UK GDPR Art. 35
Data Protection Impact Assessment — summary
ICO guidance: a DPIA is required when processing is likely to result in high risk to individuals — including large-scale special category data with innovative tech. ReadyPath stores special-category-adjacent content on-device at the user’s initiative. Users remain responsible for what they store and share. This summary records residual risk and mitigations for the publisher.
1. Processing description
Users optionally store assessment referral admin evidence (notes, photos, scores, informant contacts) and pathway progress on their iPhone. Optional postcode/location is sent to postcodes.io / NHS ODS for organisation lookup. No ReadyPath dossier cloud.
2. Necessity & proportionality
Processing is limited to what the user adds for their own admin organisation. Health write and location are opt-in. Screening framed as pack artefact, not diagnosis.
3. Risks to individuals
- Device loss / theft while unlocked → mitigated by AES-GCM, file protection, optional Face ID, backup exclusion
- User exports/shares pack too widely → user responsibility; app and legal pages label admin-only and warn on share
- Misunderstanding screening as diagnosis → in-app disclaimers and legal scope
- Third-party site tracking when opening Safari links → separate controllers; user-initiated
- Support email containing special category data → user warned not to attach packs; publisher minimises retention
4. Mitigations implemented in product
- No ReadyPath dossier upload API
- On-device encryption + Keychain ThisDeviceOnly
- Privacy notice acceptance gate
- Delete-all local data control
- Health default off; location When In Use only
- No advertising SDK for the dossier
5. Publisher actions still required
- Confirm ICO registration / data protection fee if the publisher is a controller (support email, website analytics)
- Keep a signed internal DPIA if counsel advises Art. 35 applies at scale
- Maintain https://www.readypath.live/privacy in App Store Connect
- Keep marketing claims admin-only (see Medical device stance)
- Monitor ICO / Data (Use and Access) Act guidance updates
6. Decision
Residual risk is accepted for an on-device admin tool with the mitigations above, provided the publisher does not add cloud sync, advertising, or clinical decision features without a fresh DPIA, and users remain clearly responsible for exports and device security.