EQUINOX PHYSIOTHERAPY 

Data Protection & Confidentiality Policy 

(UK GDPR & Data Protection Act 2018) 

1. Purpose 

This policy outlines how Equinox Physiotherapy complies with the UK General Data  Protection Regulation (UK GDPR) and the Data Protection Act 2018, ensuring patient  information is handled lawfully, securely, and confidentially. 

2. Scope 

This policy applies to all staff, contractors, and anyone working on behalf of Equinox  Physiotherapy. 

3. Data Controller 

The Registered Manager (Bethan DRINKALL) acts as the Data Controller and is responsible  for ensuring compliance. 

4. Lawful Basis for Processing 

Personal data is processed under the lawful bases of: 

• Provision of healthcare (Article 6(1)(e) & 9(2)(h)) 

• Legal obligations 

• Contractual necessity 

5. Principles of Data Protection 

Equinox Physiotherapy adheres to the principles of: 

• Lawfulness, fairness and transparency 

• Purpose limitation 

• Data minimisation 

• Accuracy 

• Storage limitation 

• Integrity and confidentiality 

• Accountability

Equinox Data Protection & Confidentiality Policy V1 12/02/26 1 

6. Confidentiality 

Patient information is confidential and will only be shared where: 

• There is patient consent 

• There is a legal obligation 

• Safeguarding concerns require disclosure 

7. Data Security Measures 

• Secure electronic record systems with password protection 

• Encrypted devices 

• Locked storage for paper records 

• Restricted staff access 

• Secure disposal of confidential waste 

8. Data Retention 

Clinical records are retained in accordance with NHS Wales retention schedules (normally 8  years after last treatment, or until age 25 for children). 

9. Subject Access Requests (SAR) 

Patients have the right to request access to their records. Requests will be responded to  within one month. 

10. Data Breaches 

Any suspected data breach must be reported immediately to the Registered Manager.  Where required, breaches will be reported to the Information Commissioner’s Office (ICO)  within 72 hours. 

11. Staff Responsibilities 

All staff must: 

• Maintain confidentiality 

• Use secure systems 

• Report concerns promptly 

12. Monitoring & Review 

This policy will be reviewed annually or sooner if legislation changes.

Equinox Data Protection & Confidentiality Policy V1 12/02/26 2 

Document Control

Policy Ref Version Date Owner Review Date
Equinox Data Protection &  Confidentiality Policy1.0 12 February 2026 Clinical Director 12 February 2027

Equinox Data Protection & Confidentiality Policy V1 12/02/26 3