Privacy Notice

Heathcot Medical Practice

Version: 2.0
Effective date: 30 July 2026
Next review date: July 2027, or sooner if our services, suppliers or legal obligations change

1. About this privacy notice

Heathcot Medical Practice is committed to protecting the privacy, confidentiality and security of your personal information.

This privacy notice explains:

  • What information we collect about you

  • Where we obtain your information

  • Why and how we use it

  • Our lawful bases for processing it

  • Who we may share it with

  • Which organisations process information on our behalf

  • Whether information may be processed outside the United Kingdom

  • How long we retain information

  • Your rights under data-protection law

  • How to contact us or raise a concern

This notice applies to patients, former patients, prospective patients, carers, representatives and other people whose personal information we process when providing or managing healthcare services.

Some services have their own supplementary privacy notices. These should be read alongside this main practice privacy notice.

2. Who is responsible for your information?

Heathcot Medical Practice is the Data Controller for the personal information it holds about its patients and service users.

This means that the practice is responsible for deciding why and how your personal information is collected, used, shared and protected.

Data Controller contact details

Dr Navin Kumar
Heathcot Medical Practice
York House Medical Centre
Heathside Road
Woking
Surrey
GU22 7XL

Telephone: 01483 761100
Email: heathcotmedicalpractice@nhs.net

Data Protection Officer

Our Data Protection Officer provides independent advice and support regarding our data-protection responsibilities.

Dan Clement
Associate Director ICS Information Governance/Data Protection Officer
NHS Kent and Medway Integrated Care Board

Email: kmicb.ig@nhs.net
Telephone: 01634 335095

Postal address:

NHS Kent and Medway Integrated Care Board
2nd Floor, Gail House
Lower Stone Street
Maidstone
ME15 6NB

3. What information do we collect?

The information we collect depends on the care or service you receive.

Personal and identifying information

This may include:

  • Your name

  • Address

  • Date of birth

  • NHS number

  • Telephone number and email address

  • Sex and gender information

  • Marital or relationship status

  • Next-of-kin details

  • Details of parents, guardians, carers or representatives

  • Preferred language and communication requirements

  • Information about disabilities and reasonable adjustments

  • Photographs or identity documents where necessary

Health and care information

This may include:

  • Your medical history

  • Diagnoses and health conditions

  • Symptoms and healthcare concerns

  • Medications, allergies and adverse reactions

  • Vaccination records

  • Test and investigation results

  • Consultation notes

  • Hospital letters and discharge information

  • Referrals

  • Treatment and care plans

  • Details of appointments, home visits and telephone contacts

  • Mental health information

  • Sexual and reproductive health information

  • Family history relevant to your care

  • Social-care and safeguarding information

  • Information provided through questionnaires, online forms or digital services

Other sensitive information

Where relevant to your care or our legal responsibilities, we may process information about:

  • Racial or ethnic origin

  • Religious or philosophical beliefs

  • Sexual orientation

  • Genetic or biometric information

  • Criminal allegations or convictions

  • Immigration status

  • Safeguarding concerns

  • Domestic abuse or other risks to safety

Communications and technical information

This may include:

  • Emails and text messages

  • Online consultation submissions

  • Webchat and online-form information

  • Telephone-call information, recordings or transcripts where applicable

  • IP addresses and device information

  • Audit trails showing who has accessed or changed a record

  • Information about the use of our website and digital services

Financial and administrative information

Where relevant, we may process:

  • Information needed to confirm eligibility for NHS services

  • Payment information for private or non-NHS services

  • Information required for invoicing, claims or funding

  • Complaint and feedback records

We only collect information that is relevant and reasonably necessary for the purpose for which it is being used.

4. Where do we obtain your information?

We normally obtain information directly from you when you:

  • Register with the practice

  • Attend an appointment

  • Speak to a clinician or member of staff

  • Contact us by telephone, email, letter or online service

  • Use the NHS App or another approved digital service

  • Complete a questionnaire or form

  • Request a prescription

  • Ask for advice or treatment

  • Make a complaint or provide feedback

  • Ask another person to contact us on your behalf

We may also receive information from:

  • Your previous GP practice

  • NHS hospitals and community services

  • Mental health services

  • Ambulance and out-of-hours services

  • Pharmacies

  • Dentists and optometrists

  • NHS England

  • Surrey Heartlands Integrated Care Board

  • GP federations and Primary Care Networks

  • Local authorities and social-care services

  • Public-health organisations

  • Care homes and home-care providers

  • Schools and education providers, where appropriate

  • Police, courts and safeguarding organisations

  • Private healthcare providers

  • Your relatives, carers, representatives or advocates

  • Patient-facing applications and approved digital services

We also create information about you while providing care, such as consultation notes, diagnoses, referrals, test results and care plans.

