Sample policy · GP

Patient data and information governance policy (gp)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). The primary data-protection framework is UK GDPR and the Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025, with the common law duty of confidence and the Caldicott Principles. Regulation 17 is the engaged CQC regulation through which CQC assures records, security and governance. · primary source

1. What the regulation says

The primary law for this policy is UK GDPR and the Data Protection Act 2018 as amended, neither of which is held verbatim in the Verivius regulation manifest. The engaged CQC regulation, quoted verbatim below, is Regulation 17 (good governance), which requires accurate, secure records and effective governance of how information is processed.

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) (Reg 17(2)(a): quality)

assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity (Reg 17(2)(b): risk)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. The primary data-protection law is at https://www.legislation.gov.uk/eur/2016/679/contents (UK GDPR) and https://www.legislation.gov.uk/ukpga/2018/12/contents (Data Protection Act 2018). Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.

For information governance specifically, that good-governance duty sits on top of UK GDPR, the Data Protection Act 2018, the common law duty of confidence and the Caldicott Principles. The Practice must hold a lawful basis for each processing activity, keep patient records secure and accurate, control who can see them, respond to subject access requests through the current ICO process, and assess and report personal data breaches against the current ICO wording.

3. Purpose

This policy sets out how the Practice governs patient data, record access, Caldicott decision-making, data-breach response, subject access requests and learning from information-governance incidents.

It reflects the higher risk in primary care because GP records contain dense longitudinal clinical and personal information.

4. Sources to verify before adoption

5. Scope

This policy applies to:

It applies to all staff, GP partners, locums, contractors, trainees and suppliers who handle patient data for the Practice.

5.1 Local arrangements before adoption

Before adoption, the Practice records:

An NHS-funded GP practice should appoint a Caldicott Guardian or make a proportionate shared arrangement under National Data Guardian guidance. The Practice must document the arrangement it actually uses rather than naming an unavailable role.

6. Lawful basis and Caldicott process

The Practice keeps a lawful-basis record for each main category of patient-data processing.

6.1 Lawful basis register

The lawful-basis register records:

The Practice verifies each entry against current UK GDPR, Data Protection Act 2018 and ICO source material before adoption.

6.2 Caldicott Guardian role

The Practice identifies the person or role responsible for Caldicott decisions.

The Caldicott Guardian or equivalent senior information-governance lead:

The Practice records whether it appoints its own Caldicott Guardian or uses a shared arrangement, and keeps the current contact details available to staff who need advice.

6.3 Access to records

Staff access patient records only where there is a work-related reason.

The Practice:

Staff do not access their own record, family records or records of people they know unless there is a clear and recorded work reason approved by the Practice.

7. Data-breach decision tree

The Practice records every suspected personal data breach and assesses it promptly.

The decision tree covers:

If a breach is likely to risk people's rights and freedoms, the Practice notifies the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If notification is later, the Practice records the reason. Where a breach is likely to create a high risk, affected people are informed without undue delay. Every breach is documented, including a decision not to notify.

8. Email, subject access and patient communication

The Practice treats misdirected email or message incidents as potential data breaches.

Staff:

The Practice handles subject access requests through the current ICO and local Practice process. Staff log the request, verify identity, check exemptions or third-party information where relevant and record the response decision.

The Practice does not use this policy to restate statutory response deadlines. Staff check the current ICO source before recording a deadline.

9. Responsibilities

10. Recording requirements and evidence fields

The Practice keeps a current record of processing activities or equivalent lawful-basis register. Each entry records the purpose, data categories, people affected, recipients, processors, Article 6 basis, Article 9 condition, relevant Data Protection Act condition, transfers, retention, security controls, owner and review date.

The following fields must be recorded in each suspected personal data breach record:

The subject access or other rights-request log records receipt, identity verification, request scope, clarification, third-party or exemption review, deadline, searches completed, decision-maker, disclosure method and date closed. Access-control evidence records the user, role, approval, permissions, start, review, change and removal dates. Caldicott and data-sharing decisions record the question, legal and ethical factors, advice, decision, authoriser, recipients and review conditions.

The Practice also retains DPIA screening and completed assessments, processor due diligence and contracts, data-sharing agreements, retention and destruction evidence, access audits, training records and linked improvement actions. Records are kept securely and access is limited to staff who need them for care, governance or legal compliance.

11. Audit cadence

The Practice uses the following Verivius default audit rhythm unless current source material requires more frequent review:

Audit findings are recorded as improvement actions with an owner and review date.

12. Version control and review date

The Practice keeps a controlled copy of this policy. The footer or document-control table records:

13. Related policies and companion artefacts

The Practice maintains a data-breach register, subject access request log, Caldicott decision log, staff access-control register, processor register, DPIA register and retention schedule.

Read this policy with:

Review cadence: annual or on regulatory change, whichever sooner. Owner: Registered Manager.

14. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

15. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

16. Document control

Version Date Author Changes
v1 2026-06-10 Verivius (sample) Conformed to the Verivius policy standard: added statutory anchor, verbatim Regulation 17 quotes, plain-English summary, sources and further reading, when-to-seek-advice and document-control blocks. Original purpose, scope, lawful-basis, breach, communication, responsibilities, recording, audit and related-records sections preserved and renumbered.
v1.1 2026-07-19 Verivius (sample) Added current data-law context, local governance decisions, detailed breach and rights-request evidence fields, Caldicott arrangements and companion-policy links.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 19 July 2026