Sample policy · GP

Patient data and information governance policy (gp)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). The primary data-protection framework is UK GDPR and the Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025, with the common law duty of confidence and the Caldicott Principles. Regulation 17 is the engaged CQC regulation through which CQC assures records, security and governance. · primary source

1. What the regulation says

The primary law for this policy is UK GDPR and the Data Protection Act 2018 as amended, neither of which is held verbatim in the Verivius regulation manifest. The engaged CQC regulation, quoted verbatim below, is Regulation 17 (good governance), which requires accurate, secure records and effective governance of how information is processed.

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) (Reg 17(2)(a): quality)

assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity (Reg 17(2)(b): risk)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. The primary data-protection law is at https://www.legislation.gov.uk/eur/2016/679/contents (UK GDPR) and https://www.legislation.gov.uk/ukpga/2018/12/contents (Data Protection Act 2018). Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.

For information governance specifically, that good-governance duty sits on top of UK GDPR, the Data Protection Act 2018, the common law duty of confidence and the Caldicott Principles. The Practice must hold a lawful basis for each processing activity, keep patient records secure and accurate, control who can see them, respond to subject access requests through the current ICO process, and assess and report personal data breaches against the current ICO wording.

3. Purpose

This policy sets out how the Practice governs patient data, record access, Caldicott decision-making, data-breach response, subject access requests and learning from information-governance incidents.

It reflects the higher risk in primary care because GP records contain dense longitudinal clinical and personal information.

4. Sources to verify before adoption

5. Scope

This policy applies to:

It applies to all staff, GP partners, locums, contractors, trainees and suppliers who handle patient data for the Practice.

5.1 Local arrangements before adoption

Before adoption, the Practice records:

An NHS-funded GP practice should appoint a Caldicott Guardian or make a proportionate shared arrangement under National Data Guardian guidance. The Practice must document the arrangement it actually uses rather than naming an unavailable role.

6. Lawful basis and Caldicott process

The Practice keeps a lawful-basis record for each main category of patient-data processing.

6.1 Lawful basis register

The lawful-basis register records:

The Practice verifies each entry against current UK GDPR, Data Protection Act 2018 and ICO source material before adoption.

6.2 Caldicott Guardian role

The Practice identifies the person or role responsible for Caldicott decisions.

The Caldicott Guardian or equivalent senior information-governance lead:

The Practice records whether it appoints its own Caldicott Guardian or uses a shared arrangement, and keeps the current contact details available to staff who need advice.

6.3 Access to records

Staff access patient records only where there is a work-related reason.

The Practice:

Staff do not access their own record, family records or records of people they know unless there is a clear and recorded work reason approved by the Practice.

7. Data-breach decision tree

The Practice records every suspected personal data breach and assesses it promptly.

The decision tree covers:

If a breach is likely to risk people's rights and freedoms, the Practice notifies the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If notification is later, the Practice records the reason. Where a breach is likely to create a high risk, affected people are informed without undue delay. Every breach is documented, including a decision not to notify.

8. Email, subject access and patient communication

The Practice treats misdirected email or message incidents as potential data breaches.

Staff:

The Practice handles subject access requests through the current ICO and local Practice process. Staff log the request, verify identity, check exemptions or third-party information where relevant and record the response decision.

The Practice does not use this policy to restate statutory response deadlines. Staff check the current ICO source before recording a deadline.

9. Responsibilities

10. Recording requirements and evidence fields

The Practice keeps a current record of processing activities or equivalent lawful-basis register. Each entry records the purpose, data categories, people affected, recipients, processors, Article 6 basis, Article 9 condition, relevant Data Protection Act condition, transfers, retention, security controls, owner and review date.

The following fields must be recorded in each suspected personal data breach record:

The subject access or other rights-request log records receipt, identity verification, request scope, clarification, third-party or exemption review, deadline, searches completed, decision-maker, disclosure method and date closed. Access-control evidence records the user, role, approval, permissions, start, review, change and removal dates. Caldicott and data-sharing decisions record the question, legal and ethical factors, advice, decision, authoriser, recipients and review conditions.

The Practice also retains DPIA screening and completed assessments, processor due diligence and contracts, data-sharing agreements, retention and destruction evidence, access audits, training records and linked improvement actions. Records are kept securely and access is limited to staff who need them for care, governance or legal compliance.

11. Audit cadence

The Practice uses the following Verivius default audit rhythm unless current source material requires more frequent review:

Audit findings are recorded as improvement actions with an owner and review date.

12. Version control and review date

The Practice keeps a controlled copy of this policy. The footer or document-control table records:

13. Related policies and companion artefacts

The Practice maintains a data-breach register, subject access request log, Caldicott decision log, staff access-control register, processor register, DPIA register and retention schedule.

Read this policy with:

Review cadence: annual or on regulatory change, whichever sooner. Owner: Registered Manager.

14. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

15. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

16. Document control

Version Date Author Changes
v1 2026-06-10 Verivius (sample) Conformed to the Verivius policy standard: added statutory anchor, verbatim Regulation 17 quotes, plain-English summary, sources and further reading, when-to-seek-advice and document-control blocks. Original purpose, scope, lawful-basis, breach, communication, responsibilities, recording, audit and related-records sections preserved and renumbered.
v1.1 2026-07-19 Verivius (sample) Added current data-law context, local governance decisions, detailed breach and rights-request evidence fields, Caldicott arrangements and companion-policy links.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

A GP record is the densest longitudinal record most people will ever have: decades of consultations, mental health, sexual health, substance use, terminations of pregnancy and safeguarding markers, held in a practice where staff and patients often live in the same few streets. That combination makes staff looking up records out of curiosity, rather than the outside attacker, the live risk in primary care, and it looks like a receptionist opening the record of a neighbour, an ex-partner or their own family. When it happens and nothing catches it, the harm is clinical as well as legal, because people who suspect their notes are read locally stop telling their GP the things that matter most, and consultations then run on incomplete information. Subject access carries the mirror risk, since a GP record released whole can expose the relative who raised a safeguarding concern or a third party named in a historic entry. Access records that show removal as well as approval, breach assessments that are honestly reasoned including the decision not to notify, and a Caldicott route that someone actually answers are how a practice knows, rather than merely asserts, that the confidence patients place in it is warranted.

