How CureCast supports
UK requirements.
Built to support UK GDPR and the Data Protection Act 2018, for plastic surgery, aesthetic, dermatology and medical spa practices handling special category health data.
The regulation that applies to your practice
UK healthcare practices, including plastic surgery, aesthetic surgery, dermatology, and medical spa practices handling patient data, are subject to UK GDPR and the Data Protection Act 2018 (DPA 2018), overseen by the Information Commissioner’s Office (ICO).
What Counts as Sensitive Data Here
Under UK GDPR Article 9, health data is classed as special category data, meaning it’s subject to stricter processing rules than general personal data. Patient photos, clinical records, and any patient-identifying information connected to treatment fall into this category.
Processing special category data for clinical care generally requires both a lawful basis under Article 6 and a specific Article 9 condition. For most clinical care, practices rely on the Article 9(2)(h) health or social care condition, together with a corresponding Schedule 1 condition under the DPA 2018, and typically need an Appropriate Policy Document documenting the safeguards in place.
Under UK GDPR, a personal data breach covers accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Where a breach is likely to result in risk to individuals, the ICO must generally be notified within 72 hours of the organization becoming aware of it.
Data residency & Data Processing Agreement
CureCast hosts UK data on AWS’s secure cloud infrastructure, encrypted at rest with AES-256 and protected in transit with TLS 1.3, with TLS 1.2 supported as a fallback.
UK law doesn’t require patient data to stay within the UK. NHS England’s own published guidance confirms health and care data can be hosted outside the UK when the right safeguards are in place. CureCast’s AWS infrastructure meets that bar. If your practice needs a specific regional hosting arrangement, our team can discuss it directly.
How CureCast supports UK Requirements
Frequently asked Questions
Is CureCast UK GDPR compliant?
CureCast supports UK GDPR requirements. There is no official third-party UK GDPR certification for software vendors. Each practice remains responsible for its own compliance.
Is patient data stored in the UK?
UK law doesn’t require patient data to stay within the UK. CureCast hosts UK accounts on AWS’s secure cloud infrastructure, encrypted at rest with AES-256. NHS England’s own guidance confirms offshore hosting is acceptable with the right safeguards in place.
What counts as a data breach under UK GDPR?
UK GDPR defines a breach as unauthorized access, disclosure, alteration, or destruction of personal data. Where a breach is likely to risk people’s rights and freedoms, it generally must be reported to the ICO within 72 hours of becoming aware of it.
Do I need a separate agreement with CureCast for UK use?
A UK-specific Data Processing Agreement is separate from any US-facing agreement. Contact CureCast to confirm the right agreement for your account.
How do patients send photos to CureCast securely in the UK?
Patients can upload photos through CureCast’s secure remote upload link. No app download or account creation is required on their end.

See How CureCast Fits Your Practice
Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.
Prefer email? [email protected]