Close

Privacy notice

Last updated: 27 August 2026

This guide explains how we use your personal information. As the UK regulator of dental care professionals, the General Dental Council is a ‘controller’, as defined in the UK General Data Protection Regulation (UK GDPR), Data Protection Act (DPA) and the Data Use and Access Act 2025 (DUAA). We take our responsibilities very seriously and are committed to keeping your information secure.

We are accredited to international information security standards and are Cyber Essential Plus certified, which means that we keep your information safe and secure.  We also adhere to the ICO Accountability Framework, which is a standard to measure organisations’ compliance with data protection law.

The following terms are defined by the UK GDPR, the DPA and DUAA.

By personal data, we mean information relating to a living identified or identifiable person.

By special category personal data, we mean:

  • Personal data that reveals any of the following about an individual: racial or ethnic origin; political opinions; religious or philosophical beliefs; or trade union membership.
  • Personal data that consists of: genetic data; biometric data used for the purpose of identifying an individual; data concerning health; or data concerning an individual’s sex life or sexual orientation.

By criminal offence data we mean personal data about whether an individual is alleged to have committed or has been convicted of a criminal offence.

What data protection rights do you have?

Under data protection law, you have rights over the information we hold about you:

  • You can ask us to give you access to your personal data
  • You can ask for your personal data to be erased
  • You can ask us to restrict the processing of your personal data, so that the data will only be used for limited purposes
  • You can object to the processing of your personal data
  • You can ask for your personal data to be provided to you in a structured, commonly used and machine-readable format, and you can transmit that data to another controller

You can make a request for any of these by emailing us.

If you have any questions or concerns about how the GDC is using and sharing your personal data, then you can contact our Data Protection Officer. The GDC’s Data Protection Officer (DPO) assists in monitoring internal compliance, informs and advises on data protection obligations, and acts as a contact point for data subjects and the Information Commissioner.

The Information Commissioner's role is to improve the information rights practices of organisations by gathering and dealing with concerns raised by members of the public.

Information about their work, including how to submit a complaint, is available on their website. You can also call their advice line on 0303 123 1113 or email casework@ico.org.uk.

Contents

Contacting the GDC

How we use your personal data if you are a:

Member of the public

Registrant or applicant to the Register

Education provider/student

Stakeholder

GDC employee/job applicant

Whistleblower

CCTV

GDC websites

Contacting the GDC

Phone calls

Like many other organisations, we record and may monitor our telephone calls for quality improvement, training, compliance and security purposes. We record calls using a secure third party application.

All calls received into Customer Services are recorded and retained for a period of six months. In addition, we record details of all calls received for reporting purposes.

Calls to any other telephone numbers to the GDC are not recorded. When calls are transferred from our Customer Services team to another GDC staff member, the call recording will end once the call is transferred.

Calls are sometimes retrieved and monitored for the following purposes:

  • It is necessary to investigate a complaint
  • There is a threat to the health and safety of staff or visitors
  • For the prevention or detection of crime
  • We need to check compliance with regulatory procedures
  • They are required for legal proceedings
  • It is necessary in order to respond to a data subject rights request
  • It is part of a ‘spot check’ to ensure that our customer service standards are being met
  • To improve standards in call handling through training and coaching of our staff. In this instance the call will be edited to ensure the callers details are anonymised. The staff member will also need to agree to the call being used in this way. 

All calls that are used for quality monitoring are retained.

Emails

All emails relating to a fitness to practise case, registration or enquiry from a member of the public are stored on our Customer Relationship Management (CRM) system.

All other emails received by the GDC are retained on our email system for a period of 12 months (plus a 28-day period for deletion) before they are automatically deleted.

Web forms

All web forms we receive are stored in our CRM.

Letters

All letters we receive are scanned and saved either into our CRM system or by the relevant team in their electronic files.

How we use your personal data

How we use your personal data depends on what relationship you have with the GDC.

Members of the public

We will collect different information from you, depending on the type of communication you have with us. General enquiries such as checking a dental professional’s registration should not require us to collect personal data.

If you are raising a concern about a registered dental professional, we may need to collect personal data to investigate your concerns. 

