This practice complies with the Data Protection Act 1998 and this policy describes our procedures for ensuring that personal information about patients is processed fairly and lawfully. 

Personal data that we hold

We must keep comprehensive and accurate personal data about you to provide you with a high standard of appropriate dental care. We also need to process personal data about you to provide care under NHS arrangements and to ensure the proper management and administration of the NHS. 

The personal data that we hold includes: 

  1. Personal details such as your date of birth,NHS number,address, telephone number, email address and your general medical practitioner. 
  2. Your past and current medical and dental health. 
  3. Radiographs, clinical photographs and study models. 
  4. Information about the treatment that we have provided or propose to provide and its cost. 
  5. Notes of conversations about your care. 
  6. Records of consent to treatment. 
  7. Correspondence with other health care professionals relating to you, for example in the hospital or community services. 
Processing data

We will process this personal data in the following way: 

Retaining information

We will retain your dental records while you are a practice patient and after you cease to be a patient, for at least eleven years or, for children, until age of 25, whichever is the longer. 

Security of information

Personal data about you is held in the practice computer system and in some cases achieved paper records. The information is not accessible to the public; only authorised members of staff have access to it. Staff are trained yearly in their legal responsibilities under the Data Protection Act and practical procedures for maintaining confidentiality. 

We take precautions to keep the practice premises, filing systems and computers physically secure. Our computer system has secure audit trails and we back-up information daily. We use cloud computing facilities for the storage and processing of some of your data. The practice has a rigorous service level agreement with Just Tech, our cloud provider to ensure that all our obligations in this policy are fulfilled and that your information is secure. 

Disclosure of information

To provide proper and safe dental care, we may need to disclose personal information about you to: 

  1. Your general medical practitioner 
  2. The hospital or community dental services 
  3. Other health professionals caring for you 
  4. NHS payment authorities 
  5. HM Revenue and Customs 
  6. The Department for Work and Pensions and its agencies, where you are claiming exemption or remission from NHS charges 
  7. Private dental insurance schemes of which you are a member. 

Where possible, you will be informed of these requests for disclosure. 

Disclosure will take place on a ‘need-to-know’ basis. We will only provide information to individuals or organisations that need it to provide care to you or to ensure the proper administration of government (whose personnel are covered by strict confidentiality rules). We will only disclose information that the recipient needs to have. 

In limited circumstances or if required by law or a court order, personal data may be disclosed to a third party not connected with your health care. 

In all other situations, disclosure that is not covered by this Code of Practice will only occur when we have your specific consent. 

Access

You can have access to the data that we hold about you and receive a copy by submitting a written request. This request is free of charge however we may charge a reasonable fee when a request is excessive or repetitive. The fee will be based on the administrative cost of providing the information requested. We will provide the requested information (and an explanation if you require it) within 30 days of receiving your request. It may be necessary to extend this period by a further two months where requests are complex or numerous. We will inform you within one month of receipt of the request and explain why the extension is necessary. 

If you do not agree

If you do not wish personal data that we hold about you to be disclosed or used in the way that is described in this Code, you should discuss the matter with your dentist. You should be aware; however, that objecting to how we process your information may affect our ability to provide you with dental care. 

The Right to Erasure

The right to erasure is also known as ‘the right to be forgotten’. The right to erasure does not provide an absolute ‘right to be forgotten’. Individuals have a right to have personal data erased and to prevent processing in specific circumstances: 

  • Where the personal data is no longer necessary in relation to the purpose for which it was originally collected/processed.
  • When the individual withdraws consent.
  • When the individual objects to the processing and there is no overriding legitimate interest for continuing the processing.
  • The personal data was unlawfully processed (ie otherwise in breach of the GDPR).
  • The personal data has to be erased in order to comply with a legal obligation.
  • The personal data is processed in relation to the offer of information society services to a child.
    If the practice has shared your information with other health care professionals for example the hospital or community services we will inform these services with regard to the erasure of your data.

The practice can refuse a request for erasure where the personal data is processed for the following reasons:

  • to exercise the right of freedom of expression and information;
  • to comply with a legal obligation for the performance of a public interest task or exercise of official authority. 
  • for public health purposes in the public interest; 
  • archiving purposes in the public interest, scientific research historical research or statistical purposes; or 
  • the exercise or defence of legal claims. 
The Right to Erasure for Children’s Personal data

There are extra requirements when the request for erasure relates to children’s personal data, reflecting the GDPR emphasis on the enhanced protection of such information, especially in online environments. 

This practice processes the personal data of children; consent will be obtained where required. A child has the right to request erasure of their data at a later date (regardless of age at the time of the request), especially on social networking sites and internet forums. This is because a child may not have been fully aware of the risks involved in the processing at the time of consent.