Third-Party Data Submission Agreement v1.0
DATED: Insert Date
Patients Know Best,
of St John's Innovation Centre, Cowley Road, Milton, Cambridge, CB4 0WS.
– and –
[Full Legal Name of Provider]
PART 1 – DEFINITIONS AND CLAUSES
This Agreement is dated [Effective Date].
PARTIES
A. Patients Know Best Limited (“PKB”), a company incorporated in England and Wales (Company No. 06517382) whose registered office is at St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS; and
B. [Full Legal Name of Provider] (“Provider”), a company incorporated in [Jurisdiction] (Company No. [●]) whose registered office is at [●],
each a “Party” and together the “Parties”.
BACKGROUND
A. PKB operates a patient-held digital health record platform enabling individuals to store, manage, and share personal health information.
B. The Provider operates an application or digital service through which individuals may generate or access personal data, including health-related data.
C. Individuals may choose, at their own discretion, to initiate the transfer of data held by the Provider into their PKB account (a “Patient-Initiated Submission”).
D. This Agreement governs the submission mechanism and the data protection, security, and integrity obligations associated with such submissions.
E. This Agreement does not govern access to or use of data within PKB by healthcare providers or professionals, which is subject to separate legal and governance arrangements.
F. Each Party acts as an Independent Controller of the Personal Data it processes under this Agreement. This Agreement does not establish a processor relationship or joint controllership between the Parties.
DEFINITIONS AND INTERPRETATION
3.1 Unless specifically provided for in this Agreement, the following terms shall have the following meanings:
“Controller” has the meaning given in UK GDPR.
“Data Protection Law” means UK GDPR, the Data Protection Act 2018, and all applicable UK laws and regulations relating to the Processing of Personal Data and privacy.
“Data Subject” or “Patient” means the identified or identifiable individual whose Personal Data is submitted via a Patient-Initiated Submission.
“Effective Date” means the date on which this Agreement commences, as set out in clause 5.
“Independent Controller” means a Controller that determines the purposes and means of its Processing of Personal Data independently of the other Party and does not process Personal Data on behalf of, or jointly with, that Party.
“Patient-Initiated Submission” means a submission triggered directly and intentionally by the Data Subject via the Submission Interface.
“Personal Data”, “Personal Data Breach”, “Processing” including “Process” and “Processed”, and “Special Category Data” have the meanings given in UK GDPR.
“Provider” means the organisation identified as such in clause 1 that enables Patient-Initiated Submissions via the Submission Interface.
“Submitted Data” means Personal Data transferred to PKB via a Patient-Initiated Submission.
“Submission Interface” means the technical mechanism enabling submission.
“UK GDPR” means the UK General Data Protection Regulation as implemented into UK law by the Data Protection Act 2018 and as amended from time to time.
3.2 The following rules of interpretation apply to this Agreement:
3.2.1 clause, schedule, and paragraph headings shall not affect the interpretation of this Agreement;
3.2.2 a person includes a natural person, corporate or unincorporated body whether or not having separate legal personality;
3.2.3 the Schedules form part of this Agreement and shall have effect as if set out in full in the body of this Agreement. Any reference to this Agreement includes the Schedules;
3.2.4 unless the context otherwise requires, words in the singular shall include the plural and, in the plural, shall include the singular;
3.2.5 a reference to a statute, statutory provision or other legal instrument is a reference to it as amended, extended, or re-enacted from time to time; and
3.2.6 any words following the terms including, include, in particular, for example or any similar expression shall be construed as illustrative and shall not limit the sense of the words, description, definition, phrase or term preceding those terms.
3.3 In the event and to the extent of a conflict between the main body of this Agreement and the Schedules, except as expressly stated otherwise, the main body of this Agreement shall prevail.
SCOPE AND APPLICATION
4.1 This Agreement governs the submission mechanism by which the Provider enables Patient-Initiated Submissions of Personal Data into PKB, and the data protection, security, and integrity obligations associated with such submissions.
