Get started
ComplianceLive · in the productRegister

GDPRDesk

UK and EU privacy operations: the record of processing, the one-month access clock and the 72-hour breach notice.

Offered in: United Kingdom only.
Get GDPRDeskOpen the appAvailable nowHow pricing works →

What it is

UK GDPR and GDPR as running registers. The record of processing activities (Article 30) is kept here: each activity’s purpose, lawful basis, the Article 9 condition (required when the activity names health data), whose data and what data, who receives it, any transfer outside the UK or EEA with the safeguard it rests on (refused without one), how long it is kept and how it is protected, with an owner and a review date that comes round. Subject access requests run in the Security Centre on a one-month clock, extendable once by two months with the reason the requester is told. A UK or EU practice’s data breach in IncidentIQ opens the 72-hour notice to the supervisory authority, the ICO in the UK. The desk shows all three together.

Who uses it
Built for: Every specialty
Reads
Access requests, incident breach notices
Writes
The record of processing activities
Never
It does not choose a lawful basis or decide an erasure — those stay a person’s decision; it keeps them written down, reviewed and on the clock.
Access
Only people whose role includes it — the clinic owner decides who
Your data
Full PHI. Hosted in Boston, United States. On uninstall: Every record stays; only the workflow leaves.

How it works

  1. The clocksSubject access requests from the Security Centre on their one-month clock, and 72-hour notices to the supervisory authority from IncidentIQ.
  2. Record of processingAdd each activity with its lawful basis, the Article 9 condition when it names health data, and any transfer’s safeguard; the desk refuses one without them.
  3. Review and retireMark an activity reviewed today, next due in a year, or retire it with the reason it stopped.

Rules it keeps

What it does not do, by design. A listing with only benefits is an advertisement.

It does not choose a lawful basis or decide an erasure — those stay a person’s decision; it keeps them written down, reviewed and on the clock.

AI in GDPRDesk

AskQuestions about what is on screen — “What needs attention in GDPRDesk today?” — answered with the records it read.
DraftSummaries and notes for the team, marked as drafts until a person signs.
Every answer shows its sources. Nothing AI writes is saved until a person accepts it.

See it on screen

Live product
01GDPR — Keep the record of processing, subject access clocks and the 72-hour breach noticeCaptured from the running demo clinic
GDPRDesk — GDPR — Keep the record of processing, subject access clocks and the 72-hour breach notice
1 of 1

Connected to

Read out of the code, not the brochure: each app below is here because one service queries the other’s tables. Install either side and the hand-over is already wired.

See the whole clinic →

Questions clinics ask

What does GDPRDesk do?
UK and EU privacy operations: the record of processing, the one-month access clock and the 72-hour breach notice. UK GDPR and GDPR as running registers. The record of processing activities (Article 30) is kept here: each activity’s purpose, lawful basis, the Article 9 condition (required when the activity names health data), whose data and what data, who receives it, any transfer outside the UK or EEA with the safeguard it rests on (refused without one), how long it is kept and how it is protected, with an owner and a review date that comes round. Subject access requests run in the Security Centre on a one-month clock, extendable once by two months with the reason the requester is told. A UK or EU practice’s data breach in IncidentIQ opens the 72-hour notice to the supervisory authority, the ICO in the UK. The desk shows all three together.
What data does GDPRDesk read and write?
GDPRDesk reads access requests, incident breach notices and writes the record of processing activities. Its data class is Full PHI. Every app works on the same patient record — nothing is copied into a silo.
What does GDPRDesk deliberately not do?
It does not choose a lawful basis or decide an erasure — those stay a person’s decision; it keeps them written down, reviewed and on the clock.
What happens to our data if we uninstall GDPRDesk?
Every record stays; only the workflow leaves.
Is GDPRDesk available today?
Yes — GDPRDesk is live in clinics today. Set up your practice on MedAppz and install it from your dashboard.
Where is GDPRDesk offered?
GDPRDesk is offered in United Kingdom only: it is built on that market's own systems and rules.

Want to see GDPRDesk running on your own patients?

Tell us what you run and we will show you this app inside a practice shaped like yours — or answer the question the page above did not.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.

More in Compliance

All 154 →