Medical data privacy by country
Medical data privacy in United Kingdom.
UK law still mirrors Europe's, and private clinics hold your records under the same law as the NHS. Ask how long the clinic keeps them, and share a full history by a channel you control.
General information, checked against the law on 23 September 2026. For your own case, ask a lawyer in United Kingdom.
What the law says
How United Kingdom treats your health data.
- The law
- UK GDPR and the Data Protection Act 2018[S105]
- The regulator
- Information Commissioner's Office (ICO)[S105]
- Health data
- Health data is a special category under the UK GDPR, processed only on a listed ground, such as your explicit consent or care by health professionals bound by confidentiality.[S105]
- Sending it abroad
- Data may leave the UK to countries the UK government has found adequate, or under safeguards such as the UK's international data transfer agreement.[S105]
- EU adequacy
- Yes. The EU renewed its adequacy decisions for the UK in December 2025, valid until December 2031.[S104]
- If there is a breach
- Within 72 hours to the ICO where feasible, and to the people affected without undue delay when the risk to them is high.[S105]
- Fines
- Up to GBP 17.5 million or 4% of worldwide annual turnover, whichever is higher.[S105]
Questions
United Kingdom: common questions.
Is it safe to email medical records to a clinic in United Kingdom?
Email is protected between mail servers only when both providers support TLS, and it stays readable on each server afterwards. Once your records reach a clinic in United Kingdom, local law applies: health data is a special category under the UK GDPR, processed only on a listed ground, such as your explicit consent or care by health professionals bound by confidentiality. For a full history, use a channel where you hold the key, such as a link that expires by itself.
How does United Kingdom protect health data?
Health data is a special category under the UK GDPR, processed only on a listed ground, such as your explicit consent or care by health professionals bound by confidentiality. Breaches must be reported within 72 hours to the ICO where feasible, and to the people affected without undue delay when the risk to them is high. The regulator is the Information Commissioner's Office (ICO).
Can a clinic in United Kingdom send my medical records abroad?
Data may leave the UK to countries the UK government has found adequate, or under safeguards such as the UK's international data transfer agreement.
Keep reading
More on United Kingdom, and elsewhere.
- Is it safe to send your medical records to a clinic abroad?
- Medical data privacy in South Korea
- Medical data privacy in Turkey
- Medical data privacy in Thailand
- Medical data privacy in China
- Medical data privacy in Vietnam
- Medical data privacy in Indonesia
- Medical data privacy in Switzerland
- Medical data privacy in France
- Medical data privacy in Germany
- Medical data privacy in Spain
- Medical data privacy in Hungary
Sources are numbered in the text and listed in full in the reference list.