Our Customer Services team manages most of the communication we receive. This includes calls made to 020 7167 6000, emails sent to us and most web forms sent to us. 

There are two web forms managed by other teams. These are the ‘Complaint about a dental professional’ form, which is managed by our fitness to practise team, and the complaint form on the Dental Complaints Service (DCS) website, which is managed by the Dental Complaints Service.

Raising a complaint or concern about a registrant

You can use the Dental Complaints Service (DCS) to make a complaint about private dentistry, or the NHS complaints service to make a complaint about NHS treatment.

If you report a serious concern about a dental professional, which then leads to a fitness to practice (FtP) case with the GDC, we will process your personal data. We may also need to disclose your identity to the dental professional. If an informant requests that they are kept anonymous in an investigation, we will try to respect this.

However, if it appears there is a need to disclose because it is not possible for a case to be progressed without disclosing the identity of the informant, then we may disclose their identity even if they have asked us not to. This is so that we can meet our statutory objectives, which include protection of the public, or because there is otherwise a legal obligation to do so. If we are required to do this, we will inform the informant beforehand, and they will be able to raise any concerns they have.

It is possible that a dental professional may be able to identify the informant from the nature of the concerns raised, even if the informant is not named by FtP.

Where the FtP investigation relates to clinical matters, we may need access to the medical or dental records of the informant or other relevant people, such as other patients treated by the dental professional.

Equality monitoring data in FtP

We have a duty to work to eliminate discrimination, harassment and victimisation. That means advancing equality of opportunity and fostering good relations between those who share relevant protected characteristics and those who do not. These requirements are set out in the Public Sector Equality Duty.

To help us to identify issues and monitor our progress, we ask those who raise public protection issues or concerns with us to complete an equality monitoring form. The form is a multiple choice questionnaire which asks about your sex, gender, whether you consider yourself to have a disability, any legal marital or registered civil partnership, your religion, sexual orientation and ethnic group. Every question includes a ‘prefer not to say’ option.

The personal data we collect using the equality monitoring form is allocated a unique identification number and stored on our Customer Relationship Management system.

That data record is linked to your contact information. It is only available to those who need to access it for the purposes of data analysis, monitoring and reporting. It is not available to, or used by, fitness to practise caseworkers or decisionmakers.

If you report illegal practice

We collect personal data from anyone who complains to us about illegal dental practice. This may include witness statements provided to us and medical records of any informants.

Public consultations

A public consultation is any exercise where we are seeking agreement or views on a set of proposals to amend policies, procedures, rules or guidance.

When exercising our regulatory functions, we must have proper regard for the interests of the public and patients and dental professionals. In some circumstances, we have a statutory duty to consult if we are proposing changes to fitness to practise rules.

A consultation is normally a formal, timebound and public process, where our proposals are set out and explained in full. Public consultations typically invite responses from dental professionals, the public and patients, and other stakeholders. That can be done by asking for responses to specific questions or simply inviting comments on the proposals. Public consultations tend to be done in writing, but can include engagement activities, such as facilitated focus groups, stakeholder meetings etc.

Personal data is often collected or created as part of a consultation exercise. The processing and sharing is necessary for us to perform a task in the public interest or to meet our statutory duties. Your information will be shared with relevant GDC staff members and may be shared with GDC Council members.

The information you provide will be used to:

  • Clarify any issues raised by the respondent
  • Assess the potential impacts of the proposed changes
  • Analyse the views of respondents. 

Providing personal data as part of a public consultation means you understand it will be used for the purposes set out above. If you do not wish it to be used in this way, you should limit any personal data you provide or remove it completely. 

An anonymised summary of consultation respondents and the responses received will be included in a consultation outcome report. Consultation outcome reports are published in the consultations and responses section of our website.

All information contained in consultation responses, including personal data, can be subject to potential disclosure if requested under the Freedom of Information Act 2000. Personal data will not be published if doing so would breach data protection laws.

Attending Council meetings as an observer

Members of the public who wish to attend Council meetings as an observer are able to submit their request via our webform. Observers can join virtually or in person.

