GDPR: Record rights and wrongs

Source: NHE May/June 18

As patients get stronger legal rights to access and challenge the contents of their medical records, Dr Carol Chu, Medical Defence Union (MDU) medico-legal adviser, looks at the implications for clinicians and healthcare managers.

Requests from patients to see their records are likely to become more frequent amid growing public interest in the way organisations use personal information and the publicity surrounding the General Data Protection Regulation (GDPR), which came into force on 25 May. 

If you work in the NHS, you need to understand how to respond appropriately to access requests or your organisation could be reported to the Information Commissioner’s Office (ICO).


The GDPR requires data controllers to inform patients about how their personal data will be used and their rights as a data subject. It’s likely that your organisation will have updated its privacy policies which set out these details. For example, the MDU’s privacy policy states that members can review and update the information we hold about them.

Privacy policies are expected to be written in clear and plain language and be easily accessible. You should be familiar with its content in case a patient needs clarification on any point. It’s also a good idea to find out the name of your organisation’s data controller and of your local data protection officer (DPO).

Access requests

Under the GDPR there are time limits to respond to Subject Access Requests, so it is important to understand how the process works so as not to cause unnecessary delays or mislead anyone who approaches you and asks to see their records. Here are some key points to know:

  • A Subject Access Request does not have to be in writing. A verbal request is also valid;
  • The identity of the person making the request should be verified;
  • The subject cannot be charged for copies of records unless the request is “manifestly unfounded, excessive or repetitive.” There is no definition of what constitutes this, however. Such cases should be discussed with your DPO;
  • The information should be provided within one month. This can be extended by a further two months if requests are complex or numerous. If you need an extension, the patient should be informed within one month;
  • Requests that are unfounded or excessive can be refused, but in such cases this should be explained and the subject told of their right to complain to the ICO and to seek judicial remedy;
  • Access requests must be documented, including details of any delay in providing the information and when requests have been refused.

Rights of rectification

Occasionally, patients may raise concerns about the information held in their records or ask for corrections. It is important to know how to respond appropriately to a request for rectification as these do not have to be made in writing to a specific person, even if they are ultimately managed by your organisation’s data controller. The time limits for responding to rectification requests echo those for Subject Access Requests and in most circumstances there should be no charge.

Requests for rectification of healthcare records can be problematic, as there is a risk that patients may object to the content because it is upsetting or they disagree with doctors’ clinical opinions. Although the GDPR gives data subjects the right to correct data if it is factually inaccurate or incomplete, the ICO has clarified that this does not extend to clinical opinions. However, it may be possible to make an additional note recording that the patient disagrees with the opinion. In the event that a factual correction is necessary, such as a misspelt name or incorrect date of birth, it must be obvious who made the amendment and when.

Four questions to ask

Here are four questions to consider now about the new data protection regulations:

  1. Does my organisation need a DPO?

The GDPR obliges data controllers to appoint a DPO if they are a public authority or a ‘large-scale’ processor of special category personal data. A public authority is defined by the Freedom of Information Act 2000 in England, Wales and Northern Ireland and the Freedom of Information (Scotland) Act 2002. Public authorities were required to appoint or make arrangements to share a DPO by 25 May.

Although it is not clear what large-scale processing entails, the need to appoint a DPO may not apply to an individual independent practitioner, for example.

DPOs must have proven expert knowledge of data protection law and practice. It is recognised they will not fully understand all the ramifications of the new legal requirements from 25 May, and they will need to keep up-to-date with any changes and clarifications (for example from the ICO) and understand the impact of these changes as the law becomes embedded. Further information about DPOs can be found on the ICO website and the Information Governance Alliance website.

  1. On what basis are we processing personal data?

The GDPR applies to ‘personal data,’ meaning any information relating to an identifiable person who can be directly or indirectly identified by reference to an identifier. You must have a valid lawful basis for processing (Article 6) and inform the subject of the basis or bases you are relying on.

Health data is considered to be special category data and therefore you will also need an additional condition for processing (Article 9).

Consent is one lawful basis for processing, but it may not be the best category for healthcare records and it may be better to choose a different basis.

