What is GDPR?
GDPR stands for General Data Protection Regulation. It sets out how organisations must collect, use, store, share and delete personal data. For health and social care providers, it governs some of the most sensitive information you hold: the health and care records of the people you support.
In the UK, data protection law is made up of the UK GDPR and the Data Protection Act 2018, both as amended by the Data (Use and Access) Act 2025, whose changes are being phased in. The UK GDPR is based on the EU GDPR, which the UK kept in its own law after leaving the European Union, so the core principles remain very similar.
In the European Union and the wider European Economic Area (EEA), the EU GDPR applies directly in all 27 EU member states and in Iceland, Liechtenstein and Norway. If you process personal data about people in the EU or EEA, the EU GDPR may apply to you as well as the UK GDPR.
In the UK, data protection law is regulated by the Information Commissioner’s Office (ICO).
Examples of Personal Data
Personal data is any information relating to an identified or identifiable living person. A person can be identified directly or indirectly, for example by their name, an identification number, location data or an online identifier.
Data protection law applies to personal data held electronically and to paper records held in a structured filing system. Personal data that has been pseudonymised (for example, key coded) is still personal data if it can be linked back to a particular person using additional information.
Examples of personal data include, but are not limited to:
- Name
- Date of birth
- Address or location data
- Contact details
- NHS number or CHI number
- Occupation
- Personal preferences
Special category data
Some personal data is more sensitive and is given extra protection. This is known as special category data. It includes information about a person’s health, racial or ethnic origin, religious or philosophical beliefs, sex life or sexual orientation, political opinions, trade union membership, and genetic and biometric data. Care records, care plans, assessments and medication records almost always contain health data, so most of what a care provider holds about the people it supports is special category data.
Processing means anything you do with personal data, including collecting, recording, reading, storing, sharing, amending and deleting it.
Who GDPR Affects
Data protection law applies to every organisation that processes personal data, from large NHS bodies to small care providers, charities and sole traders. This includes all care providers that hold information about the people they support, their families and their staff.
The law distinguishes between a controller, which decides why and how personal data is processed, and a processor, which processes personal data on the controller’s behalf. A care provider is usually the controller of its care records. Software suppliers that host or process those records for you, such as StoriiCare, usually act as processors.
Your Key Obligations
Lawful basis and special category conditions
You must have a lawful basis under Article 6 of the GDPR for each purpose you process personal data for. To process special category data such as health information, you also need a condition under Article 9, for example the provision of health or social care. Under UK law, some Article 9 conditions also require a condition from Schedule 1 of the Data Protection Act 2018.
Data Protection Impact Assessments (DPIAs)
You must carry out a DPIA before starting any processing that is likely to result in a high risk to individuals. Processing health data on a large scale, introducing new technology and sharing data with new partners are common examples in health and social care.
Records of processing activities
You must keep a record of your processing activities, setting out what personal data you hold, why you hold it, who you share it with, how long you keep it and how you protect it.
Data Protection Officer (DPO)
You must appoint a Data Protection Officer if you are a public authority or body, or if your core activities involve processing special category data, such as health data, on a large scale. Many care providers fall into this group. Even if you are not required to appoint a DPO, you should make sure a named person is responsible for data protection in your organisation.
Personal data breaches
If you have a personal data breach that is likely to result in a risk to people’s rights and freedoms, you must report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to the people affected, you must also tell them without undue delay.
Contracts with suppliers
When you use a processor, such as a software supplier, you must have a written contract in place (often called a data processing agreement) that sets out what the processor may do with the data and how it will protect it.
NHS Data Security and Protection Toolkit (DSPT)
In England, organisations that have access to NHS patient data and systems must complete the NHS Data Security and Protection Toolkit every year to show that they meet the required data security standards. This includes many adult social care providers.
The Caldicott Principles
Health and social care organisations should also follow the eight Caldicott Principles, which guide how confidential information about people is used and shared. Many organisations appoint a Caldicott Guardian to oversee this.
Rights of Individuals
People have a number of rights over their personal data, including:
- The right to be informed: you must tell people why and how you use their personal data, usually through a clear privacy notice.
- The right of access: people can ask for a copy of their personal data, known as a subject access request. You must usually respond within one month. This can be extended in some circumstances.
- The right to rectification: people can ask for inaccurate or incomplete data to be corrected.
- The right to erasure: also known as the right to be forgotten, people can ask for their data to be deleted in certain circumstances. This right is not absolute, and health and care records often have to be kept for set retention periods.
- The right to restrict processing: people can ask you to limit how you use their data in certain circumstances.
- The right to data portability: people can ask to receive data they have given you in a structured, commonly used format, or to have it sent to another organisation, where processing is based on consent or a contract and is carried out by automated means.
- The right to object: people can object to processing in certain circumstances, for example where it is based on legitimate interests or a public task.