We collect personal data of those who request to view the stream through the webform only - we do not collect data using our stream provider.

While the video feed for the stream is focused on Council members, it is possible that observers may be visible on the stream. We do not keep recordings of these streams.

Registrants/applicants to the Register

We have a statutory responsibility to maintain a register of dentists and dental care professionals.

Applicants to our Register

Everyone who applies to join our register will be required to provide personal data via our online portal, MyGDC. This may include special category data, for example, information about your health and criminal offence data (including declaring a past criminal offence).

We use a third party service to verify the identity of applicants. This is to ensure that only the verified holders of the qualifications provided are admitted to the register.

We may need to contact referees or other persons named in your application form or provided subsequently. This is to verify the information you provided or to obtain further information. Where you have declared a health issue, we may need to obtain information from your doctor or other healthcare professional involved in your care or treatment. 

The registration application form includes equality monitoring questions, which are voluntary. Some of the information that we hold from this form is special category personal data (eg racial or ethnic origin).

Where we process personal data, special category personal data or criminal offence data in connection with registration, we do it on the basis that this is necessary to carry out our statutory functions, and in the substantial public interest. In addition, some special category personal data is processed by us for the purpose of monitoring equality of opportunity or treatment.

In some cases, providing data to us for registration is a statutory requirement. Not providing data, or providing inaccurate data, may mean that your application for registration is refused or you become subject to our fitness to practise procedures. This may lead to various outcomes, including conditions being imposed on your registration, the suspension of your registration, or removal (erasure) from the register.

Some applicants, such as overseas qualified dentists and dental care professionals, will be required to undergo an assessment of their qualifications by our Registration Assessment Panel, an independent panel of dentally qualified assessors.

Overseas Registration Examination (ORE) candidates

Some applicants for registration will be required to take the Overseas Registration Exam (ORE). This consists of Part 1 (a written exam) and Part 2 (a clinical exam).

ORE candidates who have refugee status in the UK are offered priority placement on exam sittings. If a candidate chooses to provide this information in order to request priority then it will be kept alongside their application. 

Part 1 and Part 2 of the ORE are administered by external providers, UCL Consultants, under contract with the GDC.

We provide UCL Consultants with a list of the candidates sitting the ORE, together with information to enable them to identify candidates when they arrive to sit the exams. We also receive personal data from these external providers about candidates’ performance in the ORE. We may share equality monitoring data with the external providers after the exam has taken place to quality-assure the exam.

Registrants

Registered dental professionals must renew their registration annually to remain on the Register, which includes paying an annual retention fee (ARF).

We collect banking transaction and payment data for this purpose and contract with a Direct Debit collection service provider to manage the bulk processing of Direct Debit payments.

As part of the renewal process, we will also confirm and update personal information and ask for indemnity and continuing professional development (CPD) declarations.

We use external providers and applications to send out the emails, letters and texts that support our renewal and registration communications. 

Our online portal, MyGDC, allows you to maintain your registration with the GDC. The portal uses cookies to record personal information changes, banking and transaction information, IP address and online activity data for security purposes.

Sharing registrant information

We may share our register information with the NHS and other healthcare bodies in the UK.  A list of monthly removals is also shared with the NHS to alert them of the people we have removed from the register.

If you provide your GDC number to the Care Identity Service to request access to NHS software applications, we will confirm your name, registration, date of birth and registration status to the NHS.

We share the outcomes of Continuing Professional Development (CPD) appeals on our Dental Professionals Hearings Service website and with healthcare bodies following each CPD hearing. This is a redacted version of the Committee outcome statement, including name, registration number, fact of decision and town/city of registered address. Additionally, we publish details of upcoming CPD appeals two weeks in advance of each CPD hearing on the Dental Professionals Hearings Services’ website. We do this to meet the GDC’s overarching statutory objective under Section 1 of the Dentists Act 1984, and our obligation to protect the public.

Working patterns data

We ask dental professionals to answer a small number of questions about their working patterns as part of their annual renewal process. These questions are voluntary, and you can choose not to answer these if you prefer. You will hear about this through our annual retention fee communications. 

