Privacy
DPIA summary
Risk assessment for optional My Shift health tracking.
Processing assessed
Account-backed progress, measurements, Health MOT/check-ins, wellbeing notes, progress photos and plan personalisation chosen by signed-in members.
Why a DPIA
The scope includes health-related information, which deserves a higher standard of necessity, transparency, access control, security and user control.
Main risks considered
- Health information being collected without a clear purpose or choice.
- Unauthorised access to one member's information by another member.
- Over-retention or inability to erase/export data.
- Health information leaking into analytics or logs unnecessarily.
- Users mistaking personalised information for diagnosis or prescribing.
- New services or processors changing the risk without review.
Controls
- Separate explicit health-tracking consent.
- Member-scoped account access and session controls.
- Export, health-history erasure and account deletion controls.
- Privacy filtering and minimisation around analytics/logging.
- Clear non-clinical boundaries for automated recommendations.
- Change review before new health-data purposes or regulated pathways.
Residual risk
No online health-data service is risk-free. The current product is designed to keep the processing optional, limited and user-controlled. Material changes to scope require DPIA review before they are treated as part of this assessment.
Review trigger
Review when the data categories, purpose, processor set, automated decision logic, retention model or regulated-care pathway changes materially.
