Preparing your healthcare experience...
Protecting your information, respecting your privacy: A commitment we take seriously
We retain personal data only for as long as necessary to comply with legal, clinical, and regulatory requirements.
Medical records are retained in accordance with the Records Management Code of Practice (https://transform.england.nhs.uk/information-governance/guidance/records-management-code/records-management-code-of-practice/) published by NHS England.
For example, General Practice records are typically retained for 10 years after the patient’s death.
Child health records are usually kept until the patient’s 25th birthday, or 26th birthday if they were 17 when treatment ended.
These periods may be extended where clinically appropriate or required by law.
Financial records (e.g. invoices, payment logs) are retained for at least 6 years to comply with HMRC requirements.
Under UK data protection law, you have the right to:
Request access to your personal data
Ask for corrections to inaccurate data
Request deletion of your data (where legally possible)
Object to or restrict certain types of processing
Withdraw consent at any time (where consent is the basis for processing)
Lodge a complaint with the ICO if you are concerned about how your data has been handled
More information is available from the ICO: www.ico.org.uk