Data Protection Policy
Last updated: 26 August 2026
1. Introduction
Sevenoaks Dental & Implant Centre is committed to protecting the privacy, confidentiality and security of personal information entrusted to us.
This Data Protection Policy explains the principles and procedures we follow when collecting, using, storing, sharing and disposing of personal information.
We recognise that our patients’ dental and health information is particularly sensitive and must be handled with a high level of confidentiality and care.
This policy supports our compliance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable legislation and professional requirements.
2. Scope of This Policy
This policy applies to personal information processed by or on behalf of Sevenoaks Dental & Implant Centre.
It applies to:
- Employees
- Dental professionals
- Practice managers
- Administrative staff
- Temporary staff
- Contractors
- Locum professionals
- Students and trainees where applicable
- Third-party service providers processing information on our behalf
Everyone who handles personal information on behalf of the practice is expected to follow appropriate confidentiality, security and data protection procedures.
3. Our Data Protection Principles
We follow the core data protection principles that apply to the processing of personal information.
Personal information should be:
- Processed lawfully, fairly and transparently
- Collected for specified and legitimate purposes
- Adequate, relevant and limited to what is necessary
- Accurate and kept up to date where necessary
- Kept for no longer than necessary
- Protected using appropriate security measures
We also maintain appropriate documentation and procedures to demonstrate compliance with applicable data protection requirements.
4. What Is Personal Information?
Personal information is information relating to an identified or identifiable individual.
Examples processed by the practice may include:
- Name
- Address
- Telephone number
- Email address
- Date of birth
- Appointment information
- Patient identification information
- Payment information
- Correspondence
- Photographs
- Dental records
5. Health and Special Category Information
Dental records frequently contain information concerning a person’s health. Health information is special category personal data under UK data protection law and requires additional protection.
Examples may include:
- Medical history
- Dental history
- Medication information
- Allergy information
- Clinical examination findings
- Dental X-rays
- Clinical photographs
- Digital scans
- Treatment records
- Information relating to diagnosis and treatment
We only process health information where an appropriate legal condition applies.
Health information is handled with particular care because of its confidential nature.
6. Lawful Processing
We only process personal information where we have an appropriate lawful basis.
Depending on the circumstances, our lawful bases may include:
- Performance of a contract
- Compliance with a legal obligation
- Legitimate interests
- Consent
- Protection of vital interests
Where special category information is processed, an additional condition under applicable data protection law must also apply.
7. Purpose Limitation
Personal information will only be collected and used for specified, explicit and legitimate purposes.
Examples include:
- Providing dental care
- Maintaining patient records
- Managing appointments
- Communicating with patients
- Processing payments
- Managing referrals
- Meeting professional and legal obligations
- Managing complaints
- Maintaining practice security
Where information is intended to be used for a new purpose, we will assess whether that use is compatible with the original purpose and whether any additional information, consent or other legal basis is required.
8. Data Minimisation
We aim to collect and use only the personal information that is adequate, relevant and necessary for the purpose for which it is processed.
Staff should not collect or record unnecessary personal information.
Where information is no longer necessary, it should be securely deleted, destroyed or anonymised in accordance with the practice’s retention procedures.
9. Accuracy
We take reasonable steps to ensure that personal information is accurate and, where necessary, kept up to date.
Staff should correct inaccurate information when they become aware of an error.
Patients may contact the practice if they believe information held about them is inaccurate or incomplete.
10. Patient Confidentiality
Patient information is confidential.
Access to patient records should be limited to people who have a legitimate reason to access the information for clinical, administrative, legal or other authorised purposes.
Staff must not disclose patient information to friends, relatives, colleagues or other individuals unless there is an appropriate legal or professional basis for doing so.
Where information needs to be shared with another healthcare professional involved in a patient’s care, only relevant information should normally be shared.
Dental professionals must also comply with applicable General Dental Council requirements relating to confidentiality and patient information.
11. Access to Patient Records
Patients have rights under data protection law to request access to personal information held about them, subject to applicable legal exemptions.
Requests for access to dental records should be handled in accordance with the practice’s procedures for individual rights requests.
Staff must not obstruct or unnecessarily delay a legitimate request for access to personal information.
12. Data Sharing
Personal information may be shared where there is a lawful and appropriate reason to do so.
