DDatim-QI← Back to site
OverviewDisclaimerTerms of UsePrivacy PolicyCookie PolicyAccessibility StatementData Protection Impact Assessment (DPIA)

Data Protection Impact Assessment (DPIA)

Service: Datim-QI · Data controller: Datim-QI Ltd · Version 2.0 · Assessment date: 30 July 2026

1. Introduction

This DPIA assesses the data protection implications of Datim-QI, a benchmarking and quality-improvement tool for NHS general practice built on published, aggregate NHS data. The service is designed not to process patient data, clinical records, or any special-category personal data.

2. Scope

This assessment covers:

  • Account data provided by practice staff who register (see the Privacy Policy §2)
  • Aggregate, practice-level NHS benchmark data used to generate AI quality-improvement plans
  • Processing by third-party providers (Supabase, a third-party AI model provider, Cloudflare)
  • Data security, storage and retention

This DPIA does not cover clinical, safeguarding or HR data, as the service is not designed to process these and users are instructed never to enter them.

3. Nature of processing

Data processed:

  • Account holder’s email, name and professional role
  • Practice, PCN and ICB affiliation (public NHS organisation codes)
  • Aggregate practice-level QOF, prescribing and clinical-audit rates (never individual patient records)
  • AI-generated quality-improvement plan text, saved to the account
  • Technical data: IP address, browser/device information, authentication session cookies

Data not processed: patient names, NHS numbers, dates of birth, clinical records, or any other patient-identifiable or Article 9 special-category data. Users are instructed not to enter this anywhere in the service.

4. Purpose

To operate practice accounts, generate benchmark comparisons and AI-drafted quality-improvement suggestions, and maintain the security and reliability of the service.

5. Third-party processors

  • Supabase — account authentication and database hosting
  • A third-party AI model provider — quality-improvement plan generation, receives aggregate practice-level benchmark data only (the specific provider may change from time to time; the same data-minimisation constraint always applies)
  • Cloudflare — application hosting

6. Legal basis and necessity

Processing is necessary to perform the contract with each registered user (Article 6(1)(b) UK GDPR). Only the data needed to provide the account and benchmarking features is collected; no profiling or automated decision-making with legal effect is carried out.

7. Risk assessment

RiskMitigation
A user enters patient-identifiable data despite instructions not toProduct has no free-text patient input field; account fields only collect professional/organisational data; Disclaimer and Terms explicitly prohibit patient data entry
AI-generated plan is treated as clinical advice rather than a starting point for reviewDisclaimer and in-product framing require clinician review before any patient-facing action
Unauthorised access to another practice’s dataRow-level security in the database scopes each account to its own practice; explicit “viewing another practice” mode is logged and time-limited
Third-party processor breach or outageUse of established, GDPR-compliant processors only; no long-term storage of sensitive data by any processor

Residual risk is assessed as low, given no patient-identifiable data is processed by design.

8. Consultation

This DPIA reflects an internal self-assessment by the data controller. No formal external legal or GDPR advisory review has been carried out yet; this is recommended before the service is used beyond an initial pilot group of practices.

9. Accountability and open action items

The following are open items the controller is actively working through, listed transparently rather than presented as complete:

  • ICO data protection fee registration — complete; registration reference number to be added here once to hand
  • Formal legal review of this DPIA and the accompanying policies by a qualified solicitor
  • Self-service account deletion (currently handled manually on request — see Privacy Policy §8)
  • Confirmation of the hosting region for the underlying database

10. Review

This DPIA will be reviewed at least annually, and whenever a material change is made to what data the service collects or which third-party processors it uses.

11. Contact

Datim-QI Ltd
Email: gp.drgillespie@gmail.com

Datim-QI Ltd is a company registered in England and Wales, company number 17370894. Registered office: 82a James Carter Road, Mildenhall, IP28 7DE, United Kingdom.

Datim-QI uses published NHS data only — no patient-identifiable data.

© 2026 Datim-QI Ltd (company number 17370894). All rights reserved.