Trust Keith resources

Data Protection for HealthTechs | Trust Keith

Written by Trust Keith | Jul 30, 2026, 2:57:09 PM

Quick answer: Health data counts as special category data under UK GDPR, so HealthTechs work under tighter lawful bases, near-mandatory DPIAs, and a level of scrutiny from the ICO, NHS procurement teams and investors that most scale-ups never encounter. Getting this right isn't extra paperwork bolted onto a generic GDPR programme, it's a different starting point altogether. Trust Keith works with UK HealthTechs specifically because a standard compliance checklist doesn't cut it here.

 

Why HealthTechs Face Heightened Regulatory Scrutiny

Every scale-up handling personal data has obligations under UK GDPR. HealthTechs have all of those, plus a few more, and the stakes attached to getting it wrong are higher.

That's because health data isn't just sensitive in the abstract. If it's mishandled, the consequences for the person it belongs to can be serious and lasting: it can affect employment, insurance, relationships and how someone is treated by the very services meant to help them. Regulators know this, which is why health data sits in its own protected category under the law rather than being treated like a name or an email address.

It also means HealthTechs get more attention from more directions at once. The ICO treats health data as a priority area. NHS trusts and Integrated Care Systems run their own supplier assurance processes before they'll let a HealthTech near patient data. Investors doing due diligence on a health-data business ask sharper questions than they would of a generic SaaS company, because they know the downside risk is bigger too.

None of this means HealthTechs need to be afraid of growth. It means the compliance foundation has to be built properly from the start, not retrofitted once a big NHS contract or funding round is already on the table.

 

What Counts as Special Category Health Data

Under UK GDPR Article 9, health data is a special category of personal data, alongside things like genetic data, biometric data used for identification, and information about a person's sex life or sexual orientation. Processing it is prohibited by default unless you can point to one of a short list of specific conditions that allow it.

The obvious examples are easy to spot: diagnoses, prescriptions, treatment records, mental health notes, test results. HealthTechs usually get those right without much prompting.

Where it gets trickier is the data that isn't obviously "health data" on its face, but reveals health information once you look at what it actually tells you. A step-tracking app knows a lot more than step counts. A wellbeing platform that flags mood patterns is processing information about mental health, whether it labels it that way or not. Search terms, symptom-checker inputs and even purchase history from a health app can count as special category data if they let you infer something about a person's physical or mental health.

This is one of the most common gaps Trust Keith sees in HealthTechs: a data map that lists the obvious clinical fields, but misses the inferred and behavioural health data sitting quietly in analytics events and product logs.

 

The Lawful Bases HealthTechs Actually Rely On

Processing special category data legally means clearing two hurdles, not one. You need a standard lawful basis under Article 6, the same one every business needs for any personal data, and a separate condition under Article 9 specifically for the special category element.

Explicit consent is the one most people reach for first, and it does work, but it's not always the most practical or robust choice for a product that needs to keep functioning even if someone withdraws consent, or that processes health data as a core part of delivering care rather than as an optional extra.

Other Article 9 conditions HealthTechs commonly rely on

  • Health or social care purposes, where processing is necessary to provide care or treatment, under the responsibility of a health professional or someone bound by an equivalent duty of confidentiality.
  • Public health, where processing is necessary for reasons of public interest in the area of public health, such as monitoring outbreaks or ensuring quality and safety of care.
  • Substantial public interest conditions, a set of specific, narrower conditions set out in UK law that can apply to things like safeguarding or research, each with its own extra requirements.

Which condition fits depends entirely on what your product actually does, not what sounds most reassuring in a privacy policy. This is exactly the kind of decision that should be documented and revisited every time the product changes, not decided once and forgotten.

 

NHS DSPT: What HealthTechs Need to Know

If your product touches NHS data or NHS systems in any way, you'll run into the NHS Data Security and Protection Toolkit, usually shortened to the DSPT. It's an annual self-assessment against a set of data security and protection standards, and for most HealthTechs working with the NHS, it's non-negotiable rather than a nice-to-have.

The DSPT covers areas like staff training and awareness, access controls, incident management, and how you handle third-party suppliers of your own. It's reassessed every year, and letting it lapse or drift out of date is one of the fastest ways to stall or lose an NHS contract.

The tricky part usually isn't the assessment itself, it's keeping the evidence behind it current all year round. A DSPT submission that's accurate in April and stale by October doesn't actually reflect reality, and NHS procurement teams increasingly expect ongoing evidence, not just a certificate.

 

ICO Enforcement Trends in Health and HealthTech

The ICO's guidance makes clear that health data processing gets closer scrutiny than most other categories, and its enforcement record reflects that. The regulator has repeatedly focused on a handful of recurring problems in the health sector: weak security around large datasets, data sharing between organisations that wasn't properly documented or authorised, and consent mechanisms that didn't hold up once actually tested.

