Start with the current framework and the factual roles

The Data (Use and Access) Act 2025 amended, rather than replaced, the UK GDPR and Data Protection Act 2018. Older templates should not be assumed current simply because they mention GDPR. PECR may also apply to electronic marketing and similar technologies.

A controller determines purposes and essential means of processing; a processor acts on a controller’s instructions. An independent practice will commonly be a controller for information it decides to collect and use to assess, deliver a service, invoice and meet its own responsibilities. Commissioner arrangements can be more complex. Map real decisions rather than applying labels mechanically.

Map the information before writing policies

Follow information from collection to deletion. Include enquiries, client and family information, referrals, health, disability, education and social-care information, assessments, behaviour data, plans, notes, recordings, safeguarding material, communications, invoices and worker records. For each activity record purpose, people and data involved, source, Article 6 basis, Article 9 condition where required, recipients, processors, transfers, retention, security and rights.

Health information is special category data. Processing it requires an Article 6 lawful basis and a separate Article 9 condition. Some conditions need a Schedule 1 Data Protection Act condition. Do not assume that all private practice processing uses a health-or-social-care condition, or select a basis after the event.

Keep professional consent distinct from data protection consent

Informed consent may be ethically and professionally essential, but it is not automatically the data protection lawful basis. The UK-SBA Code distinguishes consent to assessment and procedures, assent, recordings, sharing and specified anonymised uses. Data protection consent must meet its own standard, with particular care where it is a condition of service. A contract signature cannot be treated as consent for all processing.

Maintain a proportionate record of processing activities. The small-organisation exemption does not cover all routine, risky or special-category processing. Give clear privacy information about identity, purposes, bases, recipients, transfers, retention, rights and ICO complaints.

Security, suppliers and transfers are part of the system

Use access based on roles and cases, strong authentication where appropriate, secure devices and transfers, update management, backups and leaver controls. A platform cannot compensate for shared passwords, uncontrolled exports or former associates retaining access. Where a supplier is a processor, use an Article 28 contract with the required terms, understand subcontractors and plan for return or deletion at the end of the relationship.

Hosting location alone does not settle international transfers. Support access and subcontractors can matter. Record relevant countries, transfer mechanism and assessment. Do not promise that all data remains in the UK unless the full chain supports that statement.

Retention, rights and incidents

There is no universal UK GDPR retention period. Use a schedule that distinguishes enquiry, active and closed records, safeguarding and complaint material, tax records, recordings, backups and worker data. For further detail see record keeping and retention.

SARs can be verbal or written and normally have a one-month response period. The right to erasure is not absolute. A personal data breach may include loss, unauthorised access or disclosure; certain breaches must be reported to the ICO within 72 hours where feasible, and high-risk breaches may require notification to affected people. Keep an incident procedure that works outside normal hours.

A DPIA is required for likely high-risk processing, not every routine activity. A small practice does not automatically need a formal DPO simply because it handles health information, but someone must own privacy work. Check the ICO fee with its assessment tool rather than assuming small or healthcare status is exempt.

References

  1. ICO, DUAA 2025: what it means; summary of changesCurrent framework and implementation.
  2. ICO, Controllers and processors; Special category dataRoles, Article 6 and Article 9.
  3. UK-SBA Code of Ethical and Professional ConductConsent, assent, recordings and sharing.
  4. ICO, Documentation; Who needs to document processing?; Privacy informationROPA and transparency.
  5. ICO, Security outcomes; Records access; Encryption and storageAccess, authentication and encryption.
  6. ICO, processor contracts; International transfers; Adequacy regulationsArticle 28 terms and restricted transfers.
  7. ICO, Storage limitation; Disposal and deletionRetention and deletion.
  8. ICO, Subject access; Right to erasure; Personal data breachesRights, time limits and breach reporting.
  9. ICO, DPIAs; Data protection officers; Data protection feeHigh risk, DPO decisions and fee assessment.