Policy

Consent and Confidentiality Policy

Lawful consent, information governance and the protection of patient confidentiality within general practice

For GP SurgeryRef BS-GP-POL-002See a sample (PDF) →
£54.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This policy is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Policy statement
  • 4. Definitions
  • 5. Obtaining valid consent for care
  • 6. Capacity and best interests
  • 7. Children and young people
  • 8. Consent for intimate and chaperoned examinations
  • 9. The duty of confidentiality and lawful information sharing
  • 10. Practical confidentiality in the practice environment
  • 11. Patient rights and transparency
  • 12. Roles and responsibilities
  • 13. Training
  • 14. Records, monitoring and audit
  • 15. Related documents
  • 16. Version control and review
  • 17. Disclaimer
  • Appendix A: Consent and confidentiality consultation checklist
  • Appendix B: Staff confidentiality undertaking (template)

Legislation & standards it maps to

  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - Regulation 11 (Need for consent), Regulation 9 (Person-centred care), Regulation 10 (Dignity and respect), Regulation 17 (Good governance)
  • UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • Common law duty of confidentiality
  • Mental Capacity Act 2005 and its Code of Practice
  • Human Rights Act 1998 (Article 8)
  • Health and Care Act 2022 and the National Health Service Act 2006 (section 251)
  • Caldicott Principles (National Data Guardian) and the Data Security and Protection Toolkit (DSPT)
  • Access to Health Records Act 1990; Gillick competence and the Fraser guidelines (case law)

Who it applies to

All GPs, salaried and locum clinicians, nurses, healthcare assistants, practice managers, reception and administrative staff, attached and visiting professionals, students, trainees, contractors and volunteers working for or on behalf of [Organisation Name]

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Advance decision to refuse treatment
A legally binding statement made in advance by a person with capacity, setting out treatment they would refuse if they later lose capacity.
Best interests
A decision made for someone who cannot decide for themselves, choosing the option that is best for them.
Caldicott Guardian
The senior person responsible for protecting the confidentiality of people's health and care information and enabling appropriate sharing.
Caldicott Principles
A set of principles that guide how health and care organisations handle confidential patient information.
Capacity (mental capacity)
Whether a person can understand and make a particular decision for themselves at the time it needs to be made.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Chaperone
A trained person present during an intimate examination to support and protect the patient and the clinician.
Common law duty of confidentiality
The long-established legal duty, set by court decisions, to keep information given in confidence private.
Confidentiality Advisory Group
The independent body that advises on whether identifiable patient information may be used without consent for certain purposes.
Contemporaneous record
A note made at the time of, or very soon after, an event so it accurately reflects what happened.
Court-appointed deputy
A person appointed by the Court of Protection to make certain decisions for someone who lacks capacity.
Data Protection Act 2018
The UK law that sits alongside the UK GDPR and governs how personal information is used.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Protection Officer (DPO)
The person responsible for advising an organisation on data-protection law and monitoring its compliance.
Data Security and Protection Toolkit (DSPT)
An online self-assessment that health and care organisations complete each year to show they handle data safely.
De-identified data
Information from which details that could identify a person have been removed.
Direct care
The care and treatment provided to a patient by the team directly involved in looking after them.
Explicit (express) consent
Consent given clearly in spoken or written form, required for more significant interventions and most disclosures beyond the direct care team.
Fraser guidelines
Criteria for providing contraceptive and sexual health advice and treatment to a person under 16 without parental consent.
General Medical Council (GMC)
The body that registers doctors in the UK and sets the standards they must follow.
Gillick competence
Where a child under 16 has enough understanding and intelligence to consent to their own treatment.
Health and Care Act 2022
An Act that reformed how health and care services in England are organised and overseen.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting the fundamental standards that registered health and care providers must meet.
Human Rights Act 1998
The UK law that gives effect to basic rights, including (in Article 8) the right to respect for private and family life.
Implied consent
Consent reasonably inferred from a patient's actions in the context of their care, such as rolling up a sleeve for a blood-pressure check.
Independent Mental Capacity Advocate (IMCA)
A trained advocate appointed to represent and support a person who lacks capacity and has no one else to speak for them.
Information Commissioner's Office (ICO)
The UK regulator that upholds information rights and enforces data-protection law.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Informed consent
Agreement to treatment given freely after the risks, benefits and alternatives have been clearly explained.
Intimate examination
An examination of an intimate part of the body, such as the breasts, genitals or rectum, which a patient may find sensitive.
Lasting Power of Attorney (health and welfare)
A legal authority letting a chosen person make health and care decisions for someone if they lose capacity.
Lawful basis
One of the specific legal grounds that data-protection law requires before personal information can be used.
Least restrictive option
The choice that achieves what is needed while interfering as little as possible with a person's rights and freedom.
Mental Capacity Act 2005
The law that protects and supports people who may be unable to make particular decisions for themselves.
Montgomery standard
The legal standard requiring clinicians to tell patients about the material risks and reasonable alternatives of a treatment.
National Data Guardian
An independent adviser who champions the safe and trustworthy use of health and care information in England.
National Data Opt-out
A choice patients can register to stop their identifiable information being used for planning and research.
National Health Service Act 2006
The Act of Parliament that consolidates much of the law on publicly funded health services in England; section 251 allows identifiable patient information to be used without consent in defined circumstances.
Near miss
An event that could have caused harm but did not, by chance or because it was caught in time.
Notifiable disease
A specified infectious disease that, by law, must be reported to the authorities.
Parental responsibility
The legal rights and duties a parent or guardian has in relation to a child, including consenting to their treatment.
Personal confidential data (PCD)
Information that identifies a living individual and is held in confidence, including health information.
Privacy notice (fair processing notice)
A clear statement telling people how an organisation uses and shares their personal information.
Record of Processing Activities (ROPA)
A record an organisation keeps of the personal information it holds and how it uses it.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulated activity
A type of care or treatment the law requires a provider to register with the regulator to deliver.
Safe haven
An agreed secure location or method for receiving and handling confidential information so it is not seen by others.
Safeguarding
Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
Secondary uses
Uses of patient information beyond direct care, such as planning services, research or auditing quality.
Section 251 (support)
A legal route under the National Health Service Act 2006 allowing identifiable patient information to be used without consent where this is approved as necessary.
Senior Information Risk Owner (SIRO)
The senior person accountable for managing the risks to an organisation's information.
Single assessment framework
The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
Smartcard
A secure card used by staff to log in to clinical record systems and prove who they are.
Special category data
Sensitive personal information, such as health data, that the law protects more strictly.
Subject Access Request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
UK General Data Protection Regulation (UK GDPR)
The UK's main data-protection law governing how personal information is collected and used.
Valid consent
Agreement given voluntarily by an appropriately informed person who has the capacity to consent to the matter in question.
Venepuncture
Taking a blood sample by inserting a needle into a vein.
Virtual private network (VPN)
A secure, encrypted connection used to access systems and data safely over the internet.
Whistleblowing (speaking up)
Raising a concern about wrongdoing, risk or malpractice at work, protected by law.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyComplaints Handling Policy£54.99
PolicyData Protection Policy£54.99
PolicyEquality & Diversity Policy£54.99
PolicyFire Safety Policy£54.99

Need the whole set?

Buy the full GP Surgery pack and save versus buying documents individually.

View the GP Surgery pack