Back to Home

Data Protection Policy

Last Updated: March 2026

Introduction

Waterden Dental Practice is committed to protecting your privacy and ensuring that your personal information is handled in a safe and responsible manner. This policy outlines how we collect, use, store, and protect your data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Our Promise: We take your privacy seriously and will only use your personal information to provide you with the dental care you need and to improve our services. We will never sell your data to third parties.

Data Controller

Waterden Dental Practice is the data controller responsible for your personal information. This means we determine how and why your data is processed.

Contact Details:

  • Address: 4 Waterden Road, Guildford, Surrey, GU1 2AW
  • Email: info@waterdendental.co.uk
  • Telephone: 01483 565 290

If you have any questions about this policy or how we handle your data, please contact our Practice Manager.

Information We Collect

In order to provide you with high-quality dental care, we need to collect and hold certain personal information. This includes:

Name, date of birth, and age
Home address and contact details
Email address and telephone numbers
Your general medical practitioner's details
Past and current medical history
Past and current dental condition
Radiographs (X-rays) and clinical photographs
Study models of your teeth
Treatment plans and records of care provided
Financial information (for billing and insurance)
Records of consent to treatment
Correspondence with other healthcare professionals
Notes of conversations or incidents

We need this information to provide you with safe and appropriate dental care. Without it, we may not be able to treat you effectively.

How We Use Your Information

We use your personal information for the following purposes:

  • To provide dental care: Assessing your dental health, diagnosing conditions, and planning and delivering treatment.
  • For administrative purposes: Managing appointments, billing, and insurance claims.
  • To communicate with you: Sending appointment reminders, treatment estimates, and practice updates.
  • For quality improvement: Analysing patient feedback and treatment outcomes to improve our services.
  • To comply with legal obligations: Maintaining accurate records as required by law and regulatory bodies.
  • For referral purposes: Sharing information with specialists or other healthcare providers involved in your care.

Legal Basis for Processing

Under UK GDPR, we must have a valid legal basis to process your personal information. We rely on the following:

  • Performance of a contract: Processing is necessary to provide you with dental care under our patient agreement.
  • Legal obligation: We are required by law to maintain accurate patient records and comply with regulatory requirements.
  • Legitimate interests: For activities such as improving our services and patient communication.
  • Consent: For specific uses such as clinical photographs for marketing or sharing data with third parties not directly involved in your care.
  • Vital interests: In emergency situations where your life or health is at risk.

Who We Share Your Information With

We may need to share your personal information with other organisations to provide you with the best possible care. These include:

  • Your general medical practitioner (GP) - when relevant to your dental care
  • Hospital or community dental services - if you need specialist treatment
  • Other health professionals involved in your care - such as orthodontists or oral surgeons
  • Dental laboratories - for creating crowns, bridges, dentures, or other appliances
  • Dental insurance companies - if you make a claim under your policy
  • Private dental schemes - of which you are a member
  • Regulatory bodies - such as the General Dental Council or Care Quality Commission, when required

We only share information on a "need-to-know" basis and ensure that any third parties we work with are also compliant with data protection laws.

Data Security

We take the security of your personal information seriously. We have implemented appropriate technical and organisational measures to protect your data, including:

  • Secure computer systems with password protection and access controls
  • Audit trails to track who has accessed patient records
  • Daily backups to prevent data loss
  • Secure filing systems for paper records
  • Staff training on data protection and confidentiality
  • Confidentiality agreements with all staff members

Only authorised members of staff have access to your personal information, and they are trained to handle it appropriately.

Data Retention

We will retain your personal information for as long as necessary to provide you with dental care and to comply with legal and regulatory requirements.

  • Adult patients: We retain your records for 11 years after your last treatment, or until 11 years after you cease to be a patient.
  • Child patients: We retain records until your 25th birthday, or 26th if you were 17 at the time of last treatment (whichever is longer).

After these periods, your information will be securely deleted or anonymised for research purposes where appropriate.

Your Rights

Under UK GDPR, you have the following rights regarding your personal information:

  • Right to be informed: You have the right to know how your data is being used (this policy provides that information).
  • Right of access: You can request a copy of the personal information we hold about you.
  • Right to rectification: You can ask us to correct any inaccurate or incomplete information.
  • Right to erasure: In certain circumstances, you can request that we delete your information.
  • Right to restrict processing: You can ask us to limit how we use your information.
  • Right to data portability: You can request a copy of your information in a machine-readable format.
  • Right to object: You can object to how we use your information in certain situations.
  • Rights related to automated decision-making: We do not use automated decision-making in our practice.

Subject Access Requests

To request a copy of the information we hold about you, please make a written request to our Practice Manager. Under UK GDPR:

  • No fee: We will provide this information free of charge (unless requests are manifestly unfounded or excessive).
  • Response time: We will respond within one month of receiving your request.
  • Identification: We may need to verify your identity before providing information.

To make a request, please email: info@waterdendental.co.uk or write to us at the address below.

Cookies

Our website uses cookies to improve your browsing experience. For detailed information about the cookies we use and how to manage them, please see our Privacy & Cookie Policy.

Changes to This Policy

We may update this Data Protection Policy from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on this page, and where appropriate, we will notify you by email.

This policy was last updated in March 2026.

Right to Complain: If you are not satisfied with how we handle your personal information, you have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.

ICO Contact: www.ico.org.uk | 0303 123 1113