4.2 This Agreement governs only the submission of data from the Provider to PKB and PKB's ingestion of that data. It does not govern how Submitted Data may subsequently be accessed, shared, or used within the PKB platform, whether by the Data Subject or by third parties authorised by the Data Subject, which is subject to separate legal, organisational, or individual arrangements as applicable.
4.3 For the avoidance of doubt, this Agreement does not determine the controllership status of PKB and any healthcare provider, healthcare organisation, or other third party in relation to any downstream access to or use of Submitted Data.
COMMENCEMENT AND DURATION
5.1 This Agreement shall commence on the Effective Date and shall continue until terminated in accordance with clause 21.
PATIENT AND REGULATORY ENGAGEMENT
6.1 The Provider shall provide transparency information to the Data Subject prior to submission, including that Personal Data will be transmitted to PKB as an Independent Controller. Such transparency shall include, at a minimum: PKB's identity as the receiving Controller; the categories of Personal Data to be submitted; the purpose of submission, including inclusion within the Data Subject's PKB record; confirmation that submission is initiated by the Data Subject; information on the Data Subject's rights; and how queries, rights requests, or complaints may be raised.
6.2 PKB shall provide transparency regarding ingestion and use of Submitted Data, including how Submitted Data will be stored, labelled, and shared within the PKB platform, and information on Data Subject rights and how individuals may raise queries, exercise rights, or make complaints.
6.3 PKB may reasonably rely on the fact of a Patient-Initiated Submission, together with the transparency information provided at the point of submission, as evidence that the Data Subject instructed the transfer of their Personal Data via the Submission Interface.
AGREED PURPOSES
7.1 The Parties agree that Submitted Data shall be Processed under this Agreement for the following purposes:
7.1.1 enabling the Data Subject to initiate transfer of data from the Provider application into the Data Subject's PKB record;
7.1.2 enabling PKB to receive, ingest, store, display, label, and maintain Submitted Data within the PKB platform;
7.1.3 maintaining provenance, audit, and security records relating to Submitted Data;
7.1.4 enabling amendment, correction, deletion, and lifecycle management of Submitted Data in accordance with this Agreement; and
7.1.5 supporting Data Subject rights handling, security, integrity, and compliance obligations in respect of Submitted Data.
7.2 Submitted Data shall be limited to categories agreed between the Parties, which may include device metrics and wearable data, observations and vital signs, symptom logs, patient-reported outcomes, treatment adherence data, and limited demographic identifiers for matching.
7.3 Any expansion of scope beyond the Agreed Purposes requires a written variation and governance review, including a Data Protection Impact Assessment where required.
PART 2 – APPLICABLE WHERE PKB AND THE PROVIDER ACT AS INDEPENDENT CONTROLLERS
LAWFUL BASES FOR PROCESSING AND CLASSIFICATION OF PARTIES
8.1 Each Party acts as an Independent Controller in respect of the Personal Data it processes under this Agreement.
8.2 The Provider is Controller in respect of the Personal Data it processes within its application prior to transmission to PKB, including the collection or generation of data, user authentication and account management, determination and authorisation of the Patient-Initiated Submission, and secure transmission to PKB.
8.3 PKB is Controller in respect of Personal Data it processes within the PKB platform, including receipt and ingestion of Submitted Data, storage and management of data within the platform, data contributed directly by the Data Subject via PKB interfaces, presentation of data to the Data Subject, access controls and sharing settings, and platform-generated metadata necessary for system operation, security, and audit.
8.4 The Provider shall identify an appropriate lawful basis under Article 6 UK GDPR and, where required, an Article 9 condition, and PKB shall identify its own lawful basis under Article 6 UK GDPR and, where applicable, an Article 9 condition, each in respect of the Personal Data for which it is Controller.
PROVIDER'S RESPONSIBILITY FOR PATIENT-FACING COMMUNICATIONS
9.1 The Provider shall ensure only authenticated users can initiate submissions.
9.2 Users must be presented with a clear confirmation action before a Patient-Initiated Submission is transmitted.
9.3 The Provider shall maintain auditable records of each Patient-Initiated Submission, including the user identifier, date and time of submission, data categories transmitted, and confirmation of the user action initiating transmission.
