What is a DPIA?
A Data Protection Impact Assessment (DPIA) is a process designed to help you systematically analyse, identify and minimise the data protection risks of a project or plan. It is a key part of your accountability obligations under the UK GDPR, and when done properly helps you assess and demonstrate how you comply with all of your data protection obligations.
It does not have to eradicate all risks but should help you minimise and determine whether or not the level of risk is acceptable in the circumstances, taking into account the benefits of what you want to achieve.
What do practices need to do about it?
π‘ As a practice you will need to review the DPIA and keep a record of it - It doesn't need to be sent to anyone!
As the data controller when using Accurx, it is your responsibility to complete a DPIA.
As a data processor, we cannot complete it for you. However, to be as helpful as we can, we have filled in the key parts of DPIA Templates for:
A breakdown of the Accurx Paid features DPIA:
Patient Triage
Patient Responses
SMS Plus
Florey Plus
Appointment Reminders
Batch Messaging
More information on IG and Security
Extra Resources
How to delete a photo from Accurx - permanent deletion of audit trail
How does Accurx Desktop check for consent within the patient record
If there's anything else we can help with that's not covered above, you can chat to us using the little green speech bubble in the bottom right hand corner of the website π