessary and with appropriate safeguards in place. This includes sharing with:

  • Other ICG Medical brands providing related services
  • Third-party processors (e.g. payroll, IT, compliance services)
  • Clients for service fulfilment
  • Regulators, auditors and legal advisers
  • Authorities or acquiring companies where legally required

All sharing is governed by data processing agreements or equivalent safeguards.

8 – International Data Transfers

Your data may be transferred outside your jurisdiction. We apply:

  • UK/EU adequacy decisions
  • Standard contractual clauses (SCCs)
  • Government-approved safeguards where applicable (e.g. India, China)

For transfers from China and India, we meet local security assessments and certification rules, including approval pathways.

9 – Data Retention

Data is retained only for as long as necessary for:

  • Contractual and legal compliance
  • Operational support or audit purposes
  • Service improvement (in anonymised form)

Retention is governed by our internal policy. Secure deletion or anonymisation follows expiry of the relevant period.

10 – Data Security

We apply strong protections aligned with ISO/IEC 27001 principles, including:

  • Encryption
  • Role-based access controls
  • Intrusion detection and monitoring
  • Security training
  • Incident response protocols

If you suspect misuse or breach, please contact us immediately.

11 – Your Rights

Depending on your location, you may exercise:

  • Right of access
  • Right to correct inaccurate data
  • Right to erasure
  • Right to restrict processing
  • Right to object to certain uses (including profiling)
  • Right to data portability
  • Right to withdraw consent
  • Right to lodge complaints with your data protection authority

Contact: DPO@icgmedical.co.uk to exercise your rights.

12 – Marketing Preferences

You can opt out of marketing:

  • By clicking 'unsubscribe' in emails
  • By contacting us directly
  • Via account settings on our platforms

We never sell your data.

13 – Policy Changes

This policy may be updated periodically. We will provide notice where material changes occur.

14 – Contact

Global Data Protection Officer

Email:DPO@icgmedical.co.uk

Post: Suite 1, Wrest Park Business Centre, Capability House, Wrest Park, Silsoe, Bedfordshire, MK45 4HR, United Kingdom


Regional Compliance Appendices

Appendix A – Asia-Pacific Compliance

This appendix outlines the additional obligations, safeguards, and operational controls applicable to personal data processed or transferred in or from the Asia-Pacific region, specifically: China, Japan, Australia, and India.

China – Personal Information Protection Law (PIPL) Compliance

  • Compliance Audits: Formal compliance audits every two years for processing over 10 million individuals
  • Cross-Border Data Transfer Mechanisms: Security Assessment, Standard Contracts, or Certification requirements
  • Localisation and Data Mapping: Classification and inventory of all personal data collected within China

Japan – Act on the Protection of Personal Information (APPI) Amendments (2025)

  • AI Training: Personal data may be used for AI model training with pseudonymisation and opt-out options
  • Biometric and Children's Data: Enhanced protections with explicit opt-in consent
  • Breach Notification: 30-60 days for certified entities, 5 days for non-certified

Australia – Privacy Act Reforms (Effective June 2025)

  • Statutory Tort: Privacy Impact Assessment register for high-risk activities
  • Strengthened Consent: Freely given, informed, specific, and unambiguous consent requirements
  • Penalty Framework: Up to AU$50 million or 30% of adjusted turnover penalties

India – Digital Personal Data Protection Act (DPDP 2023)

  • Consent Requirements: Free, informed, specific, clear, and withdrawable consent
  • Consent Manager Integration: Interoperability with authorised Consent Manager Platforms
  • Data Protection Board: Compliance with penalties up to INR 250 crore

Appendix B – European and UK Compliance

This appendix outlines compliance with EU GDPR, UK GDPR, and UK Data Protection Act 2018 - forming the baseline of our global data protection model.

Key Compliance Areas:

  • Lawful Basis: All processing meets Article 6 requirements with additional Article 9 conditions for special category data
  • Data Subject Rights: Full suite of rights under Articles 12-22 processed within one calendar month
  • Record of Processing Activities (ROPA): Group-wide ROPA updated quarterly
  • Data Protection Impact Assessments: Conducted for high-risk processing activities
  • International Transfers: Adequacy decisions, SCCs, BCRs, or Article 49 derogations

Appendix C – Americas Compliance

Compliance approach across the United States, Canada, and Mexico with tailored safeguards for each region.

United States – Multi-State Privacy Laws

  • Core Principles: Data minimisation, transparency, opt-out rights for sale/sharing and profiling
  • California CPRA: Enhanced protections for Sensitive Personal Information including neural data
  • Vendor Compliance: Data Processing Agreements with prohibition of secondary use

Canada – PIPEDA and Bill C-27 (CPPA)

  • Consent Framework: Express or implied consent with clear purpose disclosures
  • Algorithmic Accountability: Right to explanation and opt-out for automated decisions
  • Data Classification: Distinction between anonymised and de-identified data

Mexico – LFPDPPP

  • ARCO Rights: Access, Rectification, Cancellation, Opposition within specified timeframes
  • Cross-border Transfers: Binding contracts ensuring equivalent protection
  • Breach Notification: Notification to data subjects for significant impacts

Appendix D – Africa and Middle East Compliance

Regulatory requirements and operational measures for compliance within South Africa under the Protection of Personal Information Act (POPIA).

South Africa – POPIA Compliance

  • Processing Conditions: Eight processing conditions ensuring lawful, reasonable, and transparent handling
  • Purpose Specification: Processing limited to employment, regulatory, and service delivery purposes
  • Objection Rights: Form 1 process for objections with balancing test documentation
  • Cross-border Transfers: Equivalent protection requirements with Transfer Assessment Files
  • Security Safeguards: Administrative, technical, and physical protections with breach notification
  • Information Officer: Appointed IO for compliance promotion and regulatory liaison

Note: This privacy policy is effective as of the date of publication and may be updated periodically to reflect changes in our practices or applicable laws. Please check this page regularly for updates.

Privacy Policy | Greenstaff HomeCare