GDPR Compliance

Record of Processing

Action: Peamount to ensure DISK is recorded on the relevant RoPA
Currently there is no reference in the website privacy notice to data processed for the DISH system – here is the wording that should be included
Action: Peamount to update the website privacy notice

Website privacy Notice

Purpose Examples Legal Basis Retention
Nutritional care and meal planning using the DISH system (Nutritics) • Management and delivery of individualised meal plans tailored to each patient’s/resident’s health needs and dietary restrictions
• Processing of dietary and health-related data through the DISH system operated by Aramark and hosted by Nutritics
• Support for catering staff to ensure accurate and timely delivery of meals aligned with medical and nutritional guidance
Article 6(1)(B) – performance of a contract
Article 9(2)(h) – medical diagnosis, provision or management of health or social care
Retained for a maximum of 6 years by Nutritics, unless earlier deletion is requested by Peamount. Data is deleted when no longer required, such as upon patient/resident discharge.