Data Protection Impact Assessment (DPIA)

Conducted in accordance with UK GDPR Art. 35 and WP248 (rev.01) — Edition: 2026-05-26

1. Necessity and scope of the assessment

This DPIA is published by Project Line, the data processor for the Intelligent Clinic Management Platform. Under Art. 35(3)(b) UK GDPR, processing of special-category health data on a large scale meets the mandatory-DPIA threshold. Three criteria of the EDPB-endorsed list of mandatory-DPIA operations (WP248 rev.01, criteria 1, 4 and 7) are met: special-category data + automated decisions informing services + innovative-technology (AI voice agent).

2. Description of processing

ItemDescription
NatureHosting of clinic + patient health records, AI voice receptionist (real-time; calls not recorded), AI visit-scribe transcription, automated SMS/WhatsApp reminders.
ScopePatients of clinics that license the Service. Volume scales with clinic count.
ContextB2B SaaS; clinic = controller, Project Line = processor.
PurposesAppointment scheduling, electronic health records, billing, reminders, AI clinical-decision-support (non-binding).
Data categoriesName, contact, date of birth, identity document numbers, medical history, prescriptions, payment metadata (tokenised — no PAN).
Data subjectsPatients (including minors, whose data is processed only with verified parent / legal-guardian consent), clinic staff, clinic owners.
RetentionActive duration of the licence + 30 days grace + minimum statutory retention (7–30 years, depending on the country).

3. Lawful basis

4. Necessity and proportionality

Each processing operation is mapped to a specific clinical or administrative purpose. Data minimisation: only fields required for that purpose are collected. Pseudonymisation in audit logs. Granular access controls at the per-clinic boundary; cross-clinic data access is technically impossible.

5. Risks to data subjects

RiskLikelihoodSeverityMitigation
Unauthorised access to medical dataLowHighPer-tenant SQL isolation, TLS 1.2+, AES-256 at rest, optional MFA (TOTP) available for clinical roles, PIN lockout, audit log with hash chain, outbound budget guard.
AI hallucination influencing clinical decisionMediumHighVoice agent prompts present suggestions as documentation only; the treating clinician retains all clinical authority. Disclaimers in agreement.
Undisclosed AI interactionLowHighMandatory AI-disclosure announcement in the patient's language at call start (and, where the clinic also serves patients in the EU, EU AI Act Art. 50); per-patient AI-processing consent captured + versioned. Calls are not recorded.
Sub-processor incidentLowMediumCore sub-processors: Azure / OpenAI / Twilio / Meta / Zoho (transactional e-mail). Optional payment + invoicing (clinic opt-in): Stripe / PayPal / Cardcom / Tranzila / PayPlus / Meshulam / Green Invoice / iCount. Optional OAuth (clinic opt-in): Google / Microsoft. Optional US insurance-claims clearinghouse (clinic opt-in, US clinics only): Stedi. Each has binding DPA. 30-day notice on changes.
Cross-border transferLowMediumEU SCCs (EU GDPR) / UK IDTA or UK Addendum B1.0 + TRA (UK GDPR) for transfers; Azure Israel Central region by default.
Lengthy retentionLowMediumTermination workflow hard-deletes data after 30-day grace; statutory retention windows enforced.
Processing of minors' dataLowHighPatients under 18 are flagged; consent is blocked server-side unless a parent / legal guardian signs (guardian name + relationship recorded, encrypted). Minors' data receives the same per-tenant isolation, AES-256 encryption and AI-disclosure as all patient data.

6. Consultation

Each clinic, as controller, is invited to review and add jurisdiction-specific risks before processing. Feedback channel: support@projectlineil.com.

7. Residual risk and conclusion

After application of the mitigations the residual risk is assessed as LOW. Prior consultation with the supervisory authority under Art. 36(1) UK GDPR is not required at present, but Project Line will consult the ICO again if a future processing operation materially increases the risk.

8. Review schedule

This DPIA is reviewed annually and whenever a sub-processor changes, a new data category is added, or applicable supervisory-authority guidance is updated.

© 2026 Project Line. All rights reserved.