Back to Compliance

Data Protection Impact Assessment

CareLedgerPro

Version 1.0 — Last updated: 6 August 2026

This is the DPIA carried out by CareLedgerPro as Processor for the processing performed by the platform. It is published so that care providers acting as Controller can reuse it as evidence when completing their own DPIA. It does not replace the Controller's assessment of how the service is used in their setting. See also the DPIA support statement.

1. Why a DPIA was carried out

The platform processes financial records relating to adults who receive care, some of whom may lack capacity to manage their own money. Although the data is financial rather than clinical, it concerns vulnerable individuals and is used to evidence safeguarding practice. A DPIA was therefore carried out voluntarily, applying the Article 35 criteria and the ICO's screening list, rather than waiting for a strict legal trigger.

Screening outcome: processing involves vulnerable data subjects and financial data at scale across multiple provider organisations. A full assessment was appropriate.

2. Description of the processing

Nature. Care providers record deposits, purchases, cash handed to a service user, and petty-cash movements against individual service-user ledgers and care-unit cash floats. Staff attach receipt images, capture signatures, run reconciliation and reporting, and exchange notes in a communication log.

Scope. Personal data processed: service-user name and internal reference, date of birth, keyworker, next-of-kin contact details, capacity flag and authority basis, care-related notes entered by the provider, balances and transaction history, receipt images, and signature images. Staff data processed: name, work email, role, group assignments, and full activity history.

Context. Users are care staff, managers, administrators and data protection officers within a single provider organisation. Service users do not have accounts. Data is entered on shared devices in care settings as well as on desktops.

Purposes. Accurate stewardship of service-user money, prevention and detection of financial abuse, evidence for CQC inspection and internal audit, and administration of the provider's subscription.

3. Necessity and proportionality

Lawful basis (Controller). Providers typically rely on legitimate interests or legal obligation for financial record-keeping, and on substantial public interest — safeguarding of individuals at risk — where special category or vulnerability-related information is involved. The Controller determines and documents its own basis; CareLedgerPro acts only on documented instructions.

Data minimisation. Only the fields needed to operate a money ledger are mandatory. Care notes, next-of-kin details and date of birth are optional. The platform does not collect clinical records, medication data, or care plans.

Proportionality. The alternative — paper cash books and unindexed receipt folders — offers no access control, no audit trail and no reliable reconciliation. Digital processing with role-scoped access and an append-only audit log is a less intrusive route to the same safeguarding outcome.

Data subject rights. Access, rectification, erasure and portability requests are handled by the Controller, with export and deletion support from CareLedgerPro. No automated decision-making with legal or similarly significant effects takes place; receipt text extraction is a data-entry aid that a staff member always confirms.

4. Consultation

The assessment drew on care-sector managers and finance administrators during product design, on the published expectations of the CQC quality statements for safeguarding and governance, and on ICO guidance for DPIAs and vulnerable data subjects. Service users and their representatives are consulted by the Controller as part of their own DPIA, since it is the Controller that holds that relationship.

5. Risk register

Risks are scored on likelihood and impact to the rights and freedoms of data subjects, with residual risk assessed after the stated mitigations.

RiskLIMitigationResidual
Unauthorised staff view financial records of a service user they do not support.LowMediumRow-level security in the database restricts every read and write to the caller's assigned client groups. Role checks are evaluated server-side, never in the browser. All record views of clients and transactions are written to an append-only data-access log.Low
Account takeover through a stolen or reused password.LowHighMandatory time-based one-time-password (TOTP) two-factor authentication for every account regardless of role, leaked-password screening at sign-up and password change, invite-only account creation, idle-session timeout, and an admin-only 2FA reset that is recorded in the user audit log.Low
Financial abuse of a service user by a member of staff.LowHighEvery transaction records the acting staff member, timestamp, funding source and category. Receipts are required above a configurable threshold, high-value entries require countersignature, corrections are limited to a 24-hour self-service window with a mandatory reason, and voids and corrections are appended to the audit log rather than overwriting the original entry.Low
A service user without capacity is treated as having consented to a transaction.LowHighEach client record carries a capacity flag and an authority basis field. Where capacity is not recorded, the signature workflow switches to 'signed on behalf of' and captures the staff member acting and their stated authority.Low
Excessive retention of personal and financial data.MediumMediumPublished retention schedule aligned to the seven-year financial-records expectation, client archiving to remove inactive records from day-to-day views, and a documented deletion process on termination of the Controller's account.Low
Data loss or prolonged unavailability of the service.LowHighManaged database with automated backups and point-in-time recovery, infrastructure defined in migrations so the schema can be rebuilt, and a published backup and disaster-recovery statement with recovery objectives.Low
Personal data exposed through email delivery (alerts, invites, password links).LowMediumEmails contain summary counts and links rather than service-user financial detail, links are single-use and time-limited, delivery is through a contracted sub-processor, and suppression and unsubscribe handling is built in.Low
Receipt images processed by an automated text-extraction model contain personal data.MediumLowExtraction runs server-side on the receipt image only, returns structured fields for staff confirmation, and results are always reviewable and editable by the staff member before saving. The model provider is listed as a sub-processor.Low
A personal data breach is not reported to the ICO within 72 hours.LowHighBuilt-in breach register with automatic 72-hour deadline calculation from the detection time, an auto-generated timeline of status changes, and a required rationale where notification is delayed.Low

6. Technical and organisational measures

  • Mandatory TOTP two-factor authentication for all accounts, with admin-only reset recorded in the user audit log.
  • Row-level security on every table holding personal data, enforced in the database rather than the application.
  • Role model of administrator, manager, staff and DPO, with roles held in a separate table and checked through a security-definer function.
  • Append-only audit log and user audit log; update and delete are blocked by database triggers.
  • Data-access logging for views of client and transaction records.
  • Encryption in transit (TLS) and at rest at the storage layer.
  • Private storage buckets for receipts and communication attachments, served through short-lived signed URLs.
  • Invite-only account creation, leaked-password screening, and idle-session timeout.
  • Built-in breach register with automatic 72-hour ICO deadline tracking.
  • Automated database backups with point-in-time recovery.

7. International transfers and sub-processors

Primary data storage is in UK/EU regions. Where any processing takes place outside the UK, appropriate safeguards are applied, including the UK International Data Transfer Addendum or Standard Contractual Clauses. The full list, with purpose and safeguards for each provider, is published on the sub-processors page, and the Article 28 position of the hosting and database provider is set out in the processor statement.

8. Retention

Financial transaction records, receipts, signatures and audit entries are retained for seven years from the end of the relevant financial year, consistent with UK financial record-keeping expectations. Account and access data is retained for the life of the subscription. On termination, data is exported and then deleted in line with the published retention and deletion policies.

9. Outcome and review

Conclusion. With the measures above in place, no residual risk is assessed as high. Processing may proceed without prior consultation with the ICO under Article 36. This conclusion is CareLedgerPro's own assessment of the platform and is not an independent certification.

Review. This DPIA is reviewed at least annually, and additionally whenever a new category of personal data is introduced, a sub-processor changes, or a significant security or safeguarding feature is added or removed.

Contact

For a copy of this DPIA in document form, or for questions from your DPO or auditor, contact support@careledgerpro.co.uk.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.