Skip to main content

Privacy notice

Privacy Notice for General Practice

How we use your personal information

This fair processing notice explains why the GP practice collects information about you and how that information may be used.

The health care professionals who provide you with care maintain records about your health and any treatment or care you have received previously (e.g. NHS Trust, GP Surgery, Walk-in clinic, etc.). These records help to provide you with the best possible healthcare.

NHS health records may be electronic, on paper or a mixture of both, and we use a combination of working practices and technology to ensure that your information is kept confidential and secure. Records which this GP Practice holds about you may include the following information;

  • Details about you, such as your address, carer, legal representative, emergency contact details
  • Any contact the surgery has had with you, such as appointments, clinic visits, emergency appointments, etc.
  • Notes and reports about your health
  • Details about your treatment and care
  • Results of investigations such as laboratory tests, x-rays etc.
  • Relevant information from other health professionals, relatives or those who care for you

To ensure you receive the best possible care, your records are used to facilitate the care you receive. Information held about you may be used to help protect the health of the public and to help us manage the NHS. Information may be used within the GP practice for clinical Audit to monitor the quality of the service provided.

Some of this information will be held centrally and used for statistical purposes. Where we do this, we take strict measures to ensure that individual patients cannot be identified. Sometimes your information may be requested to be used for research purposes – the surgery will always gain your consent before releasing the information for this purpose.

Risk Stratification

Risk stratification data tools are increasingly being used in the NHS to help determine a person’s risk of suffering a particular condition, preventing an unplanned or (re)admission and identifying a need for preventive intervention. Information about you is collected from a number of sources including NHS Trusts and from this GP Practice. A risk score is then arrived at through an analysis of your de-identified information using software managed by Manchester Health Care Commissioning (MHCC), and is only provided back to your GP as data controller in an identifiable form. Risk stratification enables your GP to focus on preventing ill health and not just the treatment of sickness. If necessary your GP may be able to offer you additional services. Please note that you have the right to opt out of your data being used in this way.

OpenSAFELY Data Analytics and COVID-19 Research

NHS England has been directed by the government to establish and operate the OpenSAFELY COVID-19 Service and the OpenSAFELY Data Analytics Service. These services provide a secure environment that supports research, clinical audit, service evaluation and health surveillance for COVID-19 and other purposes

Each GP practice remains the Data Controller for its own GP patient data but is required to allow approved users to run queries on pseudonymised patient data within the OpenSAFELY platform. This means that personal identifiers are removed and replaced with a pseudonym.

Only approved users are permitted to run these queries, and they cannot access information that directly or indirectly identifies individual patients. Data is accessed and analysed in a highly secure environment and is subject to strict governance and controls.

Patients who do not wish for their GP data to be used in this way can register a Type 1 Opt-Out with their GP practice. This opt-out prevents identifiable data from being used for purposes beyond individual care.

Med Management

The Practice may conduct Medicines Management Reviews of medications prescribed to its patients. This service performs a review of prescribed medications to ensure patients receive the most appropriate, up to date and cost effective treatments.

How do we maintain the confidentiality of your records?

We are committed to protecting your privacy and will only use information collected lawfully in accordance with:

  • Data Protection Act 1998
  • Human Rights Act 1998
  • Common Law Duty of Confidentiality
  • Health and Social Care Act 2012
  • NHS Codes of Confidentiality, Information Security and Records Management
  • Information: To Share or Not to Share Review

Every member of staff who works for an NHS organisation has a legal obligation to keep information about your confidential.

We will only ever use or pass on information about you if others involved in your care have a genuine need for it. We will not disclose your information to any third party without your permission unless there are exceptional circumstances (i.e. life or death situations), where the law requires information to be passed on and / or in accordance with the new information sharing principle following Dame Fiona Caldicott’s information sharing review (Information to share or not to share) where “The duty to share information can be as important as the duty to protect patient confidentiality.” This means that health and social care professionals should have the confidence to share information in the best interests of their patients within the framework set out by the Caldicott principles. They should be supported by the policies of their employers, regulators and professional bodies.

Who are our partner organisations?

