0111 003 400 info@lutonhospital.co.ke China Centre, Ngong Road, Nairobi
Home / Policy Centre / Data Protection Policy
Public Policy Centre

Data Protection Policy

Clear information about how Luton Hospital collects, uses, discloses, retains and protects personal data when patients, website visitors and service users interact with our hospital.

01 • Data controller Luton Medical Hospital Limited
02 • Privacy contact info@lutonhospital.co.ke
03 • Last updated 22 July 2026
04 • Public document Available for download

Lawful handling

We collect and use personal data only for lawful, clear and necessary hospital purposes.

Health data protection

Health and sensitive personal data is handled with additional confidentiality and access safeguards.

Patient rights

Patients and service users may request access, correction, restriction, objection and other applicable rights.

Secure communication

Privacy concerns and rights requests can be sent to the official hospital privacy contact.

1. Overview and scope

Luton Medical Hospital Limited is committed to protecting personal data and handling it lawfully, fairly, transparently and securely.

This Data Protection Policy applies when you use our website, submit an appointment request, contact us, receive or enquire about healthcare services, or otherwise interact with us.

This policy should be read together with any specific privacy notice, consent form or service notice given at the time your data is collected.

Data controller Luton Medical Hospital Limited
Postal address P.O. Box 34444–00100, China Centre, Ngong Road, Nairobi, Kenya
Privacy contact info@lutonhospital.co.ke
Telephone +254 111 003 400; +254 726 510 000; +254 711 300 900

2. Personal data we may collect

The data we collect depends on how you interact with Luton Hospital and the service requested. We only ask for information that is relevant to the purpose.

  • Identity and contact information
  • Appointment and enquiry information
  • Health and medical information
  • Payment, insurance and cover information
  • Communications and documents
  • Website and device information

3. Why we process personal data

We process personal data for lawful and specified purposes connected with healthcare, administration, communication, safety, compliance and service improvement.

1

Collect

We receive information through care, forms, calls, email, WhatsApp or authorised sources.

2

Use

We use it for healthcare, appointments, billing, communication, compliance and safety.

3

Protect

We apply access control, confidentiality and security safeguards appropriate to the data.

4

Retain or delete

We keep data only as needed, then securely delete, destroy or anonymise where appropriate.

  • Receiving, assessing and responding to enquiries and appointment requests.
  • Identifying patients or service users and maintaining accurate records.
  • Arranging, coordinating and providing healthcare or related services.
  • Communicating about appointments, care, service availability, follow-up or administration.
  • Verifying SHA, insurance, corporate-cover or payment information and administering billing or claims.
  • Managing complaints, incidents, quality assurance, clinical governance, audit and service improvement.
  • Preventing and investigating fraud, misuse, unlawful activity, cyber threats and threats to safety.
  • Operating, securing, maintaining and troubleshooting our website, communications and information systems.
  • Complying with legal, regulatory, professional, public-health, reporting and recordkeeping duties.

5. When we may disclose personal data

We may disclose the minimum personal data reasonably necessary to recipients who have a lawful need to receive it. We do not sell personal data.

  • Healthcare professionals and authorised staff involved in care or administration.
  • Laboratories, imaging centres, referral facilities or other healthcare providers involved in a requested service.
  • SHA, insurers, employers or corporate-cover administrators for verification, authorisation, billing or claims.
  • Professional advisers, auditors and insurers acting under appropriate duties.
  • Authorised providers supporting hosting, communications, cybersecurity, records, maintenance or hospital systems.
  • Regulators, courts, law-enforcement agencies, public-health bodies and other public authorities where required or permitted by law.
  • Another person where the patient or service user has authorised disclosure.

6. Data security, confidentiality and breaches

We apply technical, organisational and physical safeguards appropriate to the nature of the data, the processing and the risks involved.

Access to personal data should be limited to persons who need it for an authorised purpose and who are subject to confidentiality or professional duties.

We maintain procedures for assessing and responding to suspected personal-data breaches. Where the legal threshold is met, the hospital will notify the relevant authority and affected persons as required by law.

7. Data retention

We keep personal data only for as long as it is reasonably needed for the purpose for which it was collected and for any applicable legal, clinical, professional, accounting, reporting, insurance, claims or dispute-resolution requirement.

Retention periods may differ for appointment requests, communications, clinical records, prescriptions, billing and cover information, complaints, security logs and website data.

When retention is no longer justified, data will be securely deleted, destroyed or anonymised, subject to technical limits and lawful exceptions.

8. Your data-protection rights

Subject to applicable conditions, exemptions and verification requirements, you may have the following rights under applicable data-protection law.

  • Be informed about how personal data is used.
  • Request access to personal data held about you and receive a copy.
  • Request correction of inaccurate or incomplete personal data.
  • Request erasure where there is a lawful basis for deletion.
  • Request restriction of processing in qualifying circumstances.
  • Object to processing based on particular grounds, including direct marketing.
  • Request data portability where legal requirements are met.
  • Withdraw consent for future processing that depends on consent.
  • Seek safeguards concerning qualifying automated decisions.

9. How to exercise your rights or raise a concern

Send a clear request to info@lutonhospital.co.ke or write to the Privacy and Data Protection Contact, Luton Medical Hospital Limited, P.O. Box 34444–00100, China Centre, Ngong Road, Nairobi, Kenya.

Please describe the right you wish to exercise and the data or interaction concerned. We may request information reasonably necessary to verify identity, authority and the scope of the request.

Telephone +254 111 003 400
Location China Centre, Ngong Road, Nairobi

Public policy note

This public page provides general information about Luton Hospital’s data protection approach. It does not replace any specific privacy notice, patient consent form, clinical confidentiality duty, employment notice or legal obligation applicable to a particular service.

Download the full Data Protection Policy

The PDF version is stored in public/uploads/policies/data-protection-policy.pdf. Use the open button to confirm the file is reachable, and the download route to force download.