Data Protection & GDPR Policy
for Johnston and Farrell Ltd
(Applicable in England, Wales & Scotland)
- Introduction
Johnston and Farrell Ltd is committed to protecting the personal data of our clients, their animals, our employees, and any third parties with whom we interact.
This policy outlines how we comply with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018 (DPA 2018)
- Privacy and Electronic Communications Regulations (PECR)
- Relevant provisions of Scots law, including the application of UK GDPR and DPA 2018 in Scotland, as well as applicable local civil and criminal enforcement mechanisms.
This policy applies to all staff, contractors, locums, students, and volunteers working at or on behalf of the Practice within England, Wales, or Scotland.
- Definitions
- Personal Data – Any information relating to an identified or identifiable natural person (e.g., name, address, phone number, CCTV images).
- Special Category Data – Sensitive data requiring extra protection (e.g., health information of staff members). Note: animal medical records are not personal data unless linked to an identifiable owner.
- Processing – Any operation performed on personal data, including collection, storage, transmission, or deletion.
- Data Controller – Johnston and Farrell Ltd which determines how and why personal data is processed.
- Data Processor – Any third party who processes data on our behalf.
- What Personal Data We Collect
We may collect and process the following data:
3.1 Client & Animal Records
- Client name, address, email, phone numbers
- Payment information
- Insurance details
- Animal details (species, breed, age, clinical history)
- CCTV footage (where applicable)
3.2 Staff & Contractor Data
- Contact details
- Employment history
- Veterinary registration numbers
- Training certifications
- Payroll and financial information
- Health information where required for work purposes (special category data)
3.3 Website & Communication Data
- IP addresses and cookies (subject to PECR rules)
- Online enquiries and booking information
- Lawful Basis for Processing
We process data under the following lawful bases of the UK GDPR:
- Contract – To provide veterinary services to clients or fulfil employment obligations.
- Legal Obligation – Veterinary medicines regulations, HMRC requirements, animal health legislation, professional record-keeping obligations.
- Legitimate Interests – Preventing fraud, practice management, service improvements.
- Consent – Marketing communications or optional services.
- Vital Interests – Emergency situations involving risk to human or animal welfare.
Where processing involves special category data, we rely on:
- Article 9(2)(b) employment and social protection law
- Article 9(2)(h) healthcare and medical diagnosis (animal health where it involves owner identification)
- Article 9(2)(a) explicit consent, where required
- How We Use Personal Data
We use personal data to:
- Create and maintain client records
- Provide clinical care for animals
- Process payments and insurance claims
- Communicate regarding appointments, reminders, and treatment updates
- Meet legal and regulatory obligations (e.g., RCVS, VMD)
- Manage staff employment and payroll
- Ensure security and safety (e.g., CCTV)
We never sell personal data to third parties.
- Data Sharing & Third Parties
We may share personal data with:
- Referral practices
- Out-of-hours providers
- Laboratories and diagnostic services
- Pet insurance companies
- Microchip databases
- IT system providers and payment processors
- Regulatory bodies (RCVS, VMD)
- Law enforcement, where required by law (including Scots law authorities)
Any processors acting on our behalf are subject to data-processing agreements.
- Data Transfers Outside the UK
If personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions
- Standard Contractual Clauses
- Additional technical and organisational security measures
- Data Retention
We keep personal data only as long as necessary:
- Clinical records: minimum 7 years after last interaction
- Financial/transaction data: 6 years (HMRC requirement)
- Insurance claims: 7 years
- CCTV: usually 30–90 days, unless required for investigations
- Recruitment records: 6 months
- Employee records: 6–7 years after employment ends
Where Scots law differs in enforcement periods, we comply with the stricter obligation.
- Data Security Measures
We implement appropriate technical and organisational measures including:
- Encrypted clinical software systems
- Access controls and password policies
- Secure data backups
- Staff training in data protection
- Confidentiality agreements
- Secure disposal of documents and digital data
- Rights of Data Subjects
Individuals have the following rights under UK GDPR, which apply in both the rest of the UK and in Scotland:
- Right to be informed
- Right of access (Subject Access Request – SAR)
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object
- Rights relating to automated decision-making
Requests must be answered within one month, extendable by two months for complex requests.
All requests should be directed to the Data Protection Lead.
- Subject Access Requests (SARs)
We will:
- Verify identity
- Respond within statutory timescales
- Provide copies of personal data free of charge
- Withhold third-party data (unless consent is obtained or legally permitted)
In Scotland, SAR procedures follow the same UK GDPR standards but may involve different enforcement routes via the Court of Session or sheriff courts if litigation occurs.
- Children & Vulnerable Persons
If we interact with children (e.g., as clients or staff relatives), parental/guardian consent is obtained where required.
Special protections apply under both UK and Scots safeguarding laws.
- Data Breach Procedures
If a personal data breach occurs:
- Assess severity and potential risk to individuals.
- Record all breaches in the Practice’s Breach Log.
- Notify the ICO within 72 hours if there is a risk to data subjects’ rights.
- Notify affected individuals when risk is high.
- Follow any Scots law reporting obligations where applicable (e.g., police involvement in criminal breaches).
- Marketing & Communications
We will only send marketing communications (newsletters, promotions) where:
- The individual has opted in, or
- We rely on legitimate interests under PECR (soft opt-in for existing clients)
Clients can opt out at any time.
- Responsibilities
- Data Protection Lead: [Name/Title]
- Oversees compliance
- Responds to SARs
- Trains staff
- All employees and contractors
- Must follow this policy
- Must report any data breach immediately
- Compliance in Scotland
The Practice complies fully with UK GDPR as it applies in Scotland. Key notes:
- UK GDPR and DPA 2018 apply identically across the UK
- Enforcement may occur via the ICO or Scottish courts
- Scots law on confidentiality, contracts, and CCTV may also apply
- Any data stored or processed by a branch or contractor in Scotland is covered by this policy
- Policy Review
This policy is reviewed annually or whenever regulatory changes occur.
Last updated: 14th NOV 2025
Next review due: 14th NOV 2026

