Ethics in IEMT Practice: Lesson 2.5

Records and Data Protection

Welcome

Client records and personal information are some of the most sensitive things you hold. In this lesson we look at what records to keep, your legal duties as the person responsible for your clients' data, how long to keep records, how to keep them secure, and what to do if something goes wrong. The law described is that of the United Kingdom.

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain what makes a good client record.
  • Describe your duties under UK data protection law, including special-category data and the ICO fee.
  • Set a justified retention period and handle requests for access.
  • Apply practical security measures, and respond to a data breach.

Why records matter

Good records support safe work, help you notice change or deterioration, show how you reached your decisions, and protect both you and the client if questions arise later. The Standards of Competence (section 7) ask for timely, factual and proportionate records of consent, suitability, work done, outcomes, decisions, referrals and significant events. The HCPC's tenth standard is simply “Keep records of your work”.

  • Keep client report, your own observation and your interpretation separate, and make it clear which is which.
  • Write records at the time, or as soon afterwards as you can.
  • Record what you did and why, including decisions not to proceed, referrals and any confidentiality disclosure with its lawful basis.
  • Never alter a record to hide a mistake. If you need to correct one, keep the original and add a dated note, so that there is an audit trail.

You are the responsible person

Under UK data protection law, the person who decides why and how personal data is used is called the controller. The Association is the controller for its own membership, directory and training data. Each practitioner is a separate controller for their own client records. The Association does not hold your client files. The Data Protection and Online Privacy Policy (section 10) says independent practitioners must:

  • decide whether they are a controller, joint controller or processor;
  • give clients a privacy notice;
  • identify a lawful basis, and for health data a special-category condition;
  • collect only what is needed;
  • set justified retention periods;
  • protect records;
  • answer requests from clients about their data;
  • manage anyone who processes data for them; and
  • have a process for dealing with incidents.

The legal framework in plain English

The UK GDPR and the Data Protection Act 2018 apply to the personal data you hold. At their heart are principles that data must be used lawfully, fairly and transparently; for specified purposes; only as far as needed; accurately; kept no longer than necessary; and kept secure. You must also be able to show that you comply.

Health information is special-category data

Information about a person's physical or mental health is special-category data. To use it you need a lawful basis under Article 6 and, in addition, a separate condition under Article 9. For many independent IEMT practitioners, the client's explicit consent is the simplest basis to rely on, given alongside your privacy notice. The Association's policy makes the same point: consent is not the only possible basis, but you must identify the right one. If you are unsure, take advice or use the ICO's guidance on special-category data.

The ICO data protection fee

The Information Commissioner's Office (ICO) says that organisations, including sole traders, that use personal information must pay a data protection fee unless they are exempt. The smallest tier is currently £52 a year, or £47 by direct debit, and higher tiers apply to larger organisations. The ICO has a short self-assessment on its website. Check it for your own situation: you can find the page at ico.org.uk/for-organisations/data-protection-fee.

Privacy notice

Give each client a clear privacy notice before you collect information. It should say who you are, what you collect and why, your lawful basis, who it might be shared with (including the limits of confidentiality), how long you keep it, the client's rights, and how to complain to you and to the ICO.

Client information must not be entered into generative AI, transcription, recording, cloud or messaging systems merely because they are convenient.

The Association for IEMT Practitioners, Data Protection and Online Privacy Policy, section 10

Before you use any tool that stores or processes client information, including cloud storage, email, messaging apps, note-taking apps, transcription or AI tools, check where the data goes, who can see it, and whether you have a lawful basis and a suitable contract with the provider.

Clients' rights

  • Access. A client can ask for a copy of their data (a subject access request). You must respond without undue delay and within one month of receiving the request. The time can be extended by up to two further months if the request is complex or numerous. You need only carry out reasonable and proportionate searches. There is normally no fee.
  • Correction. Clients can ask for inaccurate data to be corrected.
  • Erasure. This is not absolute. Do not promise deletion where you have a lawful reason or duty to keep a record. The Scope of Practice Policy says so explicitly.
  • Complaints. Since 19 June 2026 organisations have been required to make it easy to make a data protection complaint and to acknowledge complaints within 30 days. Tell clients they can also complain to the ICO.

