Data Protection Statement
Our obligations under UK GDPR and how claimant data is handled throughout the medico-legal process.
Data controller details
Data controller: 23 Health Care Ltd, ICO registration ZC007435. Responsible clinician: Dr Syed Hassan, GMC 7554136.
Contact: admin@drsyedhassanreports.co.uk
Data we process
We process personal data — including special category health data — solely for the purpose of preparing independent medico-legal reports by direct instruction from solicitors. This includes claimant identity, medical history, examination findings and clinical opinion.
Lawful basis
Processing is carried out under Article 6(1)(e) UK GDPR (public task) and Article 9(2)(g) UK GDPR (substantial public interest — administration of justice). All processing is conducted in accordance with the Data Protection Act 2018.
Data security
All claimant data is stored securely and accessed only by authorised individuals involved in preparing the report. Data is transmitted to instructing solicitors via secure means only. We do not store unnecessary personal data and do not transfer data outside the UK.
Retention & deletion
Medico-legal files are retained for a minimum of eight years from the date of the report. Files are reviewed at the end of the retention period and securely destroyed if no longer required.
Your rights
Under UK GDPR you have the right to: access your data, correct inaccuracies, request erasure (subject to legal retention obligations), restrict processing, and lodge a complaint with the ICO at ico.org.uk.
Subject access requests
To make a subject access request or exercise any data rights, contact us at admin@drsyedhassanreports.co.uk. We will respond within one calendar month as required by UK GDPR.
Last updated: June 2026 · ICO ZC007435 · Privacy Notice · Complaints Policy