Governance
Data protection and information governance
We handle sensitive health information every day, and treat information governance as part of clinical safety, not a back-office task.
Our commitment
We comply with the UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality, and healthcare information-governance standards. This page describes the framework behind our privacy policy.
Accountability and roles
| Role | Held by | Responsibility |
|---|---|---|
| Data controller | [LEGAL ENTITY NAME] | Accountable for all processing of personal data. |
| Data Protection Officer | [DPO NAME], [DPO EMAIL] | Advises on and monitors compliance; contact point for individuals and the ICO. |
| Caldicott Guardian | [CALDICOTT GUARDIAN] | Protects the confidentiality of patient information and enables appropriate sharing. |
| Senior Information Risk Owner | [SIRO] | Owns information risk at senior level. |
Some clinicians we work with, in particular the independent consultant psychiatrists we refer to and share care with, are not employed by or incorporated within The Members’ Clinic. They act as separate data controllers for the care they provide, keeping their own records and meeting their own regulatory duties. We share information with them with your consent and under appropriate data-sharing arrangements; they are not our processors.
The Caldicott Principles
When we use confidential patient information we apply the eight Caldicott Principles: justify the purpose; use it only when necessary; use the minimum necessary; access on a strict need-to-know basis; everyone is aware of their responsibilities; comply with the law; the duty to share information for care can be as important as the duty to protect confidentiality; and inform patients about how their data is used.
How we protect information
- Security: access controls, encryption in transit and at rest, audited systems, and secure disposal.
- Need-to-know: staff see only the information their role requires; access is logged.
- Contracts: every processor (IT, records, payments) is bound by a written data-processing agreement.
- Training: all staff complete information-governance and confidentiality training and refresh it regularly.
- By design: we run Data Protection Impact Assessments for higher-risk processing (for example genetic data or the workplace-to-clinical transition).
Personal data breaches
We have a breach procedure. We investigate and contain any incident, notify the ICO within 72 hours where the law requires, and tell affected individuals without undue delay where there’s a high risk to them.
How long we keep records
We keep records only as long as necessary, in line with the Records Management Code of Practice 2021. Indicative periods:
| Record type | Indicative retention |
|---|---|
| Adult clinical / health records | 8 years after last contact |
| Children & young people’s records | Until 25th birthday (or 26th if last entry at 17); defined exceptions apply |
| Mental health records | Per the Records Management Code of Practice; some categories longer |
| Enquiries not proceeding to care | Short period (e.g. up to 12 months), then deleted |
| Recruitment (unsuccessful applicants) | 6 to 12 months |
| Financial / invoicing records | 6 years (tax) |
Your individual rights, and how to exercise them, are set out in our privacy policy. For any information-governance query, contact [DPO EMAIL]. You can complain to the ICO at ico.org.uk. Effective [EFFECTIVE DATE] · Last updated [LAST UPDATED].