Policy

Data Protection Policy

Lawful, fair and secure processing of personal and special category data within an independent ADHD assessment and treatment service

For ADHD ClinicRef BS-ADH-POL-005See a sample (PDF) →
£54.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This policy is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Policy statement
  • 4. Definitions
  • 5. Data protection principles
  • 6. Confidentiality and information sharing
  • 7. Data security and access controls
  • 8. Individual rights and subject access requests
  • 9. Data Protection Impact Assessments (DPIAs)
  • 10. Personal data breaches
  • 11. Retention and secure disposal
  • 12. Roles and responsibilities
  • 13. Training
  • 14. Records, monitoring and audit
  • 15. Related documents
  • 16. Version control and review
  • Appendix A: Data breach reporting checklist
  • Appendix B: Subject access request log (template)
  • 17. Disclaimer

Legislation & standards it maps to

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Data (Use and Access) Act 2025
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (Regulation 17 Good governance)
  • Care Quality Commission (Registration) Regulations 2009
  • Common law duty of confidentiality
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • Caldicott Principles (National Data Guardian) and the Records Management Code of Practice 2023

Who it applies to

All directors, employees, bank and locum clinicians, prescribers, administrative and reception staff, students, volunteers, contractors and data processors acting on behalf of [Organisation Name]

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

ADHD (Attention Deficit Hyperactivity Disorder)
A neurodevelopmental condition affecting attention, activity levels and impulse control.
Article 28 (processor contract)
The part of data-protection law that says a written contract must be in place whenever one organisation processes personal data on another's behalf.
Article 6 lawful basis
One of the legally recognised reasons an organisation must have before it may use any personal data.
Article 9 condition
An extra legal reason required, on top of an Article 6 basis, before sensitive data such as health information may be used.
Caldicott Guardian
The senior person responsible for protecting the confidentiality of people's health and care information.
Caldicott Principles
A set of national rules guiding when and how confidential patient information may be used and shared.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Cold chain
Keeping vaccines and certain medicines within a safe temperature range from delivery to use.
Common law duty of confidentiality
The long-standing legal duty to keep information given in confidence private and to share it only with good reason.
Comorbidity
An additional health condition a person has alongside their main diagnosis, such as anxiety or autism alongside ADHD.
Controlled drug
A medicine whose supply, storage and records are tightly restricted by law because of its potential for misuse.
Data controller
The organisation that decides why and how personal data is collected and used.
Data processor
A third party that handles personal data on a controller's behalf, following the controller's written instructions.
Data Protection Act 2018
The UK law that sits alongside the UK GDPR and sets additional national data-protection rules.
Data Protection by design and by default
Building privacy and data protection into systems and services from the outset, rather than adding it later.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Protection Officer (DPO)
The named person who oversees an organisation's compliance with data-protection law and advises on it.
Data subject
The living individual that a piece of personal data is about.
Data (Use and Access) Act 2025
A UK law that updates and adds to existing data-protection rules.
Data Security and Protection Toolkit (DSPT)
An annual online self-assessment that shows an organisation handles personal and health data safely.
Driver and Vehicle Licensing Agency (DVLA)
The government body responsible for driver licensing, which must be told about medical conditions that may affect driving.
Electronic patient record (EPR)
The digital clinical record holding a patient's assessments, treatment and notes.
Electronic Prescription Service
A system that sends prescriptions electronically from a prescriber to a dispensing pharmacy.
General Dental Council (GDC)
The body that registers and regulates dental professionals in the UK.
General Medical Council (GMC)
The body that registers and regulates doctors in the UK.
General Pharmaceutical Council (GPhC)
The body that registers and regulates pharmacists and pharmacy technicians in the UK.
General practitioner (GP)
A doctor who provides general medical care in the community and often coordinates a patient's overall care.
Gillick competence
The test of whether a child is mature enough to understand and consent to their own treatment without a parent.
Health and Care Professions Council (HCPC)
The body that registers and regulates a range of health and care professionals in the UK.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting the fundamental standards that registered care providers must meet.
Information Commissioner's Office (ICO)
The UK regulator that enforces data-protection and information-rights law.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Multi-factor authentication
A login method that requires two or more proofs of identity, such as a password plus a code, for added security.
National Data Guardian
The independent national champion for keeping people's health and care data safe and used appropriately.
Nominated Individual
The senior person responsible to the regulator for supervising how a service is provided.
Personal data
Any information that identifies, or could identify, a living person.
Personal data breach
A security failure that leads to personal data being lost, stolen, altered or wrongly disclosed or accessed.
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
The law governing electronic marketing, cookies and the privacy of electronic communications.
Processing
Any action taken with personal data, from collecting and storing it to sharing or deleting it.
Record of Processing Activities (ROPA)
A written record of what personal data an organisation holds, why, and how it is used and shared.
Records Management Code of Practice 2023
National guidance on how long health and care records should be kept and how they should be managed.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulation 17 (Good governance)
The standard requiring providers to run their service well, including keeping accurate, secure records.
Single assessment framework
The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
Safeguarding
Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
Senior Information Risk Owner (SIRO)
The senior person who owns an organisation's information-risk decisions and accepts any remaining risk.
Special category data
Particularly sensitive personal data, such as health, genetic or biometric information, that needs extra protection.
Subject Access Request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
Telehealth
Providing clinical care remotely using video, phone or other technology rather than in person.
Titration
The careful process of starting a medicine at a low dose and adjusting it to find the most effective, safe level.
UK General Data Protection Regulation (UK GDPR)
The UK's main data-protection law governing how personal information is collected and used.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyADHD Assessment Policy£54.99
PolicyMedication Management Policy£54.99
PolicySafeguarding Children Policy£54.99
PolicyConsent & Capacity Policy£54.99

Need the whole set?

Buy the full ADHD Clinic pack and save versus buying documents individually.

View the ADHD Clinic pack