We may also have to share your information, subject to strict agreements on how it will be used, with the following organisations;

  • NHS Trusts / Foundation Trusts
  • GPs
  • NHS Commissioning Support Units
  • Independent Contractors such as dentists, opticians, pharmacists
  • Private Sector Providers
  • Voluntary Sector Providers
  • Ambulance Trusts
  • Clinical Commissioning Groups
  • Social Care Services
  • Health and Social Care Information Centre (HSCIC)
  • Local Authorities
  • Education Services
  • Fire and Rescue Services
  • Police & Judicial Services
  • Voluntary Sector Providers
  • Private Sector Providers
  • Other ‘data processors’ which you will be informed of

Car Park Monitoring and Parking Enforcement

 You will be informed who your data will be shared with and in some cases asked for explicit consent for this happen when this is required. We may also use external companies to process personal information, such as for archiving purposes. These companies are bound by contractual agreements to ensure information is kept confidential and secure.

Barlow Medical Centre provides car parking facilities to support access for patients, staff and emergency services.

Parking management on the practice car park, including the use of Automatic Number Plate Recognition (ANPR) technology, is carried out by Northwest Parking Management Ltd, who operate and enforce the parking system on this site.

Northwest Parking Management Ltd is the Data Controller for any personal data collected in connection with car park monitoring, permit management and parking enforcement. This includes vehicle registration numbers and, where applicable, registered keeper details obtained from the DVLA.

Barlow Medical Centre does not access, store or control ANPR or parking enforcement data.

For information about how parking-related personal data is used, retained and your data protection rights, please refer to Northwest Parking Management Ltd’s Privacy Notice, which is available via car park signage or directly from Northwest Parking Management Ltd.

Any queries, complaints or data protection requests relating to parking charges or car park data should be directed to Northwest Parking Management Ltd, not the GP practice.

Use of AI and Ambient Voice Technology

We may use approved artificial intelligence and automation tools to support the delivery of healthcare and improve our administrative processes. These tools are used to assist our staff and clinicians; they do not replace professional judgement or make decisions about your care without human oversight.

Surgery Intellect – AI-assisted clinical documentation

  • We use Surgery Intellect, an ambient voice technology provided by X-on Health and powered by Tortus AI, to support clinicians with clinical documentation.
  • With your knowledge, Surgery Intellect may securely process the conversation during your consultation and use artificial intelligence to produce a draft clinical note. It may also suggest relevant clinical codes or help prepare letters based on the consultation.
  • Your clinician remains responsible for your medical record and any decisions about your care. They will review, amend and approve any information produced by Surgery Intellect before it is added to your medical record. The technology does not independently diagnose you, prescribe treatment or make clinical decisions.
  • We use Surgery Intellect to support direct patient care and to allow clinicians to focus more fully on the patient during the consultation. Its use is subject to appropriate data-protection, information-governance, clinical-safety and security checks.
  • You will be informed when the technology is being used. You can ask the clinician not to use it during your consultation, and this will not affect your care. Where it is not used, the clinician will record the consultation using their usual method.
  • Information processed using Surgery Intellect remains confidential and must only be used for authorised healthcare purposes. Further information about how we use and protect your information is available in this privacy notice.

Access to personal information

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the right to ask whether we hold personal information about you, to receive a copy of that information and to ask us to correct information that is inaccurate or incomplete.

You can make a subject access request verbally or in writing, including by letter, email, telephone or in person. You do not need to use a particular form or refer specifically to data protection law. For information held by another organisation, such as a hospital, you should normally contact that organisation directly.

We will normally provide your information free of charge. We may charge a reasonable administrative fee where a request is manifestly unfounded or excessive, or where you ask for further copies of information already provided. We may refuse all or part of a request where permitted by law, including where a relevant legal exemption applies. If we refuse a request or withhold information, we will explain our reasons and tell you about your right to complain.

We will respond without undue delay and normally within one calendar month. Where we reasonably require further information to confirm your identity or a representative’s authority to act for you, the time limit will begin when we receive that information. If your request is unclear, we may ask you to clarify the information you require.

If your request is complex, or you have made a number of requests, we may extend the response period by up to two further months. We will tell you within one month if an extension is necessary and explain why.

We may ask you to provide enough information to help us confirm your identity and locate the information, such as your full name, previous names, date of birth, address, NHS number and details of the information or period you are asking about. We will only request identification that is reasonable and proportionate in the circumstances.

If you are unhappy with how we have used your personal information or handled a request, please contact the practice using the details shown on this website.

You also have the right to complain to the Information Commissioner’s Office:

Website: ico.org.uk

Telephone: 0303 123 1113

Reports about you, including insurance reports

We use iGPR Technologies Limited (“iGPR”) to support the administration and preparation of certain requests involving your medical records. These may include subject access requests made by you or by someone authorised to act on your behalf, and medical-report requests made by insurers or other authorised organisations.

