top of page

Outsourcing Solutions

A valuable asset or a tick-box appointment?


The role of a Data Protection Officer has long been established in law, but across healthtech it is appointed and utilised in different ways, quite different to that of other roles such as Clinical Safety Officers (CSOs). So, what is a DPO, do healthtech companies need one, and what should organisations look out for when appointing one?


The starting point.

The first thing to note is that the DPO is a statutory role. This means the individual undertaking the role has statutory tasks they must undertake. These are primarily to:


  1. Provide advice and guidance on data protection law

  2. Monitor the organisation’s compliance with data protection law

  3. Act as the point of contact with the data protection regulator 


The position of the DPO is also set out in law. A DPO must:


  1. Not receive instruction on how to exercise their tasks

  2. Have no conflict in exercising their tasks. This means a C-suite executive (CEO, CTO, CDO etc.) is unable to be the Data Protection Officer.

  3. Be involved in a timely manner in all issues relating to data protection.

  4. Be able to report to the highest level of management

  5. Be appointed on the basis of their ‘professional qualities and, in particular, expert knowledge of data protection law and practices’ [UK GDPR Article 37(5)].


In some instances, a DPO is mandated by data protection law, including where the core activities of the organisation involve large-scale processing of special category data (including health data).

Both controllers and processors may be required to appoint a DPO, depending on their processing activities.

What this means in practice.

As a statutory role, if a DPO is appointed, the individual undertaking that role, and the organisation appointing the role, must ensure that the DPO is involved in all aspects. It cannot be a ‘lip-service’ role.

What your DPO will be doing:


  1. Providing advice and guidance to any new or changing product features.

  2. Monitoring your organisation’s compliance with UK/EU data protection laws. 

  3. Keeping you up to date with changes in law and guidance and providing proactive advice and recommended changes based on this.

  4. Reviewing Data Protection Impact Assessments.

  5. Having routine calls with relevant teams/groups in the organisation. 

  6. Supporting data breach management, qualification and communication.

  7. Supporting advice and guidance in relation to individual rights.

  8. Advising on the set-up and management of personal data involved in any clinical investigation or study in relation to your product.

  9. Supporting conversations with commercial partners and NHS IG teams.

  10. Advising on implementation of data strategy.

  11. Supporting due diligence of potential suppliers.


A good DPO can be far more than a compliance function, acting as a strategic advisor when properly integrated into the organisation and involved in decision-making.

Practical steps to a DPO in HealthTech.

The first question is whether your organisation is legally required to appoint a DPO.

If the answer is yes, a DPO must be appointed. If no, then you need to decide whether you want to appoint one voluntarily, or whether you want to appoint a data protection lead in a non-statutory position.

Note: Although the Digital Technology Assessment Criteria (DTAC) Version 2 removed the question regarding DPO appointment, this has not changed anything in law and you are still required to appoint a DPO in the circumstances noted above.

If appointing a DPO, this can be done internally or externally. 

If appointing internally it is recommended that you:


  • Assure yourself there is no conflict of interest, where the individual also makes decisions in the organisation about using personal data. This means that the individual should not be a CEO, CTO, CDO or Head of Marketing, for example.

  • Assure yourself they have the relevant experience and knowledge to advise on data protection law.


If appointing externally it is recommended that you:


  • Understand the experience of your named DPO

  • Understand whether your named DPO has experience in health

  • Understand the inclusions of the service: how do they undertake all the statutory tasks?

  • Understand the flexibility of their services. Some limit contact by hours, or pre-assigned days.


Takeaway

A DPO is a statutory role in law with the tasks they must undertake also set out in law. If appointing a DPO, either internally or externally, they can be of immense value. 

Whether you are looking to undertake an innovative project utilising data, looking to gain approval from local NHS Information Governance Teams for your product or have an overview of your information risk exposure, the DPO should be a key part of your team.


Whether you are looking for a statutory Data Protection Officer, reviewing your current supplier or looking for strategic support for a growing organisation, l

earn more about Iniver's Outsourced DPO service here or contact our team to discuss your requirements.


Summary: A Data Protection Officer (DPO) is more than a compliance requirement for many HealthTech companies. This guide explains when a DPO is legally required, the statutory responsibilities of the role under UK GDPR, what effective DPO support looks like in practice, and how a DPO can become a strategic advisor for organisations handling health data, working with the NHS, or scaling innovative digital health products.


