Legal

    Data Protection.

    How patient records are held and secured at Sunny Dental, and how to request a copy of yours.

    Last updated 21 September 2026

    Our responsibilities

    Sunny Dental is the data controller for all patient and website information described here, and is responsible for handling it in line with UK GDPR, the Data Protection Act 2018 and the common law duty of confidentiality.

    Day-to-day responsibility for data protection sits with the practice's Data Protection Lead, who can be reached at hello@sunnydental.com or on +44 7356 215372.

    What we collect and why is set out in our Privacy Policy; this page covers how it is stored, secured and disposed of.

    How patient records are held

    • Clinical records, radiographs, scans and clinical photographs are held in access-controlled practice systems, backed up securely and encrypted in transit.
    • Access is limited to the clinicians and staff who need it to deliver or administer your care, each with their own credentials.
    • Paper documents, where they exist, are kept in locked storage on the premises and are never left unattended.
    • Website submissions — enquiries, reviews and mailing list sign-ups — are held in a secured database with policies that prevent public access, readable only by authorised practice accounts.
    • Devices used at the practice are encrypted, password-protected and kept up to date.

    Confidentiality

    Everyone working at the practice, clinical and non-clinical, is bound by a confidentiality agreement and by professional standards set by the General Dental Council. We discuss your care only with you, with those involved in providing it, and with anyone you have authorised in writing.

    Making a subject access request

    You have the right to a copy of the personal information we hold about you, including your clinical record. Write to hello@sunnydental.com or to the practice address, telling us what you need and, where it is not obvious, how we can verify your identity.

    We respond within one month and free of charge. If a request is unusually complex we may extend this by up to two further months and will tell you why. We may withhold information only in the limited circumstances the law allows, such as where releasing it would identify another person who has not consented.

    Requests for a copy of a record on behalf of someone else, or for a deceased patient's record, need proof of authority — written consent, power of attorney, or evidence of entitlement under the Access to Health Records Act 1990.

    Retention and disposal

    Clinical records are kept for at least eleven years after your last appointment, or until a patient treated as a child reaches 25, whichever is longer. When records reach the end of their retention period they are securely destroyed: confidential shredding for paper, certified deletion for digital records.

    If personal information is lost or exposed

    • Any suspected breach is reported internally the same day and contained immediately — access revoked, devices isolated, systems locked down.
    • We investigate what happened, whose information is involved and what the likely consequences are, and we record every incident whether or not it is reportable.
    • Where a breach is likely to affect people's rights we report it to the Information Commissioner's Office within 72 hours of becoming aware of it.
    • Where the risk to you is high we contact you directly, in plain language, telling you what happened and what to do about it.
    • After every incident we review what allowed it and change our processes so it cannot happen the same way again.

    Raising a concern

    You can raise a concern with us at any time, using our Complaints Procedure or the contact details on this page. You can also complain directly to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

    CallWhatsAppBook