Privacy Policy

The practice aims to meet the requirements of the Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), the guidance on the Information Commissioner’s Office website, as well as our professional guidelines and requirements.

The data controller is Lina Shah, who is also the Information Governance Lead and the Data Protection Officer.

This Privacy Notice is available on the practice website at wheathampsteaddental.com, at reception, by email if you contact wheathampsteaddentalsurgery@gmail.com, or by calling 01582 833232.

You may be asked to provide personal information when joining the practice, receiving treatment, contacting us, or submitting an enquiry through our website. The purpose of us processing this data is to provide dental care, manage the practice effectively, respond to enquiries, and arrange appointments where requested.

The categories of data we process are:

  • Personal data for the purposes of patient care and practice administration
  • Personal data for the purposes of staff and self-employed team member management
  • Personal data submitted through the website contact form, including name, email address, telephone number and message content
  • Technical website usage data collected through cookies and analytics tools
  • Personal data for the purposes of direct mail, email, text or other marketing, where consent has been given
  • Special category data including health records for the purposes of the delivery of health care
  • Special category data including health records and details of criminal record checks for managing employees and contracted team members

If you submit an enquiry through the website contact form, the information you provide is used only to respond to your enquiry or to help arrange an appointment. This information is not stored on the website itself and is sent by email to wheathampsteaddentalsurgery@gmail.com.

We use Google Analytics on our website to help us understand how visitors use the site and to improve website performance and user experience. Google Analytics collects information such as pages visited, time spent on the site, browser type and general location data. Analytics cookies are only used where you have given consent through our cookie banner.

We never pass your personal details to a third party unless we have a lawful basis to do so and, where required, a contract for them to process data on our behalf. We will otherwise keep your information confidential. If we intend to refer a patient to another practitioner or to secondary care such as a hospital, we will gain the individual’s permission before the referral is made and the personal data is shared, unless there is another lawful basis to do so.

  • Personal data may be stored in the UK or EEA in digital or hard copy format
  • Some digital service providers, such as Google, may process personal data outside the UK or EEA. Where this happens, appropriate safeguards are used
  • Personal data is obtained when a patient joins the practice, when a patient is referred to the practice, when a patient subscribes to an email list, and when a website visitor submits an enquiry through the contact form

The lawful basis for processing personal data and special category data such as patients’ and employees’ health data includes the following:

Provision of healthcare

Processing is necessary for the purposes of preventative or occupational medicine, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services, on the basis of law or pursuant to a contract with a health professional.

Consent of the data subject

Processing may also be based on the consent of the data subject where applicable, including for certain marketing communications and for the use of non-essential website cookies such as analytics cookies.

Contract

Processing may be necessary for the performance of a contract with the data subject or to take steps at the request of the data subject before entering into a contract.

Legitimate interests

Processing website enquiry data is necessary for our legitimate interests in responding to enquiries, managing communications and arranging appointments.

The retention period for special category data in patient records is a minimum of 10 years and may be longer for complex records in order to meet our legal and professional requirements. The retention period for staff records is 6 years. The retention period for other personal data is generally 2 years after it was last processed, unless a longer period is required for administrative or legal reasons. Website contact form enquiries are retained only for as long as necessary to respond to the enquiry and manage any related administrative follow-up. Details of other retention periods are available in the Record Retention procedure available from the practice.

You have the following personal data rights:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure, although clinical records must be retained for certain time periods
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • The right to withdraw consent where processing is based on consent

Further details of these rights can be seen in our Information Governance Procedures or at the Information Commissioner’s Office website. Here are some practical examples of your rights:

If you are a patient of the practice, you have the right to withdraw consent for important notifications, newsletters, surveys or marketing. You can ask us to correct errors in your personal details or change your communication preferences, including telephone, email or text. You have the right to obtain a copy of your patient records, subject to applicable rules and timescales.

If you are not a patient of the practice, you have the right to withdraw consent for processing based on consent, to request a copy of your personal data, to correct errors in it or to ask us to delete it where appropriate. You can also withdraw consent from communication methods such as telephone, email or text.

We have carried out a Privacy Impact Assessment and you can request a copy using the contact details below. Details of how we ensure the security of personal data are contained in our Security Risk Assessment and Information Governance Procedures.

Comments, suggestions and complaints

Please download and read our Complaints Procedure here.

Please contact Lina Shah at the practice for a comment, suggestion or complaint about your data processing by email at wheathampsteaddentalsurgery@gmail.com, by phone on 01582 833232, or by writing to or visiting Wheathampstead Dental Surgery, 12 High Street, Wheathampstead, Herts, AL4 8AA. We take complaints very seriously.

If you are unhappy with our response, or if you need any advice, you should contact the Information Commissioner’s Office (ICO). Their telephone number is 0303 123 1113. The ICO can investigate your claim and take action against anyone who has misused personal data. You can also visit their website for information on how to make a data protection complaint.

Related practice procedures

You can also use these contact details to request copies of the following practice policies or procedures:

  • Data Protection and Information Security Policy, Consent Policy
  • Privacy Impact Assessment, Information Governance Procedures

Last updated: April 2026

Let us know how we can help

Get in touch
affiliate affiliate affiliate affiliate