Data protection

UK GDPR and the Data Protection Act 2018.

Halo processes personal data — including special-category health data — on behalf of care providers, NHS trusts, ICSs, and home-care services. Every UK GDPR obligation is engineered into the platform, not bolted on. Here’s exactly how.

UK GDPR / Data Protection Act 2018 compliance badge

Our position, in detail

Roles: who’s controller, who’s processor

For most deployments, the care provider is the data controller and Halo (DXN Design Ltd) is the data processor. A signed Data Processing Agreement in the shape of Article 28 sits with every customer. Where Halo operates its own monitoring service, we’re a joint controller for that specific processing — declared separately in the DPA.

Lawful basis

Health data processing under Article 9(2)(h) — provision of health or social care — supplemented by explicit consent for family-view sharing and any secondary use. Legitimate interest is only relied on for security and fraud-prevention logs. Every processing activity is recorded in our Record of Processing Activities (Article 30).

DPIA process

A Data Protection Impact Assessment is drafted for every new feature that changes what personal data is processed, how, or with whom. Living document in the platform; latest snapshot available on request. High-risk residual findings are reviewed with the DPO before ship.

Data subject requests

Access, rectification, erasure, portability, and restriction requests are handled through a single admin surface in Halo. Access requests generate a machine-readable export in under 30 days. Erasure is honoured with tombstone records to preserve audit integrity per regulatory obligation.

Cross-border transfers

Live systems are UK-hosted (AWS eu-west-2, London). No routine transfer to third countries. Sub-processors are UK or EEA where possible; where not, Standard Contractual Clauses (2021/914) plus a transfer risk assessment apply.

Retention

Retention schedule per data class: real-time telemetry — 90 days hot, 7 years cold in Object Lock; care notes — 8 years per NHS record retention; audit logs — 8 years, immutable; anonymised aggregates — indefinite.

Breach notification

Confirmed breach = notification to the customer’s DPO within 24 hours of confirmation. Notification to ICO within 72 hours where required. Notification to affected data subjects when likely to result in high risk. IR playbook exercised quarterly.

Documents & evidence available under NDA

  • Statement of Applicability / Record of Processing / policy documents (as applicable to this framework)
  • Sub-processor register
  • Data Processing Agreement template
  • Incident response runbook (redacted)
  • Independent penetration test summary
  • Latest internal audit findings (redacted)

Need this evidence for procurement?

Send us an NDA and we’ll return the full evidence pack for UK GDPR / Data Protection Act 2018 within 3 working days.