Roles
- Controller: care home management.
- Processor: the software vendor.
- Data Protection Officer (DPO): may be mandatory under GDPR Article 37 and applicable national law when legal criteria apply (e.g. large-scale processing of special categories of data). There is no automatic threshold by bed count; see your supervisory authority guidance.
Technical checklist
- AES-256-GCM encryption at rest and in transit.
- Immutable audit of every clinical access.
- Mandatory multi-factor authentication for privileged roles.
- Encrypted backups with verified quarterly restoration.
- Centralised logs with retention >= 12 months.
- No providers outside the EU in the production data path.
Organisational checklist
- Up-to-date record of processing activities (RoPA).
- Data Protection Impact Assessments (DPIA) for each new critical flow.
- Incident management policy with 72-hour deadline.
- Processor agreements signed with every vendor.
- Internal policies for rights management (access, rectification, erasure, restriction, portability, objection) with 30-day deadline.
Contractual checklist
- Standard EU clauses for sub-processors.
- Exit guarantee with data in standard format.
- Penalisable SLA for incidents without response.
Want to download it in Excel? Request it and we will adapt it to your centre.