10. DATA MINIMISATION AND PSEUDONYMISATION
10.1 Mandatory metadata accompanying each submission shall include the submission timestamp, source application identifier, and patient-initiated designation.
10.2 PKB may reject or quarantine data where matching is unsafe, metadata is incomplete, or security or integrity risks exist.
10.3 PKB shall apply matching controls appropriate to patient safety risk, relying on reliable identifiers such as the PKB user identifier, the Provider identifier plus date of birth, or verified contact details, and shall quarantine or reject submissions where matching cannot be safely achieved.
10.4 Submitted Data shall not overwrite clinician-entered records.
11. GENERAL OBLIGATIONS OF THE PARTIES
11.1 Submissions of Personal Data to PKB must be initiated directly and intentionally by the Data Subject via the Provider's application using the Submission Interface.
11.2 The Provider shall not automate submissions, send bulk or cohort data, or initiate submissions on behalf of users, unless separately agreed in writing. This restriction does not apply to amendments, corrections, or deletions by the Provider in respect of data previously submitted via a Patient-Initiated Submission, which are treated as the Provider exercising its own Controller responsibilities within the scope of the Data Subject's original authorisation.
11.3 The Provider shall ensure Submitted Data is transmitted without unauthorised alteration and with accurate attribution.
11.4 The Parties shall cooperate to correct any mis-routing, mis-identification, integrity issue, or Personal Data Breach affecting Submitted Data.
11.5 Each Party shall implement appropriate technical and organisational measures to protect Personal Data against unauthorised or accidental access, loss, alteration, disclosure, destruction or other unauthorised or unlawful forms of Processing.
11.6 Each Party shall ensure that its personnel who have access to Personal Data under this Agreement are subject to appropriate obligations of confidentiality and that such access is limited to those individuals who need to know and access such Personal Data.
11.7 Each Party shall notify the other Party in writing without undue delay upon becoming aware of a Personal Data Breach affecting Submitted Data within its control, and shall provide reasonable assistance in investigating, mitigating, and remediating the breach.
11.8 Each Party shall provide reasonable assistance to the other Party in ensuring compliance with Data Protection Law in respect of the activities governed by this Agreement.
12. JOINT CONTROLLERS
12.1 Nothing in this Agreement establishes joint controllership between the Parties in respect of the submission and ingestion activities governed by this Agreement.
13. USE OF PROCESSORS
13.1 Nothing in this Agreement establishes a processor relationship between the Parties.
13.2 Where either Party uses a processor in connection with its own Processing of Personal Data under this Agreement, that Party shall ensure that such Processing is subject to an agreement as required by Article 28 UK GDPR.
14. COMBINATION WITH OTHER DATA
14.1 PKB shall maintain provenance metadata for Submitted Data, including source Provider, submission timestamp, and patient-initiated status.
14.2 Submitted Data shall be clearly labelled within PKB as patient-submitted and not clinically validated unless reviewed, and shall remain distinguishable from clinician-entered information at all times.
15. DATA RETENTION AND DELETION
15.1 PKB shall retain Submitted Data only for so long as it forms part of the Data Subject's patient-held record within the PKB platform, and in accordance with its published retention schedules and platform data lifecycle policies applicable to patient-held record content and user account data.
15.2 The Provider shall retain submission logs for a period sufficient to meet its legal, regulatory, and audit obligations.
15.3 Where Submitted Data originates from the Provider following a Patient-Initiated Submission, the Data Subject may request deletion via the Provider application, or may submit such a request to PKB, in which case PKB shall handle or redirect the request where applicable in accordance with clause 16.2.
15.4 Where the Provider transmits a verified deletion request via authenticated API credentials, PKB shall delete the relevant Submitted Data without undue delay.
15.5 Deletion shall not be conditional upon whether the data has been viewed or accessed by healthcare professionals or other authorised users within PKB.
15.6 This deletion model applies only to data originating from the Provider and identifiable via provenance metadata as patient-submitted. It does not require deletion of clinician-entered records, clinical documentation created outside or within PKB clinical workflows, or references to Submitted Data recorded within clinician notes.
