Data Protection Impact Assessment (DPIA) Screening Record

FieldDetails
Document TitleDPIA Screening Record
Project/System NameAryash Health Patient Education Platform
OrganisationAryash Health
Data ControllerDr Krishnan Pasupathi
Date of Screening4 January 2026
Review Date4 January 2027
Document Version1.0

1. Project Description

1.1 What is the project?

A suite of patient education websites providing health information in plain English. The platform consists of:

DomainPurpose
tools.aryash.healthBlood test education (35+ tests), audio guides (40+), downloadable infographics (15)
heart.aryash.healthCardiovascular health education (conditions, medications, investigations, recovery)
mens.aryash.healthMen's health education (prostate, testosterone, testicular health, mental health)
aryash.healthLanding page linking to all resources

1.2 What is the purpose?

To help patients understand their health conditions and blood test results through accessible, plain-English educational content. The tools empower patients to have better conversations with their healthcare providers.

1.3 Who will use it?

Members of the public seeking to understand:

2. DPIA Screening Questions

2.1 Does the project involve processing personal data?

QuestionAnswerNotes
Does the system collect patient names?NONo data entry fields for identification
Does the system collect NHS numbers?NONo data entry fields
Does the system collect dates of birth?NONo data entry fields
Does the system collect addresses?NONo data entry fields
Does the system collect any contact details?NONo data entry fields
Does the system store any data?NONo database, no localStorage, no cookies
Does the system transmit any data?NOStatic sites; no API calls
Does the system use analytics or tracking?NONo third-party scripts, no cookies

2.2 Special Category Data (Article 9 UK GDPR)

QuestionAnswerNotes
Does the system process health data?NOUsers read information; no input of personal health data
Does the system create patient records?NONo records created or stored
Is any data retained after session ends?NOStatic pages; nothing persists

2.3 Data Processing Activities

ActivityPresent?Details
CollectionNONo personal data collected
StorageNONo database or file storage
TransmissionNONo external API calls
SharingNONo data sharing with third parties
ProfilingNONo automated decision-making about individuals
International transferNOAll processing local in browser

3. Screening Outcome

Is a full DPIA required?

NO - A full DPIA is not required.

3.2 Rationale

Under UK GDPR Article 35, a DPIA is required when processing is "likely to result in a high risk to the rights and freedoms of natural persons."

This platform:

  1. Collects no personal data - No input fields for patient identifiable information
  2. Stores no data - Static websites with no database, cookies, or local storage
  3. Transmits no data - No API calls, no external services
  4. Makes no automated decisions - Educational content only; no health decisions made
  5. Provides information, not diagnosis - Users read general health education

The ICO's screening checklist criteria for mandatory DPIA are not met:

4. Residual Considerations

4.1 Web Hosting Logs

The sites are hosted on Vercel. Standard web server logs may record IP addresses, access timestamps, and browser information.

Mitigation: These are standard infrastructure logs managed by Vercel, not health-related personal data. Vercel's privacy policy applies to infrastructure logging.

4.2 Printed/Saved Content

Users may print or save content from the sites.

Mitigation: Educational content only; no patient-specific information to print. "Questions for GP" printouts contain generic questions, not personal data.

5. Sign-Off

Screening completed by:

RoleNameSignatureDate
Data ControllerDr Krishnan Pasupathi

Decision:

6. Review Schedule

This screening should be reviewed:

7. Sites Covered by This Screening

SiteURLData Collection
Aryash Health (Landing)aryash.healthNone
Health Tools Hubtools.aryash.healthNone
Heart Health Hubheart.aryash.healthNone
Men's Health Hubmens.aryash.healthNone

Document ends