GDPR Data processing modelHealthcare Data Processing via Secure Messaging (UK NHS context)
Purposes (2)
A purpose is the objective pursued by the setting up of your file. It indicates what the processing of personal data will be used for, its purpose. This purpose must be clear and understandable
Data categories (3)
Personal data is any information relating to an identified or identifiable natural person. A natural person can be identified either directly (eg surname and first name) or indirectly (eg phone number, social security number, email or postal address, but also voice or image)
Patient Data
Data details
Data conservation rules
Active base:
Retained during professional activity and contract of care.
Intermediate archiving:
Mailboxes deleted after 1 year of inactivity. Technical traces (logs) retained for 1 year.
Destruction
System Administration Data
Data details
Data conservation rules
Active base:
Duration of administrative role.
Intermediate archiving:
Deleted after 1 year of inactivity.
Destruction
Healthcare Professional Data
Data details
Data conservation rules
Active base:
For the duration of the professional’s registration and role.
Intermediate archiving:
Mailbox deleted after 1 year of inactivity; logs retained for 1 year.
Destruction
Data subject (3)
A data subject is any person whose data is collected, retained or processed by the data processing. e.g. In a recruitement process, any candidate for a position proposed in recruitement management process
- Patients
- Other
- Healthcare Professionals
Attribution / Pas d'utilisation commerciale
CC-BY-NC

