Policy

Data Protection Policy

Lawful, fair and secure processing of patient and staff personal data in general practice

For GP SurgeryRef BS-GP-POL-003See a sample (PDF) →
£54.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This policy is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Policy statement
  • 4. Definitions
  • 5. Data protection principles
  • 6. Lawful bases for processing
  • 7. Confidentiality and the Caldicott Principles
  • 8. Transparency and the privacy notice
  • 9. National data opt-out
  • 10. Data sharing and processors
  • 11. Data protection by design and Data Protection Impact Assessments
  • 12. Individual rights and subject access requests
  • 13. Information security
  • 14. Retention and secure disposal
  • 15. Personal data breach management
  • 16. Roles and responsibilities
  • 17. Training
  • 18. Records, monitoring and audit
  • 19. Related documents
  • 20. Version control and review
  • Appendix A: Subject Access Request log
  • Appendix B: Data protection self-audit checklist
  • 21. Disclaimer

Legislation & standards it maps to

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Data (Use and Access) Act 2025
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 17 (Good governance)
  • Common Law Duty of Confidentiality
  • Caldicott Principles (UK Caldicott Guardian Council)
  • Data Security and Protection Toolkit (DSPT)
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • Access to Health Records Act 1990
  • National Health Service Act 2006

Who it applies to

All partners, salaried GPs, locums, nursing and clinical staff, practice management, administrative and reception staff, attached/visiting staff, students, volunteers, contractors and data processors acting on behalf of [Organisation Name].

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Access to Health Records Act 1990
The law that governs who may see the health records of a person who has died.
Adequacy decision
A formal finding that a country outside the United Kingdom protects personal data well enough for data to be sent there safely.
Anonymised data
Information from which all details that could identify a person have been removed, so it can no longer be linked back to them.
Article 28 contract
A written contract required by data-protection law that sets out how a third party must handle personal data it processes on an organisation's behalf.
Caldicott Guardian
The senior person responsible for protecting the confidentiality of people's health and care information and enabling appropriate sharing.
Caldicott Principles
A set of eight principles that guide the safe and appropriate use of confidential patient information.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Closed-circuit television (CCTV)
A camera and recording system used to monitor premises for safety and security.
Commissioning Support Unit (CSU)
An organisation that provides shared services, such as data-protection support, to local health bodies.
Common law duty of confidentiality
A long-standing legal duty to keep information given in confidence private and to use it only for proper purposes.
Confidential patient information (CPI)
Information that identifies a patient and is held under a duty of confidence.
Data controller
The organisation that decides why and how personal data is processed and is legally responsible for it.
Data Protection Act 2018
The United Kingdom law that sits alongside the UK GDPR and sets the national rules for handling personal data.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Protection Officer (DPO)
The appointed expert who advises an organisation on data protection, monitors compliance and acts as a contact point for individuals and the regulator.
Data processor
A third party that handles personal data on behalf of, and under the instructions of, the data controller.
Data subject
The living individual that personal data is about.
Data (Use and Access) Act 2025
Recent United Kingdom legislation that updates how personal data and digital information may be used and accessed.
Data Security and Protection Toolkit (DSPT)
An online self-assessment that health and care organisations complete each year to show they handle personal data and protect systems securely.
Data Security Awareness (Level 1)
The basic annual data-security and information-governance training that all health and care staff are expected to complete.
Encryption
Scrambling information so that only someone with the correct key can read it, keeping it safe if a device is lost or intercepted.
EMIS Web
A widely used clinical record system for general practice (named here only as an example).
General Medical Council (GMC)
The body that registers and regulates doctors in the United Kingdom.
GP Connect
A service that lets authorised health and care staff view and share a patient's general practice record to support their care.
Information Commissioner's Office (ICO)
The United Kingdom regulator responsible for upholding data-protection and information rights.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Information sharing agreement
A written agreement between organisations setting out what data they will share, why and how it will be protected.
Integrated Care Board
The local statutory body responsible for planning and arranging publicly funded health services in an area.
International Data Transfer Agreement
A standard contract that allows personal data to be sent outside the United Kingdom while keeping it protected.
Lasting power of attorney
A legal arrangement that lets a person appoint someone to make decisions on their behalf if they are unable to.
Lawful basis
The specific legal reason, set out in data-protection law, that an organisation must have before it can process personal data.
Lloyd George envelope
The traditional folder used to store a patient's paper general practice records.
Multi-factor authentication
A security method that requires two or more proofs of identity, such as a password plus a code, before access is granted.
National Data Opt-Out
A national choice that lets patients stop their confidential information being used for purposes beyond their own care, such as research and planning.
National Health Service Act 2006
The Act of Parliament that provides the legal framework for the health service in England, including the rules on using confidential patient information.
Notifiable breach
A personal data breach serious enough that the law requires it to be reported to the regulator.
Nursing and Midwifery Council (NMC)
The body that registers and regulates nurses and midwives in the United Kingdom.
Personal data
Any information that relates to a living person who can be identified from it.
Personal data breach
A security incident that leads to personal data being lost, stolen, destroyed, altered or disclosed without authorisation.
Phishing
A scam in which fraudulent messages try to trick people into revealing passwords, data or money.
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
The rules that govern marketing and other communications sent by electronic means such as email, text and telephone.
Privacy notice
A public statement explaining what personal data an organisation collects, why, and what rights people have over it.
Quality and Outcomes Framework (QOF)
A voluntary scheme that rewards general practices for the quality of care they provide against agreed measures.
Ransomware
Malicious software that locks or encrypts an organisation's data until a ransom is paid.
Record of Processing Activities (ROPA)
A documented register of all the ways an organisation uses personal data, which data-protection law requires it to keep.
Records Management Code of Practice
National guidance setting out how long health and care records should be kept and how they should be managed and disposed of.
Redaction
Blacking out or removing parts of a document so that certain information cannot be read.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulation 17 (Good governance)
The part of the care regulations requiring providers to have effective systems for running the service safely, including good record-keeping.
Senior Information Risk Owner (SIRO)
The senior leader accountable for managing the organisation's information risk.
Serious harm test
The check used to decide whether releasing health information could seriously harm a person's physical or mental health, in which case it may be withheld.
Shared Care Record
A local system that brings together a person's records from different health and care organisations to support their care.
Single assessment framework
The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
Smartcard
A secure card used to log in to clinical systems and confirm a staff member's identity and access rights.
Special category data
Particularly sensitive personal data, such as health, genetic or biometric information, that needs extra protection in law.
Subject Access Request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
SystmOne
A widely used clinical record system for general practice (named here only as an example).
UK General Data Protection Regulation (UK GDPR)
The United Kingdom's main data-protection law governing how personal information is collected and used.
Unique patient identifier
The individual number used to identify a patient correctly across health and care services.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyComplaints Handling Policy£54.99
PolicyConsent & Confidentiality Policy£54.99
PolicyEquality & Diversity Policy£54.99
PolicyFire Safety Policy£54.99

Need the whole set?

Buy the full GP Surgery pack and save versus buying documents individually.

View the GP Surgery pack