UK GDPR & DPA 2018

How CureCast supports
UK requirements.

Built to support UK GDPR and the Data Protection Act 2018, for plastic surgery, aesthetic, dermatology and medical spa practices handling special category health data.

AWS infrastructure, encrypted at rest with AES-256, TLS 1.3 in transit
No requirement to keep patient data within the UK
Staff access, audit trail and device management scoped per clinic
Confidential Patient Access for special category health data
Also supports compliance for
HIPAA PHIPA Australia Privacy Act
๐Ÿ‡ฌ๐Ÿ‡ง
UK Account
UK GDPR-aligned controls
Active
Staff Access Control
Module & action-level, scoped per clinic
Audit Trail
Staff, device, IP & timestamp on every event
Device Management
End sessions on lost or stolen devices
Encryption
AES-256 at rest, TLS 1.3 in transit
๐Ÿ‡ฌ๐Ÿ‡ง Hosted on AWS ยท NHS England confirms offshore hosting is acceptable
Breach notice
Within 72 hours
Regulated by
ICO under UK GDPR

The regulation that applies to your practice

UK healthcare practices, including plastic surgery, aesthetic surgery, dermatology, and medical spa practices handling patient data, are subject to UK GDPR and the Data Protection Act 2018 (DPA 2018), overseen by the Information Commissioner’s Office (ICO).

What Counts as Sensitive Data Here

Under UK GDPR Article 9, health data is classed as special category data, meaning it’s subject to stricter processing rules than general personal data. Patient photos, clinical records, and any patient-identifying information connected to treatment fall into this category.

Processing special category data for clinical care generally requires both a lawful basis under Article 6 and a specific Article 9 condition. For most clinical care, practices rely on the Article 9(2)(h) health or social care condition, together with a corresponding Schedule 1 condition under the DPA 2018, and typically need an Appropriate Policy Document documenting the safeguards in place.

Under UK GDPR, a personal data breach covers accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Where a breach is likely to result in risk to individuals, the ICO must generally be notified within 72 hours of the organization becoming aware of it.

Data residency & Data Processing Agreement

CureCast hosts UK data on AWS’s secure cloud infrastructure, encrypted at rest with AES-256 and protected in transit with TLS 1.3, with TLS 1.2 supported as a fallback.

UK law doesn’t require patient data to stay within the UK. NHS England’s own published guidance confirms health and care data can be hosted outside the UK when the right safeguards are in place. CureCast’s AWS infrastructure meets that bar. If your practice needs a specific regional hosting arrangement, our team can discuss it directly.

How CureCast supports UK Requirements

Staff Access Control

Administrators control staff access to patient records, clinical photos, albums, and sensitive actions through module-level and action-level permissions. For multi-location practices, access is scoped to each clinic account.
See how staff permissions work โ†’

Audit Trail

CureCast records defined activity across patient records, files, clinical modules, consent workflows, and exports with staff, device, IP, and timestamp context. Filter and export in CSV or PDF.

See how audit trail works โ†’

Device Management

Administrators can review every device connected to their account and end a session when a device is lost, stolen, or no longer trusted. Deactivating a staff account ends sessions across their devices.

See how device-management work โ†’

Session Timeout

CureCast automatically ends inactive sessions after 2 hours on desktop and 4 hours on supported mobile devices, with a warning before logout and a required sign-in to continue.

Learn about reauthentication โ†’

Encryption

Patient records and clinical photos are encrypted at rest using AES-256 and protected in transit using TLS, with TLS 1.3 as the primary protocol and TLS 1.2 supported as a fallback.

Learn about Encryption โ†’

Confidential Patient Access

Mark a patient confidential and their record no longer appears in search results, patient lists, or before-and-after galleries for staff who don’t hold that specific permission. Only an administrator can grant it, per staff member.
Learn about Confidential Patient Access โ†’

1M+
Patient records managed on CureCast
10M+
Photos, videos and documents stored
4M+
Appointments managed
0%
Churn โ€” clinic stay because it works

Frequently asked Questions

Is CureCast UK GDPR compliant?

CureCast supports UK GDPR requirements. There is no official third-party UK GDPR certification for software vendors. Each practice remains responsible for its own compliance.

Is patient data stored in the UK?

UK law doesn’t require patient data to stay within the UK. CureCast hosts UK accounts on AWS’s secure cloud infrastructure, encrypted at rest with AES-256. NHS England’s own guidance confirms offshore hosting is acceptable with the right safeguards in place.

What counts as a data breach under UK GDPR?

UK GDPR defines a breach as unauthorized access, disclosure, alteration, or destruction of personal data. Where a breach is likely to risk people’s rights and freedoms, it generally must be reported to the ICO within 72 hours of becoming aware of it.

Do I need a separate agreement with CureCast for UK use?

A UK-specific Data Processing Agreement is separate from any US-facing agreement. Contact CureCast to confirm the right agreement for your account.

How do patients send photos to CureCast securely in the UK?

Patients can upload photos through CureCast’s secure remote upload link. No app download or account creation is required on their end.

Plastic surgeon using CureCast photo management app during patient consultation

See How CureCast Fits Your Practice

Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.

 

Prefer email? [email protected]