We collect this data as we believe having a better understanding of how dental professionals are working throughout the UK will provide important insight into the issues affecting dental professionals and patients. 

This insight will help the profession develop future services that will bring about the changes the profession and patients want and need. Working patterns data will be used alongside other information we hold, including registrant equality, diversity and inclusion data, to better meet this purpose. 

The responses we receive will help us and others to better understand: 

  • Where dental professionals are working  
  • What dental professionals are doing
  • The number of hours they are working
  • Whether they are working in NHS or private practice
  • How the way dental professionals are working changes over time  

We analyse the responses and produce and share reports about working patterns in dentistry and how it changes over time.

We share this data with external organisations and stakeholders, such as NHS organisations. 

Our working patterns survey asks registrants for the postcode of their primary place of work. The lookup will include a full address for you to select but only the postcode itself, not the full address, will be visible to and retained in the GDC database.

We will share and report datasets in a format where no individual is directly identifiable and only following approval under our report request process. 

We will ensure that no individual can be identified when we publish reports based on this data. 

Working patterns data, including postcode, will not be used to make decisions about fitness to practise cases, your registration or your annual renewal nor will they affect your access to GDC services or how we treat you.  

The responses you provide are your personal data but will only be viewable by specific GDC staff who technically manage our data and systems and undertake data analysis. The datasets do not include directly identifiable information such as names.

Under data protection law, the basis we use to process this information is our ‘legitimate interests’. This means we have judged it ‘necessary’ for us to use personal data to meet the purposes we have for this work. 

When we process special category data, such as some equality, diversity and inclusion information for this purpose, we do so as it is necessary for our public task and for reasons of substantial public interest. 

Monthly email newsletter

We extract data from the online register for the purposes of issuing the email newsletter to all registered dental professionals. We use email address, name for personalisation and region for segmenting relevant content. Only dental professionals who are indefinitely suspended are excluded. The data is extracted from the register one or two days ahead of issue.

We do not allow dental professionals to opt out or unsubscribe from our email newsletter.  Our email newsletter is considered key correspondence and is closely linked to our regulatory role. It includes important updates and reminders, such as annual renewal deadlines. Our email newsletter is therefore not issued on the basis of consent.

Research

The personal data which we use to carry out our regulatory functions is used for statistical analyses and research. Personal data includes demographic information, employment, and data generated during the fitness to practise process.

We conduct data analyses, commission and support research on a range of topics to provide evidence that informs our approach to regulatory functions related to registration, fitness to practise, and education and training.

We process personal data in carrying out research on our own behalf on the basis that it is necessary to exercise our statutory functions and is carried out in the public interest. Where the processing includes special category data, it is also on the basis that it is necessary for research purposes. 

As part of data analyses and research, we use personal data including special category and protected characteristics to help us understand more about a range of issues and their impact on dental professionals across everything we do. We do this to help ensure we are not discriminating against anyone and being fair. 

Statistical analysis of personal data or research is never used to make decisions about a dental professional’s registration or about a fitness to practise case. 

We share personal data with researchers working on our behalf if it is necessary to do so. We do so under contract and ensure we have adequate safeguards in place, only sharing what is necessary for the research, using secure methods. When we commission research to contractors or provide support to external research not commissioned by GDC, we default to providing them with anonymised data. 

When we publish research or statistics, we ensure individuals cannot be identified from reports. We will never identify individuals in published data analyses or research without first gaining consent from those involved. 

In some circumstances we want to use non-anonymised data. These requests for internal or external use are carried out under our report request process, which includes advice from our Data Protection Officer. Decisions to allow these data uses are made by the relevant Executive Director and if needed the Chief Executive and Registrar.  

Third party research

As well as conducting our own research, we co-operate with third party organisations that are conducting research. We default to sharing anonymised or pseudonymised data (where a unique reference is used instead of personal data). Sometimes we share non-anonymised personal data with third parties. 

Third party research will typically support our regulatory functions, for example registration, fitness to practise, and education and training.

We share data with third party organisations conducting their own research on the basis that it is carried out in the public interest. Where the processing includes special category data, it is also on the basis that it is necessary for research purposes.

