Reference-based client records
The core platform is intended to use a unique Five Faces reference and password. It should not require a client's name, home address, date of birth or NHS number.
Privacy & GDPR
Five Faces is designed to minimise the identifying information held in its core client record.
The core platform is intended to use a unique Five Faces reference and password. It should not require a client's name, home address, date of birth or NHS number.
A provider may be able to connect a Five Faces reference to a person using its own separate records. The reference approach therefore reduces unnecessary identifying data but does not automatically remove UK GDPR obligations.
Provider access should be created only when a service-reference relationship is confirmed. Providers should not be able to search a general population of client records.
Before live launch, Five Faces needs a completed privacy notice defining controller/processor roles, lawful bases, special-category conditions, retention, deletion, data-subject rights, breach handling and contractual responsibilities.