Subject Access Requests (SARs), also known as Data Subject Access Requests (DSARs), can be a compliance headache for many organisations. Whislt the right for data subjects to request copies of their personal data has been around long before the introduction of the General Data Protection Regulation (GDPR), it feels that more are becoming increasing broader and complex.

Handled well, DSARs demonstrate transparency and accountability. Handled poorly, they expose organisations to ICO complaints, enforcement action, reputational damage, and unnecessary operational strain.


This guide explains how to manage DSARs effectively under UK GDPR, reflecting current ICO guidance, recent legislative changes, and the realities faced by UK organisations today.


What Is a SAR?


A Subject Access Request (SAR) is a request made by an individual to access the personal data a Data Controller holds about them. Under Article 15 of the UK GDPR, individuals have the right to:

  • Confirm whether their personal data is being processed

  • Receive a copy of that personal data

  • Understand how and why it is being used, shared, and retained

A DSAR does not need to mention “GDPR”,  “SAR”, “DSAR”, or “data protection” to be valid. Requests can be made verbally, in writing, via email, contact forms, or even social media channels.


SAR Time Limits Under UK GDPR


UK GDPR sets clear statutory deadlines:

  • One calendar month to respond from the date of receipt

  • The deadline can be extended by up to two further months where requests are complex or numerous

  • The clock can be paused where reasonable clarification is required to understand the scope of a request

The ICO’s guidance is explicit that organisations must act without undue delay, even where extensions apply.


Recent Changes: Reasonable and Proportionate Searches


Data protection law is ever changing, and one helpful update for Data Controllers that came into force through the Data (Use and Access) Act (DUAA) was the ability to undertake reasonable and proportionate searches, rather than exhaustive searches across every possible system. This is especially for those requests from data subjects who request a copy of ‘everything’ held by an organisation.

This means:

  • You are not required to search every archive or legacy system if it would be disproportionate

  • Search decisions must be defensible, documented, and consistent

  • Organisations should focus on systems where relevant personal data is most likely to be held

The burden remains on the controller to justify why a search was reasonable if challenged.


AI‑Generated Outputs Are Now In Scope of SARs


As organisations introduce AI and generative tools, AI‑generated outputs must now be treated as in scope of a SAR under UK GDPR. Personal data includes not only information provided by individuals, but also data that is derived, inferred or generated about them, such as scores, risk ratings, classifications, summaries or predictions produced by AI systems. Where those outputs relate to an identifiable person, they are likely disclosable under Article 15 and must be included in SAR searches. UK organisations therefore need to ensure AI tools are mapped as data sources within SAR processes.


Common SAR Challenges for UK Organisations


In practice, SAR compliance fails most often due to operational issues, not legal misunderstanding.

1. Requests Spread Across Multiple Systems

Personal data often exists across:

  • Email and collaboration tools (Outlook, Teams, Slack)

  • CRM and case management systems

  • HR platforms and shared drives

  • CCTV, call recordings, and AI‑generated summaries

Without a clear data map, organisations lose time identifying where to search.


2. Mixed Third‑Party Data

Many SARs involve emails or documents containing information about multiple individuals. This requires careful redaction and balancing of rights, particularly in employment, NHS, and public sector contexts.


3. Tactical Requests

SARs are increasingly used alongside grievances, litigation, or complaints. This increases legal risk and requires stricter governance, audit trails, and privilege handling.


What Good SAR Management Looks Like

Organisations that manage SARs well tend to have the same foundations in place.


Clear Internal Recognition

Staff know how to recognise a SAR regardless of the channel it arrives through.


Defined Registration

There is a consistent process for:

  • Logging requests

  • Verifying identity (where necessary)

  • Clarifying scope without delaying unnecessarily


Structured Search and Review

Searches are planned, documented, and proportionate. Review and redaction are performed methodically, not reactively.


Secure Disclosure

Responses are issued securely, in an intelligible format, with the required supplementary information.

These expectations are set out clearly in ICO guidance and form part of the accountability principle under UK GDPR.


