Skip to main content

Privacy Notice for Patients

Privacy Notice for General Practice

Introduction

At Barlow Medical Centre, all staff have a legal and professional responsibility to maintain the confidentiality and security of the information we hold about our patients.

All staff undertake appropriate training in confidentiality, data security and information governance. These confidentiality obligations continue after a member of staff’s employment or engagement with the Practice ends.

We are also legally required to explain how and why we collect, use, store and share personal information about you. This privacy notice explains how we do this and applies to information held electronically on paper and in other formats.

The healthcare professionals who provide your care maintain records about your health and any treatment or care you have received. These records help us, and other healthcare professionals involved in your care, to provide safe and appropriate healthcare.

Who is responsible for your information?

Barlow Medical Centre is the Data Controller for the personal information contained within your GP medical record and for other personal information processed by the Practice.

This means that we are responsible for deciding why and how your information is used and for ensuring that it is handled lawfully, fairly and securely.

Our Data Protection Officer can be contacted through:

Data Protection Officer Barlow Medical Centre 828 Wilmslow Road Didsbury Manchester M20 2RN

Telephone: 0161 445 9000

If you have any questions about this privacy notice, how we use your information or your data-protection rights, please contact the Practice Manager or Data Protection Officer using the details above.

Why do we provide this privacy notice?

We are required by law to explain:

· why we collect personal and healthcare information about you;

· what information we collect;

· where we obtain it from;

· how we use it;

· our lawful basis for using it;

· who we may share it with and why;

· how we protect it;

· how long we retain it;

· your rights in relation to it; and

· how you can raise a concern or complaint.

The main data-protection legislation applying to the Practice is the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

The Data (Use and Access) Act 2025 (DUAA) amended aspects of UK data-protection and privacy legislation. It does not replace the UK GDPR or Data Protection Act 2018. Barlow Medical Centre will maintain its policies, procedures and information-governance arrangements in accordance with the legislation as amended.

We also work in accordance with other relevant legal and professional requirements, including the Common Law Duty of Confidentiality, the Human Rights Act 1998, relevant NHS legislation and guidance, and the Caldicott Principles.

What information do we collect about you?

Information held by the Practice may include:

  • your name and preferred name;
  • sex and gender information where relevant to your care;
  • date of birth;
  • NHS number;
  • current and previous addresses;
  • telephone numbers and email addresses;
  • communication preferences;
  • emergency contact and next-of-kin details;
  • details of carers, representatives or people authorised to act on your behalf;
  • language and communication requirements;
  • accessibility requirements;
  • registration information;
  • appointment and contact information;
  • medical notes and clinical records;
  • diagnoses and medical history;
  • treatment and care;
  • medication and prescribing information;
  • allergies and adverse reactions;
  • pathology and laboratory results;
  • X-rays, scans and other investigation results;
  • referrals and correspondence;
  • information received from hospitals and other health and social care organisations;
  • information relating to safeguarding;
  • information about complaints, concerns, compliments and other correspondence; and
  • any other information that is relevant and necessary for your healthcare or the operation of NHS services.

Special category and other sensitive information

Health information is classed as special category data under the UK GDPR and receives additional protection.

Where relevant and lawful, we may process information concerning your:

  • physical or mental health;
  • racial or ethnic origin;
  • sex life;
  • sexual orientation;
  • genetic data;
  • biometric data where used for identification;
  • religious or philosophical beliefs;
  • political opinions; and
  • trade union membership.

We may also process information concerning criminal or suspected criminal offences where this is relevant to your care, safeguarding, legal obligations or another lawful purpose.

We will only collect and use information that is relevant and necessary for the purpose for which it is being processed.

Where does your information come from?

We obtain information from a number of sources, including:

  • directly from you;
  • information you provide through online consultation or other digital services;
  • parents, guardians, carers or authorised representatives where appropriate;
  • GPs and other healthcare professionals;
  • NHS hospitals and NHS Trusts;
  • community health services;
  • pharmacies;
  • mental health services;
  • ambulance and out-of-hours services;
  • NHS England and other national NHS systems;
  • the NHS Spine;
  • screening programmes;
  • public health organisations;
  • social care organisations;
  • local authorities;
  • safeguarding organisations;
  • diagnostic and treatment services;
  • other organisations involved in your care; and
  • other third parties where obtaining the information is lawful and appropriate.

