Pendleside Medical Practice

Patient Privacy Notice


Updated: 15 October 2025

1. Introduction

Pendleside Medical Practice has a legal duty to explain how we use any personal information we collect about you as a registered patient. Staff at this practice maintain records about your health and the treatment you receive in both electronic and paper formats.

2. How we use your personal information

Being transparent and providing accessible information to patients about how we will use your personal information is a key element of the UK General Data Protection Regulation (UK GDPR).

This notice explains your rights under data protection law and how your GP Practice will use your information for lawful purposes to deliver your care and manage NHS services effectively. It applies to the use of information for:

– The management of patient records
– Communication concerning your clinical, social and supported care
– Ensuring quality of care and best clinical outcomes through audit and review
– Participation in health and social care research
– The management and clinical planning of services

We use a processor, iGPR Technologies Limited (“iGPR”), to assist us with responding to report requests relating to your patient data, such as subject access requests that you submit to us (or that someone acting on your behalf submits to us) and report requests that insurers submit to us under the Access to Medical Records Act 1988 in relation to a life insurance policy that you hold or that you are applying for. iGPR manages the reporting process for us by reviewing and responding to requests in accordance with our instructions and all applicable laws, including UK data protection laws. The instructions we issue to iGPR include general instructions on responding to requests and specific instructions on issues that will require further consultation with the GP responsible for your care.

2.a AI-Assisted Note taking During your Appointment

At Pendleside Medical Practice, we are committed to providing safe, high-quality care. To help us spend more time listening to you and less time typing during your appointment, some of our clinicians may use an AI-assisted ambient scribing tool.

What is an Ambient Scribe?

An ambient scribe is a secure digital tool that listens to the conversation between you and your clinician during your appointment. It automatically creates a draft of the clinical notes from your discussion.
Your clinician will carefully review and edit these notes before they are added to your medical record.

How Will It Be Used?

The notes created by the ambient scribe may be used to:

  • Add information to your health and care record.
  • Prepare referral letters or other clinical correspondence where appropriate.
  • Support accurate documentation of your consultation.

The AI tool does not make decisions about your care. All decisions about your treatment, diagnosis and ongoing care are made by you and your clinician, just as they always have been.

What Happens to the Recording?
The tool temporarily records the conversation during your appointment so that it can create the clinical notes.
Once your clinician has checked that the notes are accurate, the recording is securely deleted in line with NHS information governance requirements.

Is My Information Secure?

Yes. Protecting your personal information is extremely important to us. The ambient scribing technology has been assessed to ensure it meets NHS standards for security, confidentiality and data protection. Your information is handled securely and in accordance with UK data protection legislation.

If you have any questions or concerns, please speak to your clinician. If you would prefer that the ambient scribe is not used during your consultation, simply let them know. Your decision will not affect the care you receive in any way.

3. Data Controller

As your registered GP practice, Pendleside Medical Practice is the data controller for any personal data we hold about you. NHS England may also act as a data controller for certain national services, such as the GP Connect system.

4. What information do we collect and use?

We are committed to protecting your privacy and will only use information collected lawfully in accordance with:

– UK General Data Protection Regulation (UK GDPR)
– Data Protection Act 2018
– Human Rights Act 1998
– Common Law Duty of Confidentiality
– Health and Social Care Act 2012
– NHS Codes of Confidentiality and Information Security

Personal data means any information relating to an identifiable person. This includes name, date of birth, address, next of kin and NHS Number. Special category data includes information about your medical history, medications, appointments, results, ethnicity and other health information needed to provide care.

5. Why do we collect this information?

Under the NHS Act 2006 and the Health and Social Care Act 2012, GP practices have statutory functions to promote and provide healthcare in England, improve quality, conduct research, and deliver training. To do this, we process your data lawfully in order to:

– Protect your vital interests
– Pursue our legitimate interests as a healthcare provider
– Perform tasks in the public interest
– Deliver preventative medicine and medical diagnosis
– Manage the health and social care system and services

6. How do we use this information?

Your data is collected for the purpose of providing direct patient care. We may disclose this information if required by law, with your consent, or if justified in the public interest. When supporting medical research, we will always seek your explicit consent unless the law allows otherwise.

