GDC Record-Keeping and Clinical Photography Consent: A UK Dentist Guide
What the GDC standards and UK GDPR require for clinical records and patient photographs — consent, retention, and secure storage explained.
By DentalCloud
GDC Record-Keeping and Clinical Photography Consent: A UK Dentist Guide
Clinical photographs are among the most useful records a dentist can keep — and among the easiest to handle unlawfully. If you work across multiple practices as a locum, the responsibility follows you. Here is what UK standards actually require.
The GDC expectation
GDC Standards require you to make and keep complete, accurate, contemporaneous records. Photographs, where taken, form part of the clinical record. That means they must be attributable to the right patient, dated, and retained and disposed of appropriately — not left floating in a personal camera roll.
Consent is not optional
Under UK GDPR and the Data Protection Act 2018, clinical images of an identifiable patient are personal data, and intra-oral and facial images are special category health data. You need a lawful basis to process them, and for uses beyond direct care — a portfolio, teaching, marketing — you need explicit, specific, informed consent, recorded and revocable.
Practical minimum:
- Explain what the image is for, where it will be stored, and how long you will keep it.
- Record consent explicitly, with the date, alongside the image.
- Make it easy to withdraw consent and to honour that withdrawal.
Retention and security
Records must be kept securely, for the appropriate retention period, and be accessible if a patient exercises their data subject rights (access, rectification, erasure, portability). Storing patient photos in a consumer cloud gallery or WhatsApp fails on security, retention control, and auditability.
The locum problem
If you cover ten practices a year, whose records are your photos? The practice owns the patient record for care delivered there — but your professional obligation to document your own work, and your need for a defensible personal case library, does not disappear when you leave. The safe pattern is a system that keeps images encrypted, consent-tracked, and UK-hosted, with a clear audit trail of what was captured, when, and with what permission.
How DentalCloud handles it
DentalCloud is built around this: guided capture, structured consent recorded against every case, an audit trail, and encrypted storage. It is designed so a dentist — including a locum moving between practices — can keep a compliant, portable record of their clinical work without improvising with tools that were never built for health data.
This is general guidance, not legal advice. For your specific obligations, consult the current GDC standards, ICO guidance, and your indemnity provider.