Depending on the circumstances, information may be shared with:
- Members of the dental team
- GPs and other healthcare professionals
- Hospitals and specialist services
- Dental laboratories
- Referring dentists
- NHS organisations where applicable
- Payment providers
- IT and software providers
- Professional advisers
- Insurers
- Regulators and professional bodies
- Government authorities or law enforcement where legally required
Where possible, we aim to share only the minimum information necessary for the relevant purpose.
13. Third-Party Processors
The practice may use third-party organisations to provide services such as IT, hosting, practice-management software, communications, payment processing, appointment systems, laboratory services and other business functions.
Where a third party processes personal information on behalf of the practice, appropriate contractual and security arrangements will be put in place where required.
Third parties should only process information in accordance with the relevant instructions and applicable legal requirements.
14. Information Security
We take appropriate technical and organisational measures to protect personal information against:
- Unauthorised access
- Unauthorised disclosure
- Accidental loss
- Unauthorised alteration
- Destruction
- Other inappropriate processing
Security measures may include:
- Access controls
- Passwords and authentication
- Secure IT systems
- Physical security
- Secure storage
- Backups
- Confidentiality procedures
- Staff training
- Secure disposal of information
15. Access Controls
Access to personal information should be provided only where it is necessary for a person’s role.
Staff must not access patient records simply because they are able to do so.
Access should be proportionate to the individual’s responsibilities and should be removed or amended when responsibilities change.
16. Passwords and Authentication
Staff must use appropriate passwords and authentication measures when accessing systems containing personal information.
Passwords must not be shared with other members of staff.
Where multi-factor authentication is available for systems containing sensitive information, it should be used in accordance with the practice’s security procedures.
17. Paper Records
Paper records containing personal or patient information must be stored securely and should not be left unattended where unauthorised people could access them.
When paper records are no longer required, they must be securely destroyed or disposed of using an appropriate confidential waste process.
18. Electronic Records
Electronic patient and personal information must be stored using authorised practice systems.
Staff should not copy confidential patient information to personal computers, personal email accounts, removable media or unauthorised cloud-storage services.
19. Email and Electronic Communications
Care must be taken when sending personal or clinical information by email.
Staff should verify the recipient’s address before sending confidential information and use appropriate secure communication methods where required.
Where sensitive clinical information is transmitted electronically, staff should follow the practice’s approved secure communication procedures.
20. Remote Working
Where staff are authorised to work remotely, appropriate security measures must be maintained.
Confidential information must not be viewed or discussed where unauthorised individuals could see or hear it.
Practice systems should be accessed using approved devices and secure connections where required.
21. Mobile Devices
Mobile phones, tablets and laptops used to access practice information must be appropriately secured.
Staff must not store confidential patient information on personal devices unless this has been specifically authorised and appropriate security measures are in place.
22. Photographs, X-rays and Digital Scans
Clinical photographs, X-rays, digital scans and other diagnostic records are part of a patient’s confidential information where they can identify the patient.
They must be stored, accessed and shared securely and only for authorised purposes.
Images must not be posted on personal social media accounts or shared with unauthorised people.
23. Website and Online Forms
Information submitted through the practice website should be handled securely and used only for the purpose for which it was submitted or another lawful purpose.
Staff should avoid requesting unnecessary clinical information through general website enquiry forms.
For information about website privacy and cookies, please see our:
24. Marketing Information
Marketing communications must be sent in accordance with applicable data protection and electronic marketing requirements.
Where consent is required, appropriate consent must be obtained before sending marketing communications.
Marketing preferences must be recorded accurately and respected.
25. Data Retention
Personal information must not be retained for longer than necessary.
The practice maintains appropriate retention arrangements for different categories of information.
Retention periods should take account of:
- Clinical requirements
- Legal requirements
- Professional requirements
- Regulatory requirements
- Business requirements
- The purpose for which the information was collected
Retention periods must be documented in the practice’s retention schedule wherever appropriate.
Information should be reviewed periodically and securely deleted, destroyed or anonymised when it is no longer required.
Important: Specific patient-record retention periods should be maintained in the practice’s internal retention schedule and should be confirmed before being published in this policy.
26. Secure Disposal
When personal information is no longer required, it must be securely disposed of.
