1. What the regulation says
The primary law for this policy is UK GDPR and the Data Protection Act 2018 as amended, neither of which is held verbatim in the Verivius regulation manifest. The engaged CQC regulation, quoted verbatim below, is Regulation 17 (good governance), which requires accurate, secure records and effective governance of how information is processed.
Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)
assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) (Reg 17(2)(a): quality)
assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity (Reg 17(2)(b): risk)
maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)
The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. The primary data-protection law is at https://www.legislation.gov.uk/eur/2016/679/contents (UK GDPR) and https://www.legislation.gov.uk/ukpga/2018/12/contents (Data Protection Act 2018). Where this policy and the regulation diverge, the regulation wins.
2. Plain-English summary
You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.
For information governance specifically, that good-governance duty sits on top of UK GDPR, the Data Protection Act 2018, the common law duty of confidence and the Caldicott Principles. The Practice must hold a lawful basis for each processing activity, keep patient records secure and accurate, control who can see them, respond to subject access requests through the current ICO process, and assess and report personal data breaches against the current ICO wording.
3. Purpose
This policy sets out how the Practice governs patient data, record access, Caldicott decision-making, data-breach response, subject access requests and learning from information-governance incidents.
It reflects the higher risk in primary care because GP records contain dense longitudinal clinical and personal information.
4. Sources to verify before adoption
- UK GDPR, Article 5: https://www.legislation.gov.uk/eur/2016/679/article/5
- UK GDPR, Article 6: https://www.legislation.gov.uk/eur/2016/679/article/6
- UK GDPR, Article 9: https://www.legislation.gov.uk/eur/2016/679/article/9
- UK GDPR, Article 33: https://www.legislation.gov.uk/eur/2016/679/article/33
- UK GDPR, Article 34: https://www.legislation.gov.uk/eur/2016/679/article/34
- Data Protection Act 2018: https://www.legislation.gov.uk/ukpga/2018/12/contents
- Data (Use and Access) Act 2025: https://www.legislation.gov.uk/ukpga/2025/18/contents
- ICO, Personal data breaches: https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/
- ICO, Guide to UK GDPR: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/uk-gdpr-guidance-and-resources/
- GOV.UK, National Data Guardian review of Caldicott Principles: https://www.gov.uk/government/publications/the-caldicott-principles
- GOV.UK, Guidance on the appointment of Caldicott Guardians: https://www.gov.uk/government/publications/guidance-on-the-appointment-of-caldicott-guardians-their-role-and-responsibilities
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 17: https://www.legislation.gov.uk/uksi/2014/2936/regulation/17
5. Scope
This policy applies to:
- patient records
- clinical correspondence
- referrals and results
- emails, letters, text messages and online messages containing patient data
- record access by staff
- subject access requests
- data-breach assessment and notification
- Caldicott decision-making
- information held in GP clinical systems, Verivius records and local Practice systems
It applies to all staff, GP partners, locums, contractors, trainees and suppliers who handle patient data for the Practice.
5.1 Local arrangements before adoption
Before adoption, the Practice records:
- the controller's legal name, ICO registration details and the roles of the Caldicott Guardian, data protection officer where required, information-governance lead and senior accountable owner
- the approved clinical, communication, document, backup and governance systems, their processors and the access owner for each system
- the record of processing activities, Article 6 bases, Article 9 conditions, Data Protection Act conditions and retention schedule used by the Practice
- who approves, changes, reviews and removes user access, including urgent and out-of-hours access
- the confidential route and 24-hour contact used to report a suspected breach, loss of availability or unauthorised access
- the subject access, rectification, objection and other rights-request route, with responsibility for identity checks, clinical review, exemptions and response approval
- the DPIA screening and sign-off route for new systems, suppliers, data uses and other processing likely to create high risk
- the data-sharing agreement, Caldicott advice and senior escalation routes used for novel, difficult or disputed disclosures
An NHS-funded GP practice should appoint a Caldicott Guardian or make a proportionate shared arrangement under National Data Guardian guidance. The Practice must document the arrangement it actually uses rather than naming an unavailable role.
6. Lawful basis and Caldicott process
The Practice keeps a lawful-basis record for each main category of patient-data processing.
6.1 Lawful basis register
The lawful-basis register records:
- processing activity
- type of personal data
- type of special-category data
- purpose
- UK GDPR Article 6 basis
- UK GDPR Article 9 condition where health data is processed
- Data Protection Act 2018 condition where relevant
- retention position
- access controls
- data-sharing route
- source material checked
The Practice verifies each entry against current UK GDPR, Data Protection Act 2018 and ICO source material before adoption.
6.2 Caldicott Guardian role
The Practice identifies the person or role responsible for Caldicott decisions.
The Caldicott Guardian or equivalent senior information-governance lead:
- advises on patient-identifiable data use
- reviews high-risk sharing decisions
- supports breach assessment
- reviews record-access concerns
- advises on confidentiality and public-interest decisions
- reports themes to the governance group
The Practice records whether it appoints its own Caldicott Guardian or uses a shared arrangement, and keeps the current contact details available to staff who need advice.
6.3 Access to records
Staff access patient records only where there is a work-related reason.
The Practice:
- sets role-based access
- removes access when staff leave or change role
- audits access where concern is raised
- investigates access without clinical or administrative need
- records disciplinary, professional or regulatory action where required
Staff do not access their own record, family records or records of people they know unless there is a clear and recorded work reason approved by the Practice.
7. Data-breach decision tree
The Practice records every suspected personal data breach and assesses it promptly.
