1. Introduction
21D Dental Clinical FZ-LLC ("21D Clinical", "we", "us", or "our") is committed to protecting your privacy and handling your information lawfully, transparently and securely. This Privacy Policy ("Policy") explains how we collect, use, store and protect your information when you engage with us for clinical assessment, treatment or related services, who we share it with, how long we keep it for and what rights you have in relation to it.
This Policy applies to all patients and prospective patients of 21D Clinical who submit Patient Health Information to us in person or via our website www.21d.ae ("Website").
2. Who We Are
21D Clinical is a healthcare provider licensed by Dubai Healthcare City Authority ("DHCA") specialising in full jaw dental implant treatment. For the purposes of the Applicable Laws mentioned below, 21D Clinical decides how and why your information is collected and used and is the entity responsible to you and to the regulators for that information.
The privacy of your Patient Health Information is governed principally by the following laws and regulations, together "Applicable Law", and this Policy is written to comply with them:
(a) Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields, which applies throughout the United Arab Emirates including within free zones such as DHCC (the "Health Data Law");
(b) Cabinet Decision No. 32 of 2020 issuing the Implementing Regulation of the Health Data Law;
(c) Ministerial Decision No. 51 of 2021 on the Cases of Allowing the Storage and Transfer of Medical Data and Information Out of the State (the "Cross-Border Health Data Decision"); and
(d) DHCC Health Data Protection Regulation No. 7 of 2013 issued by DHCA (the "DHCC Health Data Regulation").
3. How We Classify Information and What We Collect
We classify the information we collect into the following categories:
(a) "Patient Health Information" means your medical and dental history, including but not limited to current medications and allergies, clinical notes and assessments, treatment plans and progress notes, clinical photographs and facial scans, intra-oral scans, radiographic imaging including X-rays and CBCT scans, laboratory and diagnostic reports, prosthetic and implant specifications, anaesthetic and surgical records, post-operative records and information relating to payment for your treatment including insurance details.
(b) "Patient Identification Information" means your name, date of birth, age, gender, nationality, residential address, email address, telephone number, Emirates Identity Number and passport or other identification details where required.
(c) "Other Personal Data" means information that identifies you or that can be used to identify you when combined with other information and which is neither Patient Health Information nor Patient Identification Information. This includes appointment records, correspondence with our team, enquiry form submissions, records of telephone and messaging contact, complaints and feedback, reviews you choose to provide and technical information collected through the Website.
4. How and From Whom We Collect Your Information
We collect Patient Health Information directly from you wherever possible in accordance with the Applicable Law requirements.
We may collect Patient Health Information about you from a source other than you only where that is permitted by Applicable Law, including where:
• you have authorised us to collect it from a referring clinician, a previous medical provider, a laboratory or another third party;
• you are unable to give that authorisation, and we collect the information from your legal representative or from a person authorised by your legal representative;
• collecting it from you would prejudice your interests, the purpose of collection or the safety of any person; or
• collecting it directly from you is not reasonably practicable in the circumstances.
We collect Patient Health Information when you complete a form on the Website, when you contact us by telephone, email or messaging service, during your consultation, clinical assessment and treatment, from referring clinicians and previous treating providers where you have authorised this, from laboratories and diagnostic providers involved in your care, from your health insurance provider where applicable and when you provide feedback or a review.
5. Why We Collect Your Information and Whether You Must Provide It
We collect your information for the following purposes:
• to assess your suitability for treatment and to plan, deliver and review that treatment;
• to design, manufacture and fit dental prostheses and implants specific to you;
• to maintain a complete and accurate clinical record as required by Applicable Law;
• to communicate with you about your appointments, treatment and aftercare;
• to administer payment, insurance claims and treatment financing;
• to comply with our obligations to DHCA and other competent authorities;
• to manage clinical governance, quality assurance, accreditation, risk management and patient safety;
• to investigate and respond to complaints and to defend claims; and
• where you have separately consented, for the purposes of sharing your information.
The information described in section 3(a) and (b) is mandatory. If you do not provide it, we will not be able to assess you, treat you or maintain the clinical record we are required by Applicable Law to maintain, and we may be unable to accept you as a patient.
The information described in section 3(c) is voluntary, save where it forms part of your clinical record. If you do not provide it, this will not affect your access to clinical care.
