Data Protection Impact Assessment (Summary)
How Consenta identifies and mitigates privacy risks in its processing.
Last updated: 1 July 2026
1. Purpose of this assessment
A Data Protection Impact Assessment (DPIA) is carried out because Consenta processes health data — a special category under UK GDPR — at scale. This summary describes the processing, the risks identified and the measures in place to reduce them. The full DPIA is maintained internally and reviewed regularly.
2. Nature of the processing
- Raw clinical data is processed only inside the providing organisation’s own environment (the Edge Node). It never moves onto the Consenta platform.
- The Edge Node matches patient consent, removes direct identifiers, generalises quasi-identifiers and computes a re-identification risk score.
- Only anonymised snapshots and non-identifying integrity proofs are published to Consenta and made available to approved buyers.
3. Key risks and mitigations
- Re-identification risk — mitigated by k-anonymity and l-diversity guarantees, generalisation, suppression, an acceptable-risk threshold and a mandatory review/quarantine stage before any dataset is approved.
- Processing without a lawful basis — mitigated by explicit, granular, withdrawable patient consent recorded per cohort and purpose.
- Unauthorised access — mitigated by role-based access control, encrypted storage, sign-in rate limiting, account lockout and a full audit trail.
- Loss of individual rights — mitigated by self-service data export (right of access) and erasure (right to be forgotten) for patients.
Residual risk is assessed as low once a dataset is approved, because approved data no longer contains information that can reasonably identify an individual.
4. Review
This DPIA is reviewed whenever there is a material change to the processing, and at least annually. Questions can be directed to our data protection contact at [email protected].