Security And Compliance
Last updated: 30 June 2026
Get Patient Consent handles special category health data, so security and data protection are designed in from the foundation — not added on. This page summarises how patient and clinician data is protected and how every signed consent is sealed and independently verifiable. Information-governance and procurement teams can request our full security pack for the underlying technical detail.
Where your data lives
Patient and clinician data is hosted in the United Kingdom, with reputable cloud providers under data processing agreements, and selected so that stored data stays in the UK. We do not use a sub-processor outside the UK without first putting a UK GDPR-approved transfer mechanism (the UK IDTA or equivalent) in place and updating our Privacy Policy.
Encryption
All data is encrypted in transit (TLS) and at rest (AES-256), with keys held in a managed key-management service.
Tamper-evident, signed and independently verifiable
Every meaningful action in a consent journey — what the patient was shown, when each section was viewed, every question and answer, and the final signature — is written to a tamper-evident audit trail. When a patient signs, the complete record is sealed with a digital signature and anchored to an independent trusted timestamp, so the time of signing is attested by a neutral third party rather than our own clock.
Each signed record is designed to be verified by anyone — patient, clinician, solicitor, regulator or expert witness — using standard, freely available tools, without contacting us and without having to trust us. Records are produced as self-contained archival PDFs that carry the human-readable facts a court would need, so they remain meaningful and provable on their own, years later, even without us. Verification proves the record's integrity, authorship and timing; whether the consent was clinically valid still rests on the patient's capacity, the information given, and a voluntary decision. The full method is set out in our independent verification white paper.
Consent versioning
Every signed consent stores a complete, immutable snapshot of exactly what the patient was shown — the procedure description, the specific risks, and the exact version of every leaflet. Editing a template later never alters a consent that has already been signed. What was signed is preserved, word for word.
Access controls
- Access to production systems is restricted to named individuals on a least-privilege basis.
- Administrative access is protected by multi-factor authentication.
- All access to production systems is logged.
- Within the platform, clinicians control who may act on their behalf. Every action taken by a delegated staff member is recorded under that person's own identity, showing who did what, when, and on whose behalf. Access can be revoked instantly.
Data protection & compliance
Get Patient Consent is the trading name of CSSL Ltd, registered in England and Wales (company number 03996773) and registered with the Information Commissioner's Office under reference ZB417718.
- The service is built around UK GDPR principles of data minimisation, purpose limitation, and defined retention.
- For patient health data we act as a data processor, on the documented instructions of the clinician or organisation (the data controller), under a data processing agreement. The clinician relies on Article 9(2)(h) — the provision of health care — as the condition for processing special category data.
Full detail of roles, lawful bases, and individual rights is set out in our Privacy Policy.
Sub-processors
We do not sell or rent personal data. We rely on a small number of vetted sub-processors — covering cloud hosting, database, transactional email and payments — each bound by a written contract meeting UK GDPR requirements. A current list of named sub-processors is available to IG and procurement teams on request.
Data retention
Clinicians, as controllers, determine how long consent records are kept. The default minimum we support is 8 years from the date of the procedure, in line with NHS records management guidance, and clinicians may instruct us to retain for longer. Security and audit logs are retained for up to 24 months. Retention rules are documented in our Data Retention Schedule, available on request.
Accessibility & resilience
The patient experience is designed to meet WCAG 2.1 AA and works on any modern phone, tablet, or computer, on any browser, with no app to download. Consent can be completed on the patient's own device, in their own time — which removes a common barrier to genuinely informed consent.
Business continuity
Consent is critical infrastructure, so the service is engineered for high availability and continuity is designed into the record itself. Every signed consent is a self-contained, independently verifiable PDF that the clinician and patient already hold — so an individual record stays readable and provable even if our systems are temporarily unavailable, and indeed without us at all. Our business continuity and disaster-recovery arrangements are available to IG and procurement teams on request.
Reporting a security concern
If you believe you have found a security vulnerability, please tell us at [email protected]. We welcome responsible disclosure and will acknowledge your report.
Questions from your IG or procurement team
We are happy to support due diligence. For our full security pack — including the sub-processor list, security design, DPIA summary, data processing agreement and data retention schedule — contact [email protected].