6. The Grounds on Which We Use and Disclose Your Information
We use your Patient Health Information only where we have reasonable grounds to believe that the use is permitted under Applicable Law, namely where the use is:
• authorised by you or by your legal representative;
• directly related to the purpose for which Patient Health Information was obtained;
• necessary to prevent or lessen a serious and imminent threat to public health or public safety or to your life or health or that of another person;
• for statistical purposes, provided the results are not published in a form that could reasonably be expected to identify you;
• for research purposes for which any required ethics committee approval has been obtained, provided the results are not published in a form that could reasonably be expected to identify you;• necessary to avoid prejudice to the maintenance of the law; or
• for the conduct of disciplinary or court proceedings that have been commenced or are reasonably in contemplation and limited to the purpose of those proceedings.
In accordance with the Health Data Law, we do not use Patient Health Information for any non-health purpose without your prior written approval, except in the limited cases the law permits.
We use Other Personal Data based on your consent, the performance of our agreement with you, our compliance with a legal obligation or our legitimate interests in operating and improving our services in accordance with Applicable Law.
7. DHCA Electronic Health Record
As a licensed healthcare operator within DHCA, we are required by the DHCC Health Data Regulation to develop information systems that integrate with the DHCC Electronic Health Record ("Electronic Health Record") and to submit Patient Health Information to it electronically on a regular basis.
Information from the Electronic Health Record may be extracted and held in the Healthcare Information Reporting and Analysis System ("HIRAS"), a central data repository maintained by the DHCC Centre for Healthcare Planning and Quality ("CPQ"). Under the DHCC Health Data Regulation, HIRAS information may be used for statistical analysis and reporting, quality and safety improvement, continuity of care between DHCC providers, analysis of healthcare utilisation within DHCC, providing patients with access to their own information and, subject to the requirements of the DHCC Academic and Research Council, research and education purposes.
We are notifying you of the Electronic Health Record in accordance with the DHCC Health Data Regulation. Submission of your information to the Electronic Health Record is a mandatory regulatory requirement we need to comply with.
8. Photographs, Imaging and CCTV
Clinical photographs, facial and intra-oral scans and radiographic imaging are Patient Health Information. They form part of your clinical record and are protected accordingly.
21D Clinical may use closed circuit television (CCTV) in the reception, corridors, entrances and other non-clinical common areas of our premises for the safety and security of patients, visitors and staff and for the protection of property. CCTV is not operated in treatment rooms, consultation rooms, changing areas or any other area in which you would reasonably expect privacy.
We do not audio record or video record your consultation or treatment unless you have given your prior written consent to that specific recording or unless the recording is a clinical imaging procedure forming part of your treatment.
9. Treatment Imagery and Marketing
We will not use your Patient Health Information, including any clinical photograph, scan or radiographic image, for any marketing, promotional or publicity purpose without your prior separate written consent.
Where we wish to use before and after imagery of your treatment outcome, including partial facial or smile imagery, on the Website, on social media or in other promotional material, we will ask you to sign a separate consent form. That form will identify the specific images and the media in which they may be used. It will confirm that you grant that permission without any entitlement to royalty, fee or other consideration and that you may withdraw the consent at any time by notice to us.
Where you withdraw consent, we will cease further use of the imagery and remove it from media under our control within a reasonable period. We may be unable to recall imagery already published by third parties or already distributed in printed material.
We send marketing communications only where you have consented to receive them and only using Other Personal Data. You may withdraw that consent at any time by using the unsubscribe function in the communication or by contacting our Data Protection Officer. We may continue to send you communications relating to your appointments, treatment and aftercare, which are not marketing communications.
We do not sell your information of any category to any person.
10. Data Protection Officer
In accordance with the DHCC Health Data Regulation, we have appointed a Data Protection Officer responsible for encouraging our compliance with that Regulation, dealing with requests made to us under it and otherwise ensuring our compliance with it.
