Glossary

UK GDPR

The UK's main data protection law, which sets rules for handling personal data, including health data.

What is UK GDPR?

UK GDPR is the United Kingdom's version of the EU General Data Protection Regulation, kept in UK law after Brexit. It works alongside the Data Protection Act 2018 and is overseen by the Information Commissioner's Office (ICO).

Key ideas for labs

  • Special category data: health data gets extra protection. Using it needs a lawful basis plus an additional condition, such as the provision of health care.
  • Controllers and processors: the lab usually decides why and how data is used (the controller). A software vendor acting on the lab's instructions is a processor and needs a written contract with the lab.
  • Individual rights: patients can ask to access, correct and in some cases delete their data.
  • Breach reporting: reportable breaches must go to the ICO within 72 hours of the organization becoming aware of them.
  • International transfers: sending personal data outside the UK needs suitable safeguards.

Most organizations that process personal data also pay a data protection fee to the ICO.

This is a plain-language summary for general information, not legal advice. Check the current rules with a qualified adviser for your lab.

How Lab Desk handles it

UK labs use uk.labdesk.app, hosted in the UK, so UK patient data stays in the UK. Lab Desk signs a Data Processing Agreement with each lab. See UK GDPR at Lab Desk and data residency.

Related terms

  • PIPEDA: Canada's federal privacy law for how private-sector organizations collect, use and share personal information.
  • HIPAA: The US law that sets national rules for protecting the privacy and security of health information.
  • PHI (protected health information): Health information that can identify a person and is held or shared by a HIPAA covered entity or its business associate.

Manage patients. Share results. Get paid. All from one desk.

Join early access and be one of the first labs on Lab Desk.