For this service, the practice is the data controller and iGPR acts as a data processor on our behalf. iGPR processes information under a written agreement and in accordance with our instructions and agreed operating procedures.

We determine the rules and operating parameters under which information may be disclosed, and we remain responsible for decisions that are referred back to the practice.

iGPR may receive requests, carry out initial checks, access the relevant patient record, generate a report, apply agreed redactions and securely provide the completed information to the patient or authorised requesting organisation.

The process used depends on how the report request is received:

Requests received directly by the practice

Where an insurance report request is received and processed by the practice, the completed report will be reviewed and authorised by an appropriate clinician before it is released.

Requests initiated directly by an insurer through iGPR

Where an insurer sends a request directly through the iGPR service, iGPR may generate, review, redact and release the report in accordance with the procedures and operating parameters agreed with the practice. These reports are not routinely reviewed by a clinician at the practice before release.

iGPR must refer a request back to the practice where it falls outside the agreed operating parameters, where there is a query or concern, or where a clinical or data-controller decision is required.

Before information is released, the request must be supported by appropriate evidence of the patient’s identity, authority and consent where required.

Information processed through iGPR is hosted in the UK. iGPR may use approved UK-based service providers to host and secure the service. Reports are retained within the iGPR system only for the period needed to complete and deliver the request, subject to limited audit information being retained in accordance with the contractual arrangements.

Your rights when an insurer requests a medical report

Before an insurer applies for a medical report, it must inform you that it intends to do so and obtain your consent. The practice or doctor must be satisfied that appropriate consent has been provided before information is disclosed.

Under the Access to Medical Reports Act 1988, where the report is prepared by a doctor who is or has been responsible for your clinical care, you may normally:

  • ask to see the report before it is sent to the insurer;
  • ask for factual inaccuracies to be corrected;
  • ask for a statement recording your disagreement to be attached where the doctor does not agree that the report is inaccurate; and
  • withdraw your consent and ask that the report is not sent.

Where you have asked to see the report before it is sent, it will normally be held for up to 21 days to allow you to arrange to view it. Once you have seen it, you may agree that it can be sent, ask for corrections or withdraw your consent.

A doctor is not required to remove accurate and relevant information where doing so would make the report false or misleading.

In limited circumstances, you may not be given access to all of a report, for example where disclosure would be likely to cause serious harm to you or another person, or where it would reveal confidential information about another person.

If you have any concerns about a report, including its accuracy or the information it contains, please contact the practice as soon as possible and before the end of the review period.

Reference sources –

Objections / Complaints

Should you have any concerns about how your information is managed at the GP, please contact the GP Practice Manager. If you are still unhappy following a review by the GP practice, you can then complain to the Information Commissioners Office (ICO) via their website (https://ico.org.uk/).

If you are happy for your data to be extracted and used for the purposes described in this privacy notice then you do not need to do anything. If you have any concerns about how your data is shared then please contact the practice.

Cookies

Cookies are small text files that are placed on your computer by websites that you visit. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site. For more detailed information about cookies visit: https://ico.org.uk/for-the-public/online/cookies

Change of Details

It is important that you tell the person treating you if any of your details such as your name or address have changed or if any of your details such as date of birth is incorrect in order for this to be amended. You have a responsibility to inform us of any changes so our records are accurate and up to date for you.

Notification

The Data Protection Act 1998 requires organisations to register a notification with the Information Commissioner to describe the purposes for which they process personal and sensitive information.

This information is publicly available on the Information Commissioners Office website www.ico.org.uk

The practice is registered with the Information Commissioners Office (ICO).

Who is the Data Controller?

The Data Controller, responsible for keeping your information secure and confidential is:

The Assistant Practice Manager at Barlow Medical Centre

Complaints

Should you have any concerns about how your information is managed by the Assistant Practice please contact the Assistant Practice Manager at the following address:

Barlow Medical Centre, 828 Wilmslow Road, Didsbury, Manchester, M20 2RN

If you are still unhappy following a review by the Practice you can then complain to the Information Commissioners Office (ICO)

Website: www.ico.org.uk

Email: casework@ico.org.uk,

Telephone: 0303 123 1113 (local rate) or 01625 545 745

Please read our other privacy notices/policies below by clicking on the titles for further information.

Contact Us

If you have any questions about this Privacy Notice, please contact us on 0161 445 9000. 

Changes to Our Privacy Notice

We may update this Privacy Notice from time to time. Any changes will be posted on this page.

Page published: 2 August 2023
Last updated: 29 July 2026