Policy

Information Governance / Data Protection Policy

The internal governance, clinical record-keeping, data-security, retention, rights-handling and breach-management backbone for the safe and lawful handling of patient and business information

For Aesthetic ClinicRef BS-AES-POL-016See a sample (PDF) →
£54.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This policy is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Policy statement and principles
  • 4. Definitions
  • 5. Information governance accountability
  • 6. Clinical record-keeping standards
  • 7. Information asset register and risk assessment
  • 8. Data-security controls
  • 9. Confidentiality, transfer and sharing of information
  • 10. Retention and secure destruction
  • 11. Individual rights and subject access requests
  • 12. Personal data breach management
  • 13. Data Security and Protection Toolkit
  • 14. Roles and responsibilities
  • 15. Training, awareness and confidentiality
  • 16. Monitoring, audit and compliance
  • 17. Related policies and documents
  • 18. Review and version control
  • 19. Disclaimer

Legislation & standards it maps to

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • The common-law duty of confidentiality
  • The Caldicott Principles (National Data Guardian, 2020)
  • Records Management Code of Practice (2021)
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - Regulation 17 (Good governance)
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - Regulation 20 (Duty of candour)
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • Computer Misuse Act 1990
  • Freedom of Information Act 2000 (where the organisation holds information on behalf of a public authority)

Who it applies to

All registered managers, prescribers, practitioners (medical, nursing, dental and non-medical injectors), reception and administrative staff, clinical support staff, locums, students, volunteers, contractors and data processors acting for [Organisation Name]

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Article 28 contract
A written agreement required by data-protection law whenever one organisation processes personal data on another's behalf, setting out how the data must be protected.
Caldicott Guardian
The senior person responsible for protecting the confidentiality of people's health and care information.
Caldicott Principles
A set of standards that guide when and how confidential patient information may be used and shared.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Common-law duty of confidentiality
The long-standing legal duty to keep information that someone shares in confidence, such as patient details, private.
Computer Misuse Act 1990
The law that makes it a criminal offence to access or interfere with computer systems or data without authorisation.
Confidential information
Information given in circumstances where the person providing it reasonably expects it to be kept private, including all patient clinical information.
Contemporaneous record
A note made at the time of an event, or as soon as possible afterwards, so it is accurate and reliable.
Contraindication
A reason why a particular treatment should not be given to a specific person because it could be harmful.
Controller
The organisation that decides why and how personal data is processed and is legally responsible for it.
Data processing agreement
A written contract that sets out the rules a supplier must follow when handling personal data for the organisation.
Data Protection Act 2018
The UK law that sits alongside the UK GDPR and governs how personal information must be handled.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Security and Protection Toolkit (DSPT)
An annual online self-assessment that shows an organisation is meeting recognised data-security and confidentiality standards.
Disclosure and Barring Service (DBS) check
A criminal-records check showing whether a person is suitable to work with patients or vulnerable people.
Duty of candour
The legal duty to be open and honest with a person and their family when something goes wrong with their care.
Encryption
Scrambling data so it can only be read by someone with the correct key or password, protecting it if a device is lost or stolen.
Freedom of Information Act 2000
The law giving people the right to ask public authorities for recorded information they hold.
General practitioner (GP)
A doctor who provides general medical care in the community and is often the patient's main point of contact for health.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting the fundamental standards that registered health and care providers must meet, enforced by the Care Quality Commission.
Information asset
An identifiable body of information, and the system that holds it, that has value to the organisation, such as a patient-records system.
Information asset register
A list of an organisation's key information and systems, recording what data they hold, where it is kept and who is responsible for it.
Information Commissioner's Office (ICO)
The UK's independent authority that upholds information rights and enforces data-protection law.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Informed consent
Agreement to treatment given freely after the risks, benefits and alternatives have been clearly explained.
International Data Transfer Agreement
A standard contract that allows personal data to be sent outside the UK while keeping it properly protected.
Lawful basis
One of the legally recognised reasons an organisation must have before it may use someone's personal data.
Least privilege
The security rule of giving each person access only to the information and systems they genuinely need for their job.
Locum
A practitioner who works temporarily to cover for another, for example during absence or to meet demand.
Multi-factor authentication (MFA)
A login method that requires more than one proof of identity, such as a password plus a code sent to a phone.
National Data Guardian
The independent adviser who champions the safe and appropriate use of people's health and care information in England.
Need-to-know basis
The principle that confidential information is shared only with people who require it to do their job or care for the patient.
Nominated Individual
The senior person responsible to the regulator for supervising how a service is provided.
Personal data
Any information relating to an identified or identifiable living individual, such as a name, contact details or photograph.
Personal data breach
A security failure that leads to personal data being lost, stolen, destroyed, altered or disclosed without authorisation.
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
The rules covering electronic marketing, cookies and the privacy of electronic communications, sitting alongside data-protection law.
Processor
A third party that processes personal data on behalf of the controller, such as a cloud system provider or IT support firm.
Ransomware
Malicious software that locks or encrypts an organisation's data and demands payment to release it.
Records Management Code of Practice
National guidance on how health and care records should be created, kept and how long they should be retained.
Redaction
Blacking out or removing parts of a document, such as another person's details, before it is shared or released.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulation 17 (Good governance)
The fundamental standard requiring providers to run their service well, including keeping accurate, complete and secure records.
Retention schedule
A plan setting out how long each type of record is kept before it is securely destroyed.
Senior Information Risk Owner (SIRO)
A senior person with overall responsibility for managing the organisation's information risks.
Shared care record
A joined-up electronic record that lets approved health and care professionals see relevant information about a patient.
Single assessment framework
The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
Special category data
Sensitive personal data, such as information about health, that needs extra protection under data-protection law.
Subject access request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
Summary Care Record
An electronic summary of key patient information, such as medicines and allergies, that approved clinicians can view.
UK General Data Protection Regulation (UK GDPR)
The UK's main data-protection law governing how personal information is collected and used.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyAdverse Event Management Policy£54.99
PolicySafeguarding Policy£54.99
PolicyComplaints Policy£54.99
PolicyConsent & Risk Disclosure Policy£54.99

Need the whole set?

Buy the full Aesthetic Clinic pack and save versus buying documents individually.

View the Aesthetic Clinic pack