Legal
Data protection and transfers to India
A plain-English account of what happens to your medical records when they go to a hospital in India: the legal basis, the safeguards, who is responsible for what, and what you can insist on.
01Why this page exists
The privacy notice tells you what we collect and why. This page deals with the single most sensitive thing we do with it: sending your health information outside the United Kingdom, to a country that UK law does not treat as having equivalent protection. It is written as a commitment, so that you can hold us to it.
02The legal position
Your health information is special category data under Article 9 UK GDPR. We process it only with your explicit consent, given separately from anything else, unticked by default, and withdrawable at any time. India has no UK adequacy decision, so sending data there is a restricted transfer under Chapter V UK GDPR, permitted only with appropriate safeguards. We use the International Data Transfer Agreement published by the Information Commissioner’s Office (or the UK Addendum to the EU standard contractual clauses) with every recipient, and we complete a transfer risk assessment for each.
03Who is responsible for what
Sevanta is the controller for the information you give us and for the decision to transfer it. Each hospital that receives your records becomes a controller in its own right, under Indian law, for the clinical record it creates and holds. Our partner organisation in India makes its own decisions about the hospitals it works with and is paid by them, which makes it an independent controller for the travel and admission information it receives, not our processor; our agreement with it is written on that basis. We tell you this because it affects who you complain to and under which law.
04What is transferred, and to whom
Only what a surgeon needs to assess your case and quote: imaging, clinic letters, medication list, relevant history. Only to the hospitals you have chosen to be considered by. Never to every hospital on the register, never to the partner organisation unless you ask, and never for any purpose other than your own treatment.
05How it is transferred
Through an encrypted transfer facility we provide, never by ordinary email or messaging. Each transfer is logged: what was sent, to whom, when, and under which consent. You can see the log on request.
06What you can insist on
A copy of the transfer agreement with any hospital before you consent. The transfer log. Withdrawal of consent at any time, which stops further transfers; a hospital that already holds your record keeps it under its own legal obligations, and we will help you exercise your rights against it. Deletion of what we hold, subject to our legal retention obligations. And a route to the Information Commissioner’s Office if you believe we have got any of this wrong.