Privacy Notice: Complaints, Subject Access Requests and Freedom of Information Requests

This Practice holds and uses patient data for the purposes of Complaints, Subject Access Requests and Freedom of Information Requests.

We collect and store information about your health and care that has been received directly from you or organisations such as Local Authorities, other GP Practices, NHS Trusts and NHS Integrated Care Systems.

Under UK GDPR and the Data Protection Act 2018, you have the right to see or be given a copy of any personal data we hold about you. To gain access to a copy of your information, you will need to make a Subject Access Request (SAR) to the Practice. You can do so by emailing or contacting us.

Under the Freedom of Information Act 2000, you have the right to request copies of non-personal information held by the Practice. To gain access to a copy of your information, you will need to make a Freedom of Information (FOI) Request to the Practice.

Should you wish to make a complaint to the Practice, then there may be a need for them to view and access your patient data or request some from you directly. This will allow the Practice to investigate your complaint. Information on our complaints process can be found here:

1) Controller contact details

The Westwood Surgery
24 Westwood Lane 
DA16 2HE
020 8303 5353

2) Data Protection Officer contact details

GP Data Protection Officer

3) Purpose of the processing

Legal Obligations of the Practice to manage, investigate and respond to requests for copies of personal data, FOI requests and complaints.

4) Lawful basis for processing

The lawful justifications for the processing and possible sharing of this data are:

Article 6(1)(c) “the processing is necessary for compliance with any legal obligation to which the controller is subject”

Where your complaint or SAR involves processing of special category data the relevant condition for processing that data will be 

Article 9(2)(g) “substantial public interest” as defined by Data Protection Act 2018, Schedule 1, Part 2, Section 6(2)(a) “the exercise of a function conferred on a person by an enactment or rule of law”

5) Recipient or categories of recipients of the processed data

Where a complaint you make is about another organisation, we may share details of your complaint with that organisation. We would only do so after informing you of this.

6) Rights to object

You have the right under Article 21 of the UK GDPR to object to your personal information being processed. Please contact the Practice if you wish to object to the processing of your data. You should be aware that this is a right to raise an objection which is not the same as having an absolute right to have your wishes granted in every circumstance.

GP Practices process personal data under Article 6(1)(c) on a lawful and legitimate basis where the organisation is obliged under law to comply with

  • The UK General Data Protection Regulations (GDPR)
  • The Data Protection Act 2018
  • The Freedom of Information Act
  • The NHS Constitution
  • The Local Authority Social Services and National Health Service Complaints (England) Regulations 2009

By complying with these laws, the Practice has compelling legitimate grounds for the processing which override the interests, rights and freedoms in the right to object.

7) Right to access and correct

You have the right to access any identifiable personal data that is being processed or shared and to have any inaccuracies corrected.

8) Retention period

The data will be retained for the period as specified in the national records retention schedule.

9) Right to Complain.

You have the right to complain to the Information Commissioner's Office

Or calling their helpline Tel: 0303 123 1113 (local rate) or 01625 545 745 (national rate)

There are National Offices for Scotland, Northern Ireland and Wales, (see ICO website)