This may include:
- Confidential shredding of paper records
- Secure destruction of electronic storage media
- Secure deletion from systems where appropriate
- Deletion or anonymisation of information where identification is no longer required
27. Data Breaches
A personal data breach may include the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal information.
All suspected data breaches must be reported promptly to the person responsible for data protection within the practice.
The practice will assess the incident and take appropriate steps to contain, investigate and remediate the breach.
Where required by law, the Information Commissioner’s Office and affected individuals will be notified within the applicable timescales.
28. Data Protection by Design
Data protection should be considered when introducing new systems, services, processes or technologies that involve personal information.
Before introducing a significant new processing activity, the practice should consider:
- What personal information is required
- Why it is required
- Who will have access
- How the information will be secured
- How long it will be retained
- Whether information will be shared with third parties
- Whether a Data Protection Impact Assessment is required
29. Data Protection Impact Assessments
Where processing is likely to result in a high risk to individuals’ rights and freedoms, the practice will consider whether a Data Protection Impact Assessment (DPIA) is required.
A DPIA may be particularly relevant when introducing new technologies or processing activities involving large amounts of sensitive information or other high-risk processing.
30. Individual Data Protection Rights
Depending on the circumstances and subject to applicable legal exemptions, individuals may have rights including:
- The right to be informed
- The right of access
- The right to rectification
- The right to erasure in certain circumstances
- The right to restriction of processing in certain circumstances
- The right to object to certain processing
- The right to data portability where applicable
- The right to withdraw consent where consent is the lawful basis
All requests must be handled in accordance with the practice’s procedures for individual rights.
31. Staff Responsibilities
All staff and other authorised users of practice information are responsible for:
- Keeping personal information confidential
- Only accessing information required for their role
- Following practice security procedures
- Keeping passwords secure
- Reporting suspected data breaches promptly
- Keeping information accurate
- Following retention and disposal procedures
- Completing required data protection training
32. Management Responsibilities
Practice management is responsible for ensuring that appropriate data protection procedures are established and maintained.
This includes:
- Maintaining appropriate policies and procedures
- Providing appropriate staff training
- Reviewing information security arrangements
- Managing data protection risks
- Maintaining appropriate records and documentation
- Reviewing data breaches and incidents
- Ensuring appropriate contracts are in place with relevant processors
- Reviewing retention arrangements
33. Data Protection Training
Staff who handle personal information should receive appropriate data protection and confidentiality training.
Training should be refreshed periodically and when there are significant changes to relevant legal, professional or practice requirements.
34. Third-Party Suppliers
Before using a third-party supplier that will process personal information on behalf of the practice, appropriate due diligence should be carried out.
Where required, a written data processing agreement or other appropriate contractual arrangement should be in place.
Suppliers should be assessed according to the nature and sensitivity of the information they process and the risks involved.
35. International Data Transfers
Where personal information is transferred outside the United Kingdom, the practice will ensure that an appropriate legal mechanism and safeguards are in place where required by applicable data protection law.
36. Complaints and Concerns
Anyone who has concerns about the way their personal information has been handled should contact the practice.
We will investigate concerns in accordance with our complaints and data protection procedures.
Individuals may also complain directly to the Information Commissioner’s Office (ICO).
Information Commissioner’s Office – Make a complaint
37. Monitoring and Review
This Data Protection Policy will be reviewed periodically and whenever there are significant changes to:
- Data protection legislation
- Practice procedures
- Information systems
- Types of personal information processed
- Third-party suppliers
- Security arrangements
Updates will be approved by the appropriate practice management or responsible person.
38. Related Policies
This policy should be read together with the practice’s other relevant policies, including:
- Privacy Policy
- Cookie Policy
- Terms & Conditions
- Complaints Policy
- Data Retention Policy / Schedule
- Information Security Policy
- Data Breach Procedure
39. Contact Details
If you have questions about this policy or data protection at Sevenoaks Dental & Implant Centre, please contact:
Sevenoaks Dental & Implant Centre
128 High Street
Sevenoaks
Kent
TN13 1XA
Telephone: 01732 600 111
Email: info@sevenoaks-dental.co.uk
Data Protection Contact: [CONFIRM CURRENT DATA PROTECTION CONTACT]
40. Policy Review
Policy owner: [CONFIRM PERSON / ROLE]
Version: 1.0
Effective date: 26 August 2026
Next review date: [CONFIRM REVIEW DATE]
