UK GDPR and Data Protection for Veterinary Practices: A Compliance Guide
By Brian Crocker · Published
Who it applies to
The UK General Data Protection Regulation (UK GDPR), retained from the EU GDPR after Brexit and supplemented by the Data Protection Act 2018, applies to any organisation that processes personal data. A veterinary practice holds personal data routinely: client names and contact details, clinical history linked to a named owner, staff personnel records, marketing consent records, CCTV footage if the practice operates cameras, and payment records.
The gov.uk data protection guidance states that everyone responsible for using personal data must follow the data protection principles: data must be "used fairly, lawfully and transparently"; "used for specified, explicit purposes"; "adequate, relevant and limited to only what is necessary"; "accurate and, where necessary, kept up to date"; "kept for no longer than is necessary"; and handled with "appropriate security."
The data veterinary practices typically hold
Client data: name, address, phone, email, payment history. For ongoing clients, this typically runs back years and includes clinical correspondence.
Animal clinical records: clinical history linked to a named owner. Clinical records are not special category data in the UK GDPR sense (which covers human health data), but they are linked to individuals, so the standard UK GDPR obligations apply to the owner data within them.
Marketing preferences: records of whether a client has consented to reminders, newsletters, or promotional communications. If your PMS sends appointment reminders by email or SMS, you need a lawful basis for that processing.
Staff records: personnel files, payroll information, sickness absence, disciplinary records, and (for practices with CRB/DBS checks) criminal records data — which is special category data and needs a more stringent basis.
CCTV: if the practice operates cameras in waiting areas or car parks, CCTV footage of clients and staff is personal data. It requires a clear privacy notice displayed prominently, a defined retention period, and a lawful basis for processing.
Lawful bases
Every type of processing must have a lawful basis. For a veterinary practice, the most commonly applicable bases are:
Contract — processing that is necessary to fulfil your contract with the client (treating their animal and billing them for it). This covers the core clinical and invoicing data.
Legitimate interests — processing where the practice has a legitimate interest and that interest is not outweighed by the individual's rights. Appointment reminder processing often rests here. The legitimate interests test requires a three-part assessment, and the ICO's guidance recommends documenting this.
Consent — for marketing communications (newsletters, promotional offers). Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes or inactivity do not constitute consent. Consent must be recorded so you can demonstrate it.
Legal obligation — processing required to comply with a legal obligation. Keeping payroll records for HMRC, or maintaining records required by the Veterinary Medicines Regulations 2013 (see VMR 2013 compliance guide), falls here.
What needs to be documented
Article 30 of the UK GDPR requires organisations with 250 or more employees to maintain a Record of Processing Activities (ROPA). For practices below that threshold, there is an exemption from maintaining a full formal ROPA — but the exemption does not apply where the processing is likely to result in a risk to individuals' rights, involves special category data, or is not occasional.
In practice, most veterinary practices are below 250 employees but do hold staff special category data (health and absence records) and conduct regular processing of client data. The ICO's position is that even for smaller organisations, maintaining a processing register is good practice and the safest approach if a data breach or subject access request occurs.
A simple document recording: what categories of data you hold; the lawful basis for each; the purposes of processing; how long you keep each category; and who has access — covers the core requirement and gives you the reference point when a client submits a Subject Access Request (SAR).
Data retention
Data should be kept "no longer than is necessary." For a veterinary practice, this requires a retention policy per data type:
- Clinical records linked to client data: the RCVS recommendation is to keep clinical records for a minimum of six years from the last treatment, or longer where the animal is still an active patient. The RCVS guidance is professional guidance rather than a statutory retention period, but it is the appropriate benchmark.
- Staff records: personnel records should be kept for the duration of employment plus a period sufficient to defend any employment tribunal claim — typically six years from the end of employment.
- CCTV footage: industry guidance suggests 30 days is appropriate for most commercial premises unless an incident requires retention.
- Financial/invoicing records: HMRC requires retention for at least six years.
Where your PMS automatically retains data beyond these periods, you need a review mechanism to identify and delete records that have exceeded their retention period. Many practices have PMS systems holding client records from 15 years ago with no deletion process — that represents a retention compliance gap.
Subject access requests
Any individual — client or staff member — can request a copy of the personal data you hold about them (a Subject Access Request, SAR). You must respond within one calendar month. There is no fee (in most cases). The response must provide the data in a commonly used electronic format if requested.
For a veterinary practice, a SAR from a client will typically require you to extract and package: their contact records, clinical correspondence where their name appears, invoicing records, marketing consent records, and any other data fields attached to them in your PMS. For staff, it includes personnel files, communications, and any other records in which they appear.
Having a simple process for handling SARs — who is responsible, where to look, how to format the response — means a SAR is a manageable one-month task rather than a stressful scramble.
Where the compliance gaps typically appear
No marketing consent records — the PMS sends reminders and the practice sends a newsletter, but there are no records of when consent was obtained or what it covered.
CCTV with no privacy notice — cameras are installed but there is no sign informing people that CCTV is in operation, for what purpose, and how footage is retained. This is a visible compliance gap.
Staff data mixed into shared systems — personnel records held in a shared drive accessible to all staff rather than access-controlled.
No data retention policy — all data is retained indefinitely because no one has been assigned responsibility for reviewing and deleting expired records.
No breach response procedure — the UK GDPR requires you to report certain personal data breaches to the ICO within 72 hours of becoming aware of them. Most practices have no documented procedure for identifying what constitutes a reportable breach or for making the notification.
The non-clinical compliance guide covers data protection as one of several compliance streams a vet practice manages. A simple data protection policy document covering lawful bases, retention periods, and breach response is the starting point for most practices.
Registering with the ICO
Almost all veterinary practices that process personal data (which means almost all of them) must register with the Information Commissioner's Office and pay the data protection fee. The fee is tiered by size: tier 1 (micro) organisations — turnover under £632,000 or fewer than 10 staff — pay £52/year; tier 2 (small and medium) organisations pay £78/year; tier 3 (large) organisations pay £3,763/year. Registration is renewed annually.
Check your current registration status at the ICO's register of fee payers. Operating without registration when required carries a civil monetary penalty.
VetComply helps practice managers track data protection review dates, ICO registration renewals, and other non-clinical compliance obligations. Join the waitlist for early access.
Sources:
- Data protection — gov.uk
- Data Protection Act 2018 — legislation.gov.uk
- Register of fee payers — ICO
Manage all your practice compliance in one place
VetComply brings CMA compliance, RCVS PSS preparation, H&S, COSHH, and 8 more compliance streams into a single dashboard. Join the waitlist for early access.
Related guides
Veterinary Clinical Governance: Building a Compliance Framework for Your Practice
How clinical governance provides the structure for non-clinical compliance — audit cycles, evidence management, and how to organise practice compliance across multiple regulatory streams.
Preparing for a VMD Inspection: What Veterinary Practices Need to Know
How UK veterinary practices prepare for a Veterinary Medicines Directorate inspection — what inspectors check, common findings, documentation expected, and how to demonstrate medicines compliance.
Veterinary Clinical Waste Management: A Compliance Guide for Practice Managers
Practical guide to clinical waste compliance for UK vet practices — waste classification, duty of care, contractor requirements, record-keeping, and common Environment Agency findings.