1. Subject access and other rights

This module

This is module 2 of 2 (1 hour). Completing both is the full 2-hour information governance series.

Suggested study time

  • Access and other rights — 20 min
  • Breaches and the ICO clock — 18 min
  • Retention, disposal and CCTV — 17 min
  • Knowledge check — 5 min

Subject access

People can ask for a copy of their personal data. In UK GDPR the usual time limit is one month (extendable in complex cases if you tell them). You can ask enough to identify the person. You should not invent fees as a way to stall an ordinary request. Do not refuse because “the records belong to the dentist”.

Third-party data

Blank out another patient’s details, and be careful with staff opinions that identify a colleague where disclosure is not justified. Do not blank out the clinical facts the person is entitled to see.

Other rights

Rectification (correcting inaccurate data), restriction, objection, and — in limited situations — erasure. Health records are rarely “deleted on request” because you still need them for care, complaints, and legal duties. Explain that honestly. Portability is more relevant to some digital exports than to a 1998 paper card box.

Solicitors, police, insurers

A headed letter is not automatically a lawful basis. Check identity, the patient’s authority, and whether a statutory gateway or court order applies. Log what you disclosed and why. When in doubt, take advice before you email the whole chart.