Practice Manager Live
Back to resources
Legal & Contractstemplate

GDPR Data Protection Policy Template for GP Practices

A complete GDPR-compliant data protection policy template for GP practices, covering lawful basis, patient rights, and breach management.

## Data Protection Policy — GP Practice

### 1. Purpose

To ensure [Practice Name] handles personal and special category data in compliance with UK GDPR and the Data Protection Act 2018.

### 2. Lawful Basis for Processing

- Patient health data: processed under Article 9(2)(h) — healthcare provision

- Staff data: contract performance and legal obligation

### 3. Patient Rights

Patients have the right to: access their records (Subject Access Request), rectification, erasure (with limitations in healthcare), and to object to processing for direct marketing.

### 4. Data Breach Response

- Contain the breach immediately

- Assess likelihood and severity of harm

- If likely to result in high risk to individuals: notify ICO within 72 hours

- Notify affected individuals if high risk

### 5. Roles

- Data Controller: [Practice Name and Partners]

- Data Protection Lead: [Name]

- DSPT Lead: [Name]

### 6. Review

Annually and after any significant data incident.

Sign in to save this resource.

Added 9 July 2026 · 0 views