editor
hiraethified
Apols if already posted:Yes, most bad reviews are from the trial period, so give it a decent one. Not quite sure why they didn’t release a non-review test version, maybe it’s difficult.
Data generated and collected by the app is held in 3 environments. Systems are in place which support the secure and appropriate flow of data between these environments:
- app users’ phone – the NHS COVID-19 App and the majority of data collected by the Apple/Google API will be always (and only) held on the app user’s phone. This is considered a user-held record. For most functionality, data is presented to the user’s phone and is checked against the data held on the phone (for example, visited venue QR codes that could be considered at risk or other users that should be considered at risk)
- product environment – certain data items are collected from user devices (via an API) to allow core features of the app to work and be managed effectively. This data collection includes details of the phone type and operating system and the user provided postcode district, as more fully described in the data dictionary set out in appendix 1 of this document. Within the product environment service performance dashboards are provided to support the oversight and management of the app and associated services. Data and access is kept within the control of the DHSC.
- analytical environment – derived data derived from the app will flow to the analytical environment to support learning about the app and COVID-19. All data held in the analytical environment is subject to strict de-identification controls to ensure datasets are de-identified and aggregated.
NHS COVID-19 app: data protection impact assessment