Patient Privacy Notice
This explains why we collect information about you, how it's kept secure, how it's used, and your rights. It applies to Kiltearn Medical Centre as your registered GP practice.
Introduction
The General Data Protection Regulation became law on 25 May 2018. It protects the personal and sensitive data of living individuals, and is now known as the UK GDPR 2021 since the United Kingdom left the European Union.
As your registered GP practice, we’re the data controller for the personal and sensitive data we hold about you. We’re committed to protecting your privacy and only use information lawfully, in line with:
- The Data Protection Act 2018.
- The GDPR 2016 and UK GDPR 2021.
- The Human Rights Act 1998.
- The common law duty of confidentiality.
- The Health and Social Care Act 2012.
- NHS codes on confidentiality, information security, and records management.
- The Caldicott Principles.
Why we collect your information
Healthcare professionals who provide your care are required by law to keep records of any care or treatment you receive. This helps clinicians make safe, effective decisions about your health. We also use information to:
- Look after the health of the public.
- Develop future services to better serve our patients.
- Share pseudonymised data so the NHS can measure its performance and activity.
- Investigate concerns, complaints, or legal claims.
- Let clinicians review the care they give, keep standards high, and support further training where needed.
- Carry out medication reviews by a healthcare professional.
- Support research approved by a Research Ethics Committee (your consent is required for this).
What information we collect
The professionals who provide your care keep records about your health and any treatment you’ve had, here or elsewhere (such as a hospital, another GP surgery, an out-of-hours service, or A&E). These records help us give you the best possible care. They may include:
- Your personal details: address, next of kin, contact details, anyone with proxy access, and your email address.
- Contact you’ve had with the surgery: appointments, including the type, who it was with, and what happened.
- Reports about your health, treatment, and care.
- Results of investigations such as laboratory tests, X-rays, and scans.
- Relevant information from other health professionals, relatives, or carers, or information you give us (including through our website).
- Recordings of telephone conversations between you and the practice.
How we keep your information safe and secure
Every member of NHS staff has a legal duty to keep information about you confidential. We do this through yearly training, limiting access to the appropriate staff, and only sharing with organisations and individuals that have a lawful basis for access.
We’ll only ever use or pass on information about you if others involved in your care genuinely need it. We won’t disclose your information to any third party without your permission unless there are exceptional circumstances, or the law requires it, for example where:
- We believe you’re at risk of serious harm.
- We believe you’re putting another adult or child at risk of serious harm.
- We’ve been instructed to by a court order made against the practice.
- Your information is essential to investigate a serious crime.
- You are subject to the Mental Health Act 1983.
- The UK Health Security Agency needs to be told about certain infectious diseases.
- A regulator uses its legal powers to request your information as part of an investigation.
All employees sign a confidentiality agreement as a condition of employment. We also make sure any data processors who support us are legally and contractually bound to keep your information secure. We’ll email or text you about matters of medical care, such as appointment reminders and, where appropriate, test results, unless you’ve told us not to.
Who we share your information with
Confidential patient data is shared within the healthcare team here, including nursing staff, administrative staff (prescriptions, secretaries, reception, finance), and with other healthcare professionals you’re referred to.
We use data processors to carry out certain tasks for us, particularly where large numbers of patients are involved. These include companies providing our IT and core clinical systems, services that run patient-facing tools such as the website, appointment booking, and electronic prescriptions, data hosting, and document management. The systems contracted to maintain and store data on our behalf are:
- EMIS Web
- Docman clinical systems
- Accurx
- Scriptswitch
- BetterLetter
National screening and research
The NHS runs national screening programmes so certain diseases can be found early. These include bowel, breast, and cervical cancer screening.
Where research involves accessing or disclosing identifiable patient information, we only do so with your explicit consent and approval from a Research Ethics Committee, or where we have special authority to do so.
We also take part in Medicines Management Reviews, which check prescribed medication so patients get the most appropriate, up to date, and cost-effective treatment. If you’d rather opt out, contact the Practice Manager, though this may delay your direct care.
Risk stratification
The Secretary of State for Health and Social Care has granted permission for personal data to be used for risk stratification, because manually reviewing every patient would take too long. The information used includes your age, gender, NHS number, diagnosis, long-term conditions, medication history, patterns of hospital attendance, A&E admissions, and periods of community care.
This helps us decide whether you’re at greater risk of a particular condition, prevent emergency admissions, identify when you need help to stop a condition getting worse, and review the services on offer.
Data sharing schemes
Several data sharing schemes operate locally, letting healthcare professionals outside the surgery view information from your GP record when it supports your care. You can get a list of these schemes by writing to Rebecca Jenkinson and asking under the Freedom of Information Act 2000.
Summary Care Record. NHS England has created a Summary Care Record holding information about your medication, allergies, and any bad reactions you’ve had. This means you don’t have to repeat your medical history at every care setting. Your record is set up to be shared automatically, but you can ask us to stop sharing it, or to share only part of it.
GP Connect. This is a secure NHS service that lets authorised healthcare professionals see important information from your GP record to support your care, particularly when you’re seen outside your usual practice, such as in urgent care, hospital, or a care home. It may include your basic details, medical history, current medicines, test results, and allergies. Only the information needed for your care is accessed, and only by staff directly involved. Access is logged and audited, and you can ask to view, correct, or limit the sharing of your data.
When we must disclose information
We’re sometimes legally obliged to disclose information about patients to relevant authorities. In these cases we share the minimum identifiable information needed for that legal purpose, and anonymise data first where that would still serve the purpose. Organisations we may be legally required to share with include:
- NHS Digital (for example the National Diabetes Audit).