We also receive information about your health from other organisations involved in providing your care. For example, if you attend hospital for treatment or an operation, the hospital will normally send information back to the Practice so that your GP record can be kept up to date.

How do we use your information?

The main purpose for which we use your information is to provide and manage your healthcare.

This can include:

  • assessing your health;
  • diagnosing illness;
  • providing treatment;
  • prescribing and reviewing medication;
  • arranging referrals;
  • requesting, receiving and reviewing test results;
  • coordinating your care;
  • communicating with other healthcare professionals;
  • providing information to out-of-hours and emergency services where appropriate;
  • supporting continuity of care;
  • managing long-term conditions;
  • end-of-life care;
  • screening and vaccination programmes;
  • preventative healthcare;
  • safeguarding;
  • administering appointments and other Practice services;
  • responding to requests and correspondence;
  • handling complaints and concerns;
  • checking and reviewing the quality and safety of the care we provide;
  • clinical audit and clinical governance;
  • managing NHS services;
  • service evaluation and planning;
  • approved research;
  • national clinical audit;
  • public health activities;
  • preventing and detecting fraud;
  • meeting legal, regulatory and contractual requirements; and
  • protecting the health and safety of patients, staff and the wider public.

Wherever possible, information used for purposes other than your individual care will be anonymised or pseudonymised so that patients are not directly identifiable.

What is our lawful basis for using your information?

Under the UK GDPR, organisations must have a lawful basis for processing personal information and an additional condition when processing special category information such as health information.

We do not normally rely on UK GDPR consent to process your information for direct healthcare. The legal basis for providing NHS care is generally that processing is necessary to perform a public task and to provide health or social care.

Our main lawful bases include:

Providing and managing your healthcare

UK GDPR Article 6(1)(e) – processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

For health and other special category information:

Article 9(2)(h) – processing is necessary for preventative or occupational medicine, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services.

Legal and regulatory obligations

Article 6(1)(c) – processing is necessary for compliance with a legal obligation.

Where special category information is involved, an appropriate Article 9 condition and relevant provisions of the Data Protection Act 2018 will also apply.

Public health

Processing may be necessary to meet public-health responsibilities, including disease monitoring, vaccination and public-health protection.

This may include Article 9(2)(i) where processing is necessary for reasons of public interest in the area of public health.

Research, statistics and national clinical audit

Where information is lawfully used for approved research, statistics or national clinical audit, appropriate lawful bases will apply. These may include:

Article 6(1)(e) – public task; and

Article 9(2)(j) – processing necessary for scientific or historical research or statistical purposes, subject to the required safeguards.

There will also be circumstances in which explicit consent is obtained for particular research activities.

Consent will be obtained whenever the law or applicable ethical or research requirements require it. However, not all lawful NHS research depends upon individual consent, and appropriately authorised research may sometimes take place using confidential patient information subject to strict legal safeguards and the National Data Opt-Out where applicable.

Consent

There are some circumstances where we rely specifically on your consent, for example certain optional services or website cookies.

Where consent is relied upon under data-protection law, it must be freely given, specific, informed and unambiguous and can be withdrawn.

Confidentiality and the Caldicott Principles

In addition to data-protection legislation, healthcare staff have responsibilities under the Common Law Duty of Confidentiality.

We will only use or share confidential information where there is an appropriate reason to do so.

We follow the eight Caldicott Principles:

  1. Justify the purpose for using confidential information.
  2. Use confidential information only when it is necessary.
  3. Use the minimum confidential information necessary.
  4. Access should be on a strict need-to-know basis.
  5. Everyone with access to confidential information should understand their responsibilities.
  6. Everyone handling confidential information should understand and comply with the law.
  7. The duty to share information for individual care can be as important as the duty to protect confidentiality.
  8. Inform patients and service users about how their confidential information is used.

These principles apply both to information used within the Practice and information shared with other health and care organisations.

Who may we share your information with?

