Data Protection Policy
At Cramond House Dental Practice, we take the privacy and security of personal information seriously. We handle personal data in accordance with the Data Protection Act 2018, UK General Data Protection Regulation (UK GDPR), GDC and NHS requirements, together with other applicable data protection obligations.
We only collect and retain information that is relevant to providing safe and appropriate dental care, managing our relationship with patients and meeting our legal and regulatory responsibilities.
The person responsible for data protection and information security at the practice is our Information Governance Lead, Iman Namjoynik. Our Data Protection Officer (DPO) is Emma Haworth.
How we protect your information
We use appropriate technical and organisational safeguards to protect the information we hold and reduce the risk of it being lost, misused or accessed without authority.
Where appropriate, information may be pseudonymised, meaning identifying details are replaced or separated so that the information cannot readily be linked to an individual without additional information. Where information is fully anonymised, it can no longer be traced back to the individual.
We do not identify patients in research, patient feedback reports or other publicly available information. Electronic information is protected using appropriate security measures, including encryption where required.
Our team members are also required to maintain confidentiality and follow clear procedures governing how personal and special category information is accessed, used, shared and protected.
Data breaches
If a personal data breach occurs, we assess it promptly and take appropriate action.
Where required, we will report a breach to the relevant supervisory authority within 72 hours of becoming aware of it, where feasible. If a breach is likely to result in a high risk to an individual's rights and freedoms, we will also inform the affected individual without undue delay.
We maintain records of personal data breaches and have procedures in place to investigate, manage and respond to them.
Your data protection rights
Data protection law gives individuals a number of rights in relation to their personal information.
Right of access
You can ask us whether we hold or process your personal information and request access to the information we hold about you, together with relevant information about how it is being used.
Right to rectification
You can ask us to correct personal information that is inaccurate or incomplete.
Right to erasure
In certain circumstances, you may ask us to delete personal information where there is no compelling reason for us to continue holding or processing it.
For current and former patients, clinical records must be retained for the appropriate legal and professional retention period. Once that period has passed, deletion may be considered where appropriate.
Right to restriction
You may, in certain circumstances, ask us to restrict how your personal information is processed. Where a restriction applies, we may continue to store the information while limiting further processing.
Right to object
You have the right to object to certain uses of your personal information, including direct marketing and, where applicable, processing for scientific research or statistical purposes.
Data portability
Where applicable, you may ask for personal information to be provided or transferred in an electronic or other suitable format.
Data protection complaints
If you are concerned about the way we have handled your personal information, you have the right to raise a data protection complaint with the practice.
We have procedures in place to receive, acknowledge, investigate and respond to data protection complaints in accordance with the Data (Use and Access) Act 2025 and our complaints procedure.
If you remain dissatisfied after we have considered your complaint, you have the right to refer the matter to the Information Commissioner's Office (ICO).
Data protection by design
Protecting personal information is considered whenever we introduce or change systems, services or processes involving personal data.
Where a project is likely to create a risk to personal information or privacy, we undertake a Data Protection Impact Assessment (DPIA) to identify those risks and determine the appropriate safeguards before proceeding.
Information security
Our information governance procedures include measures designed to prevent personal information from being accidentally or deliberately compromised.
These include:
- clear confidentiality responsibilities for all members of our team;
- procedures for identifying, reporting and managing data breaches;
- security measures and risk assessments designed to protect the information we hold; and
- requirements governing the use of personal computers, laptops, tablets or mobile phones for practice business.
Regular review
Our data protection, information security and information governance policies, procedures and risk assessments are reviewed regularly and formally reviewed each year through iComply.
Further information about data protection and your rights is available from the Information Commissioner's Office.