• 1 hour verifiable CPD
  • 2 of 2
  • Whole dental team
  • GDC outcomes A, B, D

Module 2 of 2 — subject access and other rights, what to do when data go missing, how long to keep records, and CCTV without turning the practice into a surveillance shop.

Course aim

Give the team a calm process for access requests and incidents so patients get their rights, the ICO is not an afterthought, and records are neither dumped nor kept forever “just in case”.

2 hours in two modules: this is 2 of 2. Complete them in numerical order: 1, then 2. Both stay open — there is no lock. This is the dedicated information governance series. Completing both modules is the full 2 hours.

What you will be able to do

  1. 1Handle a subject access request without blocking it or oversharing other people’s data
  2. 2Recognise a personal-data breach and know the practice first steps, including ICO timescales
  3. 3Apply a retention schedule and secure disposal — including computers and paper
  4. 4Explain when CCTV and door cameras are justified and when they are not

The two-module series

  • 1: Lawful records and day-to-day security
  • This module — 2: Access requests, breaches and retention

Use Start course below to begin at lesson 1. Later lessons unlock as you complete each step.

Suitable for: the whole team, including reception, clinicians, and the named IG lead.

Always follow current official guidance and the law that applies in your UK nation. This course is knowledge CPD, not legal, prescribing, or emergency-care advice.