Where information is not obtained directly from you, we will only use it where there is an appropriate legal basis and confidentiality justification.

5. Why do we use your information?

Providing direct healthcare

We use your information to:

  • Assess your health needs

  • Diagnose and treat medical conditions

  • Prescribe and monitor medication

  • Request tests and investigations

  • Make referrals

  • Coordinate your care with other services

  • Review and monitor ongoing conditions

  • Provide screening, immunisations and preventative care

  • Respond to your enquiries

  • Maintain an accurate medical record

Our usual lawful bases are:

  • Article 6(1)(e) UK GDPR: processing is necessary for a task carried out in the public interest or in the exercise of official authority

  • Article 9(2)(h) UK GDPR: processing is necessary for medical diagnosis, the provision of health or social care, or the management of health or social-care systems and services

We also comply with the Common Law Duty of Confidentiality.

Managing the practice and our services

We use information to:

  • Arrange and manage appointments

  • Send appointment reminders and healthcare messages

  • Manage prescriptions, test results, referrals and correspondence

  • Respond to complaints and feedback

  • Monitor the quality and safety of our services

  • Conduct clinical audits and quality-improvement work

  • Plan and manage practice services

  • Investigate incidents and significant events

  • Process payments, invoices and NHS claims

  • Meet contractual, professional and regulatory requirements

Our usual lawful bases are Article 6(1)(e) and Article 9(2)(h) UK GDPR.

Safeguarding children and adults

We may use and share information where necessary to protect a child or adult from abuse, neglect, exploitation or serious harm.

Depending on the circumstances, we may rely on:

  • Article 6(1)(c): compliance with a legal obligation

  • Article 6(1)(e): performance of a public task

  • Article 9(2)(g): substantial public interest

  • Article 9(2)(h): provision or management of health or social care

Consent is not always required where information needs to be shared to protect someone from harm.

Public health

We may process information for:

  • Infectious-disease monitoring and reporting

  • Vaccination programmes

  • Screening programmes

  • Disease surveillance

  • Protecting the public from serious health threats

  • Monitoring the safety and quality of healthcare

Depending on the activity, we may rely on Article 6(1)(c) or Article 6(1)(e), together with Article 9(2)(i) UK GDPR.

Legal and regulatory requirements

We may process or disclose information where this is required by:

  • Legislation

  • A court order

  • A coroner

  • NHS contractual requirements

  • The Care Quality Commission

  • NHS England

  • The Information Commissioner’s Office

  • A professional regulator

  • A public-health authority

  • Another authorised public body

Our lawful basis will usually be Article 6(1)(c) or Article 6(1)(e), together with an appropriate Article 9 condition.

Research, audit and service evaluation

We may use information for approved:

  • Medical and health research

  • Clinical audit

  • Service evaluation

  • Healthcare planning

  • Quality improvement

  • Public-health surveillance

  • National disease registries

Where possible, information will be anonymised or pseudonymised so that patients are not directly identified.

Identifiable information will only be used where there is an appropriate lawful basis and a valid basis for using confidential patient information. This may include consent, statutory authority or approval under health-service legislation.

Private and non-NHS services

Where you request a private or non-NHS service, we may process information because it is necessary to provide the service or take steps at your request.

Depending on the service, the lawful basis may include:

  • Article 6(1)(b): performance of a contract

  • Article 6(1)(c): compliance with a legal obligation

  • Article 6(1)(e): performance of a public task

  • An appropriate Article 9 condition for health information

Consent

We do not normally rely on consent to provide NHS healthcare because other lawful bases apply.

We may ask for consent where it is appropriate, for example for certain research activities, optional communications or disclosure to a third party that is not otherwise involved in your care.

Where we rely on consent, you may withdraw it at any time.

Vital interests

In a medical emergency, we may process or share information where it is necessary to protect your life or the life of another person and you are unable to provide consent.

6. The Common Law Duty of Confidentiality

Health information provided in confidence is protected by the Common Law Duty of Confidentiality.

We will normally use or share confidential information:

  • For your direct care

  • With your consent

  • Where there is another lawful justification

Information may sometimes be used or shared without consent where:

  • There is a legal requirement

  • A court orders disclosure

  • It is necessary to safeguard a child or vulnerable adult

  • There is a serious risk to you or another person

  • Disclosure is necessary in the public interest

  • Statutory approval permits the use of confidential patient information

Any disclosure will be limited to what is necessary and proportionate.

