Privacy Policy

Royal College of Pharmacy (RCPharm)

v01.0

Last updated 15th April 2026

Introduction

The Royal College of Pharmacy (RCPharm) (“we”, “our”, “us”) is the controller of personal data obtained via our website and associated platforms. We comply with UK GDPR and the Digital United Adequacy Act 2025 (DUAA).

Children under 18 are not the target audience of our services.

What This Policy Applies To

– Public website (www.rcpharm.org)

– Member‑only sections

– RCPharm‑operated apps/platforms

– Third‑party platforms supporting membership, learning, assessments, events, recruitment, and professional networks

– All data processing carried out by our subsidiary organisation Royal College of Pharmacy Enterprises Limited (a limited company which delivers some commercial functions for the College, such as events administration and processing insurance products for our members)

Personal Data We Collect About You

The personal data we collect depends on the services you use. The table below sets out each category and its typical retention.

CategoryTypes of Data IncludedRetention Period
Identity DataNames, titles, membership numbers; optional equality and diversity data (only with consent)Duration of membership + 4 years; up to 40 years for assessment‑related identity data
Contact DataPostal address, email address, telephone numbersMembership duration + 4 years; +1 year after an assessment
Financial DataBank and card details (handled by third‑party processors)6 years after transaction
Transaction DataPayments, orders, services purchased6 years after transaction
Technical DataIP address, login data, browser type/version, device information28 days (cookies per cookie policy)
Profile DataUsernames, passwords, CPD entries, preferences, survey responsesMembership duration + 4 years
Pharmacist DataPractice sector, employer, GPhC registration & renewal details, credentialed statusMembership duration + 4 years; credential lists updated annually
Professional HistoryInsurance claims, Fitness‑to‑Practise investigationsMembership duration + 4 years
Assessment DataResults, candidate numbers, portfolio materialsResults up to 40 years; other assessment material 1 year
Recruitment DataApplications, special category data6 months after job closing date
Usage DataWebsite/app usage patternsMembership duration + 4 years; other usage logs anonymised after 28 days
Marketing & Communications DataCommunication and marketing preferencesMembership duration + 4 years
Video & Audio DataRecordings from meetings or eventsUp to 2 years

How Your Personal Data Is Collected

We collect data directly from you, indirectly via our systems, and from trusted third parties. The table below summarises the principal collection methods.

Category of DataCollection Method
Identity, Contact, Profile, PharmacistDirect entry on membership application forms and/or online user profiles
Identity, Contact, Profile, Pharmacist, Recruitment, Transaction, FinancialDirect interactions such as registering a profile, filling in forms, entering a contract, or corresponding by post/phone/email (e.g., purchase membership, book events, engage with interactive features, complete surveys, become a speaker/outworker)
IdentityInternal authentication from your existing RCPharm membership account verifies membership status
Identity & Contact, PharmacistIf nominated as a collaborator/peer in E‑portfolio/MyPortfolio by a Member/Registered User, your email is provided by the nominator; if you decline, we delete this data
Identity, PharmacistAuthentication with the General Pharmaceutical Council (GPhC) to check your registration number
Contact, Financial, TransactionThird‑party providers of technical, payment, and delivery services
Technical, UsageAutomated technologies such as cookies, server logs, analytics; may involve analytics providers, search information providers, and troubleshooting services
Marketing & CommunicationsDirect interactions when you opt in/out of marketing through your account settings or unsubscribe links
Identity, Contact, Pharmacist, Marketing & CommunicationsWhen you respond to lead advertising on our social media partner platforms (e.g., Facebook/Instagram)
Special Category (incl. video/audio)Direct interactions: completing surveys; registering for assessments; consenting to recording during online meetings/events; submitting job applications via our recruitment module

How and Why We Use Your Personal Data

We only process personal data where we have a lawful basis. The table below explains what we use your personal data for and the relevant legal basis.

Purpose/ActivityType of DataLawful Basis (including legitimate interests)
Register you as a new member or registered userIdentity; ContactPerformance of a contract
Process and deliver orders for events/products; manage payments, fees, and charges; collect and recover money owed; perform Direct Debit credit reference checks (via Braintree/Stripe/Worldpay)Identity; Contact; Financial; Transaction; Marketing & CommunicationsContract; Legitimate interests (recover debts)
Carry out obligations arising from our contractual relationship (membership services, elections, member database entry, membership changes)Identity; Contact; Financial; Professional History; Special Category (where relevant)Contract; Consent (where special category data is involved)
Notify third‑party organisations (e.g., NICE/HEE/NES) of pre‑registration membersIdentity; ContactContract; Legitimate interests (education and development of the profession)
Manage our relationship with you (policy/terms updates; reviews/surveys; event information and feedback)Identity; Contact; Profile; Marketing & CommunicationsContract; Legal obligation; Legitimate interests (keeping records up to date; service analysis)
Enable you to plan, record and enter CPD records on MyCPD Portfolio; prize draws/competitions; surveysIdentity; Contact; Profile; Usage; Marketing & Communications; Special CategoryContract; Legitimate interests (service development; equal opportunities monitoring)
Manage and administer assessments that you apply for or act as assessorIdentity; Contact; Assessment; Special CategoryContract (delivery of assessment); Legitimate interests (conduct fair/high‑quality assessments); Consent; Legal obligation
Collate and analyse responses to professional standards consultations; follow up on case studies supporting standards/advocacyIdentity; Contact; PharmacistLegitimate interests (represent the profession; promote excellence); Consent
Administer and protect our business and website (troubleshooting, data analysis, testing, system maintenance, support, reporting, hosting)Identity; Contact; TechnicalLegitimate interests (running our business; IT services; network security; fraud prevention; reorganisation); Legal obligation
Deliver relevant website content/advertisements and measure effectivenessIdentity; Contact; Profile; Usage; Marketing & Communications; TechnicalLegitimate interests (service development; business growth; marketing insight)
Use data analytics to improve our website, products/services, marketing, customer relationships and experiencesTechnical; UsageLegitimate interests (define customer types; keep site updated and relevant; develop business; inform marketing)
Make suggestions and recommendations about goods or services that may interest youIdentity; Contact; Technical; Usage; ProfileLegitimate interests (develop products/services; grow our business)
Process your application for a jobIdentity; Contact; Recruitment; Special CategoryLegitimate interests (recruitment); Legal obligation (employment law); Consent (special category)
Administer our Consultant Pharmacist List (credentialing)Identity; Contact; PharmacistLegitimate interests (maintain integrity of the profession)
Send you information about RCPharm products and services based on your membershipIdentity; Contact; Technical; Usage; ProfileLegitimate interests (grow our business)
Enable participation in recorded meetings/events; publish recordings of governance meetingsVideo data; Special CategoryConsent (participants); Contract (performers)
Process your nomination for a fellowshipIdentity; Contact; Professional HistoryContract (membership management); Consent

