Data Processing Agreement (Overview)
The terms that govern how Consenta processes data on behalf of partner organisations.
Last updated: 1 July 2026
1. Roles of the parties
For raw clinical data, the providing organisation (for example an NHS Trust) is the data controller and Consenta acts only in relation to anonymised outputs. Because anonymisation happens inside the organisation’s own environment, Consenta does not receive identifiable personal data.
This overview summarises the Data Processing Agreement (DPA) entered into with each partner organisation. The signed DPA takes precedence.
2. Consenta’s obligations
- Process data only on documented instructions from the controller.
- Ensure personnel are bound by confidentiality.
- Apply appropriate technical and organisational security measures.
- Not engage another processor without authorisation, and flow down equivalent obligations where one is used.
- Assist the controller with data-subject requests, breach notification and impact assessments.
- Delete or return data at the end of the engagement, subject to legal retention requirements.
3. Security measures
- Encryption of data in transit and at rest.
- Role-based access control and least-privilege access.
- Audit logging of sensitive actions.
- Anonymisation performed at source before any outbound transfer.
4. Sub-processing and transfers
Any sub-processors are subject to the same data-protection obligations. International transfers, where they occur, rely on an appropriate safeguard under UK GDPR. A current list of sub-processors is available on request from [email protected].