7. Specific ways in which information may be used or shared

Direct care and local information sharing

Relevant information may be shared with authorised health and social-care professionals involved in providing your care.

This may include information shared through approved systems such as:

  • GP Connect

  • The Summary Care Record

  • The Surrey Care Record

  • Electronic referral services

  • Electronic prescription services

  • Shared-care and medicines-management systems

Access is restricted to authorised professionals with an appropriate reason to view the information.

Child Health Information Service

Relevant information may be shared with the Child Health Information Service, health visitors and school-nursing services to support childhood immunisations, health checks and other child-health services.

Medicines management

Pharmacists and medicines-optimisation teams may access relevant information to:

  • Support safe prescribing

  • Review medication

  • Answer prescribing queries

  • Monitor medication safety

  • Improve the effectiveness and cost-effectiveness of treatment

Risk stratification

Risk stratification may be used to identify patients who may benefit from additional support, preventative care or earlier intervention.

Where possible, information used for service planning is anonymised or pseudonymised.

Invoice validation and funding

Limited information, which may include your NHS number, may be used to confirm which NHS organisation is responsible for funding your treatment and to ensure healthcare providers are paid correctly.

Care Quality Commission

The Care Quality Commission has legal powers to access information where this is necessary for it to carry out its regulatory functions.

National Fraud Initiative

Information may be used for authorised data-matching exercises to prevent and detect fraud where there is a statutory basis.

National registries, audits and data collections

Information may be provided to approved national registries, audits and data collections where there is an appropriate legal basis.

This may include:

  • National clinical audits

  • Disease registries

  • Cancer registration

  • Public-health surveillance

  • General practice data collections

  • Healthcare planning and research services

Where possible, information will be anonymised or pseudonymised.

8. Who may we share information with?

Where it is appropriate, necessary and lawful, we may share information with:

  • NHS hospitals and community services

  • Mental health services

  • Ambulance and out-of-hours services

  • Pharmacies

  • Dentists and optometrists

  • GP federations and Primary Care Networks

  • NHS England

  • Surrey Heartlands Integrated Care Board

  • Local authorities and social-care providers

  • Public-health organisations

  • Care homes and home-care agencies

  • Hospices

  • Safeguarding partnerships

  • Police, courts and coroners

  • The Care Quality Commission

  • Professional regulators

  • Approved research organisations

  • Private healthcare providers involved in your care

  • Your authorised representative, carer or advocate

  • Organisations you have asked us to share information with

We do not sell patient information.

We do not provide patient information to advertisers or use clinical information for targeted commercial advertising.

9. Organisations that process information on our behalf

A data processor is an organisation that processes personal information on behalf of the practice and under our instructions.

Our main data processors and digital-service providers include:

ProcessorService providedEMIS Group Limited, trading as Optum/EMISElectronic patient-record and clinical-administration systemsAccurx LimitedPatient messaging, online consultations, questionnaires, forms and appointment communicationsOneAdvanced/DocmanClinical-document receipt, storage, filing and workflow managementMedLink Solutions LtdLong-term-condition reviews, patient questionnaires, recall processes and communicationsQuantumLoop Technologies LtdDigital-assistant services. Please see our separate EMMA and Nina Digital Assistants Privacy Notice for further informationNHSmail and authorised NHS service providersSecure email and NHS communication servicesNHS South, Central and West Commissioning Support Unit – NHS SCW CSUIT maintenance, information security, technical support and management of practice systemsX-on Health Ltd – Surgery ConnectPractice telephone systems, call routing, call-management functions and related communication servicesLiviPractice website hosting, online website services, forms and technical supportShred-itSecure collection and destruction of confidential paper records and other confidential waste

These organisations are required to:

  • Process information only for agreed purposes

  • Follow our documented instructions

  • Maintain appropriate confidentiality and security

  • Comply with data-protection law

  • Notify us of relevant information-security incidents

  • Delete or return information when required under their contracts

Some processors may use approved sub-processors to provide specific technical functions.

The practice maintains a current processor and sub-processor register. Further information may be requested from the Practice Manager or Data Protection Officer.

10. Processing outside the United Kingdom

Some organisations that provide services to the practice may process limited personal information outside the United Kingdom.

Where information is transferred internationally, we require an appropriate legal transfer mechanism and safeguards to be in place.