Our Data Protection Officer is your point of contact for all matters relating to this Policy:
Name : Michelle Garbutt
Email : CASE@21d.co.uk
11. Use of Data for Technology, Analytics and Artificial Intelligence
We may use non-personally identifiable information to support research, the development, testing and improvement of our clinical systems and technologies related to tools that assist clinicians.Where we use information for these purposes:
• we do not use it to make automated decisions about your clinical care, and it does not replace clinical judgement;
• we do not use Patient Health Information for these purposes without your prior separate written consent and, where required, the approval of the competent authority; and
• your access to assessment, treatment and aftercare does not depend on your information being used for these purposes and is not affected if you decline.
Any use of information for these purposes that would involve storing, processing, generating or transferring health information outside the United Arab Emirates is subject to section 12 and is not undertaken unless the requirements of that section are satisfied.
12. Sharing and Cross-Border Transfer of Your Information
Your Patient Health Information is stored and processed within the United Arab Emirates.
The Health Data Law prohibits Patient Health Information and data relating to health services provided in the UAE from being stored, processed, generated or transferred outside the UAE, except in the cases specified in the Cross-Border Health Data Decision. We do not transfer your Patient Health Information outside the UAE unless one of those cases applies and the controls that the Cross-Border Health Data Decision imposes for that case are satisfied, including written approval from you where that is required, restriction of the transfer to the concerned entity and to the concerned health matter, encryption to the best available standards and retention of a copy within the UAE where required.
The cases in which a transfer may lawfully occur include:
• where you are receiving treatment outside the UAE;
• where samples are sent to a laboratory abroad;
• where you or your legal representative request in writing that your Patient Health Information be transferred abroad for your own use;
• where the transfer is required for approved scientific research using data from which you cannot be identified; and
• where the transfer is required in connection with remote medical services with your written consent.
Separately, the DHCC Health Data Regulation permits transfer of Patient Health Information to a third party located outside DHCA only where an adequate level of protection is ensured by the laws applicable to that third party and the transfer is either authorised by you or necessary for the ongoing provision of healthcare services to you.
13. How Long We Keep Your Information
We keep your Patient Health Information for not less than twenty-five (25) years from the date of the last health procedure provided to you, as required by the Health Data Law. Where the DHCC Health Data Regulation specifies a shorter minimum period, we apply the longer federal period.
You cannot require us to delete your Patient Health Information before the expiry of this period. This is a mandatory retention obligation imposed on us by Applicable Law and is not a matter on which we have discretion.Information that does not form part of your clinical record is kept only for as long as it is needed for the purpose for which it was collected and is then securely deleted or irreversibly anonymised.
Imagery used under section 9 is retained only for the duration of your consent and is deleted from media under our control following withdrawal of that consent, save where the imagery also forms part of your clinical record, in which case the retention period in this section 13 applies to the clinical copy.
14. Your Rights
You have the right to obtain confirmation of whether we hold Patient Health Information about you and to have access to that information on reasonable notice, under Applicable Law.
You have the right to request correction of your Patient Health Information.
A Patient Data Request must be made in writing to our Data Protection Officer. You may make a Patient Data Request yourself or through your legal representative. Where your representative makes the request, we require written authority from you or another proper authorisation.
We do not charge you for making a Patient Data Request, for the assistance we give you in making it, for processing it or for making information available to you in response to it. We may charge a fee only for the provision of actual photographs, X-ray films, scans, recordings and other imaging and for a repeat request relating to Patient Health Information already provided, in each case at the rate prescribed by DHCA from time to time.
Before giving you access we will satisfy ourselves as to your identity or that of your representative and we will take steps to ensure that the Patient Health Information reaches only you or your authorised representative.
In relation to Other Personal Data, you have rights to access, correction, restriction, objection, erasure where legally applicable, portability and withdrawal of consent and the right to object to direct marketing.
15. Data Security and Breach Notification
We use appropriate technical and organisational measures to protect your data, including secure systems and encryption, access controls, staff training and regular review of our data protection practices.
Where a security incident affects the confidentiality, integrity or availability of your information, we investigate it, take steps to contain and remedy it and disclose it to the DHCC Customer Protection Unit in accordance with the DHCC Health Data Regulation and to any other competent authority to which we are required to report.
Where an incident is likely to result in a significant risk to you, we will inform you and tell you what has happened, what information was affected and what steps you may wish to take.
If you believe your information held by us has been lost, accessed without authorisation or otherwise compromised, please notify our Data Protection Officer immediately.
A Leading Full Jaw Dental Implant Provider, now in the UK & UAE.