Where we share data with third party researchers, we do so under appropriate agreements and ensure we have adequate safeguards in place, only sharing what is necessary for the research, using secure methods. These are considered under our report request process. 

Consultations

When the GDC is carrying out a public consultation, the same conditions apply to registrants as to members of the public – please read Consultations for more information.  

If you are the subject of a fitness to practice case

We have a statutory responsibility to investigate whether the fitness to practise (FtP) of a registered dental professional is impaired. Where FtP is impaired, this may lead to various outcomes, including conditions imposed on a dental professional’s registration, the suspension of that registration, or erasure from the register.

We have statutory powers that allow us to obtain information as part of our fitness to practise investigations, and we may exercise these powers to help us investigate these issues.

In completing our FtP functions, we process personal data relating to the registered dental professional who is the subject of the complaint.

This may include special category personal data (eg health). It may also include criminal offence data (eg where a FtP issue arises as a result of a criminal offence).

When investigating a concern about a dental professional, we may need to share details of the concern with them, their current and (in some circumstances) previous employer(s), their legal representatives and other individuals or organisations. 

More information about the disclosure and publication of information during the fitness to practise process can be found in our Disclosure and Publication Policy.

FtP initial assessment, assessment and investigation

The concerns received will be considered by our Initial Assessment team to determine whether they should go forward to be considered at the assessment stage.

When cases are referred to the casework stage, the caseworker will obtain the information necessary to complete their investigation. This may include sharing relevant information with a clinical adviser for comment. Where the concerns raised relate to a dental professional’s health, we may need access their medical records and contact their GP or other medical practitioners. 

It may also be necessary for the dental professional to have a health assessment and for information to be shared with our contracted occupational health providers for that purpose. As part of this assessment, we may ask for hair and blood samples for the purpose of alcohol or drugs testing.

Once the caseworker has completed their investigation, they will conclude that either:

  • The issues raised need no further investigation and we will close the case
  • The information received needs further investigation and we will refer the case to our case examiners. 

Case examiners are dental professionals or lay people but are also GDC staff who have a statutory duty to make decisions at the conclusion of an investigation. The evidence is considered by two case examiners (one lay and one a dentist or dental care professional) who review the evidence obtained during our investigation, including any evidence provided by the dental professional or their representatives and the informant.

Case examiners don’t make findings of fact in a case or come to substantive conclusions regarding a dental professional’s fitness to practise. They do determine whether an allegation should be considered by a Practice Committee. They can also close a case or impose conditions on the dental professional.

FtP prosecutions

When a Fitness to Practise (FtP) case is referred by the case examiners to be heard by one of our Practice Committees, the In-house Legal Prosecutions Service (ILPS) will take responsibility for conducting the case before the Committee on behalf of the GDC. The ILPS also conducts cases where we are seeking an Interim Order and Review cases before our respective Practice Committees. 

The ILPS may need to share information with witnesses, including expert witnesses, for this purpose. In some instances, we may ask our External Legal Prosecution Service (ELPS), a third-party law firm contracted to carry out this work for us.

In preparing a case (particularly a case involving the health of a dental professional) the ILPS and/or the ELPS may need access to your medical records, and it may be necessary for us to contact your GP or other medical practitioners involved in your care and treatment.

It may be necessary for the dental professional to have a health assessment and for information to be shared with our contracted service provider for that purpose. As part of this assessment, hair and blood samples may be taken.

FtP hearings

Hearings held before our committees are managed by our Dental Professionals Hearings Service.

You can review the Privacy notice of our hearings service on the Dental Professionals Hearings Service website.

Illegal practice

It is a criminal offence for someone who is not a registered dentist or dental care professional to practise dentistry, or to say that they practise dentistry. It is also a criminal offence to use a protected dental title or to unlawfully carry on in the business of dentistry as an individual or body corporate. 

We will investigate and prosecute these offences or take other appropriate enforcement action.

As part of our review, we will collect personal data about the people we investigate to ascertain whether they are practising dentistry illegally. This may include data obtained through publicly available information or because of our investigations.

