<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Iniver Consultants]]></title><description><![CDATA[Iniver]]></description><link>https://www.iniver.co.uk/blog</link><generator>RSS for Node</generator><lastBuildDate>Mon, 05 Oct 2026 00:48:14 GMT</lastBuildDate><atom:link href="https://www.iverconsult.com/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[What does a Data Protection Officer actually do for a HealthTech company?]]></title><description><![CDATA[A valuable asset or a tick-box appointment? The role of a Data Protection Officer has long been established in law, but across healthtech it is appointed and utilised in different ways, quite different to that of other roles such as Clinical Safety Officers (CSOs). So, what is a DPO, do healthtech companies need one, and what should organisations look out for when appointing one? The starting point. The first thing to note is that the DPO is a statutory role. This means the individual...]]></description><link>https://www.iniver.co.uk/post/what-does-a-data-protection-officer-do-healthtech</link><guid isPermaLink="false">6aad320bcdf7791cf534a62e</guid><category><![CDATA[Outsourcing Solutions]]></category><category><![CDATA[Outsourced Data Protection Officer]]></category><pubDate>Fri, 18 Sep 2026 12:51:37 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/nsplsh_79d7e515c288483d9d8b0ca55f0fa1f5~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[What the CNIL's €5 Million Fine Against IQVIA Means for Health Research Organisations]]></title><description><![CDATA[In May 2026, the French data protection authority (CNIL) fined the French arm of the global clinical research company IQVIA €5 million in relation to two health research databases. Whilst the decision was made under French data protection law, and some of the findings relate specifically to French requirements, there are important lessons that health research organisations across the UK and EU should pay attention to. Background In France, IQVIA operates two major health data warehouses: LRX...]]></description><link>https://www.iniver.co.uk/post/iqvia-cnil-fine-gdpr-lessons-health-research</link><guid isPermaLink="false">6a6212f5424f5a9980a4bffc</guid><category><![CDATA[Data Protection Tips]]></category><pubDate>Wed, 22 Jul 2026 23:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/a63f69c8d7954fd4bc97169150b7cca8.jpg/v1/fit/w_1000,h_851,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[Where Can You Get an Outsourced Data Protection Officer (DPO)?]]></title><description><![CDATA[The short answer: you can appoint an outsourced Data Protection Officer through a specialist data protection consultancy. An outsourced DPO performs the full statutory DPO role under UK GDPR and EU GDPR on a service contract, so you get senior expertise without recruiting a full-time post. At Iniver, that means a named, experienced DPO for a fixed monthly fee, with no hour banks or consultancy credits. "Where can we get an outsourced DPO?" is one of the most common questions when it comes to...]]></description><link>https://www.iniver.co.uk/post/where-can-you-get-an-outsourced-data-protection-officer-dpo</link><guid isPermaLink="false">6a4f561038b98d875b8ad55e</guid><pubDate>Thu, 09 Jul 2026 08:10:14 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_283e7d4befa84e5f9b4bf310d9094b90~mv2.jpeg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[What Is a Data Processing Agreement (DPA)? When You Need One and What It Must Include]]></title><description><![CDATA[If you've ever signed up to a CRM, payroll system, cloud hosting provider or marketing platform, you've probably been presented with a Data Processing Agreement (DPA). But what is a DPA, when do you need one, and what should it contain? A Data Processing Agreement is one of the most important documents in UK GDPR compliance. It governs how a third party handles personal data on your behalf and helps ensure both organisations understand their responsibilities. In this guide, we'll explain:...]]></description><link>https://www.iniver.co.uk/post/what-is-a-data-processing-agreement-dpa-when-you-need-one-and-what-it-must-include</link><guid isPermaLink="false">6a452137463386a451655b9b</guid><category><![CDATA[Data Protection Tips]]></category><pubDate>Wed, 01 Jul 2026 14:40:08 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_9b48605888ba47b195147346aea17ad4~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[6-Month Data Protection in Health Wrap-Up]]></title><description><![CDATA[It's been a busy first half of the year for data protection in health. From alleged inappropriate access to patient records, to questions around de-identified health datasets and continued scrutiny of the NHS Federated Data Platform, a few clear themes are emerging. Just because you have access, doesn’t mean you should access. In May, we saw the news that two hospitals had taken action against their staff for accessing Personal Data in relation to local tragedies for which they had no...]]