General Data Protection (GDPR) & Privacy
What is GDPR?
The General Data Protection Regulation (GDPR) is a new EU regulation that came into force on 25th May 2018. The GDPR replaced the existing data protection legislation including the UK Data Protection Act 1998. Although we have left the EU the UK is still following GDPR rules and regulations.
Who does the GDPR apply to?
The GDPR applies to all individuals and organisations with day-to-day responsibilities for data protection.
What does this mean for patients?
Your data:
- must be processed lawfully, fairly and transparently.
- be collected for specific, explicit and legitimate purposes.
- must be limited to what is necessary for the purposes for which it is processed.
- must be accurate and kept up to date.
- must be held securely.
- It can only be retained for as long as is necessary for the reasons it was collected.
GDPR - patient information
You can also read further info about GDPR in our GDPR patient information leaflet (PDF). If you need this leaflet in a different language please contact the Practice Manager.
Practice privacy notice GDPR
You can read our practice privacy notice as a PDF. If you need this privacy notice in a different language please contact the Practice Manager.
NHS Scotland data protection notice
You can also view the NHS Scotland data protection notice which tells you what personal information NHS Scotland uses as an organisation, what the legal basis is for using it and how it is protected. It also explains what your rights are under data protection law, how you can ask to see your information and what to do if you have any concerns about how your manage personal information is managed.

