Skip to main content

GDPR and information governance policies

Woosehill Medical Centre is committed to protecting the confidentiality, integrity, and security of patient and staff information. We follow strict Information Governance standards to ensure that personal data is handled safely, securely, and in accordance with UK law and NHS requirements.

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and NHS Information Governance standards. We also complete the NHS Data Security and Protection Toolkit each year to demonstrate that we are meeting national data security requirements.

Our IT systems and data storage are provided and supported by NHS approved suppliers who meet national cyber security standards. Access to patient information is strictly controlled, and all staff receive regular training in data protection and confidentiality.

The policies below explain how we manage, protect, and use information, and outline your rights under data protection law.

If you have any questions about how your information is used, please contact the practice.

Please read our policies on Data Protection and Information Governance below:

Page published: 26 September 2024
Last updated: 18 February 2026