  1. Staff open patient records only where there is a work-related reason, access is audited when a concern is raised, and self, family and known-person access is blocked. What damages the person is a staff member opening their own record, a relative's record, or a record with no clinical or administrative need, and it going undetected.

    Strong evidence: The staff access-control register recording user, role, approval, permissions and the start, review, change and removal dates, plus the access audit run where concern is raised and any disciplinary action, professional-regulator referral or other regulatory action recorded (sections 6.3 and 10).

    Weak evidence: The access-control register is a list of names and logins with no approval, review, change or removal dates, so a receptionist who left in the spring still has a live role on the clinical system. Audits are described as annual and routine, and the practice cannot produce a single access report pulled because a concern was raised, nor any record of what was decided about a staff member who opened a relative's record.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 32(4) (with Article 5(1)(f); Data Protection Act 2018 s.170)

  2. Every suspected breach is recorded and assessed against the risk to people's rights and freedoms, with the Information Commissioner's Office (ICO) notification decision documented, including a reasoned decision not to notify. The person is left exposed when a breach likely to risk rights and freedoms is not notified without undue delay and, where feasible, within 72 hours of becoming aware, with no rationale recorded for the delay.

    Strong evidence: The data-breach register capturing when the event occurred, was detected and became known, the documented risk assessment, the ICO notification decision with rationale, time and reference (and reasons for delay where relevant), and the decision on informing affected people (sections 7 and 10).

    Weak evidence: The breach log holds a few one-line rows such as "letter sent to wrong address, resolved", with a single date that blurs when the event happened, when it was spotted and when the practice became aware. There is no written assessment of the likely risk to people's rights and freedoms, the Information Commissioner's Office (ICO) column is blank or says "not reportable" with no reasoning and no reference number, and nothing records whether the affected patient was told.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 33(1) and 33(5), with Article 34(1)

  3. The Practice can show a lawful basis for each category of patient-data processing, with a UK General Data Protection Regulation (UK GDPR) Article 9 condition wherever health data is involved, not a blanket assumption of consent. The gap that matters is health-data processing with no recorded Article 9 condition or Data Protection Act 2018 condition.

    Strong evidence: The lawful-basis register or record of processing activities recording, per activity, the UK GDPR Article 6 basis, the Article 9 condition for health data, the relevant Data Protection Act 2018 condition, retention and access controls, verified against current source material (sections 6.1 and 10).

    Weak evidence: One sentence saying the practice processes patient data "for direct care with patient consent", or the website privacy notice standing in for the register. Health data appears with an Article 6 basis but no Article 9 condition and no Data Protection Act 2018 condition recorded anywhere, and the register was written once at adoption, never verified against current source material, and still lists a clinical or messaging system the practice stopped using.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Articles 6(1), 9(2)(h) and 30(5); Data Protection Act 2018 Schedule 1 Part 1 paragraph 2

  4. Subject access requests are logged, identity is verified, and exemptions or third-party information are reviewed before anything is disclosed, with the response deadline taken from the current ICO source rather than a number carried in the policy. The person is put at risk when a request is answered ad hoc, with no identity check, no exemption review and no log, because the record can go to the wrong hands or carry someone else's information out with it.

    Strong evidence: The subject access or rights-request log recording receipt, identity verification, scope, third-party or exemption review, deadline, searches completed, decision-maker, disclosure method and date closed (sections 8 and 10). The policy deliberately does not restate the statutory response deadline.

    Weak evidence: Subject access requests are handled by whoever opens the post, with no log at all, and identity is treated as proved because the caller was recognised on the phone or in the waiting room. Nobody has recorded who reviewed the notes for third-party information or for the exemptions in the Data Protection Act 2018 before the record was released, and the response deadline was copied from an old document rather than checked against the current Information Commissioner's Office (ICO) source.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 15(1) (with Article 12(3) and 12(6)); Data Protection Act 2018 Schedule 2 Part 3 paragraph 16 and Schedule 3 Part 2

  5. A Caldicott Guardian, or the documented equivalent arrangement the Practice actually uses, signs off high-risk and disputed disclosures with the reasoning logged, so someone senior has weighed the person's confidentiality before information leaves the Practice. The give-away is a difficult or novel disclosure made with no Caldicott advice recorded, or a named role that is not in fact available.

    Strong evidence: The Caldicott decision log recording the question, legal and ethical factors, advice, decision, authoriser, recipients and review conditions, and the recorded note of whether the Practice appoints its own Caldicott Guardian or uses a shared arrangement (sections 6.2 and 10).

    Weak evidence: The policy names a Caldicott Guardian who has retired or moved practice, or a partner who has never been asked a question and does not know they hold the role, and nothing records whether the practice appoints its own Guardian or relies on a shared arrangement. The Caldicott decision log is empty even though the practice has plainly handled difficult disclosures such as a police request or a request from a coroner's officer, and where an entry exists it says only "information shared", with no note of the legal and ethical factors weighed, who authorised it, or what was actually released.

    Something your commissioner or funder requires through your contract, for example an ICB or a local authority. It applies because you agreed to it, not because the law demands it of every service.

Last verified 20 July 2026

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 19 July 2026