How long should you keep records?

UK data protection law does not set a fixed period. You must be able to justify the period you choose. The Association's Scope of Practice Policy (section 9) gives its normal expectation: a minimum of five years after the final contact, extending up to seven years where insurance, legal or professional requirements justify it. It adds that different rules may apply to children, vulnerable adults and other jurisdictions.

Type of record Starting point Notes
Adult client records At least five years after final contact, and up to seven. Check your insurer's requirements. Longer may be justified.
Records about children Do not apply the adult period automatically. Many health services keep children's records until at least the age of 25. Ask your insurer, and see Module 3.
Safeguarding records and unsubstantiated allegations Do not delete automatically. Keep a documented, reasoned retention decision (Safeguarding Policy section 8).
Assessment or screening records As client records. Store securely, in line with data protection law.

For comparison, the NHS Records Management Code sets 8 years after last contact for adult health records, until the 25th birthday for children, and 20 years for mental health records. It is written for NHS services, so you are not bound by it, but it shows that the Association's five-to-seven-year range is a minimum, not a ceiling. Whatever you decide, write it down, and delete or anonymise records securely at the end of the period.

Keeping records secure

Do’s and don’ts for client records. Do use encrypted note apps or drives, explain privacy practices to clients and shred outdated documents. Do not write notes in unsecured phone apps, assume clients understand data protection rules or leave files visible in shared spaces.

  • Use encrypted storage or a trustworthy system, with strong passwords and two-step verification where possible.
  • Lock paper files, and shred them securely when the retention period ends.
  • Do not leave records or screens visible in shared spaces.
  • Use secure channels to send anything sensitive. Think before you email client details.
  • Back up your records, and test your backups.
  • Do not discuss clients in public or unsecured places.
  • Use anonymised material for supervision and training (Lesson 2.3).

If something goes wrong

A personal data breach is a security incident that leads to personal data being lost, destroyed, altered, disclosed or accessed without authority. A lost phone or an email sent to the wrong person can be one. If you suspect a breach:

  1. Contain it: stop the cause, and retrieve or delete what you can.
  2. Record what happened, when you found out, and what you did.
  3. Assess whether it is likely to put people at risk.
  4. If it is, report it to the ICO without undue delay and within 72 hours of becoming aware. If the risk is high, tell the people affected directly.
  5. Tell your insurer as your policy requires, and follow the Association's Duty of Candour Policy in being honest with the client (Lesson 4.4).

A notifiable UK personal-data breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of awareness.

The Association for IEMT Practitioners, Data Protection and Online Privacy Policy, section 8

Scotland, Northern Ireland and elsewhere

The UK GDPR and Data Protection Act 2018 apply throughout the UK, and the ICO is the regulator for all four nations. The Data (Use and Access) Act 2025 made some changes to the UK rules. In the European Union and other countries different law applies, including different regulators and different periods. If you work with clients abroad, check the law in their country and your insurer's requirements.

Self-Reflection Exercise

Audit your own records and systems:

  • What do you keep about each client? Is all of it necessary?
  • Do you have a privacy notice, a written retention period and a breach plan?
  • Have you paid the ICO fee, or checked that you are exempt?
  • Which apps or tools hold client information, and are they secure and appropriate?

List three actions and a date for each.

Key Takeaways

  • Make factual, timely records, and never alter them to hide mistakes.
  • You are the controller of your clients' data. Health data is special-category data, which needs an Article 6 basis and an Article 9 condition.
  • Check whether you must pay the ICO fee, and give clients a privacy notice.
  • Reply to access requests within one month, and set a justified retention period. The Association expects at least five years after final contact.
  • Do not put client data into AI, transcription, cloud or messaging tools just because they are convenient.
  • Report notifiable breaches to the ICO within 72 hours.

Next Steps

In Lesson 2.6 we look at equality, inclusion and reasonable adjustments.

This ethics series is produced by The Association for IEMT Practitioners and is intended for professional development purposes. It describes law and guidance for England and Wales as at October 2026 and is not legal advice. Always follow your local law, your insurer’s conditions, safeguarding procedures and your professional judgement.