></description><link>https://www.iniver.co.uk/post/6-month-data-protection-in-health-wrap-up</link><guid isPermaLink="false">6a3ce642433568818447f083</guid><category><![CDATA[Data Protection Tips]]></category><pubDate>Thu, 25 Jun 2026 10:51:12 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_880c7b78f2784cb48e182e145a301663~mv2.jpeg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[The NHS SBS Healthcare AI Solutions Framework and the importance of data protection.]]></title><description><![CDATA[The NHS SBS Healthcare AI Solutions Framework is a framework for health AI companies, closing on 21 July. Data protection plays a key role throughout the tender, and highlights the importance of having the right governance in place for successful NHS adoption. Having a privacy notice, completing the Data Security and Protection Toolkit (DSPT), and having some policies and procedures in place are no longer enough on their own. Your data protection governance comes into play across the...]]></description><link>https://www.iniver.co.uk/post/the-nhs-sbs-healthcare-ai-solutions-framework-and-the-importance-of-data-protection</link><guid isPermaLink="false">6a350dd33306f881e52188fd</guid><category><![CDATA[Data Protection Tips]]></category><pubDate>Fri, 19 Jun 2026 10:21:46 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/e55b24370d50452987eb5c86568e1d3b.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[When Does a Healthtech Actually Need a DPO?]]></title><description><![CDATA[One of the most common questions about data protection from healthtech founders is: “Do we actually need a Data Protection Officer yet, or is that something for later?” It’s a good question. Most healthtechs are moving fast, building products, working towards NHS adoption or enterprise deals, and trying not to over‑engineer governance too early. But data protection, and specifically when a healthtech needs a DPO,  is one of those areas which can cause not just legal issues, but also can stunt...]]></description><link>https://www.iniver.co.uk/post/when-does-a-healthtech-need-a-dpo</link><guid isPermaLink="false">69e751290294e8c3f3eda0c2</guid><category><![CDATA[Outsourced Data Protection Officer]]></category><pubDate>Wed, 22 Apr 2026 09:45:32 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_d97472bf344041228d3ff324ec5edf57~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[Do We Need a DPO? A Practical Checklist for Healthtech Founders]]></title><description><![CDATA[For many healthtech founders, the Data Protection Officer (DPO) question doesn’t come up because of regulation alone, it usually surfaces during procurement, NHS assurance, or a moment of growth where governance starts to matter more. This checklist is designed to help you sense‑check where you are now, and whether appointing a DPO should already be on your roadmap. Healthtech DPO Requirement Checklist Work through the sections below honestly.If you tick any one item in the first section,...]]></description><link>https://www.iniver.co.uk/post/do-we-need-a-dpo-healthtech-checklist</link><guid isPermaLink="false">69e8960c8b2f11ff8e5ba027</guid><category><![CDATA[Outsourced Data Protection Officer]]></category><pubDate>Wed, 22 Apr 2026 09:41:34 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/be2c632522231bd3c200e58f5dc4b4a4.jpg/v1/fit/w_1000,h_683,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[Managing Subject Access Request (SARs) Under UK GDPR: A Practical Guide for UK Organisations]]></title><description><![CDATA[Subject Access Requests (SARs), also known as Data Subject Access Requests (DSARs), can be a compliance headache for many organisations. Whislt the right for data subjects to request copies of their personal data has been around long before the introduction of the General Data Protection Regulation (GDPR), it feels that more are becoming increasing broader and complex. Handled well, DSARs demonstrate transparency and accountability. Handled poorly, they expose organisations to ICO complaints,...]]></description><link>https://www.iniver.co.uk/post/managing-subject-access-requests</link><guid isPermaLink="false">69d516e3fc74251ed3c31b9b</guid><category><![CDATA[Data Protection Tips]]></category><category><![CDATA[Outsourcing Solutions]]></category><pubDate>Tue, 07 Apr 2026 14:42:08 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/2223f083ac395d233dbf0d745b39eef2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[A Complete Guide to the NHS DSPT for HealthTech Companies (and How to Get Support)]]></title><description><![CDATA[Everything you need to know to meet the 30 June 2026 deadline with confidence. For organisations that handle NHS data , completing the NHS Data Security and Protection Toolkit (DSPT)  is a mandatory self-assessment tool that must be completed annually. Yet for many healthtech teams, the DSPT can feel confusing, time‑consuming, and difficult to navigate without specialist guidance. This article breaks down the DSPT in clear, practical language and provides step‑by‑step insight into what’s...]]