By law, we must protect your information The Data Protection Act 2018 incorporated the General Data Protection Regulations (GDPR) which set out key principles about
processing personal data at this practice.

Therefore, we promise that we will:

• Process any data lawfully, fairly and transparently

• We will only collect information for specific and legitimate purposes

• We will only retain what information is necessary and only for the purposes
for which it is processed

• Your information will be accurate and kept up to date

• We will ensure that we adopt all measures to keep your information secure

• We will only retain your information for as long as it is necessary.

Information is available on our website in regards to: (website is currently bring updated)

• How your data is used

• How access to data can be obtained under a ‘Subject Access Request’

• Our different activities of business and who we share any data with

• Who to ask should you need any further advice on data protection.

We will also:

• Amend any incorrect information that we hold on you

• Restrict how your data is used

• Ensure that your data is only forwarded to health
organisations that have a legitimate need for this
information. Normally this is only forwarded with
your consent and in certain circumstances, you
do have the right to object to this information
being processed.

NHS ScotlandThis site is brought to you by My Surgery Website