UK GDPR
UK GDPR lab software, hosted in the UK.
UK labs use uk.labdesk.app. Patient data, backups, AI processing and result emails stay in London, on a stack kept apart from our US service.

UK hosting
Your patients' data stays in the UK.
uk.labdesk.app runs in the AWS London region on its own stack. It has separate databases, file storage, logs and backups from app.labdesk.app, so UK patient data is not copied to the US.
- Hosting, database and backups in London
- AI flags and summaries processed in London
- Result emails sent from London
- Encrypted in transit and at rest

Roles
Your lab is the controller. Lab Desk is the processor.
You decide why and how patient data is used. We process it on your instructions, under a written agreement.
Your lab, the controller.
You choose what to collect, who to share results with and how long to keep records.
Lab Desk, the processor.
We store and process patient data only to run the service for your lab.
A Data Processing Agreement.
Covers safeguards, the sub-processor list, data location, incident notice, patient rights help and deletion.
Patient rights
Answer patient requests from their record.
Access.
See everything held about a patient in one record, with its full history.
Export.
Export one patient's record as PDF plus CSV or JSON for access and portability requests.
Correction.
Fix a record. Every change is logged, so you can show what changed and when.
Deletion.
Delete on request, subject to the retention settings your lab chooses. Deletions are logged.
Consent record.
Each patient's consent to email and link delivery is recorded on their record.
Human review.
Staff approve every AI flag and summary, so no decision about a patient is fully automated.
Incidents
Breach notice in time for the ICO's 72 hours.
Every incident is logged. If one affects your patients' data, we notify your lab without undue delay, so you can report to the ICO within 72 hours where required.
- Incident register kept by Lab Desk
- Details your lab needs for its own report
- A written summary of what happened and what we did

Payments
Stripe, with health data kept out.
Patient payments run through Stripe, which works outside the UK. We keep health data out of what Stripe receives: only the invoice number and amount. Stripe covers the transfer under the UK terms in its data processing agreement (the UK IDTA or UK Addendum).
- No results or test names sent to Stripe
- Card details handled by Stripe, never stored by Lab Desk
- Payouts in GBP to your own Stripe account

Frequently asked questions
Is Lab Desk GDPR compliant?
Yes, including UK GDPR for labs in the UK. UK labs use uk.labdesk.app, hosted in London.
Does any UK patient data go to the US?
Patient records, backups, AI processing and result emails stay in the UK. Stripe works outside the UK, so we send it only the invoice number and amount, never results or test names.
Who is the controller?
Your lab. Lab Desk is the processor and acts only on your instructions under our DPA.
How do I handle a subject access request?
Open the patient's record and export it as PDF plus CSV or JSON. Corrections and deletions are made from the same record.
Do I still need to register with the ICO?
Most labs must pay the ICO data protection fee. It is a registration, not a certificate. Check with the ICO or your adviser.
Not legal advice
These pages describe the safeguards Lab Desk provides. They are not legal advice. Please confirm your own obligations with your legal or compliance adviser.
A UK lab looking for UK hosting?
Join early access, or talk to us about our DPA.