UK and EU privacy operations: the record of processing, the one-month access clock and the 72-hour breach notice.
Offered in: United Kingdom only.UK GDPR and GDPR as running registers. The record of processing activities (Article 30) is kept here: each activity’s purpose, lawful basis, the Article 9 condition (required when the activity names health data), whose data and what data, who receives it, any transfer outside the UK or EEA with the safeguard it rests on (refused without one), how long it is kept and how it is protected, with an owner and a review date that comes round. Subject access requests run in the Security Centre on a one-month clock, extendable once by two months with the reason the requester is told. A UK or EU practice’s data breach in IncidentIQ opens the 72-hour notice to the supervisory authority, the ICO in the UK. The desk shows all three together.
What it does not do, by design. A listing with only benefits is an advertisement.
Read out of the code, not the brochure: each app below is here because one service queries the other’s tables. Install either side and the hand-over is already wired.
Tell us what you run and we will show you this app inside a practice shaped like yours — or answer the question the page above did not.