Data Protection Impact Assessment (DPIA)
Service: Datim-QI · Data controller: Datim-QI Ltd · Version 2.0 · Assessment date: 30 July 2026
1. Introduction
This DPIA assesses the data protection implications of Datim-QI, a benchmarking and quality-improvement tool for NHS general practice built on published, aggregate NHS data. The service is designed not to process patient data, clinical records, or any special-category personal data.
2. Scope
This assessment covers:
- Account data provided by practice staff who register (see the Privacy Policy §2)
- Aggregate, practice-level NHS benchmark data used to generate AI quality-improvement plans
- Processing by third-party providers (Supabase, a third-party AI model provider, Cloudflare)
- Data security, storage and retention
This DPIA does not cover clinical, safeguarding or HR data, as the service is not designed to process these and users are instructed never to enter them.
3. Nature of processing
Data processed:
- Account holder’s email, name and professional role
- Practice, PCN and ICB affiliation (public NHS organisation codes)
- Aggregate practice-level QOF, prescribing and clinical-audit rates (never individual patient records)
- AI-generated quality-improvement plan text, saved to the account
- Technical data: IP address, browser/device information, authentication session cookies
Data not processed: patient names, NHS numbers, dates of birth, clinical records, or any other patient-identifiable or Article 9 special-category data. Users are instructed not to enter this anywhere in the service.
4. Purpose
To operate practice accounts, generate benchmark comparisons and AI-drafted quality-improvement suggestions, and maintain the security and reliability of the service.
5. Third-party processors
- Supabase — account authentication and database hosting
- A third-party AI model provider — quality-improvement plan generation, receives aggregate practice-level benchmark data only (the specific provider may change from time to time; the same data-minimisation constraint always applies)
- Cloudflare — application hosting
6. Legal basis and necessity
Processing is necessary to perform the contract with each registered user (Article 6(1)(b) UK GDPR). Only the data needed to provide the account and benchmarking features is collected; no profiling or automated decision-making with legal effect is carried out.
7. Risk assessment
| Risk | Mitigation |
|---|---|
| A user enters patient-identifiable data despite instructions not to | Product has no free-text patient input field; account fields only collect professional/organisational data; Disclaimer and Terms explicitly prohibit patient data entry |
| AI-generated plan is treated as clinical advice rather than a starting point for review | Disclaimer and in-product framing require clinician review before any patient-facing action |
| Unauthorised access to another practice’s data | Row-level security in the database scopes each account to its own practice; explicit “viewing another practice” mode is logged and time-limited |
| Third-party processor breach or outage | Use of established, GDPR-compliant processors only; no long-term storage of sensitive data by any processor |
Residual risk is assessed as low, given no patient-identifiable data is processed by design.
8. Consultation
This DPIA reflects an internal self-assessment by the data controller. No formal external legal or GDPR advisory review has been carried out yet; this is recommended before the service is used beyond an initial pilot group of practices.
9. Accountability and open action items
The following are open items the controller is actively working through, listed transparently rather than presented as complete:
- ICO data protection fee registration — complete; registration reference number to be added here once to hand
- Formal legal review of this DPIA and the accompanying policies by a qualified solicitor
- Self-service account deletion (currently handled manually on request — see Privacy Policy §8)
- Confirmation of the hosting region for the underlying database
10. Review
This DPIA will be reviewed at least annually, and whenever a material change is made to what data the service collects or which third-party processors it uses.
11. Contact
Datim-QI Ltd
Email: gp.drgillespie@gmail.com
Datim-QI Ltd is a company registered in England and Wales, company number 17370894. Registered office: 82a James Carter Road, Mildenhall, IP28 7DE, United Kingdom.