How do I comply with UK GDPR in my private practice?
Your lawful basis, privacy notice, security, patient messaging, breaches and rights, set out for a small private GP service.
The short answer
As the data controller for your private patients, you need a lawful basis and a health-care condition for using their data, a privacy notice, written contracts with suppliers, security that fits the risk, and procedures for access requests, complaints and breaches. Most problems in small practices come from everyday communication, so keep confidential detail out of unencrypted email and texts. Report serious breaches to the ICO within 72 hours.
Key points
- Health data is special category data. You need an Article 6 lawful basis and an Article 9 condition, usually the health or social care condition.
- Your record system, email and IT suppliers are processors and need written contracts.
- Keep confidential detail out of unencrypted texts and emails, and use only approved messaging tools.
- Record every breach, and report ones that put patients at risk to the ICO within 72 hours.
- Since June 2026 you must acknowledge data protection complaints within 30 days.
- A solo GP usually does not need a formal DPO, but new high-risk tools such as AI scribes need a DPIA.
The law that applies
In the UK the rules are the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Alongside them sit the common-law duty of confidentiality and GMC guidance on confidentiality, which apply to you as a doctor whether the patient pays or not.
Health information is special category data. That means stricter conditions for using it, and it means a breach is more likely to harm the patient. Treat everything you hold about patients, including booking details and emails, as confidential.
Your role: controller, with processors
If you decide how your private patients’ records are kept and used, you are the data controller. You pay the ICO data protection fee (see do I have to register with the ICO?) and you are accountable for compliance.
Your record system, email provider, IT support company and payment provider usually act as your processors. Each needs a written contract that covers what UK GDPR requires. How private GPs store their notes covers the supplier questions in more detail.
Your lawful basis
For health data you need two things: an Article 6 lawful basis and an Article 9 condition. The ICO is clear that the special category condition sits on top of the Article 6 basis. It does not replace it.
- Article 9: the health or social care condition (Article 9(2)(h)) covers providing care. It must be by or under the responsibility of someone bound by a duty of confidentiality, which a doctor is.
- Article 6: choose the basis that fits the processing, for example contract for providing care the patient has booked, and write it down.
Marketing is a separate purpose with its own rules, including consent for most marketing emails and texts. Don’t use clinical contact details for marketing without checking those rules.
Tell patients what you do
Publish a privacy notice and point to it at booking. The ICO lists what it must cover, including:
- who you are and how to contact you
- why you use their data and your lawful basis
- who you share it with, such as their NHS GP, laboratories and your suppliers
- how long you keep records
- their rights, and their right to complain to the ICO
- any transfers outside the UK, for example if a supplier hosts data abroad.
Security that fits the risk
UK GDPR requires appropriate technical and organisational measures. For a small private practice that usually means:
- a record system and email service with multi-factor authentication, and individual logins for everyone
- encrypted laptops and phones, with automatic updates and a screen lock
- no patient data on personal messaging apps, personal email or unencrypted USB sticks
- backups you have tested, and a plan for when a system is down
- staff training at induction and every year.
Cyber Essentials, the government-backed scheme run with the National Cyber Security Centre (NCSC), covers five basic controls: firewalls, secure configuration, security updates, user access control and malware protection. It is a useful baseline to meet, and certification is renewed every 12 months. If you connect to NHS systems such as NHSmail or MESH, you also need the NHS Data Security and Protection Toolkit (DSPT). See setting up your IT.
Email, texts and messaging
Most breaches in small practices involve communication: the wrong recipient, the wrong attachment, or detail sent over an insecure channel. NHS England’s guidance on messaging patients is a sensible model for private practice too:
- You do not need consent to message patients about their own care, but record and respect their preferences.
- Keep confidential detail out of unencrypted texts and emails. “Your results are ready, please log in or call us” is safer than naming a condition.
- Use encrypted email or a secure portal for letters, results and anything sensitive.
- Only use messaging tools your practice has approved.
- Check contact details at each booking, and keep a copy or summary of messages in the record.
See secure email without NHSmail and communicating with patients.
Patients’ rights and complaints
Patients can ask for a copy of their records, and you normally have one month to respond. They can also ask you to correct inaccurate information. Since June 2026, under the Data (Use and Access) Act 2025, organisations must also give people a clear way to make a data protection complaint, acknowledge it within 30 days and tell them the outcome. Build this into your complaints procedure.
When something goes wrong
Record every personal data breach, including near misses you decide not to report. If a breach is likely to put people’s rights and freedoms at risk, report it to the ICO within 72 hours of becoming aware of it. If the risk to patients is high, tell them directly as well.
Do you need a DPO or a DPIA?
A data protection officer is required when core activities involve large-scale processing of special category data. The ICO’s guidance treats an individual GP or health professional processing patient data as generally not large-scale, while a hospital is. A single-doctor service therefore usually does not need a formal DPO, although it still needs someone who owns data protection. A larger multi-site clinic should take advice.
A data protection impact assessment (DPIA) is required for high-risk processing. Do one when you introduce something new and higher risk, such as an AI scribe that records consultations. NHS England’s guidance on ambient scribing products expects a DPIA before use.
A practical checklist
- Pay the ICO fee and name who is responsible for data protection.
- List what data you hold, where it is, who can see it and how long you keep it.
- Record your Article 6 basis and Article 9 condition.
- Publish a privacy notice and link to it at booking.
- Put processor contracts in place with every supplier that handles patient data.
- Set up multi-factor authentication, encryption, updates and backups.
- Write short procedures for access requests, complaints and breaches.
- Train everyone, and review the whole list once a year.
Across the UK
UK GDPR, the Data Protection Act 2018 and the ICO cover the whole UK. The DSPT is an NHS England requirement for organisations using NHS data and systems. If you work in Scotland, Wales or Northern Ireland, check what the local NHS asks for before connecting to its systems.
Tools that can help
Frequently asked questions
Is GDPR different for private practice than for the NHS?
The same law applies, but NHS bodies usually rely on public task as their lawful basis and private providers do not. You also carry the whole compliance job yourself rather than relying on a trust or ICB information governance team.
Can I use WhatsApp to talk to patients?
Not for clinical information on a personal phone. If you use any messaging tool, it should be one your practice has approved, with messages saved to the record and no patient data left on personal devices.
Do patients need to consent to me sending their notes to their NHS GP?
Sharing for direct care is lawful under UK GDPR, but GMC confidentiality guidance and good practice mean you should tell patients and respect an objection. Ask at booking and record their answer.
How long should I keep private GP records?
UK GDPR does not set a period. Most private GPs follow the NHS Records Management Code of Practice as a benchmark and state their retention period in the privacy notice.
Do I need the DSPT if I am purely private?
Only if you have access to NHS patient data and systems, for example NHSmail or MESH. It is still a useful framework for checking your security even if you do not.
Sources
- What are the rules on special category data?
- What privacy information should we provide?
- Personal data breaches: a guide
- When do we need to do a DPIA?
- New data protection complaints law now in force
- Texting, emailing and messaging patients and service users: guidance for health and care professionals
- Cyber Essentials overview
- Guidance on the use of AI-enabled ambient scribing products in health and care settings
