Privacy & GDPR

Minimum information. Controlled access.

Five Faces is designed to minimise the identifying information held in its core client record.

Reference-based client records

The core platform is intended to use a unique Five Faces reference and password. It should not require a client's name, home address, date of birth or NHS number.

Pseudonymisation, not a magic exemption

A provider may be able to connect a Five Faces reference to a person using its own separate records. The reference approach therefore reduces unnecessary identifying data but does not automatically remove UK GDPR obligations.

Authorised attachment

Provider access should be created only when a service-reference relationship is confirmed. Providers should not be able to search a general population of client records.

Provider responsibility

Before live launch, Five Faces needs a completed privacy notice defining controller/processor roles, lawful bases, special-category conditions, retention, deletion, data-subject rights, breach handling and contractual responsibilities.

Pre-launch status: this page records the intended privacy-by-design model. It is not a substitute for the final legal documentation or a data-protection impact assessment where one is required.