- Rights related to automated decision making: people have protections where significant decisions about them are made by solely automated means.
Data Protection Principles
The GDPR sets out seven principles. Personal data must be:
- Processed lawfully, fairly and in a transparent manner in relation to individuals.
- Collected for specified, explicit and legitimate purposes and not further processed in a way that is incompatible with those purposes.
- Adequate, relevant and limited to what is necessary for the purposes for which it is processed.
- Accurate and, where necessary, kept up to date. Every reasonable step must be taken to correct or erase inaccurate personal data without delay.
- Kept in a form which permits identification of individuals for no longer than is necessary for the purposes for which it is processed.
- Processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
The seventh principle is accountability: as the controller, you are responsible for complying with these principles and must be able to demonstrate that you do.
How to Demonstrate Compliance
The ICO expects organisations to be able to show how they comply. In practice, this means:
- Putting appropriate technical and organisational measures in place, such as data protection policies, access controls, staff training and internal audits
- Keeping records of your processing activities
- Carrying out DPIAs for high risk processing
- Having written contracts with your processors
- Recording all personal data breaches and reporting them where required
- Reviewing and updating your measures regularly
There are significant penalties for not complying. Under the UK GDPR, the maximum fine is £17.5 million or 4% of total annual worldwide turnover, whichever is higher. Under the EU GDPR, the maximum fine is €20 million or 4% of total annual worldwide turnover, whichever is higher. Regulators can also issue reprimands and enforcement notices, and individuals may be able to claim compensation.
Getting GDPR Certified
There is no single official GDPR certificate that every organisation needs. The GDPR allows for approved certification schemes and codes of conduct to help demonstrate compliance, but these are voluntary. What matters is that you can evidence your compliance through your policies, records and day to day practice.
Where Personal Data is Stored
As a care provider, you probably hold personal data in many places. You should know where all of it is, why you hold it in each format and how it is protected. Consider:
- Paper records: care plans, daily notes, charts, medication records, staff files and third party contact details all need to be accounted for, stored securely and disposed of securely.
- USB sticks and portable hard drives: these are easily lost. Avoid using them for personal data where possible. If you must use them, choose hardware encrypted devices, and remember that deleting files does not always remove the data permanently.
- Printed copies: printing records from a digital system creates a second copy, which must be stored, tracked and securely destroyed like any other record.
- Email and messaging: avoid sending personal data by unsecured email or personal messaging apps.
- Cloud and digital care systems: a secure digital care system can reduce the risks that come with paper records and portable media. Ask your supplier for evidence of its security controls and data protection documentation, and make sure a data processing agreement is in place.
Practical Steps for Care Providers
We recommend getting independent legal advice where needed, but a good place to start is to:
- Map what personal data you hold, about whom, where and why
- Confirm your lawful basis and Article 9 condition for each purpose
- Keep your record of processing activities up to date
- Complete DPIAs for high risk processing. StoriiCare can share security and data protection information to support DPIAs that cover your use of StoriiCare.
- Review contracts and data processing agreements with your suppliers
- Publish a clear privacy notice
- Set up a process for handling subject access requests and other rights requests within one month
- Define a breach management and notification procedure
- Appoint a Data Protection Officer if required, or a named person responsible for data protection
- Complete the NHS Data Security and Protection Toolkit if you have access to NHS patient data and systems
- Train staff on data protection and confidentiality, and refresh that training regularly
StoriiCare Clients and GDPR
When you use StoriiCare, you remain the data controller for the personal data you record about the people you support, their families and your staff. StoriiCare acts as your data processor, processing that data on your behalf and in line with your instructions under a data processing agreement.
StoriiCare is built with security and privacy in mind. Our controls include:
- Independent certifications, including SOC 2 Type II, ISO 27001 and Cyber Essentials Plus
- Meeting the standards of the NHS Data Security and Protection Toolkit (DSPT)
- Compliance programmes covering GDPR, HIPAA and PIPEDA
- Hosting on Amazon Web Services (AWS), with StoriiCare holding the AWS Healthcare Competency
- Encryption of data in transit and at rest
- Role based access controls, so staff only see the information they need for their role
- Audit trails that record who accessed or changed records
- Regular penetration testing
We provide clients with our data protection and security documentation, which you can use alongside your own policies and records to evidence your compliance. Using StoriiCare does not make your organisation compliant on its own: as the controller, you remain responsible for how your organisation collects, uses and shares personal data.
Getting Help with GDPR
- The Information Commissioner’s Office (ICO)
- Your Data Protection Officer
- Independent data protection consultants
- Legal advice
- Your business insurance provider, for cyber and data protection cover
- StoriiCare, for questions about how StoriiCare handles your data: team@storii.com
This guide is general information, not legal advice. Last updated October 2026.


