
Guardian Medical Ltd
Document Reference: GM-POL-001
Data Protection & Retention Policy
Document Control
| Version Number | 1.0 |
| Effective Date | 2026-07-20 |
| Review Date | 2027-07-20 |
| Document Owner | Data Protection Officer |
| Approved By | Managing Director |
| Approval Date | 2026-07-20 |
| Classification | Public |
| Superseded Documents | None — initial version |
Regulatory References
- UK GDPR (retained EU law under the European Union (Withdrawal) Act 2018)
- Data Protection Act 2018
- Freedom of Information Act 2000
- Equality Act 2010
- Ofqual General Conditions of Recognition (Condition B2 — data protection)
Definitions
- Personal Data
- Any information relating to an identified or identifiable natural person, including names, contact details, date of birth, and online identifiers.
- Special Category Data
- Personal data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or data concerning sex life or sexual orientation.
- Processing
- Any operation performed on personal data, including collection, recording, organisation, storage, retrieval, use, disclosure, erasure, or destruction.
- Data Subject
- An identified or identifiable natural person whose personal data is processed by the organisation.
- Data Breach
- A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
This policy sets out how Guardian Medical Ltd handles personal data as a clinical training provider. It covers the retention periods applied to all core data types we process — including learners, instructors, safeguarding, complaints, medical information, certification records, and operational data — and explains how individuals can raise data protection concerns or exercise their rights under UK GDPR and the Data Protection Act 2018.
Part A: Data Retention Schedule
Guardian Medical Ltd retains personal information only for as long as necessary to meet legal, regulatory, safeguarding, and operational requirements. The following schedule defines the retention periods for each category of data we process.
Data Retention Rules
The following table defines the retention periods for each category of personal data processed by Guardian Medical Ltd.
Part B: Data Protection Complaints Procedure
The following procedure explains how individuals can raise concerns or complaints about how Guardian Medical Ltd processes their personal information, and how we will respond. It ensures complaints are handled fairly, promptly, and in line with UK GDPR, the Data Protection Act 2018, and ICO expectations.
2. How People Can Make a Data Protection Complaint
Individuals can submit a data protection complaint to Guardian Medical Ltd using any communication method, including:
- Our data request form (available on the portal page)
- Email to our designated data protection inbox: data@guardianmedical.org.uk
- Telephone call to our office
- Written letter sent to our postal address
- Any other communication route (e.g., general enquiries inbox, verbal complaint to staff)
All complaints are valid regardless of the channel used. Staff must treat every data protection concern seriously and ensure it is passed to the Data Protection Lead without delay.
3. Information We May Need
To investigate a complaint effectively, we may ask for:
- The individual’s name and contact details
- Details of the concern or issue
- Relevant dates, times, or supporting information
- Any evidence the individual wishes to provide
We will only request information necessary to investigate the complaint.
4.1 Acknowledgement
We will acknowledge receipt of the complaint within 5 working days.
4.2 Investigation
The Data Protection Lead will:
- Review the complaint and any supporting information
- Examine relevant records, systems, or processes
- Speak with staff involved, if necessary
- Assess whether data protection obligations have been met
- Identify any risks, errors, or areas for improvement
4.3 Response
We will provide a written response within 30 days, explaining:
- Our findings
- Any corrective actions taken
- Any changes to processes or training
- Any further steps available to the individual
If the complaint is complex, we may extend the investigation period. We will inform the individual if this is necessary.
5. Outcomes and Remedial Actions
Where a complaint is upheld, we may take one or more of the following actions:
- Correct inaccurate data
- Update or delete personal information
- Improve internal processes or documentation
- Provide additional staff training
- Report incidents internally or externally where required
- Notify affected individuals if appropriate
We will always act proportionately and transparently.
6. Escalation Options
If an individual is not satisfied with our response, they may escalate their concern to the Information Commissioner’s Office (ICO):
- Information Commissioner’s Office
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Telephone: 0303 123 1113
- Website: ico.org.uk/concerns
We encourage individuals to contact us first so we can attempt to resolve the matter directly.
7. Record Keeping
Guardian Medical Ltd will maintain a confidential record of all data protection complaints, including:
- The nature of the complaint
- Investigation steps
- Outcome and actions taken
- Dates and correspondence
Records are retained for 6 years in line with our retention schedule.
8. Review of This Procedure
This procedure is reviewed annually or sooner if legislation, guidance, or organisational practices change.
Part C: Submit a Data Request
To submit a subject access request, data correction, erasure request, general enquiry, or complaint, please email the Data Protection Lead at data@guardianmedical.org.uk.
Raise a Concern
If you need to report a concern, submit a complaint, or request a review related to this policy, please use the form below. Your submission will be routed to the appropriate team and logged in our compliance management system.
Submit a General Enquiry
Related to: Data Protection & Retention Policy (GM-POL-001)
Your submission will be sent to info@guardianmedical.org.uk and logged in our compliance system.