Where it is necessary, appropriate and lawful, information may be shared with organisations including:

  • GPs and healthcare professionals working at Barlow Medical Centre;
  • other GP practices;
  • NHS Trusts and Foundation Trusts;
  • hospitals, including emergency departments;
  • ambulance services;
  • out-of-hours and urgent care services;
  • community healthcare services;
  • mental health services;
  • pharmacies and pharmacists;
  • dentists and opticians where appropriate;
  • diagnostic and treatment centres;
  • NHS Greater Manchester Integrated Care Board;
  • NHS England;
  • the Department of Health and Social Care;
  • other organisations responsible for commissioning, funding or planning NHS services;
  • social care services;
  • local authorities;
  • safeguarding services;
  • independent or private healthcare providers involved in your care;
  • voluntary-sector organisations involved in providing services to you;
  • regulators and statutory bodies;
  • the police, courts, coroners and other judicial services where disclosure is lawful;
  • education and training organisations where appropriate;
  • authorised research organisations;
  • organisations conducting national clinical audits;
  • IT, software and system suppliers acting on our behalf; and
  • other approved data processors providing services to the Practice.

Where another organisation processes information on our behalf, appropriate contractual and information-governance arrangements are put in place.

We only share the information that is reasonably necessary for the particular purpose.

When can information be disclosed without your consent?

There are circumstances where we are required or permitted to disclose information without obtaining your consent.

These can include:

  • safeguarding children or adults at risk;
  • preventing or detecting serious crime;
  • protecting an individual from serious harm;
  • public-health requirements;
  • notification of certain infectious diseases;
  • statutory reporting requirements;
  • registering births and deaths;
  • court orders;
  • coroners’ investigations;
  • public inquiries;
  • requests made using lawful statutory powers;
  • investigations by authorised bodies;
  • requests from regulatory authorities;
  • fraud prevention and investigation; and
  • other circumstances where disclosure is required or permitted by law or justified in the overriding public interest.

Any such disclosure will be considered carefully and only relevant and necessary information will be shared.

Registering for NHS care and the NHS Spine

Patients receiving NHS care are registered on national NHS systems, including the NHS Spine, which is operated by NHS England.

The Spine supports important NHS services and allows authorised healthcare professionals and organisations to access or exchange information where appropriate.

Basic demographic information such as your name, address, date of birth and NHS number is required for NHS registration and administration.

You cannot object to essential demographic information being provided to NHS England where this is necessary for you to be registered for and receive NHS care.

Sharing information for your direct care

Sharing relevant information between healthcare professionals is often necessary to provide safe and effective care.

Examples include:

  • sharing relevant GP information with a hospital treating you;
  • providing information to an out-of-hours or urgent care service;
  • sharing medication and allergy information with another healthcare professional;
  • sharing relevant information with community nursing services;
  • sharing information with pharmacies;
  • sharing information with mental health services; and
  • sharing relevant information with social care where necessary to coordinate your care.

You may object to particular information being shared for your individual care. We will consider your objection carefully and discuss the possible consequences with you.

However, an objection is not absolute. There may be circumstances where information must still be shared, for example where the law requires it, for safeguarding, where there is an overriding public interest or where sharing is necessary to prevent serious harm.

Risk stratification

Risk stratification tools may be used within the NHS to identify patients who may be at increased risk of illness, hospital admission or deterioration and who may benefit from preventative care or additional support.

Information used for risk stratification may come from the Practice and other organisations involved in providing NHS care.

Where possible, information is pseudonymised or otherwise protected during analysis. Identifiable information is made available to appropriate healthcare professionals only where required for the provision or coordination of care.

Where an external organisation or system supplier processes information on our behalf, appropriate data-processing, confidentiality and security arrangements must be in place.

You have the right to raise an objection to the use of your information for risk stratification. Please contact the Practice if you have concerns about how your information is being used.

Medicines management

The Practice may undertake medicines management and medication reviews to ensure that patients receive safe, appropriate, up-to-date and cost-effective treatment.

This may involve Practice clinicians, pharmacists and other authorised healthcare professionals reviewing prescribing and clinical information relevant to your treatment.

Information will only be accessed and shared where necessary for this purpose.

OpenSAFELY Data Analytics and research

NHS England has established the OpenSAFELY COVID-19 Service and OpenSAFELY Data Analytics Service.

These services provide a secure environment supporting approved research, clinical audit, service evaluation and health surveillance relating to COVID-19 and other health and care purposes.

Barlow Medical Centre remains the Data Controller for its own GP patient data while that information remains within the GP record.

Approved users are able to run authorised queries against pseudonymised GP data within the secure OpenSAFELY environment. Personal identifiers are removed and replaced with a pseudonym.