If the matter proceeds to court, we are required to disclose material to the defendant. This may include details of the initial complaint we received. If the informant did not assist us in our investigation, these details will be provided in redacted form without disclosing the informant’s identity.

Where we process personal data, special category personal data or criminal offence data in connection with illegal practice, we do so on the basis that the processing is necessary to exercise our statutory functions in relation to illegal practice and is in the substantial public interest.

Specific data sharing requests from third parties 

There may be occasions where we process and share data held by the GDC where it is necessary to comply with legal obligations, for example: 

  • in relation to legal proceedings  
  • in response to requests from law enforcement agencies 
  • in response to requests from other regulators.  

We may also share information with law enforcement agencies, other regulators, or other appropriate bodies when it is necessary for either their or our statutory or public functions or legitimate interests.  

The data shared in these situations will be limited to what we are satisfied is necessary and lawful for the stated purpose. 

We are obliged to share personal and special category data with the Professional Standards Authority. We do so with an Independent Controller Agreement in place and with due regard to security of data. Their access to the data is revoked once no longer needed.

Sharing personal data to third countries

The GDC does not enter into contracts with suppliers exporting data to third countries unless they are a member of the Data Privacy Framework, or a Transfer Risk Assessment or other suitable protection mechanism has been carried out.

However, in the course of communicating with registrants resident in third countries, it is necessary that their data be shared back with them. Moreover, payments made by them will be processed by our third party provider to the territory in which they reside.

Competition and Markets Authority (CMA)

In April 2026, we provided the CMA with information relating to registered dental professionals for the purposes of its market study, in accordance with the CMA’s statutory duties under the Enterprise Act 2002. During the CMA’s 12-month market study, the CMA may decide to undertake research and contact some dental professionals to invite them to take part. 

Education providers/students

We have a statutory responsibility to set the standards for education and learning outcomes and monitor the quality of education and training programmes in the UK that lead to registration as a dentist or a dental care professional. To achieve this, we keep the standards and learning outcomes up to date and carry out quality assurance of these programmes.

In advance of inspections we will seek relevant evidence and progression data. During the inspections, our education quality assurance (EQA) team and education associates meet staff members and students and will take notes of these meetings. We will ask to see evidence of a range of information to detail the clinical work that students have carried out, for example student log books.

All student and patient data sent to us is anonymised. Any information that cannot be anonymised is only viewed in person and no details are recorded. Our EQA team and education associates may also see student exam results (anonymised) and progress reports and student FtP data (not anonymised).

 The EQA lead and education associates develop the final report, which is shared with the education provider. In this report, staff and student names are anonymised, and staff roles and gender are not disclosed to avoid identification.

On occasion, students will contact our education and quality assurance team with a complaint about their education provider. The complaint will be investigated if the student agrees that it should be investigated or if we consider that the nature of the complaint requires investigation even without the student’s agreement.

Where we process personal data, special category personal data or criminal offence data in connection with quality assurance, we do so on the basis that the processing is necessary to complete our statutory functions in relation to dental education and is in the substantial public interest.

Stakeholders

Stakeholders include membership organisations for dental professionals, trade unions, indemnifiers and other groups with an interest in dentistry.

Email communications

We send emails to our stakeholders via Microsoft Outlook. These are tailored emails updating stakeholders on announcements, events and consultations.  Stakeholders can unsubscribe from these emails by emailing our stakeholder email address.  

Monthly email newsletter

Stakeholders who sign up to our email newsletter are asked to provide their name, job title, name of their organisation and email address. They are also asked to select an option from a list of organisation types. We collect this data to enable segmenting and tailoring of information to ensure it is relevant and useful to our stakeholders.

We use third-party provider, Jisc, to collect stakeholder data. Further information about how Jisc safeguards person data can be found online.

Stakeholders can opt out of our email newsletter by using the unsubscribe function.

We use a third-party provider, Mailjet, to issue our email newsletter. Further information about how Mailjet safeguards personal data can be found online. 

GDC employees and applicants

We hold personal data about people who apply to work for us, work for us and who previously worked for us. This may include special category personal data (eg about health) and criminal offence data. 