15.7 PKB may retain minimal audit metadata necessary to evidence submission and deletion events and to meet applicable legal obligations. Where Submitted Data is deleted, PKB shall not retain the content of such data other than such minimal audit metadata.
15.8 Any amendment, correction, or deletion of Submitted Data initiated by the Provider shall be deemed an exercise of the Provider's independent Controller responsibilities, including obligations regarding data accuracy, rectification, and erasure, performed within the scope of the Data Subject's original Patient-Initiated Submission and standing authorisation. For the avoidance of doubt, such actions flow from and are governed by the Data Subject's initial mandate, including any OAuth grant or Patient Preference, which continues to govern the channel between the Parties. PKB's actioning of such requests constitutes giving effect to the consequences of the Data Subject's own standing authorisation and does not establish a processor relationship.
15.9 The Provider is responsible for the accuracy and legitimacy of deletion requests it transmits.
PART 3 – APPLICABLE WHERE PKB IS A PROCESSOR
16. DATA SUBJECT RIGHTS
16.1 Each Party is responsible for rights requests relating to data it controls.
16.2 Where a request relates wholly or partly to the other Party's Processing, the receiving Party shall inform the Data Subject that another Controller is responsible and, where lawful and appropriate, redirect or forward the request.
16.3 For the avoidance of doubt, nothing in this Part 3 establishes PKB as a Processor of the Provider in respect of the submission and ingestion activities governed by this Agreement.
PART 4 – APPLICABLE TO ALL
17. RECORDS
17.1 The Provider shall maintain auditable records of each Patient-Initiated Submission, including the user identifier, date and time of submission, data categories transmitted, and confirmation of the user action initiating transmission.
17.2 PKB shall maintain provenance metadata for Submitted Data, including source Provider, submission timestamp, and patient-initiated status.
18. REVIEW OF THIS AGREEMENT
18.1 The effectiveness of this Agreement shall be reviewed from time to time by the Parties.
18.2 Any expansion of the scope of Processing beyond the Agreed Purposes requires a written variation and governance review, including a Data Protection Impact Assessment where required.
19. WARRANTIES
19.1 Each Party represents and warrants to the other Party that:
19.1.1 it has full capacity to enter into and perform this Agreement which has been duly executed by the required corporate action;
19.1.2 entry into and performance of this Agreement does and will not violate or be subject to any restriction in or by any other agreement or obligation.
19.2 The use of Submitted Data as permitted by this Agreement does not infringe the rights of any third party.
20. LIMITATION AND EXCLUSION OF LIABILITY
20.1 The Provider is liable for breaches relating to unlawful submission, transmission failures, or misattribution prior to PKB's receipt of Submitted Data.
20.2 PKB is liable for breaches relating to storage, disclosure, or security post-receipt of Submitted Data.
20.3 Liability caps and exclusions apply as agreed in the commercial terms between the Parties.
21. TERMINATION
21.1 PKB may suspend submissions where necessary to protect patient safety, system integrity, or legal compliance.
21.2 Either Party may terminate this Agreement for convenience on ninety (90) days' written notice, or immediately for material breach or risk.
22. CONSEQUENCES OF TERMINATION
Upon termination or expiry of this Agreement:
22.1 The Provider shall cease new Patient-Initiated Submissions.
22.2 For the avoidance of doubt, Submitted Data that has been received by PKB and forms part of the Data Subject's PKB record shall be retained by PKB in accordance with its role and responsibilities as an Independent Controller and in accordance with clause 15 (Data Retention and Deletion). Termination of this Agreement does not oblige PKB to delete Submitted Data that forms part of a patient-held record, unless required by a verified deletion request under clause 15 or by Data Protection Law.
22.3 The Provider shall retain its own submission logs and records in accordance with its own retention obligations.
22.4 Termination or expiry of this Agreement shall not affect any rights, remedies, obligations or liabilities of the Parties that have accrued up to the date of termination or expiry, including the right to claim damages in respect of any breach of this Agreement which existed at or before the date of termination or expiry.