Approved users cannot directly access identifiable GP patient records and are not permitted to access information that directly or indirectly identifies individual patients.

Patients who have registered a Type 1 Opt-Out with their GP practice will not have their GP data processed as part of the OpenSAFELY services.

The National Data Opt-Out operates differently from a Type 1 Opt-Out and is not automatically applied to all OpenSAFELY processing.

Artificial Intelligence and ambient voice technology

The Practice may use approved artificial intelligence, automation and digital tools to support healthcare and administrative processes.

Before implementing AI technology involving personal information, the Practice undertakes appropriate information-governance, data-protection, security and clinical-safety assessments. This includes completing a Data Protection Impact Assessment (DPIA) where required.

AI is used as a support tool. It does not replace professional judgement, and appropriate human oversight remains in place.

Patients will be informed when relevant AI technology is being used in their consultation and will have the opportunity to object.

Surgery Intellect – AI-assisted clinical documentation

Barlow Medical Centre uses Surgery Intellect, an ambient voice technology provided by X-on Health and powered by Tortus AI, to support clinicians with clinical documentation.

During a consultation, Surgery Intellect may securely process the conversation and use artificial intelligence to create a draft clinical note. It may also support activities such as suggesting relevant clinical codes or preparing draft correspondence based upon the consultation.

Information processed may include:

  • your name and other identifying information;
  • information discussed during the consultation;
  • your medical history;
  • symptoms and diagnoses;
  • treatment information;
  • medication;
  • clinical plans; and
  • any other relevant information discussed during the consultation.

Your clinician remains responsible for your medical record and all decisions concerning your care.

Any information produced by Surgery Intellect is reviewed and, where necessary, amended by the clinician before it is approved for inclusion within your medical record.

Surgery Intellect does not independently diagnose you, prescribe medication or make decisions about your care without appropriate professional oversight.

You will be informed when the technology is being used. You can ask the clinician not to use it during your consultation and doing so will not affect your access to care. The clinician will instead document the consultation using their usual method.

Its use is subject to appropriate data-protection, information-governance, cybersecurity and clinical-safety arrangements.

Further information about our use of AI is available from the Practice on request.

Further guidance is also available from the Care Quality Commission in GP Mythbuster 109: Use of artificial intelligence (AI) in GP services.

Reports about you, including insurance reports

We use iGPR Technologies Limited (“iGPR”) to support the administration and preparation of certain requests involving medical records.

These may include:

  • Subject Access Requests made by you or by someone authorised to act on your behalf; and
  • medical-report requests made by insurers or other authorised organisations.

For these services, Barlow Medical Centre remains the Data Controller and iGPR acts as a Data Processor on our behalf.

iGPR processes information under a written agreement, in accordance with our instructions and agreed operating procedures.

We determine the rules and operating parameters under which information may be disclosed and remain responsible for decisions that require referral to the Practice.

iGPR may:

  • receive requests;
  • undertake initial administrative checks;
  • access relevant information from the patient record;
  • generate a report;
  • apply agreed redactions; and
  • securely provide completed information to the patient or authorised requesting organisation.

Requests received directly by the Practice

Where an insurance report request is received and processed by the Practice, the completed report will be reviewed and authorised by an appropriate clinician before release.

Requests initiated directly by an insurer through iGPR

Where an insurer submits a request directly through the iGPR service, iGPR may generate, review, redact and release the report in accordance with the procedures and operating parameters agreed with the Practice.

These reports are not routinely reviewed by a Practice clinician before release.

iGPR must refer the request to the Practice where:

  • it falls outside agreed operating parameters;
  • there is a query or concern;
  • a clinical decision is required; or
  • a Data Controller decision is required.

Before information is released, the request must be supported by appropriate evidence of the patient’s identity, authority and consent where this is required.

Information processed through iGPR is hosted in the UK. iGPR may use approved UK-based service providers to host and secure its service.

Reports are retained within the iGPR system only for the period necessary to complete and deliver the request, with limited audit information retained in accordance with the applicable contractual arrangements.

Your rights where an insurer requests a medical report

Before an insurer applies for a medical report, it must tell you that it intends to do so and obtain the appropriate authority or consent.

