Privacy Notice
Who we are
Child Psychiatry Consultancy Ltd is the data controller for the personal information we hold about children, young people and their parents or carers.
We are registered in England and Wales under company number 16147055. Our registered office is 320 City Road, London EC1V 2NZ. Our Information Commissioner's Office (ICO) registration number is ZC135917.
Our Data Protection Lead is Dr Athina Zakynthinaki, Consultant Child and Adolescent Psychiatrist and Registered Manager. You can contact her about data protection matters at info@childpsychiatry.uk.
This notice applies to people who contact us, make an enquiry, are referred to us or receive assessment or treatment. It also applies where an enquiry or referral does not proceed.
It explains how we collect, use, store and protect information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended.
Information collected before acceptance
We collect limited information at the initial enquiry stage to decide whether our remote service can meet your child's needs safely and appropriately.
This includes your child's name and date of birth, your name and relationship to the child, your contact details, the service requested and brief information about presenting concerns, relevant health conditions, risk, safeguarding and current professional support.
Your child's name and date of birth help us identify them correctly and establish their age. Your contact details allow us to respond or seek clarification. The clinical information supports our decision about whether to accept the referral.
Please provide only the information requested. A complete developmental or medical history is not required at this stage. Please avoid identifying other children or providing unnecessary details about other people.
Enquiry and referral information is held in Carebit's lead and referral system. If the referral is accepted, a patient record is created and the original enquiry remains accessible through the system. More detailed information is then requested to prepare for the consultation.
Submitting an enquiry does not confirm acceptance as a patient. If essential information is missing, we may need clarification before making a decision.
Information collected for assessment and treatment
Where care proceeds, we collect information relevant to assessment, treatment and service administration.
This may include names, dates of birth, addresses and contact details; parental responsibility and relevant care arrangements; GP details; medical, psychiatric and developmental history; consultation and assessment information; school reports and teacher questionnaires; assessment results and rating scales; prescribing and medication records; relevant safeguarding information; correspondence; and payment and insurance details.
Where information comes from
We receive information from parents or carers and, where appropriate, directly from children and young people. We may also receive relevant information from referrers, GPs, schools, clinicians and other professionals involved in a child's care.
We seek appropriate permission when required. Information may also be obtained or shared without consent where another lawful justification applies, including where necessary to protect someone from harm.
Why we use information and our lawful bases
We use information to review enquiries and referrals, assess suitability for our remote service, provide assessment and treatment, prescribe and monitor medication, communicate with families and professionals, maintain appropriate records and administer our service.
We identify a lawful basis for each purpose. Health information requires an additional condition because it is particularly sensitive.
Referral screening, clinical care and service administration: Article 6(1)(f)
We rely on legitimate interests in reviewing referrals, providing and administering a safe clinical service, maintaining appropriate records and responding to concerns or complaints. We have assessed that this processing is necessary and balanced these interests against the rights and interests of the individuals concerned, giving particular consideration to children's privacy and welfare.
Parents' and carers' booking and payment arrangements: Article 6(1)(b)
We use a parent's or carer's own information to arrange services they have requested and administer associated payments. This does not provide the basis for processing the child's clinical information.
Legal obligations: Article 6(1)(c)
We use information where necessary to comply with legal obligations, including accounting, regulatory, record-keeping and disclosure requirements.
Health information: Article 9(2)(h)
We process health information where necessary for medical diagnosis, health care, treatment or the management of health care services, relying on Article 9(2)(h) and Schedule 1, Part 1, paragraph 2 of the Data Protection Act 2018. Information is processed by, or under the responsibility of, a health professional bound by a duty of confidentiality.
Safeguarding and legal claims
Where we need to share information to protect a child or another person from harm, we rely on Article 9(2)(g) and the safeguarding condition in Schedule 1, Part 2, paragraph 18 of the Data Protection Act 2018. Where information is needed to establish, exercise or defend legal claims, we rely on Article 9(2)(f).
Consent to clinical assessment or treatment is separate from the data protection grounds for processing necessary clinical information. Where a particular use of information relies on consent, we explain this and how consent can be withdrawn.
The systems we use
Our main clinical and referral management system is Carebit. It holds enquiry and referral information, patient records, forms, appointments and correspondence. Carebit is encrypted and operates under a Data Processing Agreement with us.
We also use Clynxx, via Carebit, for electronic prescriptions for non-controlled medicines; Healistic for controlled medication prescriptions; Signature Rx for electronic prescribing; Zoho Forms for registration forms and questionnaires; Proton Workspace Business for email and secure document storage; Zoom Business for video consultations; MHS, including Conners 4, and Qbtech, including QbCheck, for ADHD assessment tools; and Google Workspace for routing administrative email into the clinical record.
