Trust
Data Protection at Cognitive HealthTech
Trust is fundamental to cognitive-health technology. Cognitive HealthTech is being developed with privacy, security and responsible data use considered from the outset. Our aim is not simply to comply with data-protection requirements, but to design technology around the principle that people should understand how information about them is collected, used and protected.
Privacy by design
We seek to apply privacy and data-protection principles throughout the development lifecycle. These include:
- Purpose limitation
- Information should be collected for clear and legitimate purposes.
- Data minimisation
- Only information reasonably necessary for the intended purpose should be collected.
- Transparency
- People should be given clear information about how their data is being used.
- Security
- Appropriate technical and organisational measures should be used to protect information.
- Accountability
- Data-protection decisions, risks and safeguards should be documented and reviewed.
Health and behavioural data
Cognitive and behavioural information can be particularly sensitive. Where CHT research, clinical evaluation or future technology involves health or special-category personal data, additional safeguards will be required. These may include:
- specific privacy notices
- appropriate consent or other lawful bases
- Data Protection Impact Assessments
- access controls
- encryption
- data minimisation
- defined retention periods
- secure storage and transfer
- appropriate contractual safeguards
- governance and ethical review where applicable
Individual control
Our approach is based on the principle that individuals should have meaningful information and appropriate control over how their data is used.
CHT is not intended to operate as hidden surveillance. Where behavioural information is collected or analysed, this should take place within an appropriate, transparent and governed relationship with the individual.
Healthcare and research governance
As CHT progresses through product development, research and clinical validation, information governance requirements will be considered alongside:
- clinical safety
- cybersecurity
- research governance
- healthcare information governance
- UK GDPR and Data Protection Act requirements
- relevant NHS assurance processes
- future medical-device requirements where applicable
Security
We continually review the technical and organisational safeguards appropriate to the stage of development of the platform.
Security and governance will evolve alongside the technology and its intended clinical use.
Questions about data protection
For data-protection enquiries, contact: contact@cognitivehealthtech.co.uk
For information about personal information collected through this website, please also see our Privacy Notice.
