Data Processing Agreement

This Data Processing Agreement ("Agreement") forms part of the Terms & Conditions between GP Ratings and the GP Practice using the GP Ratings platform.

This Agreement governs the processing of personal data by GP Ratings on behalf of GP Practices and ensures compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Definitions

Controller means the GP Practice that determines the purposes and means of processing personal data.

Processor means GP Ratings, which processes personal data on behalf of the GP Practice.

Personal Data means any information relating to an identified or identifiable individual.

Processing means any operation performed on personal data including collection, storage, analysis, or deletion.

Applicable Data Protection Law refers to the UK GDPR, Data Protection Act 2018, and any related legislation.

2. Roles of the Parties

The GP Practice acts as the Data Controller and determines the purposes for which personal data is processed.

GP Ratings acts as a Data Processor and processes personal data only on documented instructions from the GP Practice.

3. Subject Matter of Processing

GP Ratings provides a platform that allows GP Practices to analyse patient feedback, monitor patient experience insights, and generate reports related to service quality.

Processing activities may include the storage, aggregation, analysis, and presentation of feedback data through the GP Ratings dashboard.

4. Types of Personal Data

The types of personal data processed may include:

  • Patient feedback submitted through the GP Ratings platform
  • Practice staff account details such as name and email address
  • Platform usage and access logs
  • Technical information such as IP addresses or device identifiers

GP Ratings does not request or intentionally process clinical records or sensitive medical information.

5. Categories of Data Subjects
  • Patients providing feedback about GP practices
  • GP practice staff members accessing the GP Ratings dashboard
  • Users interacting with the GP Ratings platform
6. Processor Obligations

GP Ratings agrees to:

  • Process personal data only in accordance with instructions provided by the GP Practice.
  • Ensure that personnel authorised to process personal data are subject to confidentiality obligations.
  • Implement appropriate technical and organisational security measures to protect personal data.
  • Assist the GP Practice in fulfilling its obligations under UK GDPR where reasonably required.
  • Notify the GP Practice without undue delay if a personal data breach occurs.
7. Security Measures

GP Ratings implements technical and organisational safeguards designed to protect personal data. These measures may include:

  • Encrypted connections (HTTPS)
  • Access control and authentication mechanisms
  • Secure cloud infrastructure
  • Monitoring and logging of system access
  • Regular security reviews
8. Subprocessors

GP Ratings may engage trusted third-party service providers to assist with hosting, infrastructure, analytics, or platform operations.

Where subprocessors are used, GP Ratings will ensure that they are subject to appropriate contractual obligations that meet the requirements of UK GDPR.

9. International Data Transfers

GP Ratings will ensure that any transfer of personal data outside the United Kingdom complies with applicable data protection laws and appropriate safeguards are in place.

10. Data Subject Rights

Where a data subject exercises their rights under UK GDPR, GP Ratings will assist the GP Practice where reasonably necessary in responding to such requests.

This may include requests for access, rectification, restriction, or deletion of personal data.

11. Data Breach Notification

GP Ratings will notify the GP Practice without undue delay after becoming aware of a personal data breach that affects personal data processed on behalf of the GP Practice.

GP Ratings will provide reasonable assistance in investigating and responding to the incident.

12. Data Retention and Deletion

Upon termination of services, GP Ratings will delete or return personal data processed on behalf of the GP Practice unless retention is required by law.

Backup systems may retain limited data for security and recovery purposes for a limited period.

13. Audit Rights

The GP Practice may request reasonable information to verify that GP Ratings complies with its data protection obligations under this Agreement.

14. Duration

This Agreement remains in effect for as long as GP Ratings processes personal data on behalf of the GP Practice.

15. Governing Law

This Agreement is governed by the laws of England and Wales.

16. Contact

If you have questions regarding this Data Processing Agreement, please contact GP Ratings support.