Hi Mark
Nothing wrong with this but its not so easy nowadays, one has to declare intent, obtain consent and maintain security amongst other things.
There is no way around doing this correctly Mark if you are going to hold personal data, this applies to contact details -
you must remain GDPR Compiant , this is to ensure that information held by companies and organisations is properly safeguarded and customer privacy is protected. Any company that holds information on customers inside the EU will have to comply with the regulations.
A good start for obtaining data is here.
https://www.nhs.uk/ServiceDirectories/Pages/NHSTrustListing.aspxArticle 5 of the legislation requires that all currently held personal data be:
• Collected for a specific purpose and that purpose is made clear to all those whose data you hold.
• Data must not be used for any other purpose than for which you have sought permission.
• You should only hold as much data as you need to complete the task for which you are holding the data. (Any other data should be deleted.)
• All data must be accurate and kept up to date at all times. Inaccuracies must be rectified immediately and any rectifications shared with third parties to whom you have sold the data.
• You should only keep data for as long as is necessary to complete the task for which you have sought permission.
• Data should be securely stored and protected against unauthorised access.
Some good advice below
https://ico.org.uk/for-organisations/data-protection-advice-for-small-organisations/I hope this helps
Darren