What is GDPR?
GDPR stands for General Data Protection Regulations and is a new piece of legislation that will supersede the Data Protection Act. It will not only apply to the UK and EU; it covers anywhere in the world in which data about EU citizens is processed.
The GDPR is similar to the Data Protection Act (DPA) 1998 (which the practice already complies with), but strengthens many of the DPA’s principles. The main changes are:
Practices must comply with subject access requests
Where we needs your consent to process data, this consent must be freely given, specific, informed and unambiguous
There are new, special protections for patient data
The Information Commissioner’s Office must be notified within 72 hours of a data breach
Higher fines for data breaches – up to 20 million euros
What is ‘patient data’?
Patient data is information that relates to a single person, such as his/her diagnosis, name, age, earlier medical history etc.
What is consent?
Consent is permission from a patient – an individual’s consent is defined as “any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed.”
The changes in GDPR mean that we must get explicit permission from patients when using their data. This is to protect your right to privacy, and we may ask you to provide consent to do certain things, like contact you or record certain information about you for your clinical records.
Individuals also have the right to withdraw their consent at any time.
How we use your information
- We collect and hold data about you for the purpose of providing safe and effective healthcare
- Your information may be shared with our partner organisations to audit services and help provide you with better care
- Information sharing is subject to strict agreements on how it is used
- We will only share your information outside of our partner organisations with your consent*
- If you are happy with how we use your information you do not need to do anything
- If you do not want your information to be used for any purpose beyond providing your care please let us know so we can code your record appropriately
- You can object to sharing information with other health care providers but if this limits your treatment options we will tell you
- Our guiding principle is that we are holding your information in the strictest confidence
- For more information about who are our partner organisations and how your data is used please see the privacy notice on our website or ask at reception.
GDPR Patient Information Leaflet
Fair processing privacy notice
Data Protection Policy
Information Commissioner's Certificate 2019
To download a Subject Access Request Form please click on the link below and return to the surgery along with photo ID and proof of address.
Subject Access Request Application Form