If you hold information about your patients – and every complementary healthcare practitioner does – UK data protection law has undergone its most significant update since the introduction of GDPR in 2018.
The Data (Use and Access) Act 2025 (DUAA), which received Royal Assent in June 2025, does not replace the UK GDPR or the Data Protection Act 2018. Instead, it updates and clarifies existing legislation, making some aspects of compliance simpler while introducing a small number of new responsibilities.
The good news is that if you already have robust GDPR procedures in place, the changes are unlikely to require major alterations. However, every practitioner should take the opportunity to review their privacy policy and complaints procedure.
What hasn’t changed?
The fundamentals of good data protection remain exactly the same.
You must still:
- Process patient information lawfully and fairly.
- Keep patient records secure.
- Have a clear, easy-to-understand privacy policy.
- Protect the confidentiality of all patient information.
Remember that patient records are classified as special category data, meaning they attract the highest level of protection under UK data protection law. Case notes, treatment records, medical histories and other health information must continue to be handled with appropriate care and security.
The biggest change: A formal data protection complaints process
The most important practical change introduced by the DUAA is that individuals now have a clear statutory right to make a data protection complaint directly to your practice before approaching the Information Commission.
This means every practitioner should have a documented process explaining how patients can raise concerns about the way their personal information has been handled.
Your practice should:
- Make it easy for patients to submit a data protection complaint (for example via email or a simple complaints form).
- Explain the process clearly within your privacy policy.
- Acknowledge complaints within 30 days of receiving them.
- Investigate complaints appropriately and without unnecessary delay.
- Keep patients informed during the investigation where appropriate.
- Communicate the outcome promptly.
- Maintain records of all complaints received and the action taken.
For most practitioners this simply means updating existing documentation rather than creating entirely new procedures.
Review your privacy policy
Now is a good time to ensure your privacy notice accurately reflects how your practice operates today.
Your privacy policy should explain:
- What personal information you collect.
- Why you collect it.
- How it is stored and protected.
- How long records are retained.
- Patients’ rights regarding their information.
- How patients can make a data protection complaint.
If you have introduced online booking systems, practice management software, cloud storage or AI-assisted administrative tools since your policy was last reviewed, these should also be reflected where appropriate.
Subject Access Requests: A welcome clarification
Patients continue to have the right to request copies of the personal information you hold about them.
The new legislation provides some helpful clarification for practitioners.
When responding to Subject Access Requests, organisations are now only expected to carry out searches that are reasonable and proportionate, rather than searching every possible archive or backup. In addition, the response timeframe can pause while you verify a patient’s identity or clarify exactly what information they are requesting.
These changes do not reduce patients’ rights but help make the process more practical for smaller organisations.
Are you registered with the ICO?
Whether you need to register with the Information Commissioner’s Office (ICO) remains one of the most common questions practitioners ask.
If all patient records are kept solely on paper and no personal information is stored electronically, you may be exempt.
However, most practitioners now store at least some personal information digitally. Holding patient email addresses, electronic appointment records, online booking information, payment records or digital clinical notes may mean registration is required.
If you:
- store patient records electronically;
- use practice management software;
- offer online appointment booking; or
- accept online payments,
you should check whether you are required to register.
Most sole practitioners fall into the lowest fee tier, currently £52 per year (with a small discount for Direct Debit).
If you are unsure, use the ICO’s online self-assessment tool. If the assessment concludes that registration is not required, it is sensible to keep a copy of the result for your records.
Don’t overlook your marketing
If you send newsletters or promotional emails to patients, now is also a good time to review your mailing list.
The DUAA clarifies some aspects of legitimate interests for direct marketing, but the rules around electronic marketing remain strict. You should ensure you have an appropriate legal basis for contacting everyone on your mailing list and that every marketing email includes a simple way for recipients to unsubscribe.
The penalties for breaches of the Privacy and Electronic Communications Regulations (PECR) have increased significantly, making marketing compliance more important than ever.
A simple five-point compliance checklist
To help ensure your practice remains compliant:
- Review your privacy policy and ensure it reflects your current practice.
- Add or update a clear data protection complaints procedure.
- Confirm whether your ICO registration is required and, if so, that it is current.
- Review your electronic marketing lists and unsubscribe process.
- Check that your digital records, cloud services and practice software remain secure and GDPR compliant.
Good data protection builds patient trust
Protecting patient confidentiality has always been a fundamental part of professional practice. These latest changes do not alter that principle—they simply strengthen the procedures surrounding it.
Taking a little time now to review your privacy policy, complaints procedure and ICO registration will help ensure your practice remains compliant while continuing to demonstrate the professionalism and trust that patients rightly expect.
For further information, practitioners should consult the ICO’s guidance on the Data (Use and Access) Act 2025, data protection complaints and ICO registration requirements.

