Data Protection Impact Assessment (DPIA)

Conducted in accordance with GDPR Art. 35 / WP248 (rev.01) — Edition: 2026-05-26

1. Necessity and scope of the assessment

This DPIA is published by Project Line, the data processor of Intelligent Clinic Management Platform. Per Art. 35(3)(b) GDPR, processing of special-category health data on a large scale meets the mandatory-DPIA threshold. EDPB list of mandatory-DPIA operations (WP248 rev.01, criteria 1, 4 and 7) is fulfilled: special-category data + automated decisions informing services + innovative-technology (AI voice agent).

2. Description of processing

ItemDescription
NatureHosting of clinic + patient health records, AI voice receptionist (real-time; calls not recorded), AI visit-scribe transcription, automated SMS/WhatsApp reminders.
ScopePatients of clinics that license the Service. Volume scales with clinic count.
ContextB2B SaaS; clinic = controller, Project Line = processor.
PurposesAppointment scheduling, electronic health records, billing, reminders, AI clinical-decision-support (non-binding).
Data categoriesName, contact, date of birth, identity document numbers, medical history, prescriptions, payment metadata (tokenised — no PAN).
Data subjectsPatients (including minors, whose data is processed only with verified parent / legal-guardian consent), clinic staff, clinic owners.
RetentionActive duration of the licence + 30 days grace + minimum statutory retention (7-30y depending on country).

3. Lawful basis

4. Necessity and proportionality

Each processing operation is mapped to a specific clinical or administrative purpose. Data minimisation: only fields required for that purpose are collected. Pseudonymisation in audit logs. Granular access controls at the per-clinic boundary; cross-clinic data access is technically impossible.

5. Risks to data subjects

RiskLikelihoodSeverityMitigation
Unauthorised access to medical dataLowHighPer-tenant SQL isolation, TLS 1.2+, AES-256 at rest, optional MFA (TOTP) available for clinical roles, PIN lockout, audit log with hash chain, outbound budget guard.
AI hallucination influencing clinical decisionMediumHighVoice agent prompts present suggestions as documentation only; the treating clinician retains all clinical authority. Disclaimers in agreement.
Undisclosed AI interactionLowHighMandatory AI-disclosure announcement in the patient's language at call start (EU AI Act Art. 50); per-patient AI-processing consent captured + versioned. Calls are not recorded.
Sub-processor incidentLowMediumCore sub-processors: Azure / OpenAI / Twilio / Meta. Optional payment + invoicing (clinic opt-in): Stripe / PayPal / Cardcom / Tranzila / PayPlus / Meshulam / GreenInvoice / iCount. Optional OAuth (clinic opt-in): Google / Microsoft. Each has binding DPA. 30-day notice on changes.
Cross-border transferLowMediumEU SCCs (EU GDPR) / UK IDTA or UK Addendum B1.0 + TRA (UK GDPR) for transfers; Azure Israel Central region by default.
Lengthy retentionLowMediumTermination workflow hard-deletes data after 30-day grace; statutory retention windows enforced.
Processing of minors' dataLowHighPatients under 18 are flagged; consent is blocked server-side unless a parent / legal guardian signs (guardian name + relationship recorded, encrypted). Minors' data receives the same per-tenant isolation, AES-256 encryption and AI-disclosure as all patient data.

6. Consultation

Each clinic, as controller, is invited to review and add jurisdiction-specific risks before processing. Feedback channel: support@projectlineil.com.

7. Residual risk and conclusion

After application of the mitigations the residual risk is assessed as LOW. Consultation with the supervisory authority under Art. 36(1) is not required at present, but Project Line will reconsult should a future processing operation materially increase risk.

8. Review schedule

This DPIA is reviewed annually and whenever a sub-processor changes, a new data category is added, or applicable supervisory-authority guidance is updated.

© 2026 Project Line. All rights reserved.