Book a Free 30-Minute Demo
How long should I keep a patient record? What the Medical Council, HSE, and GDPR each say — and which one wins when they disagree

Article - 4 min read

How long should I keep a patient record? What the Medical Council, HSE, and GDPR each say — and which one wins when they disagree

Record retention for Irish consultants: Medical Council, HSE, and GDPR explained

Author

Admin

May 10, 2026

Every consultant in private practice in Ireland has had this question at some point, usually when a secretary clears out an old filing cabinet or when an indemnity form asks about retention policy.

The honest answer is that three different frameworks govern it, and they look like they're in conflict. The Medical Council talks about clinical relevance. The HSE publishes a detailed schedule of retention periods. GDPR talks about not keeping data longer than necessary.

Read each one in isolation and you can convince yourself of three different answers. Put them together and the actual answer becomes clear — but only once you understand that they sit in a hierarchy, not in conflict.

Here is what each one actually says, and what it means if you are running your own practice.

What the Medical Council says
The Medical Council's Guide to Professional Conduct and Ethics is the document most consultants know best, because they have to. But on records, it is deliberately non-prescriptive.

Section 39.1 says retention should take account of medical professional requirements to retain records — to support continuity of care, transfer of care and potentially for medico-legal purposes — alongside data protection principles. 


Section 39.2 is the operative sentence. You must keep medical records for as long as required by law or for as long as they remain clinically relevant. 

That is it. No specific number of years. The Council deliberately defers downstream — to whatever the law says, and to your own clinical judgment about relevance. They are not setting the retention period. They are telling you the retention period is set elsewhere.

What the HSE says
The HSE's National Records Retention Policy provides the schedule the Medical Council points to. It took effect on 1 December 2025, replacing the older NHO Code of Practice that had been in place since 2007.

The standard periods are:

Adult healthcare records: eight years after the last contact 
Children and young persons: until the patient's 25th birthday, or 26th if the patient was 17 at the conclusion of treatment 
Deceased patients: eight years after the date of death, or ten years in the case of suicide 
Maternity records, mental health records, and clinical trial records each carry separate, longer schedules

The HSE policy is, strictly, the HSE's own policy. It binds HSE-employed staff, public hospitals, and HSE-funded services. It does not formally bind a private consultant operating their own practice.

But it is the de facto Irish standard. The State Claims Agency works to it. Medical indemnity bodies reference it. The Data Protection Commission cites it when adjudicating erasure complaints. If you are in private practice and you retain to a shorter schedule, you should be ready to explain why. 

What GDPR says
GDPR is the framework people most often misunderstand on records.

Article 5(1)(e) — the storage limitation principle — says personal data must not be kept in identifiable form for longer than is necessary. This is the line that makes consultants nervous about over-retention.

Article 9 prohibits processing of health data, then immediately carves out Article 9(2)(h), which permits processing for the purposes of preventive or occupational medicine and medical diagnosis.

Article 17 gives patients the right to erasure — the "right to be forgotten." But Article 17(3) sets out the exceptions, and three of them apply directly to medical records:

Compliance with a legal obligation
Reasons of public interest in the area of public health, in accordance with Article 9(2)(h) and (i)
The establishment, exercise or defence of legal claims

Section 60(7) of the Irish Data Protection Act 2018 provides the domestic underpinning for these restrictions. 

The Data Protection Commission has published its own case studies confirming that refusing to erase clinical records on these grounds is consistent with Article 17(3)(c) of GDPR. The right to erasure does not apply to a properly retained clinical record. 

GDPR is not telling you to delete records early. It is telling you to have a reason for the period you have chosen. The reasons are already supplied by clinical relevance, statutory retention guidance, and the need to defend potential claims.

Where they appear to conflict — and why they don't

Read in isolation, the storage limitation principle of GDPR looks like it pushes against the longer retention periods in the HSE schedule. The Medical Council looks like it sidesteps both by deferring to "the law" without saying which one.

In practice, the three sit in a hierarchy.

GDPR sets the principle: do not retain longer than necessary, and have a justification for the period you have chosen.
The Medical Council and the Data Protection Act tell you what "necessary" means in clinical practice. It means as long as required by law, plus as long as clinically relevant, plus long enough to defend a legal claim.

The HSE schedule provides the concrete numbers that satisfy these tests for most record types.

The Statute of Limitations is the load-bearing wall underneath all of this. Medical negligence claims in Ireland must be issued within two years less one day from the date of knowledge — which can be many years after the index event. For a minor, the clock does not start until the eighteenth birthday, giving them until age 20 to issue. For a person under a legal disability, it may never start. 

This is why the HSE retention periods are calibrated as long as they are. The eight-year adult retention is not arbitrary. It is the practical floor that allows a consultant to respond to a claim issued years after the index treatment.

Which one wins

When the frameworks appear to conflict, the longest applicable retention period almost always wins — and it wins for a reason GDPR itself recognises.

Article 17(3)(e) — retention for the defence of legal claims — is the part of GDPR that does the real work in medical records. It is also the answer to almost every "why are we still holding this" question.

For a consultant in private practice, the practical position is this. Retain to the HSE schedule unless you have a documented clinical reason to retain longer. Never destroy a record while a claim window is still open. When in doubt on a paediatric record, the answer is almost always "longer than you think."

What this means for the consultant in private practice

In private practice, you are the data controller. The hospital is not. The HSE is not. Your practice management software provider is not. You are.

This is not a theoretical point. It changes who answers the subject access request. It changes who responds to an erasure request. It changes who is liable for a breach. It changes who is left holding the records when the practice closes or the consultant retires.

A surprising number of consultants run their record retention on the assumption that "the system will keep it." It usually will — until it doesn't, and you find out your software has a 90-day data clause you didn't read.

The retention rules are not the hard part. The hard part is knowing where your records actually live, who controls the schedule of deletion, and what happens to them when something changes.

If you cannot answer those three questions for your own practice in two minutes, the actual retention rules are not your biggest problem.

Share Article:

Conor Shields is a practising Consultant Surgeon, former Chief Clinical Information Officer, and founder of Enquiry Medical — the practice management platform he built because the existing tools weren’t good enough.

Prof Conor Shields

Take Your Practice To A New Level

Try Enquiry Practice Management System Today

Book a Free 30-Minute Demo

30-Day Trial - No Credit Card Required