CareFocusIQ — Focused on care. Driven by impact. One platform, multiple care solutions.
Regulatory intelligence
UK GDPR

UK GDPR & Data Protection Act 2018

The UK GDPR and the Data Protection Act 2018 form the UK data protection regime. They govern how personal data — including special category health data — is collected, stored, shared and protected.

Who it applies to

Every organisation that processes personal data, with heightened duties for special category health and care data.

Key points

What UK GDPR means for care providers in practice.

Requires a lawful basis for processing personal data.
Adds conditions for special category health data.
Grants data subject rights, including access and erasure.
Requires breach reporting to the ICO within 72 hours where applicable.
How CareFocusIQ helps

Supporting work within UK GDPR

Maintain records of processing and lawful bases.

Control access to care records with role-based permissions.

Support data subject access and rectification requests.

Log and manage data incidents ready for ICO reporting.

Where UK GDPR connects

Sectors & bodies

The care sectors most affected by UK GDPR, and the national bodies most involved. Applicability varies by provider type, programme and UK nation.

Alongside UK-wide frameworks, care is also shaped by the distinct regulators and standards of England, Scotland, Wales and Northern Ireland. Explore the nations & regions directory for nation-level intelligence.

Turn regulatory complexity into a defensible posture

CareFocusIQ brings national bodies, programmes, nations and frameworks into a single intelligent platform that supports UK care providers.

CareFocusIQ provides technology and intelligence to support care operations and compliance. It is not a medical device and does not provide legal advice. Regulatory requirements vary by provider type, service and UK nation, and remain the responsibility of each provider.