Trust

Data Protection at Cognitive HealthTech

Trust is fundamental to cognitive-health technology. Cognitive HealthTech is being developed with privacy, security and responsible data use considered from the outset. Our aim is not simply to comply with data-protection requirements, but to design technology around the principle that people should understand how information about them is collected, used and protected.

Privacy by design

We seek to apply privacy and data-protection principles throughout the development lifecycle. These include:

Purpose limitation
Information should be collected for clear and legitimate purposes.
Data minimisation
Only information reasonably necessary for the intended purpose should be collected.
Transparency
People should be given clear information about how their data is being used.
Security
Appropriate technical and organisational measures should be used to protect information.
Accountability
Data-protection decisions, risks and safeguards should be documented and reviewed.

Health and behavioural data

Cognitive and behavioural information can be particularly sensitive. Where CHT research, clinical evaluation or future technology involves health or special-category personal data, additional safeguards will be required. These may include:

  • specific privacy notices
  • appropriate consent or other lawful bases
  • Data Protection Impact Assessments
  • access controls
  • encryption
  • data minimisation
  • defined retention periods
  • secure storage and transfer
  • appropriate contractual safeguards
  • governance and ethical review where applicable

Individual control

Our approach is based on the principle that individuals should have meaningful information and appropriate control over how their data is used.

CHT is not intended to operate as hidden surveillance. Where behavioural information is collected or analysed, this should take place within an appropriate, transparent and governed relationship with the individual.

Healthcare and research governance

As CHT progresses through product development, research and clinical validation, information governance requirements will be considered alongside:

  • clinical safety
  • cybersecurity
  • research governance
  • healthcare information governance
  • UK GDPR and Data Protection Act requirements
  • relevant NHS assurance processes
  • future medical-device requirements where applicable

Security

We continually review the technical and organisational safeguards appropriate to the stage of development of the platform.

Security and governance will evolve alongside the technology and its intended clinical use.

Questions about data protection

For data-protection enquiries, contact: contact@cognitivehealthtech.co.uk

For information about personal information collected through this website, please also see our Privacy Notice.