PRIVATE THERAPY CLINIC LTD.
| Policy NO | P35 |
| Responsible Person | Registered Manager |
| Author | Dr. Rebecca Spelman |
| Date Issued | 08/08/2024 |
| Next review date | Every two years |
| Authorised by | Dr. Rebecca Spelman |
| Version No | 1 |
Data Protection Impact Assessment (DPIA)
| Version: | Review date: | Edited by: | Approved by: | Comments: |
| 2 | 08/08/2026 |
1. Introduction
This policy outlines Private Therapy Clinic Ltd.’s approach to conducting Data Protection Impact Assessments (DPIAs) in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It supports the safeguarding of personal and special category data across all remote psychiatric services provided by the clinic. A summary of this policy will be made available in alternative formats (large print, easy-read, other languages) on request.
2. Scope
This policy applies to:
- All employees, consultants, independent contractors, and third-party processors.
- All systems used to process patient and staff data, including Semble, Google Workspace Enterprise, NHS Mail, and third-party prescription services (e.g., Pharmacierge, CloudRx).
- All processing activities that involve personal, confidential, or health-related information.
- Google Workspace Enterprise (secure video consultations; encrypted by default)
3. Policy Statement
Private Therapy Clinic Ltd. is committed to:
- Identifying and mitigating data protection risks early in project lifecycles.
- Ensuring lawful, fair, and transparent data processing.
- Embedding privacy-by-design and privacy-by-default principles across clinical and administrative systems.
- Encryption & Access Controls → (see P28 Cybersecurity & IT Acceptable Use)
- Role-based Access → (see P04 Information Governance & Records Management)
- Audit Logging → (see P17 Risk Assessment Policy)
- Retention & Secure Disposal → (see P04 Information Governance & Records Management)
- Staff DPIA Training → (see P20 Staff Training & Development)
4. Legal and Regulatory Framework
This policy aligns with:
- UK GDPR (Articles 35 & 36)
- Data Protection Act 2018
- CQC Regulation 17: Good Governance
- NHS Data Security and Protection Toolkit
- ICO’s DPIA Guidance (2022)
5. DPIA – When Required
DPIAs are mandatory before initiating any data processing that is:
- Likely to result in a high risk to individual rights and freedoms.
- Involves large-scale processing of special category (e.g. health) data.
- Uses new technologies (e.g., new platforms for online assessments).
- Includes systematic monitoring (e.g., remote diagnostic platforms or AI-assisted screening tools).
Examples include:
- Launching new digital assessment platforms or tools.
- Adopting a new prescribing or data storage system.
- Introducing third-party systems for patient communications or diagnostics.
6. DPIA Process
The DPIA process involves:
| Step | Description |
| 6.1 Identify Need | Project initiator or Data Protection Officer (DPO) flags the need for DPIA during planning. |
| 6.2 Describe Processing | Detail what data will be collected, how, why, who it is shared with, and the lawful basis. |
| 6.3 Consultation | Seek views from data subjects (if appropriate), project leads, IT, clinical teams, and external providers. |
| 6.4 Assess Necessity & Proportionality | Assess alignment with data protection principles (minimisation, accuracy, security). |
| 6.5 Identify Risks | Evaluate risks to confidentiality, integrity, access rights, or individual freedoms. |
| 6.6 Identify Controls | List measures to mitigate risks (e.g., encryption, role-based access, audit logs). |
| 6.7 Approve & Sign Off | Registered Manager must review, approve, and document outcomes. |
| 6.8 Integrate into Project | Ensure actions and mitigations are implemented before live use. |
| 6.9 Review and Refresh | Reassess DPIA if processing changes or new risks emerge. |
7. DPIA Roles and Responsibilities
Registered Manager, Clinical Governance Lead, and Data Protection Officer (DPO), Nominated Individual for RA 5 – (Currently held by the same individual: Dr. Rebecca Spelman)
- Ensures DPIAs are completed where required
- Reviews DPIA submissions for legal and regulatory compliance
- Identifies and mitigates clinical and data protection risks
- Ensures DPIA outcomes are documented and integrated into clinical workflows
- Maintains the DPIA register and ensures compliance with CQC and UK GDPR
- Seeks external advice where additional objectivity is required
All Staff
- Alert the Registered Manager to any new systems, projects, or data processing activities that may require a DPIA
- Cooperate fully during DPIA reviews and the implementation of risk mitigation actions
8. Storage and Retention
Completed DPIAs are:
- Stored securely in the clinic’s protected One Drive and Semble governance folders.
- Retained for a minimum of 6 years following completion or for the duration of the processing activity plus one year.
- Audited annually for relevance and compliance.
9. Training and Awareness
All new staff are informed of DPIA procedures during induction.
Annual data protection and IT security training includes reference to the DPIA process.
All updates are communicated via internal governance briefings and documented in training logs (see P20 – Staff Training and Development Policy).
10. Review and Audit
This policy is reviewed every two years by the Registered Manager and updated in response to legislative, regulatory, or operational changes such as:
- Updates to the UK GDPR or ICO guidance.
- A significant change in data processing or systems used.
- An identified deficiency through internal audits.
11. Related Policies
- P04 – Information Governance, Records Management & Confidentiality
- P06 – Confidentiality Policy
- P17 – Risk Assessment Policy
- P19 – Serious Incident and Significant Events Reporting Policy
- P28 – Cybersecurity and IT Acceptable Use Policy
- P30 – Duty of Candour Policy