23. FORCE MAJEURE
23.1 Non-performance or delay of either Party will be excused to the extent that performance is caused by any circumstance beyond that Party's reasonable control, including strike, fire, natural disaster, governmental acts, orders or restrictions, failure of suppliers or subcontractors. In such circumstances the affected Party shall be entitled to a reasonable extension of time for performance. If the period of non-performance or delay continues for ninety (90) days, the Party not affected may terminate this Agreement immediately on written notice to the affected Party.
24. ASSIGNMENT AND OTHER DEALINGS
24.1 Neither Party may assign or otherwise transfer any of its rights or obligations under this Agreement without the prior written approval of the other Party, except as expressly permitted by clause 24.2.
24.2 A Party may, upon written notice to the other Party and subject to the prior written approval of the other Party (such approval not to be unreasonably withheld or delayed), assign or otherwise transfer this Agreement to any of its affiliates or in connection with a change of control transaction (whether by merger, consolidation, sale of equity interests, sale of all or substantially all assets, or otherwise). For clarity, where such assignment or transfer would give rise to a breach of obligations in relation to Data Protection Law or other Applicable Law or may already affect any research ethics approvals or would not be expected in accordance with the common law duty of confidentiality, such grounds shall amongst other matters be considered reasonable for refusing approval to such assignment or transfer. Any assignment or other transfer in violation of this clause will be void.
24.3 This Agreement will be binding upon and inure to the benefit of the Parties hereto and their permitted successors and assigns.
25. VARIATION
25.1 No variation of this Agreement shall be effective unless it is in writing and signed by the Parties.
26. NOTICES
26.1 All notices required or permitted under this Agreement and all requests for approvals, consents and waivers must be delivered by a method providing for proof of delivery. Any notice or request will be deemed to have been given on the date of delivery. Notices and requests must be delivered to the Parties at the addresses on the first page of this Agreement until a different address has been designated by notice to the other Party.
27. SEVERANCE
27.1 If any provision of this Agreement is found to be unenforceable, such provision will be deemed to be deleted or narrowly construed to such extent as is necessary to make it enforceable and this Agreement will otherwise remain in full force and effect.
28. RELATIONSHIP OF THE PARTIES
28.1 Nothing in this Agreement establishes a processor relationship or joint controllership between the Parties in respect of the submission and ingestion activities governed by this Agreement.
28.2 The Parties are and will be independent contractors and neither Party has any right, power, or authority to act or create any obligation on behalf of the other Party.
28.3 For the avoidance of doubt, this Agreement does not determine the controllership status of PKB and any healthcare provider, healthcare organisation, or other third party in relation to any downstream access to or use of Submitted Data.
29. RIGHTS AND REMEDIES
29.1 The rights and remedies provided under this Agreement are in addition to, and not exclusive of, any rights or remedies provided by law.
30. WAIVER
30.1 No term or provision of this Agreement will be deemed waived and no breach will be deemed excused, unless such waiver is in writing and signed by the Party claimed to have waived.
31. COUNTERPARTS
31.1 This Agreement may be executed in counterparts, each of which will be deemed an original, but all of which together will constitute the same Agreement.
32. THIRD PARTY RIGHTS
32.1 This Agreement does not give rise to any rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any term of this Agreement.
33. FURTHER ASSURANCE
33.1 Each Party shall use reasonable endeavours to procure that any necessary third party shall promptly execute and deliver such documents and perform such acts as may reasonably be required for the purpose of giving full effect to this Agreement.
34. COSTS
34.1 Each Party shall pay its own costs incurred in connection with the negotiation, preparation, and execution of this Agreement.
35. ENTIRE AGREEMENT
35.1 This Agreement constitutes the entire agreement between the Parties and supersedes and extinguishes all previous drafts, agreements, arrangements, and understandings between them, whether written or oral, relating to its subject matter.
35.2 Each Party acknowledges that in entering into this Agreement it does not rely upon, and shall have no remedies in respect of, any representation or warranty that is not set out in this Agreement.