Job applicants

For recruitment purposes, we use an applicant tracking system to collect, store and manage recruitment documentation. This is managed by an independent provider. When candidates apply, their personal data in connection with the application will be stored in the site. This includes information provided by unsuccessful applicants.

When you apply, you will be asked to provide personal data which we need to process to manage and keep records of the recruitment process, assess your suitability for employment and decide who we offer a job to. We may also need to process job applicant data to respond to and defend against legal claims. We request feedback using an online form. We capture this to improve our recruitment processes.

We process health information if we need to make reasonable adjustments to the recruitment process to support applicants who have a disability. In some cases, we need to collect and process data to ensure we are complying with our legal obligations, for example checking an applicant's eligibility to work in the UK before employment starts.

If your application is successful, we will process your data to prepare your contract and offer of employment.

You are encouraged to provide equality and diversity information, such as racial origin, disability, religious belief or sexual orientation, which will be anonymised and used for monitoring purposes. Please note that you may choose not to provide this information and it will not affect your application in any way.

Your data will be held in in confidential files held by our People Services team. Your data will be shared with the hiring manager, other selection panel members and senior managers who are involved in the decision-making process. Your information will be held on file for a maximum of 12 months.

Employees

All new employees are required to provide various items of personal data. This includes data about health, copies of passports, evidence of the right to work, and an equality and diversity form.

We process personal data in connection with employment on the basis that it is necessary to exercise our statutory functions.

Where we process special category personal data or criminal offence data in connection with employment, we do so on one or more of the following bases:

  • The processing is necessary for the exercise of our statutory functions and is also in the substantial public interest
  • The processing is necessary to perform or exercise our legal obligations and rights in connection with employment
  • The processing is necessary for health purposes (including occupational health or the assessment of an employee's working capacity)
  • Some special category personal data is processed by us in the context of employment, for the purpose of monitoring equality of opportunity or treatment. It is optional to provide this information and is collected and processed only with the consent of the employee.

Where employees are unfit to attend work, they are required to advise their line manager, who will then update the absence on our HR system. This information will be made available to our People Services team.

Employees may be referred to the external Occupational Health provider and, with the consent of the employee, we may receive copies of an individual's occupational health report. Once shared it will be stored on the employee record and will be held in accordance with GDC retention schedules.

Performance reviews are usually conducted by an employee's line manager. Statements from the employee and their manager about performance are entered and stored on our HR system. Information about performance reviews may also be held by the line manager and/or by People Services.

Information about an individual's disciplinary record will be held by People Services.

For high-risk grievance cases, we may consult an expert third party. Once the investigation is complete, all data will be deleted from their systems.

People Services may prepare reports on matters such as absence and performance to present to the management team. Such reports will be anonymised, so they do not contain personal data.

All employees are required to provide regular and considered declarations of any conflicts, or perceived conflicts of interest. To promote transparency, and public confidence in the organisation and the regulatory process, we publish the declarations of the Executive team and our Case Examiners on our website.

Council meetings

We hold Council meetings several times a year. These meetings can be attended by employees as observers and are live streamed. The focus of the live stream is on Council members, but internal presenters and other employees observing may be visible on the stream. We do not keep recordings of these streams. The personal data processed on these streams in done so as part of our public task.

GDC associates

We work with associates who provide expert advisory, investigatory or adjudicatory services to support us in carrying out our regulatory functions. 

These associates perform roles such as fitness to practice panel members or advisers, registration appeal panel members, overseas registration external examiners, education inspectors, clinical advisers, expert witnesses, dental complaints service panellists, specialist list appeals panellists, Council members and members of other statutory and standing committees.

We hold personal data about people who apply to be associates, and about our current or former associates. This may include special category personal data (eg health) and criminal offence data.

We collect, store and manage information related to the recruitment of our associates. This site is managed by an independent provider. When candidates apply to work at the GDC, their personal data in connection with the application is stored. This includes information provided by unsuccessful applicants.

