GDPR Data Protection Policy Template
A complete GDPR-compliant data protection policy for GP practices, covering lawful bases, patient data, staff data, and breach response obligations.
## GP Practice Data Protection Policy
### Legal Basis
This policy complies with UK GDPR (retained EU law), the Data Protection Act 2018, and NHS Data Security and Protection Toolkit requirements.
### Data Controller
[Practice Name] is the Data Controller for patient and staff data held by the practice. The Data Protection Officer (DPO) is: [Name/contact].
### Lawful Bases for Processing Patient Data
- **Legal obligation** — NHS contractual requirements, public health reporting
- **Vital interests** — emergency care
- **Public task** — provision of NHS services
- **Explicit consent** — where required (e.g. research, direct marketing)
### Patient Rights
Patients have the right to: access their data (SAR), rectification, erasure (limited in healthcare), restriction of processing, and to object to processing.
### Staff Data
Staff data is processed under legitimate interests and legal obligation. Staff must be provided with a privacy notice at the point of employment.
### Data Security
- All staff complete annual information governance training
- Clinical systems access is role-based and audited
- Portable devices must be encrypted
- Paper records must be stored securely and shredded when no longer needed
### Data Retention
Patient records: minimum 10 years after last contact (adults), or until age 25 for children.
Staff records: 6 years after employment ends.
### Breach Response
Any suspected data breach must be reported to the DPO/Practice Manager immediately. Breaches meeting the ICO threshold must be reported within 72 hours.
Sign in to save this resource.
Added 9 July 2026 · 0 views