2. Who is accountable — controller, processors, lead

Controller

The organisation that decides why and how patient data are used is the controller. In a typical practice that is the legal entity (the limited company or partnership), not “whoever turned the computer on”. Partners and principals still carry professional duties as registrants.

Processors

A processor handles data on your instructions: cloud practice software, off-site backup, a laboratory portal, a payroll bureau, an NHS mail provider. You need a written contract, and you remain responsible for choosing someone appropriate. “They are a big brand” is not a contract.

Named IG lead

Someone must own the policies, the training log, and the first call when a laptop goes missing. A deputy is needed on a Monday morning. The lead does not personally approve every SAR, but someone accountable must.

Data protection officer

Some organisations must designate a DPO. Many small dental practices do not meet the threshold — that is a legal test, not a slogan. If you have a DPO or an external adviser, staff must know how to reach them. Do not invent a DPO on the website if you do not have one.

NHS work

If you deliver NHS dental services you will also meet NHS information-governance expectations (including the Data Security and Protection Toolkit where it applies). Keep the Toolkit current. Do not copy last year’s answers if the software changed.

Staff as people

Employment records are personal data too. Do not pin a sick note on the staff-room fridge. Occupational health and HR follow the same “minimum necessary” rule.