Associates are required to provide personal data, including name, contact details, bank account details, identification, evidence of the right to work, and details of any qualifications, skills, experience and employment history. This data is held on our CRM system. Contact information such as name, addresses and telephone numbers is also stored in our database. Those associates who hold a worker agreement with the GDC will also have their details held on our HR system.

For associates who provide services to FTP as clinical advisers or experts, we will retain a list of expertise which will detail their registration number, name, contact details, specialties, and length of experience. The associates’ details are retained on the list for as long as they are an active associate with the GDC.

In addition, we process some special category personal data about associates for the purpose of monitoring equality of opportunity or treatment. Proving this information is optional and is collected and processed only with your consent.

Information about the quality of an associate's work for us is held by the line manager and may also be shared with People Services.

Associates are required to provide regular and considered declarations of any conflicts, or perceived conflicts of interest. To promote transparency and public confidence we publish these declarations.

We process personal data about associates as it is necessary to allow us to exercise the various statutory functions we carry out. 

The data is used to verify an associate's identity and work rights, to enable performance of the contract for services between the parties (including communication, payment of fees and reimbursement of expenses, if applicable), and to monitor and provide feedback on work quality.

Where we process special category personal data or criminal offence data about associates, then we do so on one or more of the following bases:

  • It’s necessary to allow us to exercise our statutory functions and is also in the public interest
  • It’s necessary for allow us to exercise our legal obligations and rights regarding any contract for services with the associate
  • It’s necessary for health purposes (including occupational health or the assessment of an associate's working capacity).

Associates with a worker agreement are paid through our payroll system, and we may share their personal data with third parties in connection with payroll processing, taxation and pension contributions if applicable.

Whistleblowers

We welcome hearing from anyone who wants to raise a concern about an individual or organisation as a whistleblower. We have described what we mean by a whistleblower in our definition of a whistleblower page on our website. We have summarised there the types of concerns that count as whistleblowing. 

We will ensure that, if you raise a genuine concern, you will not suffer any detriment or adverse treatment as a consequence. Any information you provide will be used in line with our data protection policy.

We also welcome matters raised by GDC staff and associates, and have a staff whistleblowing policy, which staff can access on our intranet. We will ensure staff who raise a whistleblowing concern will not suffer any detriment or adverse treatment as a consequence. 

We process your personal data in order to carry out our regulatory function or to comply with our legal obligations as a ‘prescribed person’ under the Public Interest Disclosure Act 1998 and The Public Interest Disclosure (Prescribed Persons) Order 2014.

We may need to use and share information you give us with other organisations, such as government departments, enforcement agencies and the police, for the purpose of investigating the issues raised. There may also be certain circumstances where we are required, by law, to share your information.

Closed-Circuit Television (CCTV)

CCTV is in operation at our offices. Where we are not the sole occupier of the building (Colmore Square) there is additional CCTV which is controlled by the building owners or management company.

We record CCTV images of people who enter and leave our premises as well as at other locations throughout the buildings. This is for the purposes of security and safety monitoring and the investigation of alleged criminal offences. We may share our CCTV images with law enforcement and courts if this is needed.

We use our premises to perform our regulatory functions. We consider that ensuring the security and safety of our premises is necessary to perform a task carried out in the public interest and/or in our official authority as a regulator.

The GDC’s websites

The GDC operates the following addresses:

gdc-uk.org

mygdc-uk.org

https://contactus.gdc-uk.org/

olr.gdc-uk.org/SearchRegister

standards.gdc-uk.org

Our privacy policies apply to our websites only. If you follow a link to an external website, you will be subject to that organisation’s privacy policies, not the GDC’s.

Cookies

Cookies are small text files that are placed on your computer or phone by websites that you visit.

We use cookies to collect and store information about how you use GDC websites, such as the pages you visit. This information is anonymised. It cannot be used to identify you personally.

Read more about the cookies we use.

Using our websites

You can use our websites without disclosing any information that identifies you as an individual.

If you enter personal details into a form, the GDC will use your information to provide the service you have requested.

Period of retention

We keep anonymised data about how our websites are used for 14 months.

Our Retention schedule sets out the length of time we keep personal data.