Data Security and Protection Statements
The Guide to the GDPR is part of our Guide to Data Protection. It is for DPOs and others who have day-to-day responsibility for data protection.
It explains the general data protection regime that applies to most UK businesses and organisations. It covers the General Data Protection Regulation (GDPR) as it applies in the UK, tailored by the Data Protection Act 2018.
It explains each of the data protection principles, rights and obligations. It summarises the key points you need to know, answers frequently asked questions, and contains practical checklists to help you comply.

Where relevant, this guide also links to more detailed guidance and other resources, including ICO guidance, statutory ICO codes of practice, and European guidance published by the European Data Protection Board (EDPB).
You may also find other sections of the Guide to Data Protection useful:
- Introduction to data protection – for more on how the DPA 2018 works
- Guide to law enforcement processing – for more on the separate regime for law enforcement
- Guide to intelligence services processing – for more on the separate regime for the intelligence services
- Key data protection themes – for specific guidance on key themes and topics, including children’s data
The relevants statements are available for all patients to view in patient waiting room.
We use cookies to make this site work. We'd also like to set optional cookies so we can understand how the site is used and improve it. We will not set optional cookies unless you accept them. You can change your choice at any time from the Cookie settings link in the footer.
Strictly necessary cookies
These cookies are required for the site to work. They store your cookie preferences and keep your session secure. They are exempt from consent under PECR Regulation 6(4) because they are essential to deliver the service you have requested.
Optional cookies
Optional cookies help us understand how the site is used and provide additional features such as analytics, accessibility tools and translation. We will only set them if you accept.
