Privacy Notice


How we use your medical records

Important information for patients

  • This practice handles medical records in-line with laws on data protection and confidentiality.
  • We share medical records with those who are involved in providing you with care and treatment.
  • In some circumstances we will also share medical records for medical research, for example to find out more about why people get ill.
  • We share information when the law requires us to do so, for example, to prevent infectious diseases from spreading or to check the care being provided to you is safe.
  • You have the right to be given a copy of your medical record.
  • You have the right to object to your medical records being shared with those who provide you with care.
  • You have the right to object to your information being used for medical research and to plan health services.
  • You have the right to have any mistakes corrected and to complain to the Information Commissioner’s Office.

Why we need your personal information

We collect information about you mainly to provide you with health and care services. This is in accordance with the statutory obligations under the NHS Act 2006 and Health and Social Care Act 2012.

The information we collect is used for medical purposes that include:

  • Preventative Medicine
  • Medical Diagnosis
  • Medical Research
  • Provision of Direct Care and Treatment

We collect your personal information so that your care team has accurate and up-to-date information to plan your treatment options.


The new data protection law

The General Data Protection Regulation (GDPR) is a new law which allows and regulates the processing of personal data for health and social care, where data are processed by a public authority, such as this organisation.

Health, social care and genetic data are amongst special categories of data requiring special protection and subject to additional controls.


What information we collect about you

Health and care organisations have a legal duty to keep complete, accurate and up-to-date information about your health. This is so that you can receive the best possible care, both now and in the future.

This information is known as your ‘health record’ and is stored securely on managed systems. The information stored includes:

  • Identifiers - Your name, date of birth, NHS Number.
  • Contact Details - Your address, telephone number, email address (if provided).
  • Support Contact Details - Names, contact details of carers, relevant close relatives, next of kin, representatives.
  • Physical, Social or Mental Health Situation or Condition - Your medical history, treatments, test results, referrals, care plans, care packages, medication, medical opinions and other relevant support you are receiving.
  • Protected Characteristics - Your ethnicity, religion, sexual orientation, gender, which are required for equality monitoring and ensuring that the services are suitable and provided in the right way for the people being cared for.

Where we get your information from

Most of the information we collect about you is from:

  • Your previous GP
  • Directly from you or a friend or relative
  • Other health and care organisations

Information also comes from local authorities, schools and other government agencies.

Typically, we get information by referral. For example, if your GP decides you need an appointment with a hospital team or social care professional, they will provide those professionals with information about you so that you can be supported appropriately. This may include a diagnosis, and medications. This information is increasingly being made available electronically to improve the quality, safety and speed of care delivery.

All care professionals, and others working with them in care services, have a legal duty to keep information about you confidential and secure and only use it for the purposes of providing and improving the care they provide. Similarly, anyone who receives information from us has a legal duty to keep it confidential.


Who we share your information with

We will share your information with those health and care partners who are directly involved in your care. These may include:

  • Local NHS hospitals
  • Other GP practices if you access care there
  • Local voluntary and private care providers
  • Urgent and emergency care services, such as NHS 111 and the London Ambulance Service
  • Our eHub partners (see eHub)

You may be receiving care from other people as well as the NHS, for example social care services. Health and social care providers may need to receive or share some information about you if they have a genuine need to. This may help them form a complete picture of your health needs and provide care and treatment that is most suited to your needs and preferences. They should only share information with your permission.

We will not normally give your information to any other third party for any reason outside your individual care and treatment without your permission. However, there may be exceptional circumstances where we do, such as if someone’s health and safety is at risk or if the law requires us to pass on information.


See a short animation that explains how your personal data is used in health and care.


If you would like to understand the structure of the NHS in England, core organisations and their roles, learn more here.


Why we share your information

People often access a range of services available to them to support their health and care needs. Care organisations are increasingly providing services in regional partnerships.

See a list of all regional care partnerships

These services are not restricted by geographical boundaries or by organisational structures. There is also crossover in the information these services need to make sure the care they deliver is safe and of the highest quality. Health and care services use a range of IT systems and increasingly there is the ability to share special category personal data between systems. Care professionals and others supporting your care use IT systems developed and monitored according to strict rules to share your personal data securely and lawfully.

If care services do not share information about you, then they may be making decisions without the best available information. This may affect the quality and safety of care they give you.

You have a legal right to opt out of having your data shared between your care professionals. However, you should be aware of the risks to the safety and the quality of the care you receive.

