Sample policy · Termination of pregnancy

Patient confidentiality and data protection policy (termination of pregnancy)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936), in particular the secure, accurate record-keeping duty. This policy also engages UK General Data Protection Regulation and the Data Protection Act 2018, the common law duty of confidence, and the termination-specific confidentiality regime in regulation 5 of the Abortion Regulations 1991. · primary source

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Regulation 17(1))

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Regulation 17(2)(c))

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3, and you have to keep an accurate, complete and contemporaneous record for each patient securely. For a termination service this sits on top of UK data protection law: termination data is special-category data under UK GDPR and the Data Protection Act 2018, and the HSA4 notification record carries the extra statutory confidentiality regime in regulation 5 of the Abortion Regulations 1991, which restricts who that information may be disclosed to. The Crime and Policing Act 2026 (section 241) removed the criminal liability of a woman in England and Wales acting in relation to her own pregnancy. It does not remove or alter the provider's obligations under the Abortion Act 1967, the Abortion Regulations 1991, the HSA1 and HSA4 process or the Care Quality Commission (Registration) Regulations 2009, which continue to apply in full.

3. Purpose

This policy sets out how the Service handles patient confidentiality and personal data, with specific attention to the additional confidentiality protections that apply to termination services.

Termination data is special-category data under UK GDPR. It is also subject to the specific statutory confidentiality regime in regulation 5 of the Abortion Regulations 1991, which constrains who the HSA4 notification information may be disclosed to. The Service holds both layers.

4. Scope

This policy applies to:

5. Roles and responsibilities

6. The default position

The default position is that no information about a patient's termination care is disclosed to anyone other than the patient and Service staff with a legitimate clinical need.

This includes:

Information is only shared where the patient consents, where a statutory disclosure obligation applies (FGM Act 2003 mandatory reporting under-18s; police court order; safeguarding referrals), or where the public-interest threshold for disclosure is met (rare; clinical-lead decision).

7. Operational disclosure procedure

  1. Verify identity. Confirm the identity of the requester and, where they act for someone else, their authority. Do not confirm that a person uses the Service while verification is incomplete.
  2. Define the request. Record what information is requested, why it is needed, who will receive it and the deadline.
  3. Identify the authority to share. Establish the Article 6 lawful basis, Article 9 condition and any consent, statutory duty, court order, safeguarding or public-interest basis that applies.
  4. Check the additional restrictions. Review the patient's contact and GP preferences, common law confidentiality, regulation 5 of the Abortion Regulations 1991 and any risk from family, partner or third-party access.
  5. Escalate exceptions. The clinical lead and data protection lead review any disclosure without the patient's agreement, any HSA4-related request, uncertainty about capacity or authority, and any high-risk disclosure.
  6. Share the minimum securely. Release only the information needed through an approved method, confirm the recipient and protect any password or access code through a separate channel.
  7. Complete the disclosure log. Record the decision-maker, information shared or withheld, recipient, authority, method, date and any follow-up or review.

Verbal disclosures follow the same procedure. Urgency may shorten the timescale, but it does not remove the need to establish and record the authority to share.

8. The Abortion Regulations 1991 confidentiality regime

Regulation 5 of the Abortion Regulations 1991 sets out specific restrictions on disclosing information from HSA4 notifications. The Service:

The Service's clinical lead is the single point of accountability for any HSA4 disclosure decision.

9. Lawful basis under UK GDPR

The Service processes patient personal data on the following bases:

The Service does not rely on Article 6(1)(a) consent as the primary lawful basis for clinical care. Consent is a clinical-care concept (separate from the GDPR concept); withdrawal of consent does not retroactively invalidate care already provided.

10. Patient rights

Patients have rights under UK GDPR including:

The Service provides a subject access response within one month of a valid request, free of charge in the first instance. The response considers the Abortion Regulations 1991 regulation 5 constraints (see section 8 above).

11. Communications and contact preferences

At every consultation, the Service confirms with the patient:

These preferences are recorded on the patient record and respected by every staff member who contacts the patient.

12. Data minimisation

The Service collects only the data necessary for the clinical purpose. In particular:

13. Retention

The Service retains:

At the end of the retention period the Service securely destroys the record and logs the destruction.

14. Sub-processors

The Service maintains a current list of sub-processors with access to patient personal data. This list is shared with patients on request and includes for each sub-processor:

15. Data breaches

A personal data breach affecting patient information is:

Termination data carries a particularly high reputational + safety risk if breached (e.g. data exposure to a coercing partner). The risk assessment reflects this; breaches of termination data are escalated as default-high-risk unless evidence supports otherwise.

