Guardian Medical

Guardian Medical Ltd

Document Reference: GM-POL-001

Data Protection & Retention Policy

Document Control

Version Number1.0
Effective Date2026-07-20
Review Date2027-07-20
Document OwnerData Protection Officer
Approved ByManaging Director
Approval Date2026-07-20
ClassificationPublic
Superseded DocumentsNone — initial version

Regulatory References

  • UK GDPR (retained EU law under the European Union (Withdrawal) Act 2018)
  • Data Protection Act 2018
  • Freedom of Information Act 2000
  • Equality Act 2010
  • Ofqual General Conditions of Recognition (Condition B2 — data protection)

Definitions

Personal Data
Any information relating to an identified or identifiable natural person, including names, contact details, date of birth, and online identifiers.
Special Category Data
Personal data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or data concerning sex life or sexual orientation.
Processing
Any operation performed on personal data, including collection, recording, organisation, storage, retrieval, use, disclosure, erasure, or destruction.
Data Subject
An identified or identifiable natural person whose personal data is processed by the organisation.
Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

This policy sets out how Guardian Medical Ltd handles personal data as a clinical training provider. It covers the retention periods applied to all core data types we process — including learners, instructors, safeguarding, complaints, medical information, certification records, and operational data — and explains how individuals can raise data protection concerns or exercise their rights under UK GDPR and the Data Protection Act 2018.

Loading latest version from SharePoint...

Part A: Data Retention Schedule

Guardian Medical Ltd retains personal information only for as long as necessary to meet legal, regulatory, safeguarding, and operational requirements. The following schedule defines the retention periods for each category of data we process.

Data Retention Rules

The following table defines the retention periods for each category of personal data processed by Guardian Medical Ltd.

Part B: Data Protection Complaints Procedure

The following procedure explains how individuals can raise concerns or complaints about how Guardian Medical Ltd processes their personal information, and how we will respond. It ensures complaints are handled fairly, promptly, and in line with UK GDPR, the Data Protection Act 2018, and ICO expectations.

2. How People Can Make a Data Protection Complaint

Individuals can submit a data protection complaint to Guardian Medical Ltd using any communication method, including:

  • Our data request form (available on the portal page)
  • Email to our designated data protection inbox: data@guardianmedical.org.uk
  • Telephone call to our office
  • Written letter sent to our postal address
  • Any other communication route (e.g., general enquiries inbox, verbal complaint to staff)

All complaints are valid regardless of the channel used. Staff must treat every data protection concern seriously and ensure it is passed to the Data Protection Lead without delay.

3. Information We May Need

To investigate a complaint effectively, we may ask for:

  • The individual’s name and contact details
  • Details of the concern or issue
  • Relevant dates, times, or supporting information
  • Any evidence the individual wishes to provide

We will only request information necessary to investigate the complaint.

4.1 Acknowledgement

We will acknowledge receipt of the complaint within 5 working days.

4.2 Investigation

The Data Protection Lead will:

  • Review the complaint and any supporting information
  • Examine relevant records, systems, or processes
  • Speak with staff involved, if necessary
  • Assess whether data protection obligations have been met
  • Identify any risks, errors, or areas for improvement

4.3 Response

We will provide a written response within 30 days, explaining:

  • Our findings
  • Any corrective actions taken
  • Any changes to processes or training
  • Any further steps available to the individual

If the complaint is complex, we may extend the investigation period. We will inform the individual if this is necessary.

5. Outcomes and Remedial Actions

Where a complaint is upheld, we may take one or more of the following actions:

  • Correct inaccurate data
  • Update or delete personal information
  • Improve internal processes or documentation
  • Provide additional staff training
  • Report incidents internally or externally where required
  • Notify affected individuals if appropriate

We will always act proportionately and transparently.

6. Escalation Options

If an individual is not satisfied with our response, they may escalate their concern to the Information Commissioner’s Office (ICO):

  • Information Commissioner’s Office
  • Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Telephone: 0303 123 1113
  • Website: ico.org.uk/concerns

We encourage individuals to contact us first so we can attempt to resolve the matter directly.

7. Record Keeping

Guardian Medical Ltd will maintain a confidential record of all data protection complaints, including:

  • The nature of the complaint
  • Investigation steps
  • Outcome and actions taken
  • Dates and correspondence

Records are retained for 6 years in line with our retention schedule.

8. Review of This Procedure

This procedure is reviewed annually or sooner if legislation, guidance, or organisational practices change.

Part C: Submit a Data Request

To submit a subject access request, data correction, erasure request, general enquiry, or complaint, please email the Data Protection Lead at data@guardianmedical.org.uk.

Last Updated:23 July 2026
Version:"{B2D3B20C-E5FE-4901-A1B4-5258C33E97C8},2"

Raise a Concern

If you need to report a concern, submit a complaint, or request a review related to this policy, please use the form below. Your submission will be routed to the appropriate team and logged in our compliance management system.

Submit a General Enquiry

Related to: Data Protection & Retention Policy (GM-POL-001)
Your submission will be sent to info@guardianmedical.org.uk and logged in our compliance system.