The decision tree covers:
- what data was involved
- whether the data identifies a patient or staff member
- whether special-category health data was involved
- how many people were affected
- who received or accessed the data
- whether the data has been recovered or contained
- likely risk to rights and freedoms
- whether ICO notification is required
- whether the patient or other person should be informed
- whether CQC, NHS or commissioner notification is required
If a breach is likely to risk people's rights and freedoms, the Practice notifies the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If notification is later, the Practice records the reason. Where a breach is likely to create a high risk, affected people are informed without undue delay. Every breach is documented, including a decision not to notify.
8. Email, subject access and patient communication
The Practice treats misdirected email or message incidents as potential data breaches.
Staff:
- stop further sending where possible
- contact the unintended recipient where appropriate
- ask the recipient to delete or return the information where appropriate
- inform the Practice Manager or information-governance lead
- record the incident
- assess notification requirements
- update the communication process where needed
The Practice handles subject access requests through the current ICO and local Practice process. Staff log the request, verify identity, check exemptions or third-party information where relevant and record the response decision.
The Practice does not use this policy to restate statutory response deadlines. Staff check the current ICO source before recording a deadline.
9. Responsibilities
- Registered Manager: owns this policy, ensures information-governance oversight and signs off annual review.
- Caldicott Guardian or information-governance lead: owns patient-data sharing advice, breach assessment support and Caldicott decision records.
- Practice Manager: maintains access controls, supplier records, subject access logs and staff training records.
- Lead GP or GP Partner: reviews complex clinical confidentiality decisions and professional-risk cases.
- All staff: access records only for work reasons, report suspected breaches and follow secure communication procedures.
10. Recording requirements and evidence fields
The Practice keeps a current record of processing activities or equivalent lawful-basis register. Each entry records the purpose, data categories, people affected, recipients, processors, Article 6 basis, Article 9 condition, relevant Data Protection Act condition, transfers, retention, security controls, owner and review date.
The following fields must be recorded in each suspected personal data breach record:
- when the event occurred, when it was detected and when the Practice became aware that personal data may have been breached
- confidentiality, integrity and availability affected, data types, approximate records and people concerned
- containment and recovery action, people responsible and outstanding risk
- likely consequences for individuals and the documented risk assessment
- ICO notification decision, rationale, time and reference, including reasons for delay where relevant
- decision on informing affected people, communication sent and advice provided
- CQC, NHS, commissioner, police, insurer or professional reporting decisions where relevant
- cause, lessons, linked incident or risk entry, improvement actions and effectiveness review
The subject access or other rights-request log records receipt, identity verification, request scope, clarification, third-party or exemption review, deadline, searches completed, decision-maker, disclosure method and date closed. Access-control evidence records the user, role, approval, permissions, start, review, change and removal dates. Caldicott and data-sharing decisions record the question, legal and ethical factors, advice, decision, authoriser, recipients and review conditions.
The Practice also retains DPIA screening and completed assessments, processor due diligence and contracts, data-sharing agreements, retention and destruction evidence, access audits, training records and linked improvement actions. Records are kept securely and access is limited to staff who need them for care, governance or legal compliance.
11. Audit cadence
The Practice uses the following Verivius default audit rhythm unless current source material requires more frequent review:
- Monthly: the Practice Manager reviews open breach actions, subject access requests and urgent access changes.
- Quarterly: the governance group reviews data-breach themes, record-access concerns and staff training.
- Annually: the Registered Manager audits lawful-basis records, Caldicott records, access controls and this policy against ICO, UK GDPR, Data Protection Act and Caldicott source material.
Audit findings are recorded as improvement actions with an owner and review date.
12. Version control and review date
The Practice keeps a controlled copy of this policy. The footer or document-control table records:
- policy owner
- version number
- date approved
- next review date
- changes made since the last version
- source material checked during the review
13. Related policies and companion artefacts
The Practice maintains a data-breach register, subject access request log, Caldicott decision log, staff access-control register, processor register, DPIA register and retention schedule.
Read this policy with:
- Confidentiality, Information Governance and Data Protection Policy
- Record Keeping and Documentation Standards Policy
- Data Breach Policy
- Incident Reporting, Investigation and Learning Policy
- Complaints Policy
- Safeguarding Adults Policy
- Business Continuity and Emergency Preparedness Policy
Review cadence: annual or on regulatory change, whichever sooner. Owner: Registered Manager.
14. Sources and further reading
This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.
- UK GDPR
- Data Protection Act 2018
- Data (Use and Access) Act 2025 and current commencement position
- Common law duty of confidence
- ICO UK GDPR guidance
- ICO data sharing code
- ICO personal data breach guidance and reporting tool (https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/)
- NHS Records Management Code of Practice 2021, current version (https://transform.england.nhs.uk/information-governance/guidance/records-management-code/)
- NHS Data Security and Protection Toolkit (https://www.dsptoolkit.nhs.uk/)
- Caldicott Principles (National Data Guardian) (https://www.gov.uk/government/publications/the-caldicott-principles)
- National Data Guardian guidance on the appointment of Caldicott Guardians (https://www.gov.uk/government/publications/national-data-guardian-guidance-on-the-appointment-of-caldicott-guardians-their-role-and-responsibilities)
- CQC Regulation 17: Good governance
15. When to seek further advice
Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.
16. Document control
| Version | Date | Author | Changes |
|---|---|---|---|
| v1 | 2026-06-10 | Verivius (sample) | Conformed to the Verivius policy standard: added statutory anchor, verbatim Regulation 17 quotes, plain-English summary, sources and further reading, when-to-seek-advice and document-control blocks. Original purpose, scope, lawful-basis, breach, communication, responsibilities, recording, audit and related-records sections preserved and renumbered. |
| v1.1 | 2026-07-19 | Verivius (sample) | Added current data-law context, local governance decisions, detailed breach and rights-request evidence fields, Caldicott arrangements and companion-policy links. |
This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.