Privacy Notice - IGDPR

Date created: 14th April 2026

< Back to policies & procedures

The Practice is committed to protecting your personal information and handling it in a secure, lawful, and transparent way. This notice explains how we collect, use, and store your personal data in line with the UK General Data Protection Regulation (UK GDPR) and the NHS Information Governance framework. The Practice is the Data Controller for the information we process.

1) Data Controller contact details

All Croydon GP Practices 

2) Data Protection Officer contact details

Contact Laura Watson via email

3) Purpose of the processing

We process personal data to provide safe and effective healthcare, manage appointments, communicate with patients about their care, coordinate with other NHS services involved in your treatment, and carry out the administrative and operational tasks necessary to run the Practice. This includes ensuring compliance with legal obligations, maintaining patient records, and supporting quality and safety in the delivery of healthcare services.

4) Lawful basis for processing

The legal basis is:  

  • Article 6(1)(c) “processing is necessary for compliance with a legal obligation to which the controller is subject.” 
  • Article 9(2)(h) “processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3;”

5) Recipient or categories of recipients of the shared data

Personal data may be shared securely with authorised staff within The Practice who need access to deliver care or manage administrative tasks. Where necessary for your treatment, information may also be shared with other NHS healthcare providers, including hospitals, community health services, and the NHS Integrated Care Board (ICB). 

We may also share information with regulatory or oversight bodies where required by law. Personal data is not shared with commercial organisations for marketing purposes.

6) Rights to object 

Under the UK General Data Protection Regulation (UK GDPR), you have the right to object to the processing of your personal data where we rely on certain lawful bases, such as processing necessary for administrative purposes or direct communications. If you wish to object, the practice will carefully consider your request and will only continue processing your data where we have compelling legitimate reasons or where it is necessary to provide healthcare services. To exercise this right, you can contact the practice directly.

7) Right to access and correct

You have the right to access the data that is being shared and have any inaccuracies corrected. There is no right to have accurate medical records deleted except when ordered by a court of Law.

8) Retention period 

Personal data, including patient records and administrative information, is retained only for as long as necessary to provide healthcare, manage the surgery, and comply with legal obligations. Clinical records are generally kept for at least 10 years after the last patient contact, or longer for children until their 25th birthday, in line with the NHS Records Management Code of Practice. 

Staff and administrative records are retained according to NHS and legal requirements. Once the retention period has expired, data is securely deleted or anonymised in accordance with NHS-approved policies.

9) Right to Complain

You have the right to complain to the Information Commissioner’s Office (ICO).

Please note that the National Data Opt Out does not apply to this sharing of information.

For further information, please see your NHS data matters