GDPR Data Protection Policy Template for GP Practices
A complete GDPR-compliant data protection policy template for GP practices, covering lawful basis, patient rights, and breach management.
## Data Protection Policy — GP Practice
### 1. Purpose
To ensure [Practice Name] handles personal and special category data in compliance with UK GDPR and the Data Protection Act 2018.
### 2. Lawful Basis for Processing
- Patient health data: processed under Article 9(2)(h) — healthcare provision
- Staff data: contract performance and legal obligation
### 3. Patient Rights
Patients have the right to: access their records (Subject Access Request), rectification, erasure (with limitations in healthcare), and to object to processing for direct marketing.
### 4. Data Breach Response
- Contain the breach immediately
- Assess likelihood and severity of harm
- If likely to result in high risk to individuals: notify ICO within 72 hours
- Notify affected individuals if high risk
### 5. Roles
- Data Controller: [Practice Name and Partners]
- Data Protection Lead: [Name]
- DSPT Lead: [Name]
### 6. Review
Annually and after any significant data incident.
Sign in to save this resource.
Added 9 July 2026 · 0 views