These may include:

  • UK adequacy regulations

  • The International Data Transfer Agreement

  • The UK Addendum to approved standard contractual clauses

  • An approved UK international data-transfer framework

  • Contractual security requirements

  • Encryption and access controls

  • Data minimisation

  • A transfer risk assessment or equivalent assessment

Details of service-specific international processing will be included in the relevant supplementary privacy notice where appropriate.

Further information about international transfers and safeguards may be requested from the practice or our Data Protection Officer.

11. Automated decision-making

Heathcot Medical Practice does not currently use solely automated processing to make final decisions about a patient’s diagnosis, treatment or access to essential healthcare where the decision would have a legal or similarly significant effect.

Digital systems may assist staff with administrative or clinical workflows, but decisions requiring clinical or professional judgement remain the responsibility of an appropriate member of the practice team.

Where a particular digital service requires additional transparency information, this will be provided in a separate service-specific privacy notice.

12. National Data Opt-Out and Type 1 Opt-Out

National Data Opt-Out

The National Data Opt-Out allows you to choose whether your confidential patient information can be used for research and planning where the opt-out applies.

The National Data Opt-Out does not normally prevent information from being used:

  • For your direct care

  • Where there is a legal requirement

  • For safeguarding

  • For certain public-health purposes

  • Where the information is anonymised

  • Where another exemption applies

You can set or change your preference through the NHS Your NHS Data Matters service.

Type 1 Opt-Out

A Type 1 Opt-Out may prevent confidential patient information held by the practice from being shared outside the practice for certain purposes beyond your individual care.

It does not prevent information being shared where:

  • It is needed for your direct care

  • There is a legal requirement

  • An exemption applies

  • The information is anonymised

Please contact the practice if you would like further information or wish to register a Type 1 Opt-Out.

13. OpenSAFELY

NHS England has been directed by the government to establish and operate OpenSAFELY services.

OpenSAFELY is a secure data-analysis platform that supports approved:

  • Research

  • Clinical audit

  • Service evaluation

  • Health surveillance

  • Healthcare planning

  • Service improvement

Each GP practice remains the Data Controller for the patient information held within its own clinical system.

OpenSAFELY allows approved users, such as authorised researchers and analysts, to run approved analyses on pseudonymised information held securely within GP clinical-system environments.

Pseudonymised information has identifying details removed and replaced with a code.

The system is designed so that approved users do not routinely view identifiable patient records. Information remains within a secure environment, and only approved results that meet disclosure-control requirements may be released.

Projects using OpenSAFELY must have an appropriate lawful basis, approval and governance arrangements.

Patients can register a Type 1 Opt-Out with the practice. Type 1 Opt-Outs will be applied in accordance with current NHS England directions and OpenSAFELY arrangements.

Please contact the practice if you would like further information about Type 1 Opt-Outs.

14. How long do we keep your information?

We retain personal information only for as long as it is necessary.

Different types of records have different retention periods. Patient and practice records are managed in accordance with:

  • The NHS Records Management Code of Practice

  • Data-protection legislation

  • NHS contractual requirements

  • Professional and regulatory guidance

  • Relevant legal limitation periods

  • The requirements of ongoing care, complaints, investigations or legal proceedings

GP health records are retained and transferred in accordance with current NHS records-management requirements.

Other information, including messages, telephone recordings, online forms, administrative records and technical logs, may have shorter retention periods.

Information that is no longer required will be securely deleted, destroyed or anonymised.

Further information about our retention arrangements is available from the practice.

15. How do we protect your information?

We use appropriate technical and organisational safeguards, including:

  • Role-based access controls

  • Secure passwords and authentication

  • Electronic audit trails

  • Encryption

  • Secure NHS systems

  • Staff confidentiality agreements

  • Data-protection and information-security training

  • Secure backup arrangements

  • Business-continuity procedures

  • Data-processing contracts

  • Supplier security assessments

  • Data Protection Impact Assessments

  • Incident-reporting and investigation procedures

Access to patient information is limited to authorised people who require it for their role.

Everyone working for or on behalf of the practice is required to protect patient confidentiality.

16. Your data-protection rights

Your rights depend on the circumstances and the lawful basis being used.

Right to be informed

You have the right to receive clear information about how we collect and use your personal information.

Right of access

You may ask whether we hold information about you and request a copy of that information.

Right to rectification

You may ask us to correct information that is inaccurate or complete information that is incomplete.

Clinical opinions cannot necessarily be changed because you disagree with them, but your disagreement may be recorded where appropriate.

Right to erasure

You may ask for information to be deleted in certain circumstances.

