Keep your own dated notes of what happened, who was involved and what you reported, without patient names or other identifiers. Leave patient records and confidential documents on work systems and point to them by date or incident number. Taking personal data without your employer's consent can be a criminal offence under section 170 of the Data Protection Act 2018.
Key facts
- Health data
- Special category data under UK GDPR, with extra protection
- Data minimisation
- Personal data must be adequate, relevant and limited to what is necessary
- Criminal offence
- Knowingly or recklessly obtaining, disclosing or keeping personal data without the controller's consent (section 170, Data Protection Act 2018), subject to defences
- Professional duty
- GPhC, GMC and NMC standards all require you to protect patient confidentiality
- Your own data
- You can ask your employer for copies through a subject access request
What to keep
- Your own notes, written as soon as possible after each event, with the date and time you wrote them.
- The date, place and people present, described by role where names are not needed.
- What you reported, to whom, when and how, plus any reference or acknowledgement you received.
- Letters and emails sent to you about your own employment, such as a grievance outcome or a rota change.
- Changes in how you were treated after you raised the concern. Our guide to treatment after speaking up explains why these matter.
Keep facts you saw apart from things you were told and things you believe. A line such as "Saw controlled drug register unsigned for three entries on 4 October" is more useful than "the register is always a mess".
What to leave on work systems
- Patient records, clinical notes, prescriptions and dispensing records
- Screenshots or photos of clinical systems or patient-facing screens
- Bulk exports, spreadsheets, rotas with personal details or incident databases
- Email threads containing patient information, forwarded to a personal account
- Commercially confidential files, such as contracts with suppliers
Refer to these records instead by date, location and the system where they sit, for example "dispensing log, Branch 2, 4 October". An adviser, investigator or regulator can then ask for the records through proper channels. If you think evidence may be deleted, tell an adviser such as Protect before you act.
Why the law matters here
Health information is special category data under UK GDPR, and the data protection principles require personal data to be kept secure and limited to what is necessary. Section 170 of the Data Protection Act 2018 makes knowingly or recklessly obtaining, disclosing or keeping personal data without the controller's consent an offence. Defences exist, including where the conduct was justified in the public interest, but you would carry the burden of proving the defence. Do not rely on a defence as a plan.
Your regulator expects the same care. The GPhC's guidance on confidentiality, updated in November 2025, the GMC's guidance on confidentiality and the NMC Code all require you to protect patient information. A whistleblowing concern does not remove these duties. Our page on patient confidentiality when speaking up covers how to raise a concern lawfully.
Getting a record onto the employer's system
The safest evidence of a concern often sits with your employer. File an incident report through the official system and note the reference number. Raise the concern in writing, by email to a manager or a Freedom to Speak Up guardian in England, and keep the email in your work account. Later, a subject access request lets you obtain copies of personal data about you, including emails about your concern.
A simple note template
Use one page per event:
- Date and time of the event, and date and time you wrote the note
- Place, described generally
- What you saw or heard yourself
- What others told you, and who told you
- Who you reported the matter to, when and how
- Any reference number
- Your assessment, labelled as your opinion
Store notes somewhere private which you control, and do not include patient names, dates of birth, NHS numbers or addresses. Bring the notes to your adviser. Read how to prepare for employment or whistleblowing advice and how to choose where to raise a concern.
Limiting the toll of record keeping
Going back over messages every evening can keep stress high. Set a fixed time, such as 20 minutes twice a week, to update your notes, then stop. Get support for the effect on you from a GP or NHS Practitioner Health, separate from the evidence question.
Common questions
Can I forward work emails to my personal email as evidence?
Not if the emails contain patient information or confidential business data. Doing so can breach UK GDPR, your contract and your professional duties. Keep a dated note of the email instead and ask an adviser about getting copies through proper channels.
Can I take photos of patient records to prove a concern?
No. Photos of patient records are patient-identifiable data. Describe the record by date and system and let an investigator or regulator request the record.
Is taking patient data illegal when whistleblowing?
Taking personal data without the controller's consent can be a criminal offence under section 170 of the Data Protection Act 2018. A public interest defence exists, but you would need to prove the defence, so get advice first.
How do I get copies of emails about my concern?
Make a subject access request to your employer for personal data about you. Organisations usually have one month to respond.
