Skip to content

GDPR & Data Protection

GDPR & Data Protection Policy – My Pelvic Rehab

 

This GDPR & Data Protection Policy outlines how My Pelvic Health, a pelvic health physiotherapy practice based in Swindon, England, processes, stores, protects, and manages personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy applies to all personal data processed by the Practice, including special category health data.

 

  1. Lawful Basis for Processing

We rely on the following lawful bases under Article 6 UK GDPR:

  • Contract (6(1)(b)) – providing physiotherapy treatment
  • Legal obligation (6(1)©) – maintaining clinical records
  • Legitimate interests (6(1)(f)) – appointment reminders, business administration

For special category data, we rely on Article 9:

  • Healthcare provision (9(2)(h)) – processing necessary for the provision of health care
  • Explicit consent – used only for optional processing such as video recordings or marketing

 

  1. Special Category Data Policy

We process special category data essential for physiotherapy treatment, including:

  • Pelvic health history
  • Pregnancy/postnatal information
  • Surgical history
  • Medical background and medications
  • Clinical notes and outcome measures
  • Exercise programmes linked to clinical need

Special category data is collected only when necessary and processed under strict security controls.

 

  1. Data Retention Policy

Retention periods follow UK clinical standards:

  • Adults: 8 years after last treatment
  • Children: until age 25 (or 26 if treated at 17)
  • Maternity records: 25 years
  • Financial records: 6 years (HMRC)
  • Communications: 2 years unless part of clinical record
  • Website analytics: 12 months
  • Exercise programmes & clinical videos: 8 years

Data is securely destroyed once retention periods expire.

 

  1. Security Measures Policy

We protect personal and special category data using:

  • Encrypted and password-protected devices
  • GDPR-compliant cloud storage
  • Secure practice-management software
  • Restricted access controls
  • Secure backup systems
  • Locked cabinets for any paper records
  • Secure transfer protocols for external sharing

These measures ensure confidentiality, integrity, and availability.

 

  1. Data Breach Policy

If a data breach occurs:

  1. Identify and contain the breach
  2. Assess risk to individuals
  3. Notify the ICO within 72 hours if required
  4. Notify affected individuals where necessary
  5. Document the breach and corrective actions

Breaches involving special category data are treated as high priority.

 

  1. Data Subject Rights Policy

Patients have the right to:

  • Access their data
  • Request correction
  • Request erasure (where legally permissible)
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent at any time

Requests should be sent to: info@mypelvicrehab.co.uk

 

  1. Third-Party Processors

We use GDPR-compliant third-party processors for:

  • Practice-management software
  • Exercise-prescription platforms
  • Payment processing
  • Cloud storage
  • Email/SMS communication
  • Website analytics

All processors are vetted for GDPR compliance.

 

  1. ROPA Summary

A full Record of Processing Activities (ROPA) is maintained separately and includes:

  • Processing activities
  • Purposes
  • Categories of data
  • Lawful bases
  • Recipients
  • Retention periods
  • Security measures

 

  1. Privacy Notice

The Privacy Notice is a separate public-facing document and is maintained independently.

 

  1. Review Cycle

This GDPR & Data Protection Policy is reviewed annually or sooner if:

  • Legislation changes
  • Clinical practice changes
  • New systems or processors are introduced