GDPR and patient data
GetClinic processes patient data on behalf of your clinic. Under UK GDPR, your clinic is the data controller and GetClinic is the data processor.
Your responsibilities as data controller
- Obtain appropriate consent from patients before processing their data
- Ensure your Privacy Notice covers the use of GetClinic as a system processor
- Handle subject access requests (SARs) in accordance with UK GDPR
- Report data breaches to the ICO within 72 hours if required
Data retention
Clinical records should be retained in accordance with NHS and GDPR guidelines. Typically:
- Adult patient records: 8 years from last entry
- Children's records: Until age 25 or 8 years after last entry (whichever is longer)
Deleting patient data
If a patient submits a right-to-erasure request, contact support@getclinic.io to arrange data deletion in line with your legal obligations.