Privacy Policy
Privacy Policy & Privacy Notice
Last Updated: 19 August 2026
At East Ham Dental Care (“we”, “us”, “our”), we are committed to protecting and respecting your privacy. This policy explains how we collect, store, process, and protect your personal and medical information in strict accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller Information
For the purposes of data protection laws, the Data Controller is:
Practice Name: East Ham Dental Care
Address: 480 Barking Road, East Ham, London, E6 2LT
Data Protection Officer (DPO) / Lead: Dr Tajinder Deo
Contact Number: 0208 472 0638
Information Commissioner’s Office (ICO) Registration Number: Z9734298
2. Information We Collect About You
As a dental surgery, we collect both general personal data and sensitive "Special Category" health data. This includes:
Personal Contact Details: Your name, date of birth, address, telephone number, and email address.
Medical & Dental Records: Your dental history, clinical notes, treatment plans, X-rays, photos, prescriptions, and medical history (including lists of medications, allergies, and systemic health conditions).
Financial Information: Payment card details, billing history, and details of NHS fee exemptions or private dental finance plans.
NHS Information: Your NHS number and details of NHS treatments received.
Website Data: Your IP address, cookies, and browsing behaviour when you use our online booking system or contact forms.
3. Why We Process Your Data (Legal Basis)
Under the UK GDPR, we rely on the following legal bases to process your information:
Contractual Necessity: To provide you with dental treatments and manage your appointments.
Consent: When you opt-in to receive practice news or marketing emails.
Legal Obligation: To comply with NHS dental regulations, tax laws, and clinical audit requirements.
Special Category Data (Health Records): We process your health data under Article 9(2)(h) of the UK GDPR, which permits processing for the provision of health or social care treatment and management.
4. How We Share Your Information
We keep your records strictly confidential. However, to provide proper care and meet regulatory duties, we may share your data with:
The NHS: Specifically the NHS Business Services Authority (NHSBSA) to process NHS dental claims and exemptions.
Other Healthcare Professionals: Specialists, hospitals, or laboratories involved in your clinical care (e.g., sending dental scans to a lab to make a crown).
Dental Software Providers: Secure third-party platforms that host our patient practice management software.
Regulators: Regulatory bodies such as the General Dental Council (GDC) or Care Quality Commission (CQC) if required during practice inspections.
Payment processing system: We use Stripe and Barclaycard to process your payments.
We do not sell, rent, or trade your personal data with third parties for marketing purposes.
5. Data Retention: How Long We Keep Your Records
We retain dental records in accordance with the standard UK retention guidelines for health records (such as the Records Management Code of Practice):
Adult Patients: Records are kept for a minimum of 11 years after their last attendance.
Children's Records: Records are kept until the patient reaches age 25, or for 11 years after their last attendance (whichever is longer).
6. Your Data Rights
Under UK data protection laws, you have rights regarding your personal information, including:
Right of Access (Subject Access Request): You have the right to request a free copy of your dental records, treatment notes, and X-rays. We will provide this within one calendar month.
Right to Rectification: You can ask us to correct any inaccurate or incomplete personal information.
Right to Restriction: You can request that we limit the processing of your data in certain circumstances.
Right to Object: You can object to us using your data for marketing or non-clinical purposes.
Note: The "Right to Erasure" (Right to be Forgotten) does not fully apply to clinical dental records, as we are legally required to retain medical records for patient safety and regulatory compliance.
7. Security of Your Data
We employ strict physical, electronic, and managerial procedures to safeguard your data. This includes encrypted dental software, password-protected workstations, firewall systems, and restricted physical access to paper archives.
8. How to Complain
If you have any concerns about how we handle your data, please contact our Data Protection Lead using the details in Section 1.
If you remain unsatisfied, you have the right to lodge a formal complaint with the UK data regulator:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk