Healthcare providers using Google Calendar for appointment scheduling accumulate historical booking data that, over time, creates both practical and regulatory challenges. This guide explains how to approach historical data removal in a compliant and efficient way.
In many practices, Google Calendar entries include the patient's name in the event title or description. This constitutes personal data under UK GDPR and should be managed in line with your data retention policy.
The NHS Records Management Code of Practice 2021 sets retention periods for clinical records. However, Google Calendar scheduling entries are generally considered operational scheduling data rather than clinical records — the primary clinical record is held in your clinical system (EMIS, SystmOne, Vision, etc.).
Your Information Governance lead should confirm the appropriate retention period for scheduling calendar data specifically. Many practices apply a 12-month rolling retention for scheduling data, clearing entries older than one year on a regular basis.
WipeAway removes all calendar events before a date you specify. For a 12-month rolling retention policy, set the cut-off to 12 months ago and run the process quarterly or annually.
Document the process. Keep a record of when historical appointment data was cleared, who authorised it, and what date range was removed. This demonstrates active compliance with your data retention policy and supports any future ICO audit or subject access request.
If your practice is not already registered with the ICO as a data controller (required for most healthcare organisations processing personal data), this is a separate compliance step. Clearing historical calendar data is a good moment to review your overall data protection compliance posture.