Data Protection Policy
Cheadle Dental Centre complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy describes our procedures for ensuring that personal information about patients is processed lawfully, fairly and transparently. We are the data controller for the information described here, and we are registered with the Information Commissioner's Office.
In order to provide you with a high standard of dental care and attention, we need to hold personal information about you. This personal data comprises:
- Personal details such as your name, age, address, telephone numbers, email address and your general medical practitioner;
- Date of your appointments;
- Details of any complaints you have made and how these were dealt with;
- Your past and current medical and dental condition;
- Radiographs, clinical photographs and study models;
- Information about the treatment we have provided or propose to provide (and its cost);
- Information about fees we have charged, the amounts you have paid and some payments details;
- Notes of conversations or incidents that might occur for which a record needs to be kept;
- Records of consent to treatment;
- Any correspondence (relating to you) with other healthcare professionals: such as referrals to specialists, for example.
We need to keep comprehensive and accurate personal data about our patients in order to provide them with safe and appropriate dental care. We also use this information for the legitimate interest of ensuring the quality of the treatment we provide.
Our lawful basis for holding your information
Your dental records include health information, which the UK GDPR treats as a special category of personal data. We rely on the following bases:
- Article 6(1)(c), to meet our legal obligations, and Article 6(1)(f), our legitimate interest in running the practice safely and effectively;
- Article 9(2)(h), the provision of health care and treatment by professionals bound by a duty of confidentiality;
- Your consent, where we ask for it separately, for example before we send you marketing or appointment reminders by a channel you have chosen.
Where we rely on your consent, you may withdraw it at any time. Withdrawing consent does not affect any processing carried out before you withdrew it.
How we hold and retain your information
We will retain your dental records while you are a practice patient. If you cease to be a patient, we will continue to hold them for at least another eleven years, or in the case of children until they reach the age of 25, whichever is the longer.
Personal data about you is held in the practice's computer system and/or in a manual filing system. The information is not accessible to the public and only authorised members of staff have access to it. Our computer system has secure audit trails and we back up information on every working day.
Dr David Ellis (data protection officer) is responsible for keeping the information secure that we hold about you. At the practice we comply with data protection requirements to ensure we collect, use, store and dispose of your information correctly.
Who we may share it with
In order to provide proper and safe dental care, we may need to disclose personal information about you to:
- Your general medical practitioner.
- The hospital or community dental services.
- Other health professionals caring for you.
- Specialist dental or medical services to which we may refer you.
- Dental laboratories.
- Debt collection agencies.
- Dental Insurance Companies of which you are a member.
- Private dental schemes of which you are a member.
Disclosure will take place on a "need-to-know" basis. Information will only be given to those individuals and organisations who need to have it in order to provide care to you and for the proper administration of Government (whose personnel are also covered by strict confidentiality rules). The recipient will only be given the information that they need to know for these purposes.
In very limited circumstances or when required by law or by a court order, personal data may have to be disclosed to a third party not connected with your dental care. In all other situations, disclosure that is not covered by this policy will occur only when we have your specific consent. Where possible you will be informed of these requests for disclosure.
Access to your records
You have the right to access the data that we hold about you and to receive a copy. This is known as a subject access request, and you can make one verbally or in writing. There is no charge. We will respond within one month of receiving your request, and we will tell you if we need to extend that by up to a further two months because your request is complex or you have made several. We can charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive, and we will explain our reasons if that ever applies.
We will also give you an explanation of your record if you would like one.
If you move to another dental practice we may (at our discretion) loan original x-rays and provide copy notes direct to that practice free of charge on receipt of a written request from them to do so.
Your rights
Under the UK GDPR you have the right to:
- be informed about how we use your information, which is the purpose of this policy;
- request a copy of the information we hold about you;
- have inaccurate information corrected, or incomplete information completed;
- ask us to erase information, or to restrict how we use it, though we cannot delete clinical records we are required to keep;
- object to processing that relies on our legitimate interests;
- request that information you gave us electronically is transferred to another provider;
- withdraw consent where our processing relies on it.
If you do not wish personal data we hold about you to be disclosed or used in the way that is described in this policy, please discuss the matter with your dentist. You have the right to object, but please remember that this may affect our ability to provide you with dental care.
To exercise any of these rights, please contact the practice and ask for the data protection officer.
If something goes wrong
We keep your information secure, and we have procedures for dealing with any suspected data breach. Where a breach is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
Back to the site