Sonria Dental Clinic is committed to complying with the Data Protection Act 2018, the United Kingdom General Data Protection Regulation (UK GDPR), GDC, NHS and other data protection requirements relating to our work. We only keep relevant information about employees for the purposes of employment and about patients to provide them with safe and appropriate health care. This policy forms part of an Information Governance document suite and the other related policies and procedures are listed at the end of this policy. All data protection and information security policies, procedures and risk assessments are reviewed annually.
The person responsible for data protection and information security is the Practice Owner, H. Shahin.
The person responsible for overseeing data protection matters at Sonria Dental Clinic is H. Shahin.
Pseudonymisation means transforming personal data so that it cannot be attributed to an individual unless there is additional information.
Examples of pseudonymisation we use are:
We report certain types of personal data breaches to the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach results in a high risk of adversely affecting individuals’ rights and freedoms, we also inform those individuals without undue delay.
We keep contemporaneous records of any personal data breaches, whether or not we need to notify.
Individuals have the right to access their personal data and supplementary information. The right of access allows individuals to be aware of and verify the lawfulness of the processing.
If an individual contacts the practice to access their data, they will be provided with, as requested:
The right to erasure is also known as ‘the right to be forgotten’. The practice will delete personal data on request of an individual where there is no compelling reason for its continued processing.
The right to erasure applies to individuals who are not patients at the practice. If the individual is or has been a patient, the clinical records will be retained according to the applicable record retention requirements and may only be deleted when the relevant retention requirements allow this.
Individuals have the right to have personal data rectified if it is inaccurate or incomplete.
Individuals have a right to ‘block’ or suppress the processing of their personal data. If requested, we will store their personal data, but stop processing it where the legal requirements for restriction are met.
We will retain just enough information about the individual to ensure that the restriction is respected in the future.
Individuals have the right to object to direct marketing and processing for purposes of scientific research and statistics where applicable.
An individual can request the practice to transfer their data in electronic or in another appropriate format where the right to data portability applies.
Individuals have the right to make a data protection complaint to the practice if they consider that the way we have handled their personal information constitutes an infringement of data protection legislation.
In accordance with the Data (Use and Access) Act 2025, the practice has a process for receiving, acknowledging, investigating and responding to data protection complaints. These are managed in line with the practice’s Complaints Handling Policy.
Individuals who remain dissatisfied with the outcome of a data protection complaint have the right to refer the matter to the Information Commissioner’s Office.
We implement technical and organisational measures to integrate data protection into our processing activities.
Our data protection and information governance management systems and procedures take data protection by design as their core attribute to promote privacy and data compliance.
To identify the most effective way to comply with our data protection obligations and meet individuals’ expectations of privacy, we undertake a DPIA for any projects likely to pose a risk to personal data.
Our information governance procedures include the following information security procedures:
This policy and the data protection and information governance procedures it relates to are reviewed annually to ensure they remain effective and compliant with current requirements.
This policy should be read in conjunction with the practice’s relevant data protection and information governance policies and procedures, including:
Information Commissioner’s Office (ICO) and UK GDPR guidance.