Consequences of Poor SAR Handling


Failure to manage DSARs effectively can result in:

  • Complaints directly to the organisation (now an explicit right)

  • Escalation to the ICO

  • Enforcement action and monetary penalties

  • Loss of trust with customers, employees, or patients


Building a Sustainable SAR Process


Organisations experiencing repeat SAR issues should move away from ad‑hoc handling and towards a repeatable governance model, including:

  • SAR policies and procedures

  • Defined ownership and escalation paths

  • Data mapping and retention controls

  • Audit‑ready records of decisions and searches

This approach reduces risk, response time, and operational disruption, particularly for scaling organisations and regulated sectors.


Final Thoughts

Iniver supports organisations to manage SARs confidently under UK GDPR, including where personal data is processed through AI and automated systems. Our team have run information rights management operations within national organisations, and we utilise this real-world experience to help clients design proportionate SAR processes, identify AI‑generated personal data, and align responses with current ICO guidance. If you need support reviewing your SAR approach or understanding how AI changes your obligations, speak to Iniver for practical, regulator‑ready advice.


Contact us at hello@iniver.co.uk or understand more about how we can support here

Finding the Right Outsourced Data Protection Officer (DPO): Essential Tips for Organizations



Finding the right Outsourced Data Protection Officer (DPO) can be challenging with so many providers available. In this guide, I share five essential tips to help you select a DPO service that meets your organization’s needs.



Tip 1 - Check Their Experience


Experience is key to the successful delivery of the service. Outsourcing the role allows you to access experienced professionals at a fraction of the cost of hiring internally. Ensure you understand exactly who your Outsourced DPO is, including how many years of data protection experience they have and their previous roles in the field.


Tip 2 - Ensure Availability


When you appoint an outsourced DPO, you want to be able to contact them whenever you need assistance. Some providers only allow contact on assigned days, while others offer access as needed. Choose a provider that aligns with your availability requirements.


Tip 3 - Confirm Non-Restrictive Service


A DPO has statutory tasks they must undertake. It’s crucial to understand whether the quoted price covers all necessary tasks or if there are restrictions on their time. Restrictions could lead to additional costs, so clarify this upfront.


Tip 4 - Look for a Personable Approach


Outsourced services can sometimes feel distant, even if you pay a premium price. A personable DPO who integrates well with your team can significantly enhance communication and foster a positive compliance culture. This connection can make a big difference in how data protection is perceived within your organization.


Tip 5 - Verify Qualifications


Currently, there is no formal Data Protection Officer qualification approved by the UK regulator. However, you should look for relevant qualifications. These may include a Master's in Law (though it’s not mandatory for a DPO to be a lawyer), the BCS Data Protection Practitioner Certificate, or CIPP/E certification. These credentials can indicate a solid understanding of data protection principles.


Do Your Comparisons


With many providers available, each offering different levels and styles of service, it’s essential to compare them effectively. Use a checklist to evaluate providers based on the tips mentioned above. This will help you make an informed decision that aligns with your organization’s needs.


Understanding the Importance of a DPO


A Data Protection Officer plays a crucial role in ensuring compliance with data protection regulations. They help organizations navigate complex legal frameworks and implement best practices. By having a dedicated DPO, organizations can mitigate risks associated with data breaches and enhance their reputation in the marketplace.


The Role of Technology in Data Protection


In today’s digital landscape, technology plays a vital role in data protection. Organizations must leverage innovative tools to safeguard sensitive information. A competent DPO will not only understand the legal aspects but also be familiar with the latest technologies that can enhance data security. This combination of legal knowledge and technological expertise is essential for effective data protection.


Building a Strong Compliance Culture


A strong compliance culture is essential for organizations to thrive in a data-driven world. By fostering a culture of compliance, organizations can ensure that all employees understand the importance of data protection. A DPO can help instill this culture by providing training and resources that empower staff to take data protection seriously.


Conclusion


Choosing the right Outsourced Data Protection Officer is a critical decision for any organization. By following the tips outlined in this guide, you can ensure that you select a DPO service that meets your needs. Remember, a well-chosen DPO not only helps you comply with regulations but also strengthens your organization’s position as an industry leader.


About Iniver

Iniver is a specialist data protection consultancy firm providing only 'Full-Service' DPO services, led by Joe Stock LLM, a data protection professional with 14 years of experience.


For more information about how we can work as your Outsourced Data Protection Officer, click here.

bottom of page