Built for GDPR, HIPAA & Cyber Essentials
Consenta keeps raw patient data inside the client boundary and publishes only anonymised, risk-assessed data with verifiable, tamper-evident proofs.
GDPR
EU / UK GDPR
- ✓Lawful basis: explicit, granular, revocable patient consent captured per cohort and purpose.
- ✓Data minimisation: only anonymised, risk-assessed data leaves the client boundary.
- ✓Right to erasure: consent withdrawal removes the subject from the lake and all future snapshots.
- ✓Records of processing, audit trails and Data Processing Agreement support.
HIPAA
US Health Data
- ✓Safe Harbor de-identification: 18 identifiers suppressed or generalised at the edge.
- ✓No PHI reaches the platform — raw data is processed only inside the client environment.
- ✓Access controls, audit controls, integrity and transmission security safeguards.
- ✓Business Associate Agreement (BAA) ready operating model.
Cyber Essentials
UK NCSC
- ✓Boundary firewalls and secure configuration by default.
- ✓Least-privilege access control with multi-factor authentication.
- ✓Patch and vulnerability management across the platform.
- ✓Malware protection and continuous monitoring of privileged access.
Core security controls
Data stays at the edge
The Edge Anonymisation Engine runs inside the client’s on-premises, private cloud or VPC. Only anonymised snapshots and non-identifying proofs are published outbound.
Encryption everywhere
Encryption in transit (TLS 1.2+) and at rest, with customer-managed keys available where required.
Zero-trust access
MFA, least-privilege roles, privileged-access approval and full session logging.
Immutable audit
Every consent, certificate and sale event is recorded with a tamper-evident SHA-256 proof — anchored on Polygon or stored securely off-chain.
Revocation by design
Withdrawing consent deactivates the subject’s data lake objects and excludes them from every future dataset and sale.
Tenant isolation
A separate tenant boundary and encryption context for every client organisation.
Information governance templates
Draft governance artefacts are available in the platform documentation library for signed-in administrators. They are provided as starting-point templates and must be reviewed by your DPO / legal counsel before use.
DPIA Template
Data Protection Impact Assessment for Consenta processing activities (UK GDPR Art. 35).
DPA Template
Data Processing Agreement between Consenta and its data-controller clients.
DSPT Alignment
How Consenta maps to the NHS 10 data-security standards.
ROPA Template
Records of Processing Activities template (UK GDPR Art. 30).
Detailed user guides are available inside each portal after you sign in — patients, organisations, buyers and administrators each have guidance tailored to their role.