All policies

Data Protection Impact Assessment (Summary)

How Consenta identifies and mitigates privacy risks in its processing.

Last updated: 1 July 2026

1. Purpose of this assessment

A Data Protection Impact Assessment (DPIA) is carried out because Consenta processes health data — a special category under UK GDPR — at scale. This summary describes the processing, the risks identified and the measures in place to reduce them. The full DPIA is maintained internally and reviewed regularly.

2. Nature of the processing

  • Raw clinical data is processed only inside the providing organisation’s own environment (the Edge Node). It never moves onto the Consenta platform.
  • The Edge Node matches patient consent, removes direct identifiers, generalises quasi-identifiers and computes a re-identification risk score.
  • Only anonymised snapshots and non-identifying integrity proofs are published to Consenta and made available to approved buyers.

3. Key risks and mitigations

  • Re-identification risk — mitigated by k-anonymity and l-diversity guarantees, generalisation, suppression, an acceptable-risk threshold and a mandatory review/quarantine stage before any dataset is approved.
  • Processing without a lawful basis — mitigated by explicit, granular, withdrawable patient consent recorded per cohort and purpose.
  • Unauthorised access — mitigated by role-based access control, encrypted storage, sign-in rate limiting, account lockout and a full audit trail.
  • Loss of individual rights — mitigated by self-service data export (right of access) and erasure (right to be forgotten) for patients.
Residual risk is assessed as low once a dataset is approved, because approved data no longer contains information that can reasonably identify an individual.

4. Review

This DPIA is reviewed whenever there is a material change to the processing, and at least annually. Questions can be directed to our data protection contact at [email protected].