PATIENT PRIVACY NOTICE
Patient Privacy Notice
Clinic Name: Forest Physiotherapy (“the Clinic”)
Last Updated: September 2026
At Forest Physiotherapy, we take your privacy and the protection of your personal information very seriously. This Privacy Notice explains how we collect, store, use, and protect your personal and healthcare data in accordance with the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act (DUAA).
1. Who We Are
Forest Physiotherapy is the "Data Controller" for your information. If you have any questions about how we look after your data, please contact our Data Protection Lead:
-
Name / Role: Jonathan Lewis, Clinic Owner]
-
Email Address: theforestphysio@gmail.com
-
Phone Number: 07453 454577
-
Clinic Address: Forest Physiotherapy, Lumsdale Road, Matlock, Derbyshire, DE4 5EW
2. The Information We Collect About You
To provide you with safe, effective physiotherapy care and to manage your appointments, we process two categories of information:
-
Personal Data: Your name, date of birth, home address, email, telephone numbers, emergency contact details, and billing/payment information (including health insurance policy details if applicable).
-
Special Category (Health) Data: Your clinical case history, symptoms, medical diagnoses, doctor/specialist referral letters, lifestyle details, imaging reports (like X-rays or MRIs), and the comprehensive treatment notes recorded by your physiotherapist during each session.
3. Why We Collect Your Data and Our Lawful Bases
Under UK data protection law, we must have a valid legal reason (lawful basis) to hold and use your data:
-
For Administrative & Billing Data: We process this under the basis of Performance of a Contract. We need this information to manage your bookings, communicate appointment changes, and process your payments.
-
For Clinical & Health Data: We process your sensitive medical notes under Article 9(2)(h) of the UK GDPR (the provision of health or social care or treatment). Keeping accurate, detailed medical records is also a statutory professional duty mandated by our regulators, the Health and Care Professions Council (HCPC) and the Chartered Society of Physiotherapy (CSP).
-
For Marketing Communication: If we send you clinic newsletters, health tips, or promotional offers, we will only do so if you have given us your explicit, opt-in Consent. You can withdraw this consent instantly at any time.
4. How We Secure and Store Your Data
Your digital files and clinical notes are hosted securely on our encrypted, password-protected Patient Management Software ([Insert software name if desired, e.g., Cliniko / WriteUpp]). Access is strictly limited to authorized clinical and administrative staff who require it to manage your care. Any legacy paper documents are kept in locked, fireproof filing cabinets on our premises.
5. How Long We Keep Your Records
We do not hold your data indefinitely. To comply with both data protection laws and statutory medical regulations, we enforce strict minimum retention windows:
-
Adult Patients: Medical records are securely retained for a minimum of 8 years after your last treatment session.
-
Child / Minor Patients: Records are securely retained until your 25th birthday (or 26th birthday if you were 17 when your treatment concluded).
Once these statutory periods pass, your files are securely and permanently destroyed.
6. Who We Share Your Data With
We maintain strict medical confidentiality. We will never sell your details or share them with unapproved third parties. We only share relevant data with:
-
Healthcare Professionals: Your GP, referring consultant, or other specialists involved directly in your care pathway (with your knowledge).
-
Your Private Health Insurance Provider: If your treatment is being funded through a third-party policy, we share invoices and necessary treatment updates to secure your funding.
-
Our Core Technology Processors: Secure platforms that enable our clinic to run, such as our booking software or our encrypted digital payment merchant (e.g., Stripe).
7. Your Statutory Rights
You hold powerful legal rights over your personal data. You have the right to:
-
Access Your Data (Subject Access Request): You can request a complete copy of your medical records and clinical notes at any time, free of charge. We will fulfill this within one calendar month.
-
Rectify Inaccurate Information: If your contact details or health factors change, you can ask us to update them immediately.
-
Erasure ("Right to be Forgotten"): You can ask us to delete your personal data. Please note: This right does not override our legal and regulatory obligations to retain clinical medical records for the minimum 8-year statutory timeframe.
-
Restrict or Object to Processing: You can object to us using your data for non-clinical purposes (such as marketing).
8. How to Make a Data Complaint
If you are unhappy with the way we have handled your personal information, you have a statutory right to lodge an internal complaint:
-
Please address your complaint in writing to our Data Protection Lead using the contact details in Section 1.
-
We will formally acknowledge receipt of your complaint within 30 days.
-
We will thoroughly investigate the matter and provide you with a substantive response or a formal progress update within 3 months.
If you remain unsatisfied with our internal resolution, you have the right to escalate your complaint directly to the UK independent data regulator, the Information Commissioner’s Office (ICO), via their website at ico.org.uk.
DATA PROTECTION & GDPR POLICY
Data Protection & GDPR Policy
Organisation Name: Forest Physiotherpay (The Forest Physio)
Document Version: 2026.1
Last Reviewed: September 2026
Designated Data Protection Lead: Jonathan Lewis
1. Policy Objectives & Scope
This policy outlines how the Clinic protects personal privacy and upholds individual rights in accordance with the UK GDPR, the Data Protection Act 2018 (DPA), and the Data (Use and Access) Act (DUAA).
It applies to all data processed by the Clinic, whether stored electronically (e.g., electronic patient management systems, emails, cloud storage) or in physical paper records. All clinical practitioners, reception staff, administrative employees, and contracted self-employed therapists must read, understand, and comply with this policy.
2. Types of Data Processed
The Clinic handles highly sensitive data. It categorises information into two main classes:
-
Personal Data: Names, home addresses, dates of birth, contact phone numbers, email addresses, financial details, and private health insurance policy numbers.