Sharing information helps care professionals to work together across organisational boundaries. Up-to-date information about your health and care improves the quality of clinical decision making by care professionals. Health and care providers are increasingly using digital technology, subject to strict rules, to further improve your health. We will always inform you about new digital technology and point you to resources to help you access and use it securely.  We will always respect your right to opt out if you do not wish to make use of it.

"If you provide us with your mobile phone number we may use this to send you information relating to your health and the services we provide, reminders about your appointments or other health screening information. Please let us know if you do not wish to receive communications on your mobile by text"

In order to deliver the best possible service, the practice contracts Processors to process personal data, including patient data on our behalf.

When we use a Processor to process personal data we will always have an appropriate legal agreement in place to ensure that they keep the data secure, that they do not use or share information other than in accordance with our instructions and that they are operating appropriately.

Examples of functions that may be carried out by a Processor include:

  • Companies that provide IT services & support, including our core clinical systems, currently we use EMIS, Docman, MJOG, AccuRx, Medlinks Solutions and Ardens; We have signed Data Sharing Agreements with all of these providers.
  • systems which manage patient facing services (such as our website and services like Patient Access, NHS app which are accessible through the website);
  • data hosting service providers;
  • systems which facilitate appointment bookings or electronic prescription services (eg Pharmacy2U); document management services etc.
  • Delivery services (for example if we were to arrange for delivery of any medicines to you).
  • Payment providers (if for example you were paying for a prescription or a service such as travel vaccinations, reports- we use Izettle)

Online Access and Remote Consultations

Your health and care providers, such as your GP and hospitals are increasing providing online secure platforms for you and your care provided to access your health information.

  1. GP Online Services is secure online service, where you can book or cancel appointments, order repeat prescriptions, view parts of your GP record, including information about medication, allergies, vaccinations, previous illnesses and test results and some clinical correspondence such as hospital discharge summaries, outpatient appointment letters and referral letters- please see GP online tab.
  2. The COVID-19 pandemic has accelerated the adoption and utilisation of online and video consultations as part of core clinical practice. We aim to safely manage the receipt, storage and use of intimate images taken by patients for clinical purposes.

The receipt and use of intimate images of adults and children must be guided by the principle of the interests of the patient. The approach to video consulting, image sharing, and storage should be the same as it would be for face to face interactions.

Patients should not send an intimate image without prior communication with the clinician.

NHS app privacy notice



Integrating your care with our partners

Health and care partners in South East London, such as your GP, hospitals, and mental health, community and social care services, work together to make best use of your personal data to improve your treatment and care. This collaborative work helps us to build a more complete picture of all your health and care needs.

Learn more about South East London Integrated Care Records here:

Local Care Record in Southwark, Lambeth and Bromley

Connect Care in Lewisham, Greenwich, and Bexley

Integrated care records in South East London securely connect the electronic health record systems in your GP practice with similar systems in other care settings. These include South East London hospitals, care professionals in urgent and emergency care services (such as NHS 111 or 999), the London Ambulance Service and the National Record Locator Service, which is run by the NHS in England.

Integrating your care records means that your care teams can view your medications, previous treatments, test results and any other relevant care information at the touch of a button. This improves communication between your health and care providers, making best use of clinical resources during your appointments or hospital stay.

Sharing health records is helping to improve your care by providing your care team with essential clinical information at the touch of a button. This reduces the need for repeated phone calls and delayed letters.

Find more information about the integrated care records in South East London, including how to opt out of this form of data sharing.


Personal health records

As a patient of the practice you can use Patient Access an online secure platforms for you to access your health information.

Patient Access is secure online service, where you can book or cancel appointments, order repeat prescriptions, view parts of your GP record, including information about medication, allergies, vaccinations, previous illnesses and test results and some clinical correspondence such as hospital discharge summaries, outpatient appointment letters and referral letters.

You can also make a subject access request for copies of your health records. For more information see the section below titled ‘your legal rights’.


Other uses of your personal information

Using information for commissioning or regulatory compliance

Commissioning is when organisations plan and pay for health care services. Health and care commissioners need information from your GP practice, hospitals and other care providers about your treatment to review and plan health services. To do this, they need to be able to see information about your care but they do not need to know who you are.

The commissioners use intermediary services called Data Services for Commissioners Regional Office (DSRCO). DSRCOs specialise in analysing and converting coded clinical information within a secure environment into a format that commissioners can legally use. This is specific data about your care that does not reveal your identity or contact details.