Where a report is covered by the Access to Medical Reports Act 1988 and is prepared by a doctor who is or has been responsible for your clinical care, you may normally:

  • ask to see the report before it is sent to the insurer;
  • ask for factual inaccuracies to be corrected;
  • ask for a statement recording your disagreement to be attached if the doctor does not agree that the report is inaccurate; and
  • withdraw your consent and ask that the report is not sent.

Where you ask to see the report before it is sent, it will normally be held for up to 21 days to allow you to arrange to view it.

Once you have seen it, you may agree to its release, ask for appropriate corrections or withdraw your consent.

A doctor is not required to remove accurate and relevant information where doing so would make the report false or misleading.

In limited circumstances you may not be given access to all of a report, for example where disclosure would be likely to cause serious harm to you or another person or where it would reveal confidential information relating to another person.

If you have any concerns about a report, its accuracy or the information included, please contact the Practice as soon as possible.

Car park monitoring and parking enforcement

Barlow Medical Centre provides car-parking facilities to support access for patients, staff and emergency services.

Parking management on the Practice car park, including the use of Automatic Number Plate Recognition (ANPR) technology, is carried out by Northwest Parking Management Ltd, which operates and enforces the parking system on this site.

Northwest Parking Management Ltd is the Data Controller for personal data collected in connection with car-park monitoring, permits and parking enforcement.

This may include vehicle registration numbers and, where applicable, registered keeper information obtained from the DVLA.

Barlow Medical Centre does not access, store or control the ANPR or parking-enforcement information collected by Northwest Parking Management Ltd.

For information about how parking-related personal information is collected, used, shared and retained, and your rights in relation to it, please refer to Northwest Parking Management Ltd’s Privacy Notice available through the signage displayed in the car park or directly from the company.

Queries, complaints or data-protection requests concerning parking charges, ANPR information or parking-enforcement information should therefore be directed to Northwest Parking Management Ltd rather than Barlow Medical Centre.

Is information transferred outside the UK?

We use a range of NHS systems and approved third-party suppliers.

Where personal information is stored, accessed or processed outside the UK, this will only take place where there is a lawful basis for the transfer and appropriate data-protection safeguards are in place.

Suppliers processing personal information on our behalf are required to meet appropriate confidentiality, information-security and data-protection standards.

Specific arrangements relating to individual systems are assessed as part of our information-governance and Data Protection Impact Assessment processes where applicable.

Accuracy of your medical record

All NHS organisations have a responsibility to maintain accurate, relevant and appropriate clinical records.

If you believe factual information in your record is inaccurate, you can ask us to investigate and correct it.

Clinical records are also an account of what was known, observed or considered by healthcare professionals at a particular point in time. An entry is therefore not necessarily inaccurate simply because a diagnosis subsequently changes or because a patient disagrees with a clinical opinion.

Where an entry is clinically or factually inaccurate, we will consider the appropriate correction.

We will not ordinarily delete an accurate historic clinical record simply because its content is disputed. Where appropriate, the record may instead be updated to include subsequent findings, corrections or an explanatory statement so that it provides an accurate account of what happened.

How do we keep your information safe?

We use a combination of technical, physical and organisational safeguards to protect the personal information we hold.

These include appropriate:

  • access controls;
  • passwords and authentication;
  • role-based access;
  • staff confidentiality requirements;
  • information-governance training;
  • cybersecurity controls;
  • contractual controls with suppliers;
  • secure NHS systems;
  • audit trails;
  • secure storage;
  • confidential-waste arrangements; and
  • policies and procedures governing access to and use of patient information.

Staff should only access information necessary for them to carry out their role.

Where an external organisation processes information on our behalf, it must be subject to appropriate contractual, confidentiality and security requirements.

How long do we keep your information?

Medical records are retained in accordance with the NHS Records Management Code of Practice and other applicable national retention requirements.

Different types of information have different retention periods.

We will not normally retain personal information for longer than it is required unless there is a legal, regulatory or clinical reason to do so.

When information reaches the end of its required retention period, it will be securely destroyed or disposed of in an appropriate manner.

Paper confidential information is disposed of using secure confidential-waste arrangements, while electronic information is securely deleted or archived in accordance with applicable NHS requirements.

Your data-protection rights

Your rights depend on the circumstances and the legal basis under which information is being processed.