Special Category Personal Data

We process special category data only where necessary and lawful, including:

– Equality and diversity monitoring

– Disability accommodations during assessments

– Video/audio recordings during events

Where required, we obtain explicit consent, which you may withdraw at any time.

Marketing

We may contact you about RCPharm events, services, or updates. You can opt out via unsubscribe links, STOP codes, your preference‑centre settings, or by contacting us directly. We do not sell your data to third parties for their marketing.

Who We Share Your Personal Data With

We share data with trusted third‑party processors who support our operations (see Annex). All vendors enter into DUAA‑compliant data processing terms and are subject to appropriate technical and organisational measures.

International Transfers Under DUAA 2025

We only transfer data internationally if:

– The destination is subject to a DUAA Adequacy Regulation; or

– DUAA‑approved Standard Data Protection Clauses apply; or

– A DUAA‑recognised exception is met.

We conduct ongoing DUAA‑compliant adequacy assessments and will update this policy if transfer mechanisms change.

Cookies

See our cookie policy.

Your Rights

You may request: access, correction, erasure, restriction, portability, objection (including marketing), and withdrawal of consent by contacting our data protection officer (details shown at the bottom of this policy).

Keeping Your Data Secure

We use robust technical and organisational controls (encryption, access controls, security audits, breach‑response procedures). Unauthorised AI‑based transcription or monitoring tools are prohibited on RCPharm systems.

Data Retention

We only retain data in line with the retention periods shown in the table above (in the “Personal Data We Collect About You” section).

Changes to this Policy

We may update this policy. Significant updates will be communicated on our website or directly by email where appropriate.

How to Contact Us

Royal College of Pharmacy (RCPharm)

Email: [email protected]

Phone: 0207 572 2737

Data Protection Officer: Calvin Smith

Email: [email protected]

Phone: 0207 572 2402

ICO: https://ico.org.uk/make-a-complaint

Annex: Third‑Party Data Processors
Third‑PartyPurposeLocation
AccessRecruitment module servicesEU
Amazon Web ServicesHostingIreland & US
AonMembership servicesUK
AventriEvent booking systemUS
Axia DigitalE‑portfolioUK
Box.comCloud storageUS
BraintreePayment processingUS
Brightspace / D2LLearning platformCanada
CantarusWebsite development/hostingEU
Centre for Pharmacy Postgraduate EducationTraining programmesUK
ChrysalisMarket researchUK
Course MerchantCatalogue managementUK
CrazyEggWebsite analyticsUS
CrowdcompassMembership service supportUK
DotdigitalMailing servicesEU (with global sub‑processors)
ETC VenuesEvent hostingUK
Fusion InsightMarket researchUK
Google AnalyticsAnalyticsUS
Google AdsAdvertisingUS
GB GroupIdentity verificationEU
Hall & PartnersTelemarketingUK
HEIWEducation validationWales, UK
HMRCGovernment/regulatorUK
JIRA/AtlassianSupport ticketingUS
M+F HealthPR servicesUK
MHRARegistration validationUK
Meta (Facebook/Instagram)AdvertisingUS
MicrosoftVideo/meeting servicesUS
Monday.comProject managementUS
NICEEducation and trainingUK
Mi‑VoiceElectionsUK
NHS England / NES / HEIWTraining programmesEngland/Scotland/Wales
OneTrustCookie managementUS
OracleData storage servicesUS
PageLizardMyCPD appUK
PerformLearnDevelopMentoring platformUK
ReedwordsCopywritingUK
RestreamStreamingUS
SalesforceCRM/data storageUS
SendGridEmail deliveryUS
SurveyMonkeySurvey platformUS
StripePayment processingUS
Tray.ioMarketing integrationsUS
TUG LtdAnalytics consultancyUK
University of CardiffAssessment submissionsUK
University of East AngliaTraining programmesUK
University of SunderlandTraining programmesUK
WDMMailing houseUK
WebexWebinar servicesUS
WorldPayPayment processingUS
ZendeskSupport servicesUS
ZoomWebinarsUS