NHS Digital, formally known as the Health and Social Care Information Centre (HSCIC), can provide coded data about your care securely to commissioners under the Health and Social Care Act (2012).

NHS Digital, through its DSCROs, is allowed by law to collect, hold and process your personal data. This is for purposes beyond direct patient care, to support care commissioning organisations and the commissioning functions within local authorities.  

Service evaluation

Service evaluation contributes to the overall quality and effectiveness of clinical services to you and a group of people with a similar condition. This routine quality assessment of care services falls outside the scope of your direct care. It covers:

  • Care services management
  • Preventative care and medicine
  • Health and social care research

Service evaluations are routinely undertaken using anonymised data. Where identifiable information is to be used, the NHS will always do it lawfully and securely in a way that will always protect your privacy.


Using information for research

Our practice works with researchers to find ways to develop better treatments for care. The information in your health records can also be used to help NHS researchers understand more about the causes of illnesses and how best to treat them. They need to follow strict rules to make sure your personal data is always kept secure and confidential.

Where possible, researchers will make efforts to take out any information that could identify you, such as your name, address and postcode. If they cannot practically take out such information, it is their legal responsibility to ask for your explicit permission (consent).

Health services work with researchers and technical experts to develop computer systems and encryption techniques, such as pseudonymisation (using special codes), to enhance your privacy and protect your confidentiality before using your information for research.

For more information on such local research systems and initiatives, visit the King’s Health Partners website.

In more exceptional cases, researchers may seek special support from the Secretary of State under the health service (control of patient information) regulations (also known as ‘section 251 support’). This can allow researchers to use your personal data without your permission, only when it is not practical to do seek permission. They must also have reassured an independent committee who have reviewed the purpose and data security arrangements.

 Find more information on trials where researchers have used this special support known as ‘section 251’ support.


Research recruitment

You can give your care coordinator an advance permission for researchers to contact you in the future if you match the criteria of a trial. Your advance permission, known as ‘consent for contact’ will be noted in your health records. You will only hear from a research nurse, who will explain what that study will entail in more detail.


Clinical data linkages

Partnerships between care providers, such as between your GP practice and NHS hospitals and universities is leading to better opportunities to use clinical data for better care services and treatments by securely joining or ‘linking’ information from different clinical sources within a secure and regulated NHS environment. This joins two or more independent healthcare data sources, for example someone’s GP record and their hospital record, in order to improve the quality of information and to enable NHS researchers to look at your healthcare in more detail.  Any information that may identify individuals are all removed prior to any researchers.


Other ways your information is used

We may also use your personal data in the following areas:

  • Any complaints you have made about services.
  • Any incidents you may have been involved in while you were receiving treatment and care from us.
  • Any paid, un-paid work with us, including your involvement in volunteering, public engagement or other projects (eg social, community, art, consultation) we run solely or with partners.
  • Any training, education, supervision delivered to you by us.
  • CCTV (closed-circuit television) and use of multimedia device.

"If you provide us with your mobile phone number we may use this to send you information relating to your health and the services we provide, reminders about your appointments or other health screening information. Please let us know if you do not wish to receive communications on your mobile by text"


How we keep your information secure

Your health and care providers store and use large volumes of sensitive personal data every day, such as your health records. The majority of health records are stored electronically.

Other personal data and computerised information are stored on various other systems across your health and care providers. These systems are managed by NHS IT departments or under contract with an approved public framework supplier.

The information we collect is used by people in their work for the purposes stated in this notice. We take our duty to protect your personal information and confidentiality very seriously. We are committed to taking all reasonable measures to ensure the confidentiality and security of personal data for which we are responsible, whether computerised or on paper.

  • We encrypt all outgoing email containing personal data
  • We review our information collection, storage and processing practices, including physical security measures, to guard against unauthorised access to systems
  • We provide training to all staff on how to handle all types of data

At the most senior level, we have:

  • A senior information risk owner who is accountable for the management of all information and any associated risks and incidents (Ms Rona Sian, Practice Manager)
  • A Caldicott guardian who is responsible for the management of patient information and patient confidentiality Dr Deborah Maynard GP Prinicipal
  • A Data Protection Officer oversees all activities related to the use of data Ms Rona Sian Practice Manager.
  • They make sure data use is done within the law and best practice.

GP DPO Service Lead: Jamie Sheldrakenel 03000 428 438

 See details of these senior responsible officers and their contact details by contacting the surgery here


Your legal rights

You have several rights under the data protection law:

Right to be informed: you have a right to be informed about uses of your information, with an emphasis on transparency. This fair processing notice, in support of other privacy notices makes sure that your right to be informed is upheld.

