Policy
General Data Protection
Privacy & Data Protection (GDPR) Policy
Microsuction Ear Wax Removal – Rebecca Holt
1. Purpose
This policy explains how personal and clinical data is collected, stored, used, and protected when providing mobile microsuction ear wax removal. It ensures compliance with UK GDPR, the Data Protection Act 2018, and best practice for secure handling of patient information.
⸻
2. Scope
This policy applies to:
• All patients aged 18 and over receiving microsuction ear wax removal
• All personal and clinical data collected, including contact details, medical history, and images of the ear canal
• Data stored electronically in the TYMPA cloud-based system
⸻
3. Legal & Regulatory Framework
This policy is informed by:
• UK General Data Protection Regulation (UK GDPR)
• Data Protection Act 2018
• CQC Fundamental Standards – Regulation 17 (Good Governance)
• Professional guidance on record keeping
⸻
4. Types of Data Collected
To provide safe and effective care, the following information is collected:
• Name
• Date of birth
• Postcode
• Telephone number
• Clinical notes from appointments
• Photographs/videos of the ear canal (clinical use only)
⸻
5. Purpose of Data Collection
Data is used to:
• Deliver safe and effective microsuction ear wax removal
• Maintain accurate clinical records
• Contact patients if referral to an ENT or specialist is required
• Support clinical audit and quality improvement
⸻
6. Storage & Security
• All data is stored securely on the TYMPA cloud system
• Access is restricted to authorised personnel only
• Records are retained for 7 years, in line with professional and legal requirements
⸻
7. Use of Images & Videos
• Images/videos of the ear canal are taken for clinical documentation
• These are not personally identifiable (they do not show the face or other identifying features)
• On rare occasions, de-identified images may be used for training, education, or social media
• Consent is obtained through the TYMPA system before use
⸻
8. Patient Rights
Patients have the right to:
• Access the personal data held about them
• Request correction of inaccurate data
• Withdraw consent for images or videos at any time (without affecting their treatment)
• Request information about how their data is stored and used
⸻
9. Confidentiality & Sharing
• Information is kept strictly confidential
• Shared only on a need-to-know basis or if legally required
• Patients may be contacted if referral to a specialist is needed for their care
⸻
10. Training & Review
• The practitioner is trained in data protection and secure record keeping
• This policy is reviewed annually or sooner if guidance or legislation changes
Updated on 02/02/2026