36. GOVERNING LAW AND DISPUTE RESOLUTION
36.1 Governing law
36.1.1 This Agreement and all matters arising out of or in connection with it shall be governed by, and construed in accordance with, the law of England and Wales.
36.2 Dispute resolution
36.2.1 Where there is a dispute, the aggrieved Party shall notify the other Party in writing of the nature of the dispute with as much detail as possible.
36.2.2 A representative from senior management of each Party shall meet in person or communicate by telephone within five (5) Working Days of the date of written notification in order to reach an agreement about the nature of the dispute and any corrective action to be taken.
36.2.3 If no agreement is reached, the matter shall be escalated to board level or equivalent senior leadership within a further five (5) Working Days.
36.2.4 If the dispute cannot be resolved following escalation, either Party may seek the legal remedies to which it is entitled under this Agreement. The courts of England and Wales shall have exclusive jurisdiction.
37. CONFIDENTIALITY
37.1 Each Party shall keep confidential any non-public technical, security, or governance information shared under this Agreement.
38. INTERNATIONAL TRANSFERS
38.1 Each Party shall ensure that any international transfers of Personal Data comply with Data Protection Law and are subject to appropriate safeguards.
39. DATA PROTECTION OFFICER
39.1 PKB's Data Protection Officer is David Grange, who may be contacted at dpo@patientsknowbest.com.
40. SCHEDULE 1: DATA SUBMISSION PARTICULARS
40.1 PERSONAL DATA SUBMITTED
This Schedule describes the types of Submitted Data that may be transferred under this Agreement. The Parties may agree to amend the descriptions in this clause at any time by written variation.
Duration of processing | The duration of this Agreement, subject to clauses 15 and 22. |
Nature and purpose of processing | PKB provides a platform enabling Data Subjects to initiate the transfer of data from the Provider's application into their PKB patient-held record. |
Categories of Personal Data | Device metrics and wearable data Observations and vital signs Symptom logs Patient-reported outcomes Treatment adherence data Limited demographic identifiers for matching Mandatory metadata: submission timestamp, source application identifier, patient-initiated designation |
Categories of Data Subject | The Provider's and PKB's shared patients/users who make a Patient-Initiated Submission. |
Plan for return/destruction on completion | Submitted Data is retained only for so long as it forms part of the Data Subject's PKB record. On a verified deletion request, PKB deletes the relevant Submitted Data, retaining only minimal audit metadata, in accordance with clause 15. |
Transfers outside the UK | Any international transfer must comply with Data Protection Law and be subject to appropriate safeguards. |
Controllership | The Provider is Controller for Personal Data prior to transmission; PKB is Controller for Personal Data on and following ingestion. |
41. SCHEDULE 2: PROCESSING OPERATIONS
2A PROCESSING OPERATION A
Processing Operation: Patient-Initiated Submission from the Provider application into PKB.
Performed by: Provider and PKB.
Classification of Parties: Independent Controllers.
Lawful Bases for Processing: Each Party identifies its own lawful basis under Article 6 UK GDPR and, where applicable, Article 9 UK GDPR.
Specific Responsibilities for Parties: Provider is responsible for authentication, confirmation action, auditable submission records, and secure transmission. PKB is responsible for receipt, matching controls, ingestion, rejection or quarantine where unsafe, storage, provenance, and labelling.
Compliance with Principles
Principle 1 – Processing is lawful, fair and transparent: The Processing is initiated by the Data Subject following transparency information presented by the Provider and PKB. The Data Subject is informed that data will be sent to PKB and included in the Data Subject's PKB record.
Principle 2 – Collected for specific, explicit and legitimate purposes: Submitted Data is Processed for the Agreed Purposes set out in clause 7, including submission into the Data Subject's PKB record, storage, display, provenance, lifecycle management, and rights handling.
Principle 3 – Adequate, relevant and not excessive: Submitted Data is limited to categories agreed between the Parties and required for the Patient-Initiated Submission and safe matching.
Principle 4 – Accurate and up to date: The Provider is responsible for the accuracy and provenance of the data it submits. PKB maintains provenance metadata and labels Submitted Data as patient-submitted and not clinically validated unless reviewed.
