This policy sets out how Sunny Dental Cosmetic & Wellness Clinic complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Scope
This policy applies to all personal data processed by Sunny Dental Cosmetic & Wellness Clinic, including data held electronically, on paper or in other formats. It applies to all workers, contractors and trainees who process personal data on our behalf.
Principles
We follow the data protection principles: lawfulness, fairness & transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity & confidentiality; and accountability.
Roles
- Data Controller: Sunny Dental Cosmetic & Wellness Clinic
- Lead for data protection: Practice Manager (or delegate)
- All staff must complete training and follow this policy and related procedures.
Lawful bases & special category data
We identify and document a lawful basis for each processing activity (Contract, Legal Obligation, Legitimate Interests, Consent, etc.). For health data, we rely on Article 9(2)(h) and Schedule 1 of the DPA 2018 as appropriate and maintain appropriate policy documents and safeguards.
Individual rights
- We have procedures to respond to requests for access, rectification, erasure, restriction, portability and objection within one month.
- No fee is charged unless a request is manifestly unfounded or excessive.
Data minimisation & retention
We collect only what is necessary and keep it no longer than needed. Retention schedules: enquiry data up to 24 months; finance 6 years; clinical records in line with dentistry requirements (adults: minimum 11 years; children: until age 25, whichever is longer). Secure disposal/anonymisation is applied at end of retention.
Security
- Access controls, encryption in transit, secure configurations and patching.
- Backups and tested restore procedures.
- Processor due diligence and data processing agreements.
- Confidentiality obligations for staff and contractors.
Sharing & international transfers
We only share data with recipients who have a lawful need and appropriate safeguards. International transfers outside the UK use adequacy regulations or appropriate safeguards (e.g., UK IDTA/Addendum, SCCs).
Data breaches
We maintain an incident response process. Personal data breaches are assessed and, where required, reported to the ICO within 72 hours and to affected individuals without undue delay.
Training & review
All staff receive regular data protection training. We periodically audit compliance and review this policy annually or after significant changes.
Contact
Questions about this policy: sunnydentaluk@gmail.com or write to 2 London Road, Twickenham, TW1 3RY. Date: 2026-06-15.