Right of access: you have a right to receive:

  • Confirmation of what information is recorded about you
  • Confirmation of how your information is used
  • Access to your personal health information and other information we hold

To exercise your right of access, you will be asked to complete a subject access request (SAR) form, provide proof of identification and may be asked to explain exactly what information you require.

Your request must be made in writing to the administration team at Waterloo Health Centre, please contact us here. You will not be charged for this service.

Other people can also apply to access your health records on your behalf. These include anyone authorised by you in writing (such as a solicitor), or any person appointed by a court to manage your affairs if it decides you cannot manage them yourself.

Right to rectification: rectification means correcting inaccuracies or incomplete data we hold about you. This often applies to factual information only such as identifiers and next of kin. We are unable to remove or alter professional opinions that you may disagree with. You do however have the right to include your personal statements alongside professional opinions.

To rectify your information please contact the administration team here

Right to deletion: in some circumstances you can request that we delete the information we hold about you. This right will apply only if the processing has been based on consent which is withdrawn, the processing of data is found not to be lawful or the information is no longer required. We will tell you about activities to which this right applies

There are exceptions to the right to deletion. Your health and care providers are legally required to maintain your records in accordance with the retention guide in the Record management code of practice for health and social care

Right to object: you do not have a general right to object to processing of your personal information for your individual care, however you can object if the information is used for a secondary purpose, such as:

  • Marketing
  • Scientific or historical research
  • Statistical purposes
  • Purposes in the public interest or under an official authority (eg NHS Act 2006)
  • Public patient involvement groups

Right to restrict processing: the right to restrict processing means that, if you have disputed the accuracy of information, objected to its use or require data due for destruction to be maintained for a legal claim, you can have the data stored by the Trust but not allow other uses until the dispute is settled.

To request restriction to processing, please contact the medical administration team here.

We will respect your rights under the data protection legislation whether you are an adult or a child. We will respect the wishes of parents’ (or legal guardians’) in respect of data rights of children who are younger than 14 years old.

You should also tell us how you would like us to contact you. We will normally ask this when you register with us. Your preferences may include post, email, text messaging and phone. You should notify your care team about your preferences and ask it to be recorded in your health and care record. You can change your mind later as long as you give timely notifications to your care team about any changes to your preferences.


What other information do we collect

We collect information on all staff we employ, as well as volunteers, people with honorary contracts and agency staff for the purposes of running our services. We use the information for administrative, academic and statutory purposes and to support health and safety.

The information we collect includes:

  • Data Type Purpose of collecting
  • Names, addresses and telephone numbers Employment contracting
  • Spouse, partner, emergency contact, close relative, next of kin names, address, telephone and email details Emergency contact
  • Employment records (including professional membership, references, appraisals, professional development plans, education and training records) Statutory requirement of employment, performance management, professional development
  • Bank, National Insurance number and pension details Payment of salaries and other expenditure claims
  • Nationality/domicile Proof of eligibility to work in the UK
  • Ethnicity Equality monitoring, equal opportunities
  • Medical information including physical health or mental condition Appropriate adjustments to work arrangements, management of disability rights and other occupational health services
  • Religious beliefs Spiritual support, equal opportunities, equality monitoring

We maintain electronic staff records and other corporate systems, such as employment, payroll and finance.


Other bodies

There are some exceptional circumstances where we must share information with official bodies or other organisation about employees without their express permission. These include circumstances owing to a legal or statutory obligation. These bodies may include:

  • Disclosure and Barring Service
  • Home Office
  • Her Majesty’s Revenue and Customs (HMRC)
  • Financial institutes for e.g. banks and building societies for approved mortgage references
  • Educational, training and academic bodies
  • Department for Work and Pensions (DWP)

If you want to complain

If you think that information in your NHS health records is wrong, please talk to the health professional looking after you and ask to have the record amended. You can also ask for the information to be amended by contacting the Practice and asking for the Practice Manager, Ms Rona Sian here.

If your request to have your records amended is turned down because the information is not wrong, we will add a statement of your views to the record.

If you are unhappy with our response, you have the right to complain to the Information Commissioner’s Office (ICO), which regulates and enforces the Data Protection Act. For details of how to do this:

Make a complaint to the Information Commissioner’s Office (ICO) here

Or you can call directly by telephone: 0303 123 1113


Further information

Please talk to our team if you want to know more about how we use your health records.