16. Staff confidentiality obligations

All staff sign a confidentiality declaration at the start of employment, covering:

Breach of confidentiality is treated as a disciplinary matter and, where the breach involves a registered professional, is also referred to the relevant professional regulator (GMC, NMC, HCPC) for fitness-to-practise consideration.

17. Training

All Service staff complete:

18. Audit and monitoring

The data protection lead reviews the breach register and overdue rights requests every month. Each quarter, they sample 10 disclosures or all disclosures if fewer than 10 occurred, including at least one GP communication, one third-party request and one refusal or restricted disclosure where available.

The audit checks identity and authority, lawful basis and Article 9 condition, data minimisation, secure transfer, the disclosure log and compliance with the patient's contact preferences. Access permissions and the current processor list are reviewed at least annually and whenever a system or supplier changes.

Findings are recorded in the governance action plan with an owner, due date and closure evidence. An unexplained disclosure, repeated contact-preference failure, overdue reportable breach or unsupported access is escalated immediately rather than waiting for the next meeting. A follow-up sample must show that the corrective action worked.

19. Review

This policy is reviewed at least annually and whenever UK GDPR guidance, Data Protection Act 2018 amendments, Abortion Regulations 1991 amendments, or GMC confidentiality guidance materially changes.

20. Related policies in this pack

21. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

Original sources carried forward from this policy (verify before adoption):

Verivius source stack for this policy family:

22. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

23. Document control

Version Date Author Changes
v1.1 2026-07-19 Verivius (sample) Added role ownership, a disclosure workflow, audit cadence, governance escalation and linked companion policies.
v1 2026-06-10 Verivius (sample) Conformed the existing draft to the Verivius policy standard: added the standard disclaimer, statutory-anchor header block, verbatim Regulation 17 quotes, plain-English summary, Sources and further reading (all original source URLs carried forward plus the source-pack stack), When to seek further advice, and Document control. All original sections preserved and renumbered.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

Awaiting final verification

The Abortion Regulations 1991 regulation 5 confidentiality wording must be reconciled with your parent policy and confirmed by an abortion-law or data-protection specialist.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

Termination records are special-category data that carry an unusually direct safety risk: a controlling partner or family member who learns of the care can respond with real coercion or violence, so a single careless voicemail, an unguarded 'is she a patient here', or a leaked record is not only a confidentiality failure but a potential physical-safety one. The provider's confidentiality duty over its own record rests on the common law of confidence, UK GDPR and the Data Protection Act 2018, reinforced by GMC guidance and the exceptional sensitivity of termination data. The Abortion Regulations 1991 add a further statutory layer around the notification itself: once the HSA4 information is furnished to the Chief Medical Officer, regulation 5 restricts its onward disclosure, and even the terminating practitioner or another practitioner can be given it back only in the defined circumstances the regulation sets out. What stands between the person and a household member who is actively trying to find out is the everyday discipline: the no-confirm-or-deny default, the contact preferences recorded and honoured at every encounter, a single accountable clinical-lead sign-off on any HSA4 disclosure, and breaches of termination data treated as high-risk by default.

  1. Information from the HSA4 notification is held as a tighter class of record than the rest of the clinical file, with one named clinical lead accountable for any HSA4 disclosure, so it is not swept into a subject access response or passed to the GP on the same footing as ordinary care data. What harms the person is this exceptionally sensitive information leaving the service on the general confidentiality footing, without the explicit consent and the single accountable sign-off that termination data warrants.

    Strong evidence: The disclosure log showing HSA4-related requests routed to the named clinical lead, with the patient's explicit consent and the clinical-lead sign-off recorded before any release, and any subject access response that documents whether HSA4 material was included or withheld after the heightened confidentiality of termination data was specifically weighed (sections 8, 10).

    Weak evidence: HSA4 data handled on the same footing as the rest of the record, a subject access response that includes HSA4 material with no note that its heightened confidentiality was weighed, or no single accountable sign-off, so anyone with access could release it.

    The recognised standard from a professional or clinical body, such as NICE or a royal college. Not a legal duty, but the accepted mark of safe practice, and a departure needs a documented reason.
  2. A partner, family member or employer who contacts the service is neither confirmed nor denied to be connected to the person, and what may be shared and with whom is set by the person at every encounter, so a controlling partner cannot extract confirmation simply by telephoning. The harm here is a receptionist answering whether someone is a patient, rather than declining to confirm or deny.