Principle 5 – Kept for no longer than is necessary: Submitted Data is retained in accordance with clause 15 and the applicable PKB retention schedules and platform data lifecycle policies.
Principle 6 – Processed securely: Each Party implements appropriate technical and organisational controls, including the measures described in Schedule 3.
2B PROCESSING OPERATION B
Processing Operation: Provider-initiated amendment, correction, deletion, and lifecycle management of previously Submitted Data.
Performed by: Provider and PKB.
Classification of Parties: Independent Controllers.
Lawful Bases for Processing: Each Party identifies its own lawful basis under Article 6 UK GDPR and, where applicable, Article 9 UK GDPR. The Data Subject's original standing authorisation continues to govern the channel for amendment, correction, and deletion activity.
Specific Responsibilities for Parties: Provider is responsible for the accuracy and legitimacy of amendment, correction, and deletion requests it transmits. PKB is responsible for actioning verified requests in accordance with clause 15 and retaining only minimal audit metadata where applicable.
Compliance with Principles
Principle 1 – Processing is lawful, fair and transparent: Amendments, corrections, and deletions are carried out within the scope of the Data Subject's original Patient-Initiated Submission and standing authorisation.
Principle 2 – Collected for specific, explicit and legitimate purposes: Lifecycle management is compatible with the original purpose of enabling the Data Subject's Provider-originated data to be included and maintained accurately within the PKB record.
Principle 3 – Adequate, relevant and not excessive: Amendment, correction, and deletion activity is limited to Submitted Data identifiable via provenance metadata as originating from the Provider.
Principle 4 – Accurate and up to date: The Provider may amend or correct data it previously submitted in order to meet its Controller responsibilities for accuracy and rectification.
Principle 5 – Kept for no longer than is necessary: PKB deletes relevant Submitted Data without undue delay where a verified deletion request is transmitted, subject only to retention of minimal audit metadata where required.
Principle 6 – Processed securely: Requests are transmitted via authenticated credentials and handled in accordance with the technical and organisational measures in Schedule 3.
2C PROCESSING OPERATION C
Processing Operation: Security, audit, provenance, and rights-handling relating to Submitted Data.
Performed by: Provider and PKB, each in respect of Personal Data within its own control.
Classification of Parties: Independent Controllers.
Lawful Bases for Processing: Compliance with Data Protection Law, security obligations, and each Party's lawful basis for the underlying Processing.
Specific Responsibilities for Parties: Each Party is responsible for rights requests relating to data it controls, for breach notification and cooperation, and for maintaining appropriate records and technical and organisational measures.
Compliance with Principles
Principle 1 – Processing is lawful, fair and transparent: Security, audit, provenance, and rights-handling activities are described in the Parties' transparency information and are necessary to support lawful Processing under this Agreement.
Principle 2 – Collected for specific, explicit and legitimate purposes: Processing is limited to compliance, security, audit, provenance, and rights-handling purposes connected with Submitted Data.
Principle 3 – Adequate, relevant and not excessive: Audit and provenance metadata is limited to what is necessary to evidence submission, deletion, integrity, and compliance events.
Principle 4 – Accurate and up to date: Each Party shall maintain accurate records for the activities for which it is responsible.
Principle 5 – Kept for no longer than is necessary: Records and metadata are retained only for as long as required for legal, regulatory, audit, security, and platform lifecycle purposes.
Principle 6 – Processed securely: Each Party implements appropriate technical and organisational measures and cooperates in the investigation, mitigation, and remediation of Personal Data Breaches.
42. SCHEDULE 3: SECURITY CONTROLS
42.1 SECURITY RESPONSIBILITIES
42.1.1 Each Party shall maintain appropriate information security arrangements for Personal Data Processed under this Agreement in a manner consistent with Article 32 UK GDPR and Good Industry Practice.
42.1.2 PKB shall maintain security controls appropriate to the operation of the PKB platform, including encryption, access controls, monitoring, vulnerability management, incident response, and audit logging.