  1. Have we updated our privacy notice?

Your organisation must provide individuals with information including the purposes for processing their personal data, retention periods for that personal data and who it will be shared with, as well as contact details for your DPO. This privacy information must be provided to individuals at the time you collect their data.

The ICO has a useful checklist explaining the information that privacy notices need to contain.

  1. Have we updated our subject access request procedure?

As outlined above, there are some changes to the procedure for individuals to request access to their records. These include that requests no longer have to be in writing, that a charge cannot usually be made, and there are reduced time limits.

Your organisation will need to ensure these changes are reflected in your procedure and that these are communicated to the team.


The MDU’s GDPR guidance is available on


Other useful checklists and resources can be found on:


There are no comments. Why not be the first?

Add your comment


national health executive tv

more videos >

latest healthcare news

HEE pledges greater support for doctors’ medical school transition

17/07/2019HEE pledges greater support for doctors’ medical school transition

Health Education England (HEE) has outlined its commitment to supporting doctors in the transition from medical school into training and working ... more >
NICE approves breast cancer drug combination on Cancer Drugs Fund

17/07/2019NICE approves breast cancer drug combination on Cancer Drugs Fund

The National Institute for Health and Care Excellence (NICE) has approved a new potentially life-extending drug combination for some people with ... more >
East Midlands Ambulance Service earns ‘Good’ rating from CQC

17/07/2019East Midlands Ambulance Service earns ‘Good’ rating from CQC

The Care Quality Commission (CQC) has awarded the East Midlands Ambulance Service NHS Trust a ‘Good’ rating, following an inspec... more >

681 149x260 NHE Subscribe button

the scalpel's daily blog

Urology nurses are leading the way in adoption of prostate cancer biopsy technique

11/07/2019Urology nurses are leading the way in adoption of prostate cancer biopsy technique

Jonah Rusere, Advanced Nurse Practitioner for South East London Accountable Cancer Network, outlines an opportunity for urology nurses to make a difference to prostate cancer pathways. What is TRexit and why is it great news for prostate cancer patients all over the country? Let me explain. TRexit is the name given to a national initiative for hospitals to phase out TRUS biopsies and replace them with transperineal biopsies un... more >
read more blog posts from 'the scalpel' >


How can winter pressures be dealt with? Introduce a National Social Care Service, RCP president suggests

24/10/2018How can winter pressures be dealt with? Introduce a National Social Care Service, RCP president suggests

A dedicated national social care service could be a potential solution to surging demand burdening acute health providers over the winter months,... more >
RCP president on new Liverpool college building: ‘This will be a hub for clinicians in the north’

24/10/2018RCP president on new Liverpool college building: ‘This will be a hub for clinicians in the north’

The president of the Royal College of Physicians (RCP) has told NHE that the college’s new headquarters based in Liverpool will become a hu... more >
Duncan Selbie: A step on the journey to population health

24/01/2018Duncan Selbie: A step on the journey to population health

The NHS plays a part in the country’s wellness – but it’s far from being all that matters. Duncan Selbie, chief executive of Pu... more >
Cutting through the fake news

22/11/2017Cutting through the fake news

In an era of so-called ‘fake news’ growing alongside a renewed focus on reducing stigma around mental health, Paul Farmer, chief exec... more >

last word

Hard to be optimistic

Hard to be optimistic

Rachel Power, chief executive of the Patients Association, warns that we must be realistic about the very real effects of continued underfunding across the health service. It’s now bey... more > more last word articles >

editor's comment

25/09/2017A hotbed of innovation

This edition of NHE comes hot on the heels of this year’s NHS Expo which, once again, proved to be a huge success at Manchester Central. A number of announcements were made during the event, with the health secretary naming the second wave of NHS digital pioneers, or ‘fast followers’, which follow the initial global digital e... read more >

health service focus

NHS Clinical Commissioners respond to NHS Implementation Framework

28/06/2019NHS Clinical Commissioners respond to NHS Implementation Framework

The membership organisation for clinical comm... more >
Can the NHS find savings in their energy bills?

10/06/2019Can the NHS find savings in their energy bills?

As the NHS works harder than ever to meet cha... more >