Practice Manager Live
Back to resources
Legal & Contractstemplate

GDPR Data Protection Policy Template

A complete GDPR-compliant data protection policy for GP practices, covering lawful bases, patient data, staff data, and breach response obligations.

## GP Practice Data Protection Policy

### Legal Basis

This policy complies with UK GDPR (retained EU law), the Data Protection Act 2018, and NHS Data Security and Protection Toolkit requirements.

### Data Controller

[Practice Name] is the Data Controller for patient and staff data held by the practice. The Data Protection Officer (DPO) is: [Name/contact].

### Lawful Bases for Processing Patient Data

- **Legal obligation** — NHS contractual requirements, public health reporting

- **Vital interests** — emergency care

- **Public task** — provision of NHS services

- **Explicit consent** — where required (e.g. research, direct marketing)

### Patient Rights

Patients have the right to: access their data (SAR), rectification, erasure (limited in healthcare), restriction of processing, and to object to processing.

### Staff Data

Staff data is processed under legitimate interests and legal obligation. Staff must be provided with a privacy notice at the point of employment.

### Data Security

- All staff complete annual information governance training

- Clinical systems access is role-based and audited

- Portable devices must be encrypted

- Paper records must be stored securely and shredded when no longer needed

### Data Retention

Patient records: minimum 10 years after last contact (adults), or until age 25 for children.

Staff records: 6 years after employment ends.

### Breach Response

Any suspected data breach must be reported to the DPO/Practice Manager immediately. Breaches meeting the ICO threshold must be reported within 72 hours.

Sign in to save this resource.

Added 9 July 2026 · 0 views

GDPR Data Protection Policy Template | Practice Manager Live