None of these are exotic failures. They're the kind of gaps that build up when a HealthTech is moving fast, adding integrations, and treating data protection as something to circle back to later. The ICO doesn't tend to see it that way, and health data incidents attract a level of attention that a generic SaaS breach usually doesn't.

The practical takeaway isn't to be more scared, it's to make sure the basics are genuinely in place: an accurate record of what data you hold and why, documented data sharing agreements with every partner, and security measures that match the sensitivity of what you're protecting.

 

 

What NHS Procurement Teams Look For

Selling into the NHS means passing through a supplier assurance process before a contract gets anywhere near signature. Procurement and information governance teams typically want to see evidence, not assurances, that includes:

  • A current DSPT submission, ideally with supporting evidence that's actually kept up to date, not just refreshed once a year under deadline pressure.
  • A Data Protection Impact Assessment for the specific product or service being procured, showing the risks were considered and addressed, not just acknowledged.
  • An up to date record of processing activities, mapping what data moves where and why.
  • A tested incident response plan, specific to health data, with clear timelines for how a breach involving NHS data would be handled and reported.
  • Signed data processing agreements with every sub-processor that touches the data in question.

Trust Keith's customers who sell into the NHS use the platform as exactly this kind of evidence base: a live, current record they can hand over during procurement, rather than a set of documents someone has to dig out and hope are still accurate.

 

Building a Data Protection Programme for Clinical Partnerships

A data protection programme built for a generic scale-up usually isn't built for the pace and scrutiny of clinical partnerships. HealthTechs need a few things layered on top.

New features that touch health data need a DPIA (Data Protection Impact Assessment) before launch, not after something goes wrong. Data sharing agreements with NHS trusts and other clinical partners need to be specific about what's shared, why, and for how long, rather than relying on a generic template. Incident response needs a lower threshold for what counts as serious, because a small issue involving health data can escalate faster, both practically and reputationally, than the equivalent issue with less sensitive data.

All of this needs someone accountable for it, and this is where a lot of HealthTechs hit a genuine fork in the road. An in-house person who owns this can be brilliant, they know the product and the partnerships inside out and they're available whenever something comes up. The real weakness isn't their competence, it's continuity. If they're also running product, ops or something else day to day, keeping genuine independence is hard, and if they're on leave or they leave the company, there's often nobody else who knows the role well enough to step in.

An outsourced DPO service solves the continuity problem differently. It's not a project, it's ongoing support, exactly like having someone in-house, just sitting outside the business with genuine independence built in. Trust Keith matches HealthTech customers with an expert who gets to know their processing and their clinical partnerships the way an in-house hire would, backed by a full team of DPOs rather than working alone, so if that person is ever unavailable, someone else can step in immediately. Cover doesn't lapse, and momentum on staying compliant doesn't stall either.

 

Frequently Asked Questions

Do HealthTechs always need a Data Protection Officer?

Not automatically, but many do. Under Article 37, a DPO is mandatory if your core activities involve large-scale processing of special category data, which describes a large share of HealthTechs by definition. Even where it's not strictly mandatory, most HealthTechs benefit from DPO-level oversight given the risk involved.

What's the difference between health data and special category data?

Health data is one of several types of special category data defined under Article 9, alongside things like genetic data, biometric data and data about sexual orientation. All health data is special category data, but special category data covers more than just health information.

Do we need a DPIA for every new product feature?

Not every feature, but any feature likely to result in high risk to individuals, which for a HealthTech usually includes anything involving new special category data processing, new automated decision-making, or new data sharing arrangements.

What's the NHS DSPT, and do we have to have it?

The NHS Data Security and Protection Toolkit is an annual self-assessment against national data security standards. If your product touches NHS data or systems, having a current, accurate DSPT submission is generally a requirement for doing business with the NHS, not an optional extra.

How is data protection different for a HealthTech compared to other scale-ups?

The core UK GDPR obligations are the same, but HealthTechs face tighter lawful basis requirements, more frequent DPIAs, sector-specific frameworks like the DSPT, and closer scrutiny from regulators, procurement teams and investors alike.

 

None of this is a reason to slow down. It's a reason to make sure the groundwork is solid before an NHS contract, an investor data room, or an ICO enquiry puts it to the test.

If you're building out that groundwork, a few related reads worth a look: how to prepare for an ICO investigation covers what to have ready before the regulator ever comes knocking, and what happens after a data breach walks through the steps if something does go wrong. If you're earlier in building out the function itself, the DPO's guide to running a privacy programme at a scale-up and what a DPO actually does are both useful starting points. And if you're weighing up hiring against outsourcing that role, how to choose the right DPO service provider covers what to look for.

If any of this still feels uncertain, or you'd like to talk it through with someone who's actually handled NHS procurement and clinical data partnerships before, you're welcome to book some time with our team. We're happy to see how we can help.