GDPR Privacy Notice for Patients

How Edinburgh GP uses your information to provide you with healthcare

This privacy notice lets you know what happens to any personal data that you give to us, or any information that we may collect from you or about you from other organisations.

This privacy notice applies to personal information processed by or on behalf of the practice.

Edinburgh GP Ltd is the data controller (ICO registration number: ZB545933) and is responsible for ensuring that your personal information is processed fairly, lawfully, securely and transparently in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and applicable professional confidentiality requirements, including General Medical Council standards.

We are required to have a lawful basis for processing your personal information. Where we process health information, which is special category data, we must also meet an additional condition under Article 9 of the UK GDPR.

About the personal information Edinburgh GP uses


Any information Edinburgh GP collects will be for specific, explicit and legitimate purposes and will be adequate, relevant and limited to what is necessary in relation to those purposes. Furthermore, information will be accurate and, where necessary, kept up to date. Every reasonable step will be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.

This information is collected from:
• you as the patient when booking an appointment or enquiring by telephone, email, website or in person, or following you completing a ‘Patient Medical History Registration Form’
• health insurers by telephone or email, if they are booking an appointment on your behalf
• your employer, by email if they are booking an appointment on your behalf, or where there is a contractual agreement for a service or services we provide to your company
• by the doctor at your consultation appointment
• a family member by telephone, email or through the website if they are booking an appointment on your behalf
• other healthcare professionals or organisations involved in your care, where information is provided to us for the purposes of your healthcare
• other organisations where this is necessary to provide healthcare, administer our services, meet legal or professional obligations, or where otherwise permitted by law.

Where we obtain personal information about you from another person or organisation, we will use that information in accordance with applicable data protection legislation and our duties of confidentiality.

Your information will be retained in accordance with applicable legal, professional and regulatory requirements. The GP record for an individual must be held for the lifetime of the patient, and ten years after death (longer periods may apply in instances of, public inquiries, investigations, fatal accident inquiries etc.). We do not retain personal information indefinitely where there is no lawful or necessary reason to do so.

Information will be processed in a manner that ensures appropriate security of the records, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures.

Edinburgh GP has a legal and professional duty to keep personal health information secure and confidential. Information is recorded electronically and access is restricted to authorised individuals who require access for legitimate work purposes. Staff and clinicians are subject to confidentiality obligations.

What personal information is collected


Personal information includes facts (e.g. treatment and tests you have had) and opinions (e.g. any concerns you or the doctor might have about your medical health). To provide safe and appropriate care for you, accurate and comprehensive personal information is required.

The following records may be kept and updated regularly:
• personal information and contact details, including your name, date of birth, address, email address, NHS GP and Next of Kin
• medical history (e.g. past and/or current medical conditions and medications), family history and lifestyle
• information about appointments
• treatments and their costs
• any proposed care, including advice we give to you and referrals you might need
• details of any consents required
• correspondence with third-party providers that relates to your care, such as other healthcare providers, laboratory results and your employer, where applicable
• information relating to payments, billing, insurance and administration where applicable
• information required to meet our legal, regulatory, professional and governance obligations.

UK GDPR singles out some types of personal data as likely to be more sensitive and gives them extra protection which is referred to as ‘special category data’.

This includes:
• personal data revealing racial or ethnic origin
• personal data revealing political opinions
• personal data revealing religious or philosophical beliefs
• personal data revealing trade union membership
• genetic data
• biometric data, where used for identification purposes
• data concerning health
• data concerning a person’s sex life
• data concerning a person’s sexual orientation.
Some information relating to characteristics protected under the Equality Act 2010 may also constitute special category data depending on the circumstances, for example information concerning disability, pregnancy or gender reassignment.

Where we process special category data, we must identify both a lawful basis under Article 6 of the UK GDPR and an appropriate condition under Article 9. For the provision of healthcare and medical diagnosis, we generally rely on the Article 9(2)(h) condition for health or social care, together with the applicable condition in Schedule 1 of the Data Protection Act 2018.

We do not generally rely on your consent as the legal basis for holding and processing your medical records for the purpose of providing healthcare. Where consent is the appropriate legal basis for a particular activity, we will explain this to you and obtain consent where required.