-
Special Category Data (Health Records): Clinical case notes, past medical histories, details of physical or mental health conditions, treatment plans, exercise prescriptions, letters from GPs/consultants, and diagnostic imaging reports (e.g., X-rays, MRI scans).
-
3. Lawful Bases for Processing Data
Before any data processing takes place, the Clinic establishes its lawful grounds under the UK GDPR.
A. Standard Personal Data
The Clinic relies on Performance of a Contract to process general administrative details. Collecting names, contact details, and billing information is required to schedule appointments, manage bookings, and process payments for the services requested by the patient.
B. Special Category (Health) Data
To document and maintain clinical assessment and treatment notes, the Clinic relies on Article 9(2)(h) of the UK GDPR (The provision of health or social care or treatment).
-
Important Practice Rule: Staff do not require explicit marketing-style consent from a patient merely to document clinical notes. Recording accurate medical notes is a mandatory professional duty governed by the Health and Care Professions Council (HCPC) and the Chartered Society of Physiotherapy (CSP).
4. The Core Data Protection Principles
All staff must adhere to the six foundational pillars of data management:
-
Lawfulness, Fairness, and Transparency: Data must be processed legally and openly. Patients are informed exactly how their health records are handled via the public-facing Privacy Notice.
-
Purpose Limitation: Information gathered for a clinical treatment purpose must never be repurposed (e.g., sold or passed to third-party fitness companies) without explicit authorization.
-
Data Minimisation: The Clinic only collects what is necessary to safely assess, diagnose, and treat a patient. Unnecessary personal queries must be avoided.
-
Accuracy: Clinical records and contact information must be verified regularly. Staff must update records immediately if a patient reports a change in contact details or health status.
-
Storage Limitation: Data is never held indefinitely. The Clinic adheres strictly to statutory medical retention schedules.
-
Integrity and Confidentiality: High-level digital and physical security measures are enforced to block unauthorised access, accidental loss, or destruction.
5. Medical Records Retention Schedule
To satisfy both legal data protection limits and medical regulations, the Clinic enforces the following strict document lifecycle timelines:
-
Adult Patient Records: Retained for a minimum of 8 years from the date of their last clinical contact.
-
Child/Minor Patient Records: Retained until the patient’s 25th birthday, or 26th birthday if the child was 17 at the time of their final treatment.
-
Staff and Employment Records: Retained for 6 years following the termination of employment.
-
Financial & Tax Records: Retained for 6 years from the end of the relevant financial tax year.
Once these windows lapse, digital records must be securely deleted from servers and electronic systems, and any remaining paper files must be destroyed via an approved cross-cut shredding service.
6. Technical and Organisational Security Measures
The Clinic safeguards special category health data through rigid security protocols:
-
Digital Systems: All clinical records are managed using an encrypted, password-protected Patient Management System. Staff must use unique credentials and activate Multi-Factor Authentication (MFA) where supported.
-
Terminal Locking: Devices running clinical software must never be left unattended. Screens must be locked instantly whenever a practitioner or receptionist steps away from a desk or treatment room.
-
Physical Security: Any legacy paper intake forms, printed clinical letters, or diaries must be stored in locked, fireproof filing cabinets. Only authorised personnel hold keys.
-
Mobile Devices: Work phones, laptops, or tablets used to access clinic diaries or emails outside the premises must be encrypted and protected by secure PINs or biometrics.
7. Statutory Data Protection Complaints Procedure
Under the updated mandates of the Data (Use and Access) Act (DUAA), individuals hold a statutory right to register internal data complaints, which the Clinic must manage via a structured, compliant process:
-
Receipt & Logging: Any complaint regarding data handling, tracking, or access received from a patient, staff member, or third party must be forwarded instantly to the Designated Data Protection Lead.
-
Acknowledgment Window: The Clinic will formally acknowledge the complaint in writing within 30 days of receipt.
-
Investigation & Resolution: The Data Protection Lead will investigate the issue thoroughly without undue delay. The Clinic will provide a substantive final response, or a formal progress update, within 3 months of the initial complaint date.
-
Regulatory Escalation: If the complainant remains unsatisfied with the internal handling, the Clinic must explicitly inform them of their right to escalate the matter directly to the Information Commissioner's Office (ICO).
8. Handling Subject Access Requests (SARs)
Patients have a legal right to request a complete copy of their medical histories, treatment files, and invoices free of charge.
-
Verification: Staff must verify the identity of the requesting individual using photo ID or cross-referencing specific database markers before releasing records.
-
Response Window: Complete data packets must be compiled and sent out via secure, encrypted channels within 1 calendar month of receipt.
-
Redaction Rule: Before releasing files, the Data Protection Lead must review the notes to ensure that details identifying third parties (unless they are healthcare professionals involved in the care path) are completely redacted.
9. International Transfers
Patient data must remain hosted inside the UK unless a specific mechanism guarantees safe handling. Staff are strictly prohibited from using unapproved overseas cloud storage, transcription tools, or third-party communications apps that process information outside the UK.
Any necessary data transfers beyond the UK borders must be validated by the Data Protection Lead using valid UK International Data Transfer Agreements (IDTAs) or explicit adequacy decisions.
10. Regulatory Penalty Awareness
Serious breaches of the UK GDPR or structural data failures carry significant financial and reputational liabilities. The Information Commissioner’s Office (ICO) holds the statutory authority to issue administrative fines reaching a maximum of £17.5 million to £18 million (or up to 4% of total global annual turnover, whichever is higher). Adherence to this framework is mandatory to eliminate exposure.