Not for emergencies. If someone is seriously unwell or in immediate danger, call 999. For urgent medical help use NHS 111 or your local urgent-care route.
Display: Accessibility statement

Healing Process policy suite

Data Protection and Confidentiality Policy

StatusWorking draft
Version1.0-draft
OwnerData Protection Officer
Review date23 July 2027 or earlier
Approval status: this is a substantive governance draft for review. It is not evidence that a production control has been implemented, audited or approved. Each live NHS or care deployment must align it with the provider’s policies, law, contract and configured service.

1. Purpose

To ensure that personal data—particularly identifiable health images, messages and clinical records—is processed lawfully, fairly, transparently, securely and only for defined purposes.

2. Scope and status

This policy applies to website visitors, patients, carers, professionals, customer contacts, workers, research participants and suppliers. It covers collection, use, access, sharing, hosting, support, analytics, research, AI development, export, retention and deletion.

Core supplier and product policy

3. Policy principles

  • Health photographs and related records are highly sensitive. Convenience or product interest is not a sufficient purpose for collection or reuse.
  • Each processing activity requires a documented purpose, Article 6 lawful basis and—where special-category data is involved—an appropriate Article 9 condition, plus any additional common-law confidentiality or care requirements.
  • Controller and processor roles must reflect reality and be stated consistently in contracts and privacy information.
  • Privacy by design, minimisation, least privilege and separation of purposes apply throughout the lifecycle.

4. Mandatory requirements

  • Maintain a record of processing activities and data-flow map for website, accounts, care deployments, support, security, research, analytics and suppliers.
  • Complete and approve a data protection impact assessment before high-risk processing and update it after material change or incident.
  • Provide layered, accessible privacy information stating controller, purposes, data, lawful conditions, recipients, transfers, retention, rights, automated processing and complaints.
  • Collect only data needed for the pathway. Do not access a whole camera roll, contacts or unrelated device information without a justified and transparent requirement.
  • Use contracts meeting applicable processor requirements, conduct supplier due diligence and control international transfers with documented safeguards.
  • Provide verified processes for access, correction, restriction, objection, erasure where applicable, portability and complaints, recognising that some clinical records must be retained.
  • Prohibit sale of identifiable care data and behavioural advertising based on health information.
  • Treat product analytics, research and AI training as distinct purposes. Do not rely on broad care terms to authorise them silently.
  • Apply privacy-preserving design to support, testing and demonstrations; use synthetic or properly governed data wherever possible.

5. Procedure and escalation

  • New processing enters a privacy intake process before data is collected. The DPO determines whether a DPIA, consultation, contract or consent change is required.
  • Rights requests are logged, identity is verified proportionately, the correct controller is identified and the response is completed within the applicable timeframe.
  • A suspected breach is immediately contained and escalated under the incident process; regulatory and individual notification decisions are documented.
  • At contract end, data is returned, deleted or retained only as authorised, with deletion evidence and unresolved legal holds recorded.

6. Roles and responsibilities

Board/SIRO equivalent

provides accountability and resources for information risk.

Data Protection Officer

advises independently, monitors compliance and handles regulator/rights escalation.

Product/engineering

implements minimisation, privacy controls, rights and auditability.

All workers

use data only for authorised purposes and report incidents.

Providers

fulfil controller duties for care pathways and give lawful instructions to processors.

7. Records, confidentiality and retention

Keep processing records, DPIAs, lawful-basis assessments, privacy versions, contracts, transfer assessments, consent/authority records, rights requests, breaches, training, audits, deletion certificates and decisions.

Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.

8. Monitoring, assurance and review

Review annually and on material processing, supplier, law or architecture change. Monitor rights timeliness, access anomalies, data minimisation, retention, supplier findings, breaches and privacy complaints.

Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.

9. Training and communication

The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.

10. Related documents

11. Approval record

RoleNameDecision/date
Policy ownerTo be completedDraft pending approval
Clinical/technical specialistTo be completedDraft pending approval
Board or delegated committeeTo be completedDraft pending approval
Return to policy centre