GDPR
Last updated: 28 August 2026
This page explains what GDPR is, the principles behind it, and the rights it gives you over your personal information. For the specifics of what we collect, why, and how to exercise these rights with us directly, see our Privacy Policy.
1. What GDPR is
The General Data Protection Regulation (GDPR) is the law that governs how organisations collect, use, and protect people's personal information. It originally came into force across the EU in 2018. Since Brexit, the UK has its own version, known as the UK GDPR, which works alongside the Data Protection Act 2018. The two are very similar in substance, and together they're the law that applies to how Hello Pharmacy handles your information.
"Personal information" under GDPR means anything that can identify you, directly or indirectly, on its own or combined with other information. For a pharmacy, that includes obvious things like your name and date of birth, but also your prescription history and any health information, which the law treats as a more sensitive category requiring extra care.
2. The data protection principles
GDPR is built around a small number of principles that any organisation handling personal information has to follow:
- Lawfulness, fairness and transparency. There has to be a valid legal basis for using someone's information, and it shouldn't be used in ways they wouldn't reasonably expect.
- Purpose limitation. Information collected for one reason shouldn't then be used for an unrelated one without telling the person.
- Data minimisation. Only collect what's actually needed, not everything that might one day be useful.
- Accuracy. Information should be correct and kept up to date, and inaccurate information should be fixed or removed.
- Storage limitation. Information shouldn't be kept for longer than it's needed, except where the law specifically requires a longer period.
- Integrity and confidentiality. Information has to be kept secure, protected against loss, misuse, or unauthorised access.
- Accountability. Organisations have to be able to show they're following all of the above, not just follow them.
3. Your rights under GDPR
GDPR gives you a set of rights over your own information. In summary, you have the right to:
- Be informed about how your information is used, which is what this page and our Privacy Policy are for.
- Access a copy of the personal information an organisation holds about you.
- Rectification. Ask for inaccurate or incomplete information to be corrected.
- Erasure, sometimes called the "right to be forgotten." Ask for your information to be deleted, though this isn't absolute, for example a pharmacy can be legally required to keep certain dispensing records for a set period regardless of a deletion request.
- Restrict processing. Ask an organisation to pause using your information while a concern you've raised is looked into.
- Data portability. Receive your information in a format you can reuse or move elsewhere.
- Object to your information being used for certain purposes, such as marketing.
- Have safeguards around automated decisions. Where a significant decision about you is made using your health information, a person has to be involved rather than the decision being left to automated processing alone. This isn't something that applies to Hello Pharmacy in practice: a pharmacist reviews and makes the clinical decisions on your care.
How these apply in practice at Hello Pharmacy, and how to exercise them, is set out in section 7 of our Privacy Policy.
4. How this applies to Hello Pharmacy
As a GPhC-registered pharmacy, we're the data controller for the personal information we hold about our patients, which means we're responsible for deciding how and why it's used, and for meeting the principles above. Our Privacy Policy sets out exactly what we collect, who we share it with, how long we keep it, and how to make a request under any of the rights listed in section 3.
5. Who enforces GDPR in the UK
The Information Commissioner's Office (ICO) is the independent regulator responsible for upholding data protection law in the UK.
You also have the right to complain to us directly about how we've handled your information. See our Complaints Policy for how to do this, we'll acknowledge your complaint within 2 working days and aim to give you a full response within 10 working days.
You're also entitled to complain to the ICO directly at ico.org.uk.
6. Changes to this page
We'll update this page if data protection law changes in a way that affects it, and update the date at the top when we do.