42.1.3 The Provider shall maintain security controls appropriate to the operation of its application and the Submission Interface, including authentication, access controls, encryption, secure transmission, audit logging, and incident response.
42.1.4 PKB shall comply with the Data Security and Protection Toolkit assessment, reporting and audit requirements relevant to its organisation type, where applicable.
42.2 SECURITY MANAGEMENT
42.2.1 Each Party shall plan, implement, manage, review, and maintain security controls appropriate to the nature, scope, context, and purposes of its Processing under this Agreement.
42.2.2 Each Party shall maintain operational risk assessment and management processes for the identification, mitigation, and management of security risks.
42.3 SECURITY ADMINISTRATION
42.3.1 Each Party shall track, coordinate, implement, manage, and maintain security changes relevant to the systems and services for which it is responsible.
42.3.2 Each Party shall limit the risk of unauthorised access to Personal Data through appropriate technical and organisational measures.
42.4 SECURITY AUDIT
42.4.1 Each Party shall provide to the other Party such information as the other Party may reasonably request to demonstrate compliance with the security obligations under this Agreement, subject to reasonable confidentiality, security, and commercial sensitivity requirements.
42.5 NON-COMPLIANCE REPORTING
42.5.1 Each Party shall monitor security compliance relevant to the systems and services for which it is responsible.
42.5.2 Each Party shall notify the other Party without undue delay of any material non-compliance affecting Submitted Data.
42.6 SYSTEM ACCESS CONTROL
42.6.1 Each Party shall restrict access to Personal Data to appropriately identified, authenticated, and authorised personnel.
42.6.2 Each Party shall maintain records of access to Personal Data where appropriate to the nature and risk of the Processing.
42.6.3 Privileged access shall be subject to enhanced controls, including multi-factor authentication where appropriate.
42.7 CRYPTOGRAPHY MANAGEMENT
42.7.1 Each Party shall ensure that Personal Data is encrypted in transit and at rest as appropriate in accordance with Good Industry Practice and the risk attached to the Personal Data being Processed.
42.7.2 Each Party shall maintain appropriate processes and procedures for managing encryption keys within systems for which it is responsible.
42.8 ASSET PROTECTION
42.8.1 Each Party shall maintain mechanisms to prevent or mitigate destruction, loss, alteration, unauthorised disclosure, unauthorised access, or misuse of systems and data used in connection with this Agreement.
42.8.2 Each Party shall maintain vulnerability management and patching processes appropriate to risk.
42.8.3 Each Party shall maintain business continuity and disaster recovery arrangements appropriate to the services and systems for which it is responsible.
42.9 SECURITY AWARENESS
42.9.1 Each Party shall ensure that personnel with access to Personal Data are trained in information security and data protection requirements appropriate to their role.
42.10 DOCUMENTATION AND RECORD PRESERVATION
42.10.1 Each Party shall maintain documentation and records reasonably necessary to demonstrate compliance with its obligations under this Agreement.
42.10.2 Each Party shall ensure that documentation or records containing Personal Data are retained and disposed of securely.
43. SCHEDULE 4: AUTHORISED OFFICERS AND SIGNATORIES
43.1 PKB Data Protection Officer
David Grange, dpo@patientsknowbest.com.
43.2 Party A
Patients Know Best Ltd
PATIENTS KNOW BEST LIMITED, a company limited by shares and registered in the United Kingdom with company registration number 06517382, whose registered office is at St John's Innovation Centre, Cowley Road, Cambridge CB4 0WS.
Executed by:
Name: ___________________________
Title: ___________________________
Signature: ___________________________
Date: ___________________________
43.3 Party B
[Full Legal Name of Provider]
[Provider], a company incorporated in [Jurisdiction] (Company No. [●]) whose registered office is at [●].
Executed by:
Name: ___________________________
Title: ___________________________
Signature: ___________________________
Date: ___________________________
Revision History
Version | Date | Editor | Reviewer | Approver | Description |
1.0 | [Insert Date] | Shriti Raikundalia |
|
| Reformatted to align with PKB NHS Data Processing Contract style and structure; selected clauses copied from the standard NHS DPC for applicability review. |