7. Who will we share your information with?

To deliver and coordinate your health and social care, we may share information with organisations such as:

– NHS Trusts / Foundation Trusts
– GP practices
– Independent contractors (dentists, opticians, pharmacists)
– Private and voluntary sector providers
– Social care services and local authorities
– NHS England and NHS Digital
– Ambulance services, community and mental health teams
– Police, fire and judicial services (where legally required)

We also share data securely through national NHS systems such as GP Connect to support your direct care. Your information will only be shared when appropriate and lawful.

7.a East Lancashire Alliance Services

Pendleside Medical Practice works collaboratively with East Lancashire Alliance and other participating GP practices to provide a range of enhanced NHS services, including the Vaginal Pessary Service, Enhanced Diabetes Service, Anticoagulation Monitoring Service, Parkinson’s Service, Enhanced Access, Palliative and End of Life Care, Simple Wound Care Service and other Alliance services.

If you receive care through one of these services, or are referred to one of them, relevant information from your GP record may be securely shared with healthcare professionals and authorised administrative staff working for East Lancashire Alliance or participating GP practices where this is necessary to provide your direct care and to manage the service safely and effectively.

Information shared may include your demographic details, relevant medical history, medications, allergies, diagnoses, consultation records, investigation results, referrals, correspondence and other information necessary for the healthcare professional providing your care. Only the minimum information necessary will be shared, and access is restricted to authorised staff with a legitimate need to know.

The sharing of your information for these services is carried out in accordance with UK data protection legislation, the common law duty of confidentiality and the Caldicott Principles. The legal basis for this processing is the performance of a task carried out in the public interest and the provision of health and social care under Articles 6(1)(e) and 9(2)(h) of the UK General Data Protection Regulation.

Pendleside Medical Practice and East Lancashire Alliance act as independent data controllers (or joint controllers where required by law) for information shared under the relevant Data Sharing Agreement. Each organisation is responsible for ensuring that your information is handled securely and only used for the purposes for which it was shared.

Where organisations process information on our behalf, they do so under a written contract and are required to comply with UK data protection legislation and NHS information governance standards.

8. How do we maintain the confidentiality of your records?

We are committed to protecting your privacy and comply with the UK GDPR, NHS Codes of Confidentiality and Security, and guidance from the Information Commissioner’s Office (ICO). All staff receive annual data protection training and only have access to your information when necessary for their role.

9. How long do we keep your information?

In accordance with the NHS Records Management Code of Practice 2021, healthcare records are retained for 10 years after a patient’s death or, if a patient emigrates, for 10 years after the date of emigration.

10. OpenSAFELY COVID-19 Service and the OpenSAFELY Data Analytics Service

NHS England has been directed by the government to establish and operate the OpenSAFELY COVID-19 Service and the OpenSAFELY Data Analytics Service. These services provide a secure environment that supports research, clinical audit, service evaluation and health surveillance for COVID-19 and other purposes.

Each GP practice remains the controller of its own GP patient data but is required to let approved users run queries on pseudonymised patient data. This means identifiers are removed and replaced with a pseudonym.

Only approved users are allowed to run these queries, and they will not be able to access information that directly or indirectly identifies individuals.

Patients who do not wish for their data to be used as part of this process can register type 1 opt out with their GP.

Find additional information about OpenSAFELY.

11. Your rights

You have rights under data protection law, including the right to access your information, request corrections, object to processing, and withdraw consent where applicable. To exercise these rights, please contact the practice.

12. Contact information

If you have questions about this notice or how we use your data, please contact:
Practice Manager: Daniel Lord (Deputy: Sue Askew)
Data Protection Officer: Hayley Gidman, Lancashire and South Cumbria ICB
Email: mlcsu.dpo@nhs.net

13. Complaints

If you believe we have not complied with data protection law, you can raise your concern with the Practice Manager. If you remain dissatisfied, you can contact the Information Commissioner’s Office (ICO) at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF or online at www.ico.org.uk.

14. Review

This Privacy Notice is reviewed annually or sooner if regulations or practice operations change.

Next review due: October 2026.