16.5 Records, Information Governance & Regulation

Key Takeaways

  • Health data is special category data under UK GDPR: the usual lawful bases in a clinical setting are Article 6(1) for the processing itself and Article 9(2)(h) for health and social care purposes, not patient consent
  • A subject access request must normally be answered within one month and free of charge, and the practice cannot demand a reason for the request
  • Retention periods differ across the UK: NHS England guidance for adults is now a minimum of 15 years, and for children until the 25th birthday (26th if the last entry was at 17), so always check the current schedule for your nation
  • The Caldicott principles govern the use of confidential patient information, and the eighth principle requires that patients have clear expectations about how their data is used
  • Enhanced CPD requires a dentist to complete 100 hours over the five-year cycle with a minimum of 10 hours in any consecutive two years, and to keep a personal development plan and a CPD log
Last updated: August 2026

Why Records Are a Regulatory Issue

Outcome A1.2 names regulatory issues relating to clinical practice including record keeping and information governance, and A1.5 names formal standards, guidelines and procedures, e.g. GDC requirements. Records are simultaneously a clinical tool, a legal document and personal data governed by statute. Most complaints and claims turn on what the record does or does not show.

Data Protection: UK GDPR and the Data Protection Act 2018

Health data is special category data, which needs a lawful basis under Article 6 and an additional condition under Article 9.

ElementPosition in dental practice
Lawful basis (Article 6)Usually the performance of a task in the public interest for NHS care, or legitimate interests or contract for private care. Not normally consent — consent under GDPR must be freely given and withdrawable, which does not fit a clinical record you are obliged to keep
Article 9 conditionArticle 9(2)(h) — processing necessary for the provision of health or social care by, or under the responsibility of, a professional subject to a duty of confidentiality
Consent to treatmentA separate concept entirely. Clinical consent and GDPR consent are not the same thing, and confusing them is a common examination distractor

The data protection principles

Lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability — the practice must be able to demonstrate compliance, which is why a privacy notice, a record of processing activities and staff training are required.

Data subject rights that arise in practice

  • Right of access (subject access request) — normally answered within one month, free of charge, and the patient does not have to give a reason. The period may be extended by two further months for complex or numerous requests, and a reasonable fee may be charged only for manifestly unfounded or excessive requests.
  • Rectification — factual errors are corrected, but a clinical opinion recorded at the time is not deleted because the patient disagrees with it; an addendum is added instead.
  • Erasure — very limited for health records, because there is a legal obligation to retain them.
  • Restriction, portability and objection — apply in narrower circumstances.
  • Access to Health Records Act 1990 governs access to the records of a deceased patient by the personal representative or by someone with a claim arising from the death.

Breaches

A personal data breach likely to result in a risk to individuals' rights must be reported to the Information Commissioner's Office within 72 hours of the practice becoming aware of it, and affected individuals must be told where the risk is high. Common dental examples are a lost unencrypted laptop, an email sent to the wrong patient list, and records left visible at reception.

Retention

Retention periods are set nationally and differ across the UK, so the correct examination answer is to check the current schedule for your nation rather than to quote a single number from memory. The direction of travel in England and Wales, under the NHS Records Management Code of Practice, is a minimum of 15 years for an adult's records and, for a child, until the 25th birthday (or the 26th where the last entry was made at 17), whichever is later. Scotland and Northern Ireland operate their own schedules. Records must be retained in a form that remains readable and that preserves the audit trail; destruction must be secure and logged.

The Caldicott Principles

The Caldicott principles govern the use of confidential patient information in health and care:

  1. Justify the purpose for using confidential information.
  2. Use confidential information only when it is necessary.
  3. Use the minimum necessary.
  4. Access should be on a strict need-to-know basis.
  5. Everyone with access must be aware of their responsibilities.
  6. Comply with the law.
  7. The duty to share information for individual care is as important as the duty to protect confidentiality.
  8. Inform patients about how their confidential information is used.

Principle 7 is the one candidates most often forget: failing to share information that is needed for a patient's care is as much a failing as sharing it inappropriately.

What Belongs in the Record

Beyond the clinical content covered in the treatment-planning section, the regulatory essentials are:

  • Contemporaneous entries, made at the time or as soon as practicable afterwards.
  • Attributable — who made the entry and when; electronic systems must maintain an audit trail.
  • Unaltered — corrections to paper notes are made with a single strike-through, dated and initialled; the original must remain legible. Retrospective alteration of a record after a complaint is a serious professional offence.
  • Radiographs, with the IR(ME)R justification recorded, and a clinical evaluation (report) of every image, including any incidental findings.
  • Local anaesthetic type, dose and batch, materials used, and device or implant identifiers.
  • What the patient was told, not merely that consent was obtained.

The Regulatory Framework a Dentist Works Within

Body or instrumentWhat it governs
General Dental CouncilRegistration, Standards for the Dental Team (nine principles), Scope of Practice, enhanced CPD, fitness to practise
Enhanced CPD100 hours over the five-year cycle for dentists, with a minimum of 10 hours in any consecutive two years; dental nurses and dental technicians 50 hours, hygienists, therapists, orthodontic therapists and clinical dental technicians 75 hours; a personal development plan and a CPD log are required
IndemnityA statutory requirement for all clinical registrants; practising without it is a registration offence
Care Quality Commission (England), Healthcare Improvement Scotland, Healthcare Inspectorate Wales, RQIA (Northern Ireland)Registration and inspection of the provider, including the statutory duty of candour
IRR17 and IR(ME)R 2017Ionising radiation: employer procedures, justification, optimisation, clinical evaluation, training records
HTM 01-05 and equivalentsDecontamination and infection prevention
COSHH, RIDDOR, HASAWA 1974Hazardous substances, reportable incidents, general health and safety
Freedom of Information Act 2000Applies to public authorities; a private dental practice is not subject to it, though NHS bodies are
Test Your Knowledge

A dental practice processes patient health records. Which lawful basis under UK GDPR normally applies to that processing?

A
B
C
D
Test Your Knowledge

A patient telephones asking for a copy of her complete dental record and refuses to say why she wants it. What is the correct response?

A
B
C
D
Test Your Knowledge

A practice laptop containing unencrypted patient records is stolen from a car. What is the practice's obligation?

A
B
C
D
Test Your Knowledge

Under the GDC's enhanced CPD scheme, what are the requirements for a dentist?

A
B
C
D