top of page

GDPR +Data Protection policy – Shantalla Physio

1. Purpose
This policy outlines how our clinic collects, uses, stores, and protects personal data in accordance with the General Data Protection Regulation (GDPR) and Irish data protection legislation. We are committed to safeguarding the privacy and confidentiality of our patients and staff.

 

2. Data Controller
Shantalla Physio acts as the Data Controller for personal data collected and processed within the clinic.

Contact details:
Address: 31 Shantalla Road, Beaumont, Dublin, D09 FY22
Email: info@shantallaphysio.com
Phone: 089 411 7178

 

3. Types of Personal Data Collected
We may collect and process the following information:

Patient information

  • Name, address, phone number, and email

  • Date of birth

  • GP or referring practitioner details

  • Medical history and relevant health information

  • Treatment notes and clinical records

  • Appointment and billing information

Staff information (if applicable)

  • Employment and payroll details

  • Contact information

  • Professional registration details/Garda Vetting
     

4. Lawful Basis for Processing Data
Personal data is processed under the following lawful bases:

  • Provision of healthcare services

  • Compliance with legal and regulatory obligations

  • Legitimate interests of the clinic in managing healthcare services

Special category data (health information) is processed for the purpose of providing health treatment and care.

 

5. How Personal Data Is Used
Personal data may be used to:

  • Provide physiotherapy assessment and treatment

  • Maintain clinical records

  • Communicate regarding appointments or care

  • Process payments and invoices

  • Comply with legal and professional obligations
     

6. Sharing of Personal Data
Personal data will only be shared when necessary and appropriate - we will only do this with your explicit verbal or written consent - including with:

  • Referring doctors or other healthcare professionals involved in patient care

  • Insurance companies where relevant and authorised

  • Regulatory bodies where legally required

Information will not be shared with third parties for marketing purposes without explicit consent.

 

7. Data Security
The clinic takes appropriate measures to protect personal data, including:

  • Secure storage of paper records

  • Password-protected electronic systems

  • Restricted staff access to patient information

  • Secure disposal of confidential documents

Data is GDPR compliant, ISO 27001 and CE+ accredited with enterprise-grade security

​

8. Data Retention
Patient records will be retained in accordance with professional and legal guidance. Typically:

  • Adult records: retained for a minimum of 8 years after the last treatment

  • Children’s records: retained until the patient reaches 25 years of age

Records will then be securely destroyed.
 

9. Patient Rights
Under GDPR, individuals have the right to:

  • Access their personal data

  • Request correction of inaccurate information

  • Request restriction of processing in certain circumstances

  • Request erasure where legally permissible

  • Lodge a complaint with the Data Protection Commission

Requests should be submitted in writing to the clinic.
 

10. Data Breaches
Any suspected data breach will be recorded, investigated, and managed promptly. Where required, the breach will be reported to the Data Protection Commission and affected individuals.
 

11. Policy Review
This policy will be reviewed periodically to ensure ongoing compliance with data protection legislation.

Policy Date: 19.06.2026
Review Date: 19.06.2027

Shantalla Physio

31 Shantalla Road
Beaumont
Dublin D09 FY22

Opening Hours:​

Mon-Fri 08:00-20:00

​Sat 08:00-12:00

Bus Routes close by:

16, 104, 14, 41, 1

Email: info@shantallaphysio.com

Tel: 089 411 7178

  • Instagram
  • White Facebook Icon
  • LinkedIn

Contact Us

bottom of page