GDPR & Patient Data Protection for UK Dental Practices
The DentiPoint Team · 16 July 2026 · 9 min read
GDPR for dental practices is not just paperwork. You hold some of the most private data a person owns. That means their medical history, X-rays, contact details and payment records. UK data protection law asks you to look after all of it properly. This guide explains the rules in plain English. It covers how long to keep records, the contracts you need with suppliers, whether you need a data protection officer, and how the right software takes most of the weight off your team.
What GDPR for dental practices really means
Since Brexit, the UK follows its own version of the rules. These are the UK GDPR and the Data Protection Act 2018. They work in almost the same way as the EU version. The regulator is the Information Commissioner's Office, or ICO.
Your practice is the "data controller". That means you decide why and how patient data is used. You are responsible for keeping it safe and lawful. Patient health data is also "special category data". This is the highest-risk class of personal data. You need an extra legal condition to handle it, on top of your normal lawful basis. Getting this right sits at the heart of GDPR for dental practices.
The lawful basis for holding patient records
A common myth is that you always need consent to hold clinical records. You usually do not. For treatment notes, consent is the wrong basis. If a patient could withdraw consent at any time, you could not keep the records the law requires you to keep.
Instead, most practices rely on other lawful bases. For general data, that is often a legal obligation or legitimate interests. For the health data itself, the condition is usually the provision of health care and treatment. NHS work also sits under a "public task" basis. Consent really matters for one thing: marketing. If you want to send a newsletter or a special offer, you need a clear opt-in first.
How long to keep dental records: the 10-year rule
Dental patient data retention is one area people often get wrong. You cannot keep records forever "just in case". You also cannot delete them early to save space. There is a clear standard to follow.
The NHS Records Management Code of Practice sets the benchmark most practices use. For adults, it recommends keeping dental records for at least 10 years after the last entry. For children, you keep records until their 25th birthday, or their 26th if they were 17 at the last visit. You use whichever date is longer. Some private records are held for 11 years. These rules can change, so check the current NHS and BDA guidance for your own situation.
The practical point is simple. You need a written retention policy. You need to apply it evenly to every patient. And you need to safely destroy or archive records once the period ends.
Data processing agreements with your suppliers
You almost certainly share patient data with other companies. Your cloud software stores it. Your reminder tool sends recalls and appointment texts. Your card machine takes payments. In law, these firms are your "data processors". You remain the controller, and the duty still rests with you.
UK GDPR says you must have a written contract with every processor. This is often called a data processing agreement, or DPA. Article 28 of the regulation sets out what it must contain. A good DPA should cover:
- What data is processed, and why
- How long the supplier keeps it
- The security measures in place
- Any sub-processors they use
- Where data is stored, and that it stays in the UK or an approved country
A reputable cloud provider gives you a signed DPA as standard. Ask for it before you sign up. If a supplier cannot provide one, treat that as a warning sign.
Do you need a DPO?
A data protection officer, or DPO, is a formal role under UK GDPR. Many owners assume they must appoint one. Most small practices do not have to.
The law only makes a DPO mandatory in three cases. You are a public authority. You carry out large-scale monitoring of people. Or you process special category data on a large scale. The ICO has said a single dentist handling their own patients' data is not "large scale". So a typical independent practice does not cross that line.
Even so, someone still has to own data protection. Name a data protection lead and write it into their role. Larger groups and corporates that process data across many sites may meet the threshold. If you run a multi-branch group, take advice before you decide.
Writing a clear privacy notice
Every practice needs a privacy notice. This is the document that tells patients how you use their data. It is a legal requirement under the transparency rules. Display it on your website and keep a copy in reception.
A good dental practice privacy notice is written in plain language, not legal jargon. It should explain:
- What data you collect, and why
- Your lawful basis for using it
- How long you keep records
- Who you share data with
- The rights patients have over their data
- How to contact you or complain to the ICO
Keep it honest and specific. Avoid copying a generic template that does not match how you actually work. If your notice says one thing and your team does another, that gap is the real risk.
Keeping data secure: encryption, access and backups
Security is where most breaches happen. It is also where software helps the most. Paper notes in an unlocked cabinet are a real risk. So are shared logins and patient lists saved on a laptop.
Good security works in layers:
- Data is encrypted, both when stored and when sent over the internet
- Each team member has their own login, never a shared one
- Access is limited to what each role actually needs
- An audit trail records who viewed or changed each record
Backups matter just as much. You need regular, encrypted backups kept off-site. If a computer is lost, stolen or hit by ransomware, you can still recover the data. Moving off paper is a big part of going paperless in a safe way. This is where good dental patient records software earns its place. It builds the encryption, logins and backups in for you.
Patient rights and subject access requests
UK GDPR gives patients strong rights over their data. The one you will meet most is the subject access request, or SAR. A patient can ask for a copy of everything you hold on them. You must reply within one month. In most cases you cannot charge a fee.
Patients can also ask you to correct wrong details. They can ask you to delete data, though that right is limited for clinical records you are required to keep. Have a simple process so reception or your practice manager knows what to do when a request lands. A system that can pull a full patient record in seconds makes these requests far easier to handle.
What to do if data is breached
A data breach is any event where data is lost, stolen or seen by the wrong person. It might be a lost laptop, an email sent to the wrong address, or a hacked account. Not every breach has to be reported. Serious ones do.
If a breach is likely to risk people's rights, you must tell the ICO within 72 hours. If the risk is high, you must also tell the patients affected. Keep a written record of every breach, even the small ones. Practise your response before you ever need it. Speed and honesty count for more than a spotless history.
How software cuts the compliance load
You cannot hand your legal duty to someone else. But you can make it far easier to meet. A modern cloud system does a lot of the heavy lifting. It stores records securely with encryption and individual logins. It keeps an audit trail. It runs encrypted backups without anyone having to remember. And a trusted UK provider hands you a signed DPA on day one.
This is why so many teams move off paper and spreadsheets. Pair strong software with clear policies and trained staff, and most of the daily burden looks after itself. For the wider inspection picture, our CQC compliance checklist shows how data protection fits alongside the rest. You can also see how dental practice management software ties records, booking and automated reminders together in one place.
Frequently asked questions
Do dental practices need to register with the ICO?
Yes, in nearly all cases. If you process personal data on a computer, you must pay the ICO's annual data protection fee. Most small practices sit in the lowest tier. The exact amount changes each year, so check ico.org.uk for the current fee. Failing to register can lead to a fine.
Is patient consent the lawful basis for holding records?
No, not usually. Clinical records are held under health and legal-obligation bases, not consent. Consent mainly covers marketing, such as newsletters or offers. Treating consent as the basis for everything is a common and risky mistake.
How long must we keep dental records under GDPR?
GDPR itself sets no fixed number. It only says keep data no longer than you need it. In practice, the NHS Records Management Code sets the standard: at least 10 years for adults, and until age 25 or 26 for children. Always check the latest NHS and BDA guidance.
Does a small dental practice need a data protection officer?
Usually not. A single independent practice rarely meets the "large scale" threshold for a mandatory DPO. You still need someone responsible for data protection day to day. Larger multi-branch groups should take advice, as they may need a formal DPO.
Strong data protection is not about fear. It is about running an organised, trustworthy practice that patients can rely on. Get your policies, contracts and software right, and compliance stops being a worry hanging over the team. If you are setting up or reviewing your systems, DentiPoint brings records, booking, reminders and payments into one secure place from £15 a month. When you are ready, you can start free.