- The Care Quality Commission.
- The Driver and Vehicle Licensing Agency.
- The General Medical Council.
- HM Revenue & Customs.
- NHS Counter Fraud.
- The police (mandatory or vital interest requests).
- The courts.
- The UK Health Security Agency.
- Local authorities (social services).
- The Health Service Ombudsman.
- A medical defence organisation, in the event of legal proceedings.
When we may disclose information with your consent
We can release information from your records to certain organisations only with your explicit consent. These include your employer, insurance companies, solicitors, local authorities, the police (for non-mandatory requests), community services, child health services, urgent care and minor injury units, community and palliative care hospitals, care homes, mental health trusts, NHS hospitals, social care organisations, NHS commissioning support units, independent contractors such as dentists, opticians, and pharmacists, private and voluntary sector providers, the local ambulance trust, the Integrated Care Board, education services, and fire and rescue services.
Don't want to share your information?
You have the right to withdraw your consent at any time for any processing where consent is the legal basis. Please contact the practice to raise an objection.
You also have a choice about whether your confidential patient information is used beyond your direct care, through the National Data Opt-Out. If you opt out, your information is still used to support your own care. To set or change your choice, visit nhs.uk/your-nhs-data-matters or call 0300 303 5678. Data used beyond your direct care is never shared with insurance companies or used for marketing without your specific agreement.
Using ambient AI software during consultations
To improve the quality of your care and free up time during appointments, we may use ambient AI software to help with clinical notes. It securely captures and transcribes the conversation between you and your clinician, creating notes as you go.
We use it because it lets your clinician focus more on you and less on typing, helps create more accurate and structured notes, and makes consultations more efficient. Your privacy matters: using the software is entirely optional, and we’ll only turn it on with your explicit consent. Before your appointment, your clinician will explain how it works and ask your permission.
- If you agree, the software transcribes the conversation to create notes, which are stored securely in your medical record.
- If you decline, your clinician will write up your consultation by hand, without AI.
Either way, your information stays confidential and is handled under strict data protection rules. If you have concerns, or want to withdraw your consent at any time, just tell your clinician.
Data Protection Impact Assessments
Protecting your data is a core duty. One tool we use is a Data Protection Impact Assessment (DPIA), a structured process that identifies and reduces data protection risks, particularly when new technology or processes involving personal data are introduced.
A DPIA is usually needed where processing could be high risk, such as a new electronic health record system, sharing information with external providers, or new tools for remote consultations. Carrying one out early lets us assess how data will be collected, stored, used, and shared, and put the right safeguards in place. DPIAs are reviewed and updated as our services change.
The legal basis for processing your data
We need your personal, sensitive, and confidential data to provide you with healthcare. Under UK GDPR there are different reasons we may process it, but we mostly rely on:
- Article 6(1)(e): official authority.
- Article 9(2)(h): the provision of health and care.
These cover most of our processing, including maintaining your GP record, sharing it with professionals involved in your direct care, referrals, NHS data sharing schemes, our data processors, organising your prescriptions, and some permissive disclosures. We also rely on:
- Article 6(1)(d), vital interests: to share information in a medical emergency.
- Article 6(1)(c), legal obligation: for mandatory disclosures to NHS Digital, the CQC, and others.
- Article 6(1)(a), consent: for certain permissive disclosures, such as to insurers.
- Article 9(2)(j), research: for accredited research carried out here, with your explicit consent.
Your data rights
UK GDPR lets you ask for any information we hold about you, including your medical records, ask us to correct factual inaccuracies, and object to how your information is shared.
Right of access. You can contact us to make a Subject Access Request for a copy of your records. Some information may be withheld: the law lets us apply certain restrictions, most commonly to protect information about other people (third party data, unless they’ve consented), or information that could cause serious physical or mental harm to you or someone else. For some requests, a GP will carry out a “serious harm test”.
Right to rectification. You can ask us to correct factual inaccuracies in your record.
Right to object. If you don’t want your information shared with organisations not responsible for your direct care, you can opt out of the sharing schemes.
Right to withdraw consent. Where we’ve relied on your consent to process your data, you can withdraw it at any time.
Access to your future health records
If you have online access to your records, you’ll be able to see your full record, including free text, letters, and documents once a GP has reviewed and filed them. This doesn’t affect proxy access. If you move practice, access to your full records starts from the date you register with the new practice.
There are limited, safeguarding-based reasons access to future records might be reduced or withheld. If releasing information would be likely to cause serious harm to you or someone else, a GP can refuse or reduce access, and third party information may be withheld. Occasionally we may need to review you before granting access.
Telling us when your details change
Please tell whoever is treating you if any of your details change, such as your name or address, or if anything like your date of birth is recorded incorrectly. Keeping your details accurate and up to date helps us look after you. You can use our update your details page.
How to complain
If you have concerns about how your data is managed, please contact the Practice Manager first. For independent advice about data protection, privacy, and data sharing, you can contact the Information Commissioner’s Office:
The Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
ico.org.uk
Our Data Protection Officer
If you have concerns about how your data is shared, or want to know more about your rights, you can contact our Data Protection Officer. Any queries about data protection should be addressed to:
Sharon Forrester-Wild
Email: DPO.healthcare@nhs.net
Telephone: 07946 593082
For a shorter summary of how we use your information, see our privacy notice summary. For how to access your records, see access to your medical records.
Patient Privacy Notice, version 9.6. Due for review April 2026.