Our purpose for using personal information


We use personal information to enable us to provide appropriate healthcare services for patients, including:

• providing medical assessment, diagnosis, treatment and ongoing care
• maintaining accurate and up-to-date medical records
• arranging and managing appointments
• communicating with you about your healthcare and appointments
• making appropriate referrals to other healthcare professionals or organisations
• arranging laboratory investigations and receiving and recording test results
• communicating with your NHS GP or other healthcare providers where necessary for your care
• administering healthcare services and maintaining our accounts and records
• processing payments and dealing with health insurance arrangements
• providing occupational health or other healthcare services where these have been arranged through an employer
• meeting our legal, regulatory, professional, insurance and governance obligations
• investigating and responding to complaints, incidents and concerns
• protecting the health, safety and wellbeing of patients and others where appropriate
• preventing and detecting fraud or other unlawful activity where applicable.

We will identify an appropriate lawful basis for each purpose for which we process personal information.

Depending on the purpose, the lawful basis may include:

• Article 6(1)(b) UK GDPR – where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
• Article 6(1)(c) UK GDPR – where processing is necessary for compliance with a legal obligation to which Edinburgh GP is subject
• Article 6(1)(f) UK GDPR – where processing is necessary for our legitimate interests, where those interests apply and are not overridden by your interests or fundamental rights and freedoms.

Where health information is processed, we will also rely on an appropriate Article 9 condition. For the provision of healthcare, medical diagnosis and related healthcare activities, this will generally be Article 9(2)(h), together with the applicable condition in Schedule 1 of the Data Protection Act 2018.

Where we rely on legitimate interests, we will identify and document those legitimate interests and ensure that the processing is necessary, proportionate and fair.

Sharing personal information with others


Depending on the situation, we may share appropriate, relevant and proportionate personal information where this is necessary for your healthcare, administration of our services, compliance with legal or professional obligations, or where otherwise permitted by law.

This could include with:

• your own NHS GP
• another medical provider, such as a Specialist or consultant
• a hospital or other healthcare provider
• a laboratory
• a health insurer
• your employer, where applicable and where there is an appropriate lawful basis or other legal authority for doing so
• organisations that provide services to us, such as IT, patient management, administrative, payment or other support services
• professional, regulatory or statutory bodies where we are required or permitted to provide information by law.

We will only share information that is relevant, necessary and proportionate to the purpose for which it is being shared.

We will not normally share your medical information with your employer without an appropriate legal basis and, where required, your consent or other lawful authority.

Where third-party organisations process personal information on our behalf, we will ensure that appropriate contractual, technical and organisational safeguards are in place and that they process information in accordance with applicable data protection legislation.

Where personal information is transferred outside the United Kingdom, we will ensure that the transfer is made in accordance with applicable UK data protection legislation and that appropriate safeguards are in place.

Your rights


You have a number of rights in relation to your personal information.

These include:
• You have the right to be informed about how we use your personal information.
• You have the right to access your personal information.
• You have the right to obtain information about how your personal information is being used.
• You have the right to request rectification of inaccurate or incomplete information.
• You have the right to request restriction of processing in certain circumstances.
• You have the right to request erasure of your personal information in certain circumstances.
• You have the right to data portability where applicable.
• You have the right to object to certain processing of your personal information.
• Where we rely on consent as our lawful basis, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
• You have rights in relation to certain forms of automated decision-making and profiling, where applicable.

These rights are not absolute and may be subject to legal exemptions or restrictions. In particular, there are circumstances where we may be required to retain medical records or where information cannot be erased or restricted because of legal, professional or healthcare requirements.

If you wish to exercise any of your data protection rights, please contact Edinburgh GP’s Data Controller using the contact details below.

We will normally respond to a valid data protection rights request without undue delay and within one month of receiving the request, subject to any applicable legal provisions allowing an extension or exemption.

How to contact Edinburgh GP’s Data Controller


Name: Dr David Richardson
Address: 2 Randolph Place, Edinburgh, EH3 7TQ
Phone Number: 0131 202 5454
E-mail: [email protected]
Website: www.edinburghgp.co.uk

If you have any questions or concerns about how Edinburgh GP uses your personal information, or wish to exercise your data protection rights, please contact us using the details above.

If you have a concern about the way we have handled your personal information, you may also follow Edinburgh GP’s separate Data Protection Complaints Policy.

Information Commissioner’s Office


If you remain dissatisfied with how Edinburgh GP has handled your personal information, you have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent regulator for data protection.

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel.: 0303 123 1113
Website: www.ico.org.uk
You can also make a complaint through the ICO website.

Edinburgh GP will cooperate with the ICO and provide any information reasonably required in relation to a data protection complaint or investigation.