Your medical record and GDPR

your care data

GDPR (General Data Protection Regulations)

On 25th May 2018, GDPR came into force. The Three Spires Medical Practice has ensured that we have met our responsibilities under the new legislation.

You can find out more about the GDPR here:

One of the requirements of the GDPR is to provide detailed fair processing information – privacy notices – about all processing of personal data.

We will ensure that patients of Three Spires are made aware of their rights under the new legislation and that the surgery meets its responsibilities under the GDPR.

You have the right to both:

  • Opt out of any of the data sharing schemes
  • Opt back into any of the data sharing schemes (that you may have already opted out of).

You can find our privacy notices and other policies here:

Privacy Notice v2

Privacy Notice for Children

Your Data Rights

Personal Data Breach Policy

NHS Data Sharing at Three Spires Factsheet

Risk stratification factsheet

Data Sharing Opt Out form

Access to your medical record (the Right of Access)


You have the right to get a copy of the information that is held about you.  Click here for more information from the ICO  

This is known as a subject access request.

Please note:

  • You can sign up for secure online access to your full GP electronic record.
  • You can then look at your medical record whenever you want.

If you do wish to make a subject access request then: 

  • You can do this in writing (letter, email, fax)
  • You can download and fill in this form if easier Subject Access Request Form
  • You can make such a request verbally to a member of staff or a doctor or nurse that you are consulting with at the surgery

Please let us know exactly what information you would like.

We will provide the information within 28 calendar days.

There is usually no fee for this (from 25th May 2018).

Click here for: Our Right of Access (SAR) Policy

Summary Care Record

A Summary Care Record is an electronic record which contains information about the medicines you take, allergies you suffer from and any bad reactions to medicines you have had.  Having this information stored in one place makes it easier for healthcare staff to treat you in an emergency, or when your GP practice is closed.

More information can be found on the link below.

Download the Summary Care Record patient leaflet (PDF, 232Kb)

If you wish to opt out of having a Summary Care Record, here is the link for the form.

 Detailed Privacy Notices

In line with the GDPR requirements, The Three Spires Medical Practice provides fair processing information about all data processing activities and places privacy and data protection at the heart of all its processing.

Detailed Privacy Notices can be found here:

DPN 1 - further information

DPN 2 - general information sharing

DPN 3 - access to your medical record

DPN 4 - NHS data sharing databases

DPN 5 - statutory disclosures of information

DPN 6 - permissive disclosures of information

DPN 7 - Data Processors

DPN 8 - Pharmacies

DPN 9 - accessing your information on other databases

DPN 10 - research

DPN 11 - Online Services Texts Emails

DPN 12 - National Data Opt Out

Call 111 when you need medical help fast but it’s not a 999 emergencyNHS ChoicesThis site is brought to you by My Surgery Website