These systems operate under Data Processing Agreements or other appropriate contractual arrangements. Corresponding data protection obligations apply to authorised subprocessors. We limit the information processed through each system to what is needed for its purpose.
Where an organisation acts as an independent data controller, such as a pharmacy providing its own professional services, it has its own responsibilities for the information it processes.
Where information is processed
Our clinical records are held in Carebit's data centres in London. Some of our other service providers, including those we use for email, video consultations and assessment tools, store or process information outside the UK, for example in Switzerland, the European Economic Area or the United States.
Where information is transferred outside the UK, we make sure it is protected by UK adequacy regulations or by appropriate safeguards, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. You can contact us for more information about these safeguards.
How we keep information safe
Access to enquiry information and patient records is restricted to authorised clinicians and staff according to their responsibilities and is protected by two-factor authentication.
Our devices are encrypted and protected by endpoint security software. Video consultations use waiting rooms and unique session links. We do not store patient information on USB drives, personal cloud accounts or unencrypted devices.
Everyone who works with us is bound by confidentiality. We hold NHS Data Security and Protection Toolkit (DSPT) "Standards Met" status (2025-26).
Who we share information with
Information is confidential and is shared only where necessary, lawful and appropriate.
We share relevant information with your child's GP, including notifying them when we prescribe medication. We may also share information with associate clinicians contributing to assessment or treatment and with pharmacies dispensing prescriptions.
We communicate with schools and other professionals with appropriate permission, unless another lawful justification applies.
Where care is funded through insurance, we share information with the insurer that is necessary to administer authorised care and claims.
We may disclose information where necessary to protect a child or another person from harm, comply with a legal requirement or court order, respond to an authorised regulatory request, or obtain professional advice about a complaint or legal claim.
We explain relevant sharing arrangements and inform you about disclosures where appropriate. We may be unable to do so where notification would create a risk of harm or is legally restricted.
Children's and young people's confidentiality
Children and young people have their own rights concerning their information. We involve them in discussions about privacy in a way appropriate to their age and understanding.
Parents and carers do not automatically have access to all of a young person's confidential information. When considering access or disclosure, we take account of parental responsibility, the young person's understanding and wishes, their best interests and applicable legal requirements.
Please contact us if your child would like this notice explained in a more accessible form.
How long we keep information
We keep information for as long as necessary for its purpose, following the NHS Records Management Code of Practice, professional responsibilities and legal obligations.
Child and adolescent mental health records are normally kept for 20 years after last contact, or until the young person's 25th birthday (26th if they were 17 when treatment ended), whichever is later. Prescribing information is kept as part of this record.
Where a referral involves clinical review, advice, a suitability decision or safeguarding action, we keep the information needed to explain that decision as a clinical record, even if the child is not accepted for treatment. Routine enquiries that do not proceed and involve no clinical advice or safeguarding action are reviewed and deleted 12 months after closure, unless there is a reason to keep them longer, such as an outstanding complaint.
Safeguarding information is kept for at least as long as the clinical record, and longer where an investigation, inquiry or preservation requirement applies. Complaints records are kept for 10 years. Administrative and financial records are kept for six years after the end of the relevant financial year.
Records may be kept longer where necessary for a complaint, investigation or legal claim. Information is then securely deleted or anonymised.
Your rights
Depending on the circumstances and the lawful basis used, you may request access to personal information, correction of inaccuracies, erasure, restriction of processing or transfer of information in a portable format. You may also object to processing based on legitimate interests.
These rights are not absolute. For example, we may need to retain clinical information for a justified purpose even where deletion is requested. Where a clinical entry is disputed, it may be appropriate to add a correction or statement while preserving the original record.
Where processing relies on consent, you may withdraw that consent. This does not affect processing already lawfully undertaken.
Requests concerning a child's information are considered in light of the child's own rights and confidentiality.
To make a request, email info@childpsychiatry.uk. We may need to verify your identity and authority to act. We respond without undue delay and within one month. If a request is complex, we may extend this by up to two further months and will tell you why within the first month.
Data breaches
We assess and record personal data breaches and take steps to contain them and reduce the risk of harm.
Where a breach is reportable, we notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to an individual's rights and freedoms, we notify the affected person without undue delay, subject to applicable legal exceptions.
Questions and complaints
If you have questions or concerns about how we handle information, please contact our Data Protection Lead at info@childpsychiatry.uk.
You may also complain directly to the Information Commissioner's Office. You do not have to contact us first.
Website: https://ico.org.uk/ Telephone: 0303 123 1113
Updates to this notice
We review this notice when our services, systems or information-handling arrangements change.
Last updated: 2 October 2026 Version 4

