Sample policy · Termination of pregnancy

Patient confidentiality and data protection policy (termination of pregnancy)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936), in particular the secure, accurate record-keeping duty. This policy also engages UK General Data Protection Regulation and the Data Protection Act 2018, the common law duty of confidence, and the termination-specific confidentiality regime in regulation 5 of the Abortion Regulations 1991. · primary source

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Regulation 17(1))

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Regulation 17(2)(c))

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3, and you have to keep an accurate, complete and contemporaneous record for each patient securely. For a termination service this sits on top of UK data protection law: termination data is special-category data under UK GDPR and the Data Protection Act 2018, and the HSA4 notification record carries the extra statutory confidentiality regime in regulation 5 of the Abortion Regulations 1991, which restricts who that information may be disclosed to. Recent legislative changes may affect the criminal-law position for women in England and Wales who end their own pregnancies. Providers must verify the current primary legislation before publishing any patient-facing wording. This does not alter the provider's obligations under the Abortion Act 1967, the Abortion Regulations 1991, the HSA1/HSA4 process or the CQC Registration Regulations unless primary legislation says so.

3. Purpose

This policy sets out how the Service handles patient confidentiality and personal data, with specific attention to the additional confidentiality protections that apply to termination services.

Termination data is special-category data under UK GDPR. It is also subject to the specific statutory confidentiality regime in regulation 5 of the Abortion Regulations 1991, which constrains who the HSA4 notification information may be disclosed to. The Service holds both layers.

4. Scope

This policy applies to:

5. Roles and responsibilities

6. The default position

The default position is that no information about a patient's termination care is disclosed to anyone other than the patient and Service staff with a legitimate clinical need.

This includes:

Information is only shared where the patient consents, where a statutory disclosure obligation applies (FGM Act 2003 mandatory reporting under-18s; police court order; safeguarding referrals), or where the public-interest threshold for disclosure is met (rare; clinical-lead decision).

7. Operational disclosure procedure

  1. Verify identity. Confirm the identity of the requester and, where they act for someone else, their authority. Do not confirm that a person uses the Service while verification is incomplete.
  2. Define the request. Record what information is requested, why it is needed, who will receive it and the deadline.
  3. Identify the authority to share. Establish the Article 6 lawful basis, Article 9 condition and any consent, statutory duty, court order, safeguarding or public-interest basis that applies.
  4. Check the additional restrictions. Review the patient's contact and GP preferences, common law confidentiality, regulation 5 of the Abortion Regulations 1991 and any risk from family, partner or third-party access.
  5. Escalate exceptions. The clinical lead and data protection lead review any disclosure without the patient's agreement, any HSA4-related request, uncertainty about capacity or authority, and any high-risk disclosure.
  6. Share the minimum securely. Release only the information needed through an approved method, confirm the recipient and protect any password or access code through a separate channel.
  7. Complete the disclosure log. Record the decision-maker, information shared or withheld, recipient, authority, method, date and any follow-up or review.

Verbal disclosures follow the same procedure. Urgency may shorten the timescale, but it does not remove the need to establish and record the authority to share.

8. The Abortion Regulations 1991 confidentiality regime

Regulation 5 of the Abortion Regulations 1991 sets out specific restrictions on disclosing information from HSA4 notifications. The Service:

The Service's clinical lead is the single point of accountability for any HSA4 disclosure decision.

9. Lawful basis under UK GDPR

The Service processes patient personal data on the following bases:

The Service does not rely on Article 6(1)(a) consent as the primary lawful basis for clinical care. Consent is a clinical-care concept (separate from the GDPR concept); withdrawal of consent does not retroactively invalidate care already provided.

10. Patient rights

Patients have rights under UK GDPR including:

The Service provides a subject access response within one month of a valid request, free of charge in the first instance. The response considers the Abortion Regulations 1991 regulation 5 constraints (see section 8 above).

11. Communications and contact preferences

At every consultation, the Service confirms with the patient:

These preferences are recorded on the patient record and respected by every staff member who contacts the patient.

12. Data minimisation

The Service collects only the data necessary for the clinical purpose. In particular:

13. Retention

The Service retains:

At the end of the retention period the Service securely destroys the record and logs the destruction.

14. Sub-processors

The Service maintains a current list of sub-processors with access to patient personal data. This list is shared with patients on request and includes for each sub-processor:

15. Data breaches

A personal data breach affecting patient information is:

Termination data carries a particularly high reputational + safety risk if breached (e.g. data exposure to a coercing partner). The risk assessment reflects this; breaches of termination data are escalated as default-high-risk unless evidence supports otherwise.

16. Staff confidentiality obligations

All staff sign a confidentiality declaration at the start of employment, covering:

Breach of confidentiality is treated as a disciplinary matter and, where the breach involves a registered professional, is also referred to the relevant professional regulator (GMC, NMC, HCPC) for fitness-to-practise consideration.

17. Training

All Service staff complete:

18. Audit and monitoring

The data protection lead reviews the breach register and overdue rights requests every month. Each quarter, they sample 10 disclosures or all disclosures if fewer than 10 occurred, including at least one GP communication, one third-party request and one refusal or restricted disclosure where available.

The audit checks identity and authority, lawful basis and Article 9 condition, data minimisation, secure transfer, the disclosure log and compliance with the patient's contact preferences. Access permissions and the current processor list are reviewed at least annually and whenever a system or supplier changes.

Findings are recorded in the governance action plan with an owner, due date and closure evidence. An unexplained disclosure, repeated contact-preference failure, overdue reportable breach or unsupported access is escalated immediately rather than waiting for the next meeting. A follow-up sample must show that the corrective action worked.

19. Review

This policy is reviewed at least annually and whenever UK GDPR guidance, Data Protection Act 2018 amendments, Abortion Regulations 1991 amendments, or GMC confidentiality guidance materially changes.

20. Related policies in this pack

21. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

Original sources carried forward from this policy (verify before adoption):

Verivius source stack for this policy family:

22. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

23. Document control

Version Date Author Changes
v1.1 2026-07-19 Verivius (sample) Added role ownership, a disclosure workflow, audit cadence, governance escalation and linked companion policies.
v1 2026-06-10 Verivius (sample) Conformed the existing draft to the Verivius policy standard: added the standard disclaimer, statutory-anchor header block, verbatim Regulation 17 quotes, plain-English summary, Sources and further reading (all original source URLs carried forward plus the source-pack stack), When to seek further advice, and Document control. All original sections preserved and renumbered.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 10 June 2026