Under UK GDPR, a GP practice must appoint a Data Protection Officer because its core activity, holding and processing clinical records, involves large-scale processing of special category health data, one of the three triggers that make DPO appointment mandatory rather than optional. Getting this wrong is not just a paperwork gap: an improperly appointed, under-resourced or conflicted DPO leaves the practice exposed to ICO enforcement and undermines the very function that is supposed to catch data protection problems before they become breaches.

We regularly advise GP practices and primary care networks on data protection governance, including where the DPO role has been bolted onto an existing job without proper thought given to independence or resourcing. This post sets out where practices most often get it wrong and what is actually at stake.

Why a GP Practice Must Appoint a DPO

The ICO’s guidance on Data Protection Officers sets out three circumstances in which appointing a DPO is mandatory under UK GDPR, not optional: where the organisation is a public authority or body, where its core activities require large-scale, regular and systematic monitoring of individuals, or where its core activities consist of large-scale processing of special category data or data relating to criminal convictions and offences.

A GP practice’s core activity is providing clinical care to a registered patient list, which necessarily means processing special category health data as its primary function, not as an incidental HR or administrative task. This places GP practices squarely within the mandatory appointment requirement. Many practices are also captured as public authorities or bodies for these purposes, depending on their structure, which the Data Protection Act 2018 defines at section 7. Either basis is sufficient on its own; a practice does not need to meet both.

Some smaller practices assume that because they are a partnership rather than an NHS trust, the DPO requirement doesn’t apply to them in the same way. It does. The size of the organisation is irrelevant to whether the requirement is triggered; what matters is the nature and scale of the processing.

Where Practices Get the Role Wrong

In our experience, the risk rarely comes from practices deciding not to appoint a DPO at all. It comes from appointing one in a way that doesn’t actually meet the requirements, which can be just as exposed to enforcement as having no DPO in place.

Conflict of interest

The ICO is explicit that a DPO cannot hold a position that leads them to determine the purposes and means of processing personal data. In a GP practice, this typically rules out the practice manager holding the DPO role in substance if that same person also makes the operational decisions about which systems process patient data, how records are shared with third parties, or how marketing and patient communications are run. The ICO’s own example is a head of marketing who cannot also be DPO because their decisions and their oversight role would conflict; the same logic applies to a practice manager who both decides on data processing arrangements and is meant to independently scrutinise them.

Lack of genuine independence

The DPO must report to the highest level of management, must not be penalised for raising concerns, and must be given direct access to decision-makers. A DPO who is line-managed by, and dependent for their role and reward on, someone whose decisions they are meant to be checking does not meet this bar in substance, even if it is met on paper.

Under-resourcing

The DPO must be given adequate time, budget and access to information to actually perform the role. A GP practice that appoints a DPO on paper but gives them no protected time, no training budget, and no real visibility of data processing decisions has not met the requirement, regardless of the job title on the organisational chart.

gp practice manager meeting with a data protection officer to review compliance

Sharing a DPO Across a PCN or Federation

The ICO confirms that a single DPO can act for a group of organisations, including public authorities acting together, and this is common practice for GP practices working through a primary care network or GP federation, where a shared DPO covers several practices. This is entirely permitted, but the ICO is clear that a shared DPO must still be able to perform their tasks effectively across every organisation they cover, taking into account the size and complexity of each one. A DPO nominally covering fifteen practices with no support team and no realistic capacity to engage with each practice’s individual processing activities is a genuine compliance risk for every practice relying on that arrangement, not just a resourcing inconvenience for the DPO personally.

Before relying on a shared or outsourced DPO arrangement, a practice should be able to answer, with confidence, how much time that DPO actually has for the practice specifically, whether they have direct access to the partners when needed, and whether they are genuinely independent of decisions made at network or federation level about shared IT systems and data sharing agreements.

What Getting It Wrong Actually Exposes the Practice To

Failures around DPO appointment and independence fall under the accountability and governance provisions of UK GDPR, which sit in the standard fine tier: up to £8.7 million or 2% of annual global turnover, whichever is higher. For most GP practices the turnover-based figure will be modest, but the ICO’s enforcement powers are not limited to fines. Reprimands, enforcement notices and orders to change practice are all available and are, in practice, more commonly used against smaller organisations than headline fines.

The more immediate risk is usually indirect. A conflicted or under-resourced DPO is less likely to catch a processing problem before it becomes a reportable breach, less likely to be consulted properly before a new system or data-sharing arrangement is adopted, and less able to give the practice a credible answer when a patient submits a subject access request that touches on sensitive third-party information. We cover the practical side of handling those requests correctly in our companion post on subject access requests for GP practices. Data governance failures also feed directly into CQC’s well-led assessments, since evidence of poor information governance and process failures under the single assessment framework is exactly the kind of finding that limits a well-led rating, which we cover in our post on CQC registration and compliance for GP practices.

DPO Compliance Checklist for GP Practices

RequirementWhat good practice looks like
Appointment basis documentedA clear record of why a DPO has been appointed (public authority status and/or large-scale special category processing) and, if not appointed, a documented reason why not
IndependenceThe DPO does not also determine the purposes and means of processing (for example, does not also decide which systems process patient data or negotiate data-sharing agreements)
Reporting lineDPO has direct access to the partners or highest level of management, not filtered through an operational manager whose decisions they may need to challenge
ResourcingProtected time, budget for training, and access to relevant systems and information are documented and reviewed at least annually
Published contact detailsDPO contact details are published (for example on the practice website or in the privacy notice) and provided to the ICO
Shared DPO arrangements (PCN/federation)Written agreement setting out how much time and access the DPO has for each individual practice, reviewed if the number of practices covered changes
DPIA involvementDPO is consulted, and that consultation documented, whenever a Data Protection Impact Assessment is required (for example, for a new clinical system)

What This Means for Your Practice

Appointing a DPO on paper is not the same as meeting the UK GDPR requirement. If your practice’s DPO also makes operational decisions about data processing, reports to someone whose decisions they are meant to be checking, or has no realistic capacity to do the job across a shared network, the practice remains exposed even though a name sits against the role.

If you would like an independent review of your practice’s DPO arrangements, whether in-house, shared across a PCN, or outsourced, get in touch with our healthcare team or call us on +44 207 566 1188. You can also reach us at info@gurvelegal.com. Our data protection team works with GP practices and primary care networks on exactly this kind of governance review.