Subject to applicable legal exemptions, you may have rights including:

  • the right to be informed about how your information is used;
  • the right of access to personal information held about you;
  • the right to rectification of inaccurate or incomplete personal information;
  • the right to restriction of processing in certain circumstances;
  • the right to object to particular types of processing;
  • the right to erasure in certain limited circumstances;
  • the right to data portability where the relevant legal conditions apply; and
  • rights relating to certain types of automated decision-making.

Some of these rights are limited in relation to GP records because we have legal and professional obligations to maintain accurate healthcare records and because much of our processing is necessary to perform our NHS public functions.

In particular, there is not normally a right to have accurate and relevant information deleted from a medical record simply because you no longer wish it to be recorded.

Accessing your personal information – Subject Access Requests

You have the right to ask whether we hold personal information about you and to request access to that information.

This is commonly known as a Subject Access Request (SAR).

You can make a Subject Access Request verbally or in writing, including:

  • in person;
  • by telephone;
  • by letter; or
  • by email.

You do not need to use a particular form or specifically refer to data-protection legislation.

Where the information you require is held by another organisation, such as a hospital, you should normally contact that organisation directly.

We will normally provide access to your information free of charge.

A reasonable administrative fee may be charged in limited circumstances permitted by law, such as where a request is manifestly unfounded or excessive or where further copies of information already supplied are requested.

We may withhold information or refuse all or part of a request where a relevant legal exemption applies. If we do so, we will explain our decision where the law permits and tell you about your right to complain.

We will respond without undue delay and normally within the statutory one-month period.

Where permitted by law, the response period may be extended where a request is complex or a number of requests have been made. We will tell you if an extension is necessary.

We may also ask for information reasonably necessary to:

  • confirm your identity;
  • confirm the authority of someone acting on your behalf;
  • locate the information requested; or
  • clarify the scope of your request.

Any identification requested will be reasonable and proportionate.

Opting out of sharing your information

There are different types of data-sharing choices and it is important to distinguish between them.

Type 1 Opt-Out

A Type 1 Opt-Out is recorded by your GP practice.

It prevents confidential patient information held in your GP record from being extracted from the Practice for certain purposes beyond your individual care, including research and planning.

Existing Type 1 Opt-Outs continue to be respected.

A Type 1 Opt-Out does not prevent information being shared where it is necessary for your individual healthcare or where there is another legal requirement to share information.

If you wish to register a Type 1 Opt-Out, please contact Barlow Medical Centre. We will record the appropriate code in your GP clinical record.

National Data Opt-Out

The National Data Opt-Out allows you to choose whether your confidential patient information can be used for certain research and planning purposes by NHS and other health and care organisations.

It does not prevent information being used for your individual care, and there are some circumstances where the National Data Opt-Out does not apply, such as where information must be used because of a legal requirement or another recognised exemption.

You can make or change your choice at any time.

The Practice cannot set the National Data Opt-Out for you. It is managed through the national NHS service.

You can manage your choice:

  • Online: through the NHS “Your NHS Data Matters” service;
  • NHS App: patients able to use the National Data Opt-Out service can manage their choice through the NHS App;
  • Telephone: 0300 303 5678, Monday to Friday, 9am to 5pm, excluding English bank holidays; or
  • Print and post: using the form available through the NHS National Data Opt-Out service.

Patients aged 13 and over can normally make their own National Data Opt-Out choice.

Parents or legal guardians can make a choice on behalf of a child under 13 using the appropriate national process. A person with appropriate legal authority, such as a Lasting Power of Attorney or Court-appointed deputy, may also be able to make a choice on another person’s behalf using the relevant process.

Further information is available through:

Safeguarding

Sometimes we need to share information to protect a child, an adult at risk, healthcare staff or another person from harm.

Where safeguarding information needs to be shared, we do not always require the patient’s consent.

Information will only be shared where there is an appropriate legal or professional basis to do so and only information relevant to the safeguarding concern will be disclosed.

Further safeguarding information is available from the Practice.

Children and young people

Children and young people are entitled to confidentiality.

When a young person has sufficient understanding and competence to make decisions about their healthcare, their confidentiality will normally be respected.

A parent or person with parental responsibility does not automatically have an unrestricted right to access all of a child’s medical information.

