GDPR Agreement
1. Purpose of Data Collection and Processing
By booking an appointment online through www.bridgemedicalpractice.ie , you consent to the collection, use, and storage of your personal and medical data by Bridge Medical Practice for the purpose of:
- Managing your appointment(s)
- Providing medical care and follow-up
- Meeting legal and regulatory obligations under Irish health and data protection laws
2. Data Collected
The following data may be collected and stored:
- Personal details (name, date of birth, contact details)
- Medical history and presenting symptoms
- Appointment records and consultation notes
- Any documents or forms submitted through the platform
3. Lawful Basis for Processing
We process your data under the following GDPR lawful bases:
Article 6(1)(b): Processing is necessary for the performance of a contract (provision of medical services)
Article 9(2)(h): Processing is necessary for the purposes of medical diagnosis, treatment, and management of health or social care systems
4. Data Storage and Retention
Your data is stored securely on GDPR-compliant servers.
Data is retained in accordance with HSE and Medical Council of Ireland guidelines.
Typically, medical records are retained for a minimum of 8 years or longer where legally required.
5. Data Sharing
We do not share your personal data with third parties except:
With your explicit consent
Where required for referrals, laboratory tests, or other medical services
Where legally obligated (e.g., public health reporting)
6. Your Rights Under GDPR
As a data subject, you have the right to:
Access and obtain a copy of your data
Correct inaccuracies
Request deletion (where legally permissible)
7. Security Measures
We employ appropriate technical and organisational measures to protect your data, including:
Secure encrypted servers
Role-based access to medical records
Routine audits and compliance monitoring
GDPR controller is Dr Brid McGrath