    Strong evidence: The disclosure log and the standing rule that the service does not confirm or deny that a named person uses it, backed by the confidentiality declaration each staff member signs covering family, partner and GP enquiries (sections 6, 7, 16).

    Weak evidence: A disclosure-log entry where a caller was told a person is, or is not, a patient, or no standing rule at all, so the answer a household member gets depends on who happens to be on the desk that day.

    The recognised standard from a professional or clinical body, such as NICE or a royal college. Not a legal duty, but the accepted mark of safe practice, and a departure needs a documented reason.
  3. The person sets, and resets at each consultation, which number and channel may be used, whether a voicemail may be left and what it may say, and whether the GP may be told, and every staff member who contacts them works to those recorded preferences, so a reminder or voicemail does not disclose the care to a household member who was never meant to see it. What matters is that the preference is recorded and honoured, not just asked once and forgotten.

    Strong evidence: The recorded contact preferences on the patient record (permitted number and channel, voicemail permission and content, reminder permission, and the GP-informed choice) reconfirmed at each consultation, and the quarterly audit sampling whether contact-preference compliance actually held (sections 11, 18).

    Weak evidence: A record with no contact-preference fields, preferences captured once at registration and never revisited, or an audit that never checks whether a reminder went to a channel the person had ruled out, so the first sign of a breach is the person telling you a message reached the wrong phone.

    The recognised standard from a professional or clinical body, such as NICE or a royal college. Not a legal duty, but the accepted mark of safe practice, and a departure needs a documented reason.
  4. Each category of processing of the person's data carries a recorded lawful basis with an Article 9 condition wherever the special-category termination data is involved, and the service does not treat data-protection consent as the basis for clinical care, so withdrawing agreement to one disclosure does not unravel the lawful basis for the care record itself. The gap that matters is termination data logged with an Article 6 basis and no Article 9 condition recorded anywhere.

    Strong evidence: The record of processing activities or lawful-basis register recording, per activity, the Article 6 basis and the Article 9 condition for the special-category data, verified against current source rather than written once at adoption (section 9).

    Weak evidence: A privacy notice standing in for the register, special-category termination data carrying an Article 6 basis but no Article 9 condition, or the service relying on data-protection consent as the basis for clinical care, so the record's lawfulness looks as though it collapses the moment consent is withdrawn.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 9(2)(h), read with Article 6(1)(c); Data Protection Act 2018 Schedule 1 Part 1 paragraph 2 (health or social care purposes)

  5. A breach of termination data is risk-assessed as high by default because exposure to a coercing partner can cause real harm, the notification to the Information Commissioner and the communication to the affected person are worked as two separate decisions, and neither of them, nor a safeguarding referral, is treated as discharging the others. What exposes more people is a termination-data breach quietly assessed as low with no reasoning for departing from the high-risk default.

    Strong evidence: The data-breach register carrying the date the service became aware, the risk assessment recording why the termination-data breach was treated as high-risk, the Information Commissioner notification made without undue delay and, where feasible, within 72 hours of becoming aware, with reasons for any delay, and the separate recorded decision on informing the affected person (sections 15, 18).

    Weak evidence: A single reportable yes-or-no field, so the duty to tell the affected person is never separately tested, a termination-data breach downgraded to low with no rationale, or a breach closed on the regulator's reference number as though that discharged both the duty owed to the person and any safeguarding concern.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 33(1) (notification to the Commissioner) and Article 34(1) (communication to the data subject)

  6. Termination records are held under access by role, with access removed the day a person's role changes and access logs reviewed where a concern is raised, and no information leaves the service until the requester's identity and authority to receive it are verified and logged. The person is put at risk when a household member obtains the record by impersonation, or a staff member browses a neighbour's record undetected, because access was shared and disclosures went unverified.

    Strong evidence: The access-control register recording user, role, permissions and the start, review, change and removal dates, the disclosure log showing identity and authority verified before release, and the quarterly disclosure sample and at least annual access-permission review that test both actually happened (sections 5, 7, 18).

    Weak evidence: Shared logins to the record system, so access by role cannot be shown, a disclosure released to a caller recognised by voice with no identity check logged, or an access list with names but no removal dates, so a leaver still has a live role on the system.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 32(1) and 32(4), read with Article 5(1)(f); Data Protection Act 2018 s.170 (unlawful obtaining of personal data)

Last verified 20 July 2026

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 10 June 2026