| Field | Details |
|---|---|
| Document Title | DPIA Screening Record |
| Project/System Name | Aryash Health Patient Education Platform |
| Organisation | Aryash Health |
| Data Controller | Dr Krishnan Pasupathi |
| Date of Screening | 4 January 2026 |
| Review Date | 4 January 2027 |
| Document Version | 1.0 |
A suite of patient education websites providing health information in plain English. The platform consists of:
| Domain | Purpose |
|---|---|
| tools.aryash.health | Blood test education (35+ tests), audio guides (40+), downloadable infographics (15) |
| heart.aryash.health | Cardiovascular health education (conditions, medications, investigations, recovery) |
| mens.aryash.health | Men's health education (prostate, testosterone, testicular health, mental health) |
| aryash.health | Landing page linking to all resources |
To help patients understand their health conditions and blood test results through accessible, plain-English educational content. The tools empower patients to have better conversations with their healthcare providers.
Members of the public seeking to understand:
| Question | Answer | Notes |
|---|---|---|
| Does the system collect patient names? | NO | No data entry fields for identification |
| Does the system collect NHS numbers? | NO | No data entry fields |
| Does the system collect dates of birth? | NO | No data entry fields |
| Does the system collect addresses? | NO | No data entry fields |
| Does the system collect any contact details? | NO | No data entry fields |
| Does the system store any data? | NO | No database, no localStorage, no cookies |
| Does the system transmit any data? | NO | Static sites; no API calls |
| Does the system use analytics or tracking? | NO | No third-party scripts, no cookies |
| Question | Answer | Notes |
|---|---|---|
| Does the system process health data? | NO | Users read information; no input of personal health data |
| Does the system create patient records? | NO | No records created or stored |
| Is any data retained after session ends? | NO | Static pages; nothing persists |
| Activity | Present? | Details |
|---|---|---|
| Collection | NO | No personal data collected |
| Storage | NO | No database or file storage |
| Transmission | NO | No external API calls |
| Sharing | NO | No data sharing with third parties |
| Profiling | NO | No automated decision-making about individuals |
| International transfer | NO | All processing local in browser |
NO - A full DPIA is not required.
Under UK GDPR Article 35, a DPIA is required when processing is "likely to result in a high risk to the rights and freedoms of natural persons."
This platform:
The ICO's screening checklist criteria for mandatory DPIA are not met:
The sites are hosted on Vercel. Standard web server logs may record IP addresses, access timestamps, and browser information.
Mitigation: These are standard infrastructure logs managed by Vercel, not health-related personal data. Vercel's privacy policy applies to infrastructure logging.
Users may print or save content from the sites.
Mitigation: Educational content only; no patient-specific information to print. "Questions for GP" printouts contain generic questions, not personal data.
| Role | Name | Signature | Date |
|---|---|---|---|
| Data Controller | Dr Krishnan Pasupathi |
This screening should be reviewed:
| Site | URL | Data Collection |
|---|---|---|
| Aryash Health (Landing) | aryash.health | None |
| Health Tools Hub | tools.aryash.health | None |
| Heart Health Hub | heart.aryash.health | None |
| Men's Health Hub | mens.aryash.health | None |
Document ends