Policy

Data Protection Policy

Lawful, secure and transparent processing of personal and special category data across remote clinical services

For Telehealth & Online ClinicRef BS-TEL-POL-004See a sample (PDF) →
£54.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This policy is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Policy statement
  • 4. Definitions
  • 5. Data protection principles
  • 6. Lawful basis and consent in a remote clinical setting
  • 7. Privacy by design and Data Protection Impact Assessments
  • 8. Security of processing
  • 9. Data sharing, processors and international transfers
  • 10. Individual rights
  • 11. Personal data breach management
  • 12. Roles and responsibilities
  • 13. Training and awareness
  • 14. Records, monitoring and audit
  • 15. Related documents
  • 16. Version control and review
  • 17. Appendix A - Remote Consultation Data Protection Checklist
  • 18. Appendix B - Personal Data Breach Report Form
  • 19. Disclaimer

Legislation & standards it maps to

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - Regulation 17 (Good governance)
  • Care Quality Commission (Registration) Regulations 2009
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • Common Law Duty of Confidentiality
  • Computer Misuse Act 1990
  • Network and Information Systems Regulations 2018 (NIS Regulations)

Who it applies to

All employees, directors, registered managers, clinicians (doctors, nurses, prescribers, allied health professionals), bank and locum staff, administrative and customer-support staff, IT and platform engineers, contractors, volunteers and data processors acting on behalf of [Organisation Name].

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Age Appropriate Design Code (Children's Code)
A statutory code of practice setting out how online services should protect children's personal data.
Article 28 contract
A written data-processing contract required by data-protection law before a third party may handle personal data on an organisation's behalf.
Caldicott Guardian
The senior person responsible for protecting the confidentiality of people's health and care information and enabling appropriate sharing.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Common Law Duty of Confidentiality
A long-standing legal duty, developed by the courts, to keep information shared in confidence private and use it only for the purpose it was given.
Computer Misuse Act 1990
The law that makes unauthorised access to, or interference with, computer systems and data a criminal offence.
Contemporaneous records
Notes made at the time of, or as soon as possible after, the event they describe.
Cyber Essentials Plus
A government-backed certification that independently tests an organisation's defences against common cyber attacks.
Data controller
The organisation that decides why and how personal data is processed.
Data minimisation
The principle of collecting and keeping only the personal data that is actually needed for the purpose.
Data processor
A third party that processes personal data on the controller's behalf and on its documented instructions.
Data Protection Act 2018
The United Kingdom law that sits alongside the UK GDPR and governs how personal data is used.
Data Protection Impact Assessment (DPIA)
A check done before a new or high-risk activity to identify and reduce risks to people's personal data.
Data Protection Officer (DPO)
The independent person who advises an organisation on data-protection law and monitors its compliance.
Data Security and Protection Toolkit
An online self-assessment tool that health and care organisations use to show they handle personal information safely.
Data subject
The living individual that personal data is about.
Duty of candour
The legal duty to be open and honest with a person and their family when something goes wrong with their care.
Electronic patient record (EPR)
The digital system that stores a patient's clinical and personal information.
Encryption
Scrambling data so that only someone with the right key can read it.
Explicit consent
A clear, specific and unambiguous agreement to a particular use of personal data, required for sensitive (special category) data.
General Medical Council (GMC)
The body that registers and regulates doctors in the United Kingdom.
General practitioner (GP)
A doctor who provides general medical care in the community and usually holds a patient's main medical record.
Gillick competence
A test of whether a child under 16 has enough understanding to consent to their own treatment without a parent.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting out the fundamental standards that registered care providers must meet, enforced by the Care Quality Commission.
Information Commissioner's Office (ICO)
The United Kingdom regulator that enforces data-protection and information-rights law.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
International Data Transfer Agreement (IDTA)
A standard contract that lawfully covers transfers of personal data from the United Kingdom to another country.
Lawful basis
One of the specific legal grounds in data-protection law that must apply before personal data can be processed.
Multi-factor authentication
A login method that requires two or more proofs of identity, such as a password plus a code sent to a phone.
Near miss
An event that could have caused harm but did not, by chance or because it was caught in time.
Network and Information Systems Regulations 2018 (NIS Regulations)
The law setting cyber-security and incident-reporting duties for operators of essential and certain digital services.
Personal data
Any information that relates to an identified or identifiable living person.
Personal data breach
A security failure that leads to personal data being lost, destroyed, altered, disclosed or accessed without authorisation.
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
The law governing electronic marketing, cookies and the privacy of electronic communications.
Privacy by design and by default
Building data-protection safeguards into a service from the outset and as the standard setting.
Privacy notice
A clear statement telling people how their personal data is collected and used.
Record of Processing Activities (ROPA)
A written record of the personal data an organisation holds, why it holds it and who it is shared with.
Records Management Code of Practice
Official guidance on how long health and care records should be kept and how they should be managed.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Retention schedule
A documented timetable setting out how long each type of record is kept before secure disposal.
Role-based access control
Restricting access to information based on a person's job role and what they need to see.
Safeguarding
Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
Senior Information Risk Owner (SIRO)
The senior person accountable for managing information risk across an organisation.
Special category data
Particularly sensitive personal data, such as health, sex life, ethnicity or religious beliefs, that needs extra protection.
Standard Contractual Clauses
Approved standard contract terms used to lawfully transfer personal data to another country.
Subject access request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
Transport Layer Security (TLS)
A widely used method of encrypting data as it travels across the internet.
Triage
The process of assessing and prioritising patients according to the urgency and nature of their needs.
UK General Data Protection Regulation (UK GDPR)
The United Kingdom's main data-protection law governing how personal information is collected and used.
Virtual private network (VPN)
A secure, encrypted connection that protects data sent over a public or untrusted network.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyTelehealth Consent Policy£54.99
PolicyCybersecurity Policy£54.99
PolicyRemote Assessment Policy£54.99
PolicyEmergency Response Policy£54.99

Need the whole set?

Buy the full Telehealth & Online Clinic pack and save versus buying documents individually.

View the Telehealth & Online Clinic pack