Form PAT-01
Patient Data & UK GDPR
Accrual acts as a processor for the sites it serves. This page explains what that means under the UK GDPR, what our AI does with patient identifiable data, and — importantly — what we never do with it.
Effective 15 August 2026
1. Our role
A research site — an NHS trust, a health board, or an independent provider — is the controller. It holds the relationship with the patient, it holds the record, and it determines the purposes and means of processing. Accrual is a processor: we process patient identifiable data on the site's documented instructions, under an executed Article 28 data processing agreement, and for no other purpose.
We do not have our own independent right to use patient data. Every permitted use flows from the site's authority and the terms of the DPA. Where a site operates a Caldicott Guardian function, the purpose is agreed through it before any record is read.
2. What we do with patient data
We read the record to determine whether the patient may meet the eligibility criteria of an open protocol, and we surface that determination to the site's own clinicians and research staff.
Health data is special category data under Article 9 of the UK GDPR. The site sets the Article 6 and Article 9 conditions in the DPA — ordinarily public task and scientific research purposes — and discharges the common law duty of confidentiality through the direct care relationship, patient consent, or Confidentiality Advisory Group support under section 251 of the NHS Act 2006 where that applies. Study-level approvals from the Health Research Authority and a Research Ethics Committee remain the sponsor and site’s to hold; Accrual does not stand in for them.
Screening is continuous rather than one-off: as a record changes and as protocols open and close, the determination is recomputed. The scope of that processing does not widen because it repeats.
3. What sponsors receive — and do not
This is the question we are asked most, so we will be direct about it.
Sponsors and CROs never receive patient identifiable data from Accrual. They do not receive names, NHS numbers, dates of birth, records, or individual-level data of any kind.
What a sponsor receives is aggregate, anonymised population evidence about a site's capacity to enrol: counts, distributions, and forecasts derived from them. Where a count is small enough that it could reasonably identify an individual, it is suppressed rather than reported. Anonymisation follows the ICO's anonymisation guidance and standard small-number suppression practice, and the method applied to a given deliverable is recorded.
A patient is only ever contacted by their own care team at the site. Accrual does not contact patients, and does not enable a sponsor to.
4. How the AI is constrained
Accrual applies language models to read unstructured clinical narrative — notes, pathology and imaging reports, discharge summaries — alongside structured fields, because eligibility criteria are written against all of it. The following constraints are terms of the agreement, not aspirations.
- Patient identifiable data is never used to train or fine-tune models, and is never pooled across sites for that purpose.
- Any model provider in the processing path is bound to zero data retention and to no training on submitted data.
- Every criterion determination cites the span of the record that produced it; a determination without a citation is suppressed rather than surfaced.
- Where the record cannot settle a criterion, the output is an explicit flag for human review, not an inferred answer.
- The system takes no autonomous action regarding any patient, and makes no eligibility determination. It produces a shortlist for the site's clinical staff.
Every read of a record is logged with the model version, criteria set, cited evidence and the reviewing coordinator's disposition, so the site can audit what was done and on what basis.
5. Data minimisation
We request the narrowest data set that supports the determination, and we hold it for the period the DPA specifies. Where a site prefers to restrict categories of record — mental health notes, sexual health records, or gender identity information, for instance, all of which carry heightened confidentiality expectations — that restriction is configured at the site level and enforced in processing, not left to policy.
6. Safeguards
- Organisational: workforce training, sanction policy, access authorisation and periodic review, documented incident response.
- Physical: processing in access-controlled UK facilities operated by our infrastructure providers.
- Technical: encryption in transit and at rest, unique user identification, automatic session timeout, audit controls, and integrity verification.
We are working towards NHS Data Security and Protection Toolkit "Standards Met" status, which most trusts require before a data-sharing arrangement is signed. Our current position — including what is not yet in hand — is stated on the Security page rather than implied here.
Sub-processors that touch patient data are bound by downstream agreements no less protective than our own DPA, and are listed on the Subprocessors page.
7. Breach notification
On becoming aware of a personal data breach we notify the affected site without undue delay, with the information the site needs to make its own assessment and its own notifications. The site, as controller, notifies the Information Commissioner’s Office within 72 hours where the breach meets the threshold, and notifies affected individuals where the risk to them is high.
8. Patient questions
If you are a patient with a question about your record, contact the NHS trust, health board or clinic that holds it. They are the controller and the right party to answer, and to action any request to access your record, have it corrected, or object to a particular use of it.
We will always route a patient request to the relevant site rather than answering it ourselves, because we cannot verify identity or authority and the site can. You may also complain to the Information Commissioner’s Office at ico.org.uk.
9. Sites outside the UK
The UK GDPR and the Data Protection Act 2018 are the framework we build to. Sites in other jurisdictions are covered by the equivalent local instrument — HIPAA in the United States, where the site is a Covered Entity and Accrual signs a Business Associate Agreement rather than an Article 28 DPA; the EU GDPR with the relevant national health-data provisions; PIPEDA and provincial health legislation in Canada. The operating principle is identical everywhere: the site controls, we process, sponsors see aggregates only.
Where personal data would leave the UK we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy regulation. UK-only data residency is available and is agreed in the order form rather than assumed here.
Pre-launch notice. These documents are drafted as realistic scaffolding for a clinical-data company and have not been reviewed by counsel. Entity details, postal address, data protection officer and the subprocessor roster are placeholders pending incorporation. Do not rely on them as executed legal terms.