1. Subject access and other rights
This module
This is module 2 of 2 (1 hour). Completing both is the full 2-hour information governance series.
Suggested study time
- Access and other rights — 20 min
- Breaches and the ICO clock — 18 min
- Retention, disposal and CCTV — 17 min
- Knowledge check — 5 min
Subject access
People can ask for a copy of their personal data. In UK GDPR the usual time limit is one month (extendable in complex cases if you tell them). You can ask enough to identify the person. You should not invent fees as a way to stall an ordinary request. Do not refuse because “the records belong to the dentist”.
Third-party data
Blank out another patient’s details, and be careful with staff opinions that identify a colleague where disclosure is not justified. Do not blank out the clinical facts the person is entitled to see.
Other rights
Rectification (correcting inaccurate data), restriction, objection, and — in limited situations — erasure. Health records are rarely “deleted on request” because you still need them for care, complaints, and legal duties. Explain that honestly. Portability is more relevant to some digital exports than to a 1998 paper card box.
Solicitors, police, insurers
A headed letter is not automatically a lawful basis. Check identity, the patient’s authority, and whether a statutory gateway or court order applies. Log what you disclosed and why. When in doubt, take advice before you email the whole chart.