This right is limited in relation to medical records because the practice may be required to retain accurate information for healthcare, legal, regulatory or public-interest reasons.

Right to restrict processing

You may ask us to temporarily restrict how information is used while a concern about its accuracy or use is considered.

Right to object

You may object to certain uses of your information.

This is not an absolute right. We may continue processing where:

  • There are compelling lawful reasons

  • Processing is necessary for your care

  • There is a legal requirement

  • Processing is needed to establish, exercise or defend a legal claim

Right to data portability

This right may apply where processing is automated and is based on consent or a contract.

It does not apply to most processing of GP medical records carried out as a public task.

Right to withdraw consent

Where we rely specifically on your consent, you may withdraw it at any time.

Withdrawing consent does not affect processing that took place before consent was withdrawn. It also does not prevent us from continuing to use information where another lawful basis applies.

Rights relating to automated decisions

You have rights relating to certain decisions made solely through automated processing that produce a legal or similarly significant effect.

The practice does not currently use solely automated systems to make final clinical decisions of this nature.

17. Accessing your information

A request for access to your personal information is known as a Subject Access Request.

You may make a request verbally or in writing by contacting the practice.

We may ask for information to:

  • Confirm your identity

  • Confirm that a representative has authority to act for you

  • Help us locate the information you require

  • Clarify the scope of a large or complex request

We will normally respond without undue delay and within one month.

The response period may be extended where a request is complex or where several requests have been made. We will inform you if an extension is necessary.

There is normally no charge.

A reasonable fee may only be considered in limited circumstances, such as where a request is manifestly unfounded or excessive or where additional copies are requested.

Information may be withheld or redacted where a legal exemption applies, including where disclosure would:

  • Reveal confidential information about another person

  • Be likely to cause serious harm

  • Prejudice an ongoing investigation

  • Breach another legal obligation

18. Children, young people and representatives

Children and young people have data-protection rights in their own right.

Whether a child can exercise those rights independently will depend on their age, understanding and individual circumstances.

A parent or person with parental responsibility does not have an automatic right to all information in a child’s record.

The practice must consider:

  • The child’s best interests

  • The child’s capacity and confidentiality

  • Parental responsibility

  • Safeguarding concerns

  • Information relating to other people

A representative, carer, advocate or person with legal authority may act on someone’s behalf where appropriate.

We may ask for evidence of consent, parental responsibility, power of attorney or other legal authority.

19. Complaints and concerns

Please contact the practice if you have concerns about how your personal information has been collected, used, shared or protected.

Heathcot Medical Practice complaints team

Email: syheartlandsicb.hmpfeedback@nhs.net
Telephone: 01483 761100

Alternatively, you may complete the Feedback Form available on our website.

You may also contact our Data Protection Officer:

Dan Clement
Associate Director ICS Information Governance/Data Protection Officer
NHS Kent and Medway Integrated Care Board

Email: kmicb.ig@nhs.net
Telephone: 01634 335095

Postal address:

NHS Kent and Medway Integrated Care Board
2nd Floor, Gail House
Lower Stone Street
Maidstone
ME15 6NB

You also have the right to complain to the Information Commissioner’s Office if you are concerned about how your personal information has been handled.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113

Further information and the ICO’s online complaint service are available through the Information Commissioner’s Office website.

The Information Commissioner’s Office has offices serving England, Scotland, Wales and Northern Ireland. Contact details for each office are available on its website.

You do not have to contact the practice before approaching the Information Commissioner’s Office, although we welcome the opportunity to investigate and address your concerns directly.

20. Supplementary privacy notices

This main practice privacy notice should be read alongside any relevant supplementary privacy notices, including:

  • EMMA and Nina Digital Assistants Privacy Notice

  • Website and Cookies Privacy Notice

  • Staff Privacy Notice

  • Job Applicant Privacy Notice

  • Research-specific privacy information

  • Any other service-specific notices published by the practice

21. Reviews and changes to this privacy notice

We keep this privacy notice under regular review.

It may be updated when:

  • Our services change

  • A new system or supplier is introduced

  • A processor or sub-processor changes

  • We use information for a new purpose

  • International-processing arrangements change

  • Data-protection law, NHS guidance or government directions change

The current version will be published on the practice website. Where a change is significant, we will take reasonable steps to bring it to patients’ attention.

Date approved: 30 July 2026
Version: 2.0
Approved by: Heathcot Medical Practice Partners
Policy owner: Deputy Practice Manager/Data Protection Lead
Next review date: July 2027, or sooner if required

Date Published: 10th April, 2025
Date Last Updated: 30th July, 2026