></description><link>https://www.iniver.co.uk/post/a-complete-guide-to-the-nhs-dspt-for-healthtech-companies-and-how-to-get-support</link><guid isPermaLink="false">69b16c348d8bebb92401f35f</guid><category><![CDATA[Data Protection Tips]]></category><pubDate>Wed, 11 Mar 2026 15:17:35 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_0df7b4a726db4d0faa2759d6a027fd14~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[Data Protection Requirements for DTAC 2026: A Complete Guide for HealthTech Companies]]></title><description><![CDATA[As DTAC Version 2  launches in  2026 , HealthTech companies preparing for NHS adoption need a clear understanding of what the updated Digital Technology Assessment Criteria  requires, especially around data protection , DSPT , ICO registration , and DPIA obligations . With the NHS simplifying DTAC and reducing duplication across frameworks, strong data‑protection compliance is  a key way to support procurement and build trust with NHS organisations. What Is DTAC? (Digital Technology...]]></description><link>https://www.iniver.co.uk/post/data-protection-requirements-for-dtac-2026-a-complete-guide-for-healthtech-companies</link><guid isPermaLink="false">69aeb1dd6b9018dbd07011d6</guid><category><![CDATA[Data Protection Tips]]></category><pubDate>Mon, 09 Mar 2026 13:44:46 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_bd6497ded9a241cd8092c1f6d1b48e6b~mv2.jpeg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[GDPR Code of Practice for Contract Research Organisations (CROs)]]></title><description><![CDATA[A Practical Guide to the European CRO Federation Code of Conduct . In early 2026, the Contract Research Organisation (CRO) Code of Practice made a major leap forward when the French Supervisory Authority (CNIL) approved the supervisory body responsible for overseeing the Code of Conduct. This milestone brings CROs closer to a formally recognised, GDPR‑aligned compliance framework tailored specifically to clinical research service providers. If you’re a CRO operating in clinical trials,...]]></description><link>https://www.iniver.co.uk/post/gdpr-code-of-practice-for-contract-research-organisations-cros</link><guid isPermaLink="false">6995dbd7658df599f4fb7bef</guid><pubDate>Thu, 19 Feb 2026 12:33:56 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_c5d5574f871a437390f3d88cd7f6062d~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[Utilising ‘Recognised Notifiable Purposes’ (RPNS) to Support Data Subjects.]]></title><description><![CDATA[A thought piece into whether establishing 'Recognised Notifiable Purposes' could support data subjects understanding of processing.]]></description><link>https://www.iniver.co.uk/post/utilising-recognised-notifiable-purposes-rpns-to-support-data-subjects</link><guid isPermaLink="false">698f55526e0eff1a485933d0</guid><pubDate>Fri, 13 Feb 2026 17:01:03 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_e111fd73a30f47b298514936d08efff0~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[Are You a Data Controller or Processor? A Practical Guide for Organisations]]></title><description><![CDATA[This blog explains how organisations can determine whether they are acting as a Data Controller, Joint Controller or Data Processor under UK and EU GDPR, why the distinction matters, and how this interactive tool helps simplify the decision‑making process.]]></description><link>https://www.iniver.co.uk/post/controller-vs-processor-gdpr-guide</link><guid isPermaLink="false">697b2f2bdbf46e99c1e9d547</guid><category><![CDATA[Data Protection Tips]]></category><pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_879e5c7a896249ac9d5366936767425d~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item><item><title><![CDATA[Five things to consider before appointing an Outsourced Data Protection Officer ]]></title><description><![CDATA[Not sure what to look for in an Outsourced DPO? Use this helpful checklist.]]></description><link>https://www.iniver.co.uk/post/to-consider-when-appointing-dpo</link><guid isPermaLink="false">6964cb26f5f67715567387ba</guid><category><![CDATA[Outsourced Data Protection Officer]]></category><category><![CDATA[Outsourcing Solutions]]></category><category><![CDATA[Data Protection Tips]]></category><pubDate>Mon, 12 Jan 2026 11:03:30 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/nsplsh_e191237214754534a74c321ebf9bb2e3~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Joe Stock</dc:creator></item></channel></rss>