Requests for access to a child’s information will be considered taking account of:

  • the child’s age and understanding;
  • their competence to make decisions;
  • their wishes;
  • parental responsibility;
  • safeguarding considerations;
  • the best interests of the child; and
  • applicable legal and professional guidance.

Further information can be found in NHS guidance on consent to treatment for children and young people and the Care Quality Commission’s guidance on Gillick competence and Fraser guidelines.

Please also see our Children and Families Care Privacy Policy.

People who lack capacity

Where a person lacks capacity to make a particular decision, information will be managed in accordance with applicable legislation and guidance and with consideration of the person’s best interests.

A person holding a Lasting Power of Attorney or another legal authority does not necessarily have unrestricted access to every part of another person’s medical record.

We will consider the nature and scope of the person’s legal authority, the information requested and the circumstances before information is disclosed.

Personal data breaches

A personal data breach is a security incident that leads to the accidental or unlawful:

  • destruction;
  • loss;
  • alteration;
  • unauthorised disclosure of; or
  • unauthorised access to

personal information.

Barlow Medical Centre takes suspected data breaches seriously and will investigate them as soon as practicable after becoming aware of them.

Where required, incidents will be reported through the relevant NHS data-security and incident-reporting arrangements and to the Information Commissioner’s Office (ICO).

A reportable personal-data breach must be reported to the ICO without undue delay and, where applicable, within the statutory reporting period.

Where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will also notify those individuals where required by law.

Following an incident, we will investigate what happened, take appropriate remedial action and identify learning to reduce the risk of recurrence.

Data-protection complaints

If you are concerned about how Barlow Medical Centre has collected, used, disclosed or otherwise handled your personal information, please contact us in the first instance.

You can make a data-protection complaint to:

Practice Manager / Data Protection Officer
Barlow Medical Centre
828 Wilmslow Road
Didsbury
Manchester
M20 2RN

Telephone: 0161 445 9000

We have arrangements in place for receiving, acknowledging, investigating and responding to data-protection complaints in accordance with current data-protection legislation.

We will investigate your concerns and provide you with an outcome.

If you remain dissatisfied after giving us the opportunity to deal with your concern, you have the right to complain to the Information Commissioner’s Office (ICO).

Information Commissioner’s Office
Website: www.ico.org.uk
Telephone: 0303 123 1113

You may also contact NHS Greater Manchester Integrated Care Board where appropriate in relation to commissioned NHS primary care services.

Where your concern forms part of a wider NHS service complaint, you may also have the right to refer the matter to the Parliamentary and Health Service Ombudsman after the appropriate complaints procedure has been completed.

Guidance on our general complaints procedure is available from the Practice.

Cookies

Cookies are small text files placed on your computer, phone or other device when you visit a website.

They are widely used to make websites work, improve how they operate and provide information to website owners.

Some cookies are necessary for a website to function. Where consent is legally required for optional cookies, you will be given an appropriate choice.

Further information about cookies is available from the Information Commissioner’s Office:

ICO – Cookies

Change of details

It is important that the information we hold about you is accurate and up to date.

Please tell us if information such as your:

  • name;
  • address;
  • telephone number;
  • email address;
  • next of kin;
  • communication preferences; or
  • other relevant personal details

changes.

Please also tell us if you believe factual information such as your date of birth has been recorded incorrectly.

Keeping these details current helps us to provide safe and effective care and to contact you appropriately.

Other privacy notices and policies

Further information about privacy, information governance and how particular categories of information are handled is available in our related notices and policies:

Further information

Further information about data protection and the use of health and care information is available from:

  • the Information Commissioner’s Office;
  • NHS England;
  • the NHS “Your NHS Data Matters” service;
  • the Care Quality Commission; and
  • Barlow Medical Centre.

Review of this privacy notice

We routinely review this privacy notice to ensure that it remains accurate and reflects current legislation, NHS guidance and the way in which the Practice operates.

The notice will normally be reviewed at least annually and earlier where there is:

  • a significant change in data-protection legislation;
  • new guidance from the ICO, Government, NHS England or another relevant body;
  • implementation of a significant new system or technology;
  • a significant change in how personal information is processed; or
  • another change requiring the information provided to patients to be updated.

Any updated version will be published on the Practice website.

The Practice maintains appropriate version-control records for this notice.

Last reviewed: August 2026

Page published: 2 August 2023
Last updated: 27 August 2026