Practice: JTG Medical Ltd
Policy owner: Director / Practice Lead
Version: 2.0
Effective date: 3rd September 2026
JTG Medical Ltd is committed to protecting personal information and maintaining the confidentiality of patients, prospective patients, professional contacts and business information.
This policy explains how the practice manages personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable professional confidentiality requirements.
It is proportionate to the practice's structure and reflects that the practice does not operate its own standalone electronic clinical record or payment system.
JTG Medical Ltd is the private practice of Miss Jana Torres Grau, Consultant Paediatric Surgeon. The practice is the data controller for the information described in this policy.
Miss Jana Torres Grau is the person responsible for data protection within the practice, and can be contacted using the details above.
This policy applies to personal information processed by JTG Medical Ltd, including:
JTG Medical Ltd does not maintain a separate standalone electronic clinical record system.
Clinical information relating to patients receiving treatment through the hospital is recorded and maintained within the hospital's clinical information systems. Hospital appointments and payments relating to treatment are managed in the same way.
Access to these systems is provided to authorised members of the hospital medical team, according to the hospital's own access-control and information-governance procedures. Those records are subject to the hospital's own retention arrangements.
Where clinical information is received independently by the practice, it is handled confidentially and transferred to the appropriate clinical record or hospital system where required. The practice does not create duplicate clinical records unnecessarily.
If you wish to see or correct your clinical records, the request will usually need to be directed to the relevant hospital organisation. We are happy to help you identify the right team.
Initial enquiries may be received through the practice website or the practice's initial enquiry email service.
At this stage we ask only for the information reasonably necessary to respond to your enquiry. This is normally a name, contact details and a short description of the reason for getting in touch.
The website contact form and initial enquiry email are ordinary email services, and are not designed for detailed medical histories or highly sensitive clinical information. Where clinical information is required, we will direct you towards an appropriate secure communication route or hospital system.
The practice uses its hosted email service for initial administrative enquiries. NHSmail is used for appropriate medical correspondence where required.
Sensitive clinical information is communicated using NHSmail or another appropriately secure method rather than the ordinary website or initial enquiry email. Email addresses are checked carefully before confidential information is sent.
JTG Medical Ltd complies with the principles of UK GDPR by ensuring that personal information is:
The practice identifies an appropriate lawful basis before processing personal information. Depending on the circumstances, this may include:
Where special category health information is processed, an appropriate condition under Article 9 of the UK GDPR is also identified. This is normally the provision of health care by a health professional bound by a duty of confidentiality, or the establishment or defence of legal claims.
Where processing relies on your consent, you may withdraw that consent at any time.
This is a paediatric practice, and most patients are children.
In most cases a parent or legal guardian will contact the practice and provide information on the child's behalf. Where a young person is able to make their own decisions about their care, that will be respected, in line with normal clinical practice and the hospital's arrangements.
Information relating to children is handled with the same care and confidentiality as all other patient information.
Personal information may be shared with:
Information is only shared where there is an appropriate lawful basis and where the disclosure is proportionate. The practice does not sell personal information.
Where third-party organisations process personal information on behalf of JTG Medical Ltd, appropriate contractual arrangements are considered. Relevant suppliers include website hosting, email and other technical service providers.
The practice takes reasonable steps to ensure that suppliers provide appropriate security for personal information.
Some suppliers may store or process information outside the United Kingdom. Where this happens, the practice relies on an approved safeguard, such as an adequacy decision or the UK International Data Transfer Addendum, so that the information continues to receive an equivalent level of protection.
Information submitted through the website is retained only for as long as necessary for the purpose for which it was collected.
Cookies are small files placed on your device. Some are necessary for the website to function. Others, such as analytics cookies, are only used where you have given permission through the cookie banner, and that permission can be changed at any time.
Further detail is set out in our cookie policy.
Website technical logs and analytics information may be retained according to the relevant provider's settings and the practice's legitimate requirements.
Information associated with the practice's Google Business Profile, including reviews and business communications, may be retained as part of normal marketing and business administration.
Patient-identifiable information is not published in reviews, responses or other public content.
The practice seeks to retain information for no longer than necessary, while complying with legal, regulatory, professional and accounting requirements.
Information received through the website or initial enquiry email is retained only for as long as necessary to respond to the enquiry, arrange appropriate onward contact or referral, maintain an appropriate administrative record, and meet any applicable legal requirement. Where an enquiry does not result in treatment, unnecessary personal or clinical information is not retained indefinitely.
Relevant business and patient correspondence may need to be retained where it forms part of the administrative record. Routine or duplicate correspondence that is no longer required is deleted securely.
Invoices and financial records are retained for the period required by applicable tax, accounting and company-law requirements.
Clinical records held within hospital systems are retained under the hospital's own records-management arrangements.
Information is not destroyed where there is a legitimate reason to retain it, including an ongoing complaint, legal proceedings, an insurance matter, an investigation or a regulatory requirement.
When information is no longer required, it is securely deleted or destroyed. Confidential paper information is shredded or disposed of through an appropriate confidential-waste service. Electronic information is deleted using appropriate methods, taking account of backups and the capabilities of the relevant system.
The practice implements appropriate technical and organisational measures to protect information. These include:
No method of internet transmission or electronic storage is completely secure, but the practice takes reasonable and proportionate steps to protect the information it holds.
Any suspected loss, unauthorised disclosure, unauthorised access or other personal data breach is reported promptly to the Director / Practice Lead and assessed.
Where a breach is likely to result in a risk to individuals' rights and freedoms, notification is made to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of the practice becoming aware of it. Where a breach is likely to result in a high risk to an individual, that individual is informed where required by law.
Where an incident relates to hospital-controlled systems, it is reported through the hospital's own information-governance or incident-reporting process.
The practice does not use automated decision-making or profiling.
Individuals have rights under UK GDPR, subject to applicable exemptions. These may include rights to:
Requests are considered and handled in accordance with applicable legal requirements, and we will normally respond within one month. Where information is held within a hospital's clinical system, requests relating to those records may need to be directed to the relevant hospital organisation.
To make a request, please contact us using the details in section 21.
If you have a concern about how the practice has handled your information, please contact us first so that we can look into it.
You also have the right to raise the matter with the Information Commissioner's Office, the UK regulator for data protection.
For any question about this policy, or to exercise any of your rights, please contact:
This policy is reviewed at least annually, or following a significant change to the practice's systems, services or data-processing activities.