Javascript is required
logo-dastralogo-dastra

GDPR Data processing modelHealthcare Data Processing via Secure Messaging (UK NHS context)

HealthPublic
Processing of patients’ and healthcare professionals’ data through a secure NHS-compliant messaging system, enabling lawful, confidential exchange of health information between authorised professionals.

Purposes (2)

A purpose is the objective pursued by the setting up of your file. It indicates what the processing of personal data will be used for, its purpose. This purpose must be clear and understandable

1
Exchange of health data between authorised healthcare professionals via secure messaging
Public interest
- UK GDPR Art. 6(1)(e) – task carried out in the public interest / official authority.
2
Exchange of health data between authorised healthcare professionals via secure messaging
Other
UK GDPR Art. 9(2)(h) – processing necessary for medical diagnosis, provision of health or social care, or management of health systems.

Data categories (3)

Personal data is any information relating to an identified or identifiable natural person. A natural person can be identified either directly (eg surname and first name) or indirectly (eg phone number, social security number, email or postal address, but also voice or image)

Patient Data

Data details


health datarequiredsensitive data
NHS/NI numbersrequiredsensitive data
Emailrequired
phone numberrequired
Addressrequired
Genderrequired
Date and place of birthrequired
first and last namerequired

Data conservation rules

Active base:

Retained during professional activity and contract of care.

Intermediate archiving:

Mailboxes deleted after 1 year of inactivity. Technical traces (logs) retained for 1 year.

Destruction

System Administration Data

Data details


Natural person identifierrequired
Job function required
Name and surnamerequired

Data conservation rules

Active base:

Duration of administrative role.

Intermediate archiving:

Deleted after 1 year of inactivity.

Destruction

Healthcare Professional Data

Data details


Traces of actions on messagingrequired
Cookiesrequired
IP addressrequired
Secure health messaging addressrequired
professional titlerequired
Emailrequired
phone numberrequired
Data relating to means of authenticationrequired
Registration number for the shared directory of healthcare professionalsrequired
Name and surnamerequired

Data conservation rules

Active base:

For the duration of the professional’s registration and role.

Intermediate archiving:

Mailbox deleted after 1 year of inactivity; logs retained for 1 year.

Destruction

Data subject (3)

A data subject is any person whose data is collected, retained or processed by the data processing. e.g. In a recruitement process, any candidate for a position proposed in recruitement management process

  • Patients
  • Other
  • Healthcare Professionals

Created at:07/08/2023

Updated on:08/01/2025

License: © Creative commons :
Attribution / Pas d'utilisation commerciale
CC-BY-NC AttributionPas d'utilisation commerciale

Nb using:3


Access the full processing template

Try Dastra now to access all of our data processing templates that you can customize for your organization.It's free and there's no obligation for the first 30 days (no credit card required)

Add to my data processings record
Subscribe to our newsletter

We'll send you occasional emails to keep you informed about our latest news and updates to our solution

* You can unsubscribe at any time using the link provided in each newsletter.