Skip to main content
DPIA summaries

Data Protection Impact Assessment (DPIA) Summary - Community Care Record

Introduction

A data protection impact assessment (DPIA) helps identify and reduce data protection risks in a project or service. This DPIA was carried out by the HSE for the Community Care Record.

This is a summary of the DPIA and will be updated when new information becomes available. The HSE Data Protection Office (DPO) were consulted throughout.

Overview of the Community Care Record

The Community Care Record (CCR) is a clinical management system for Ireland's community services. It helps to remove paper files and disconnected local systems, reducing duplication and delays for over 60,000 staff. This will help staff manage referrals, appointments, caseloads, and documentation in one place, improving the health service experience for everyone.

The CCR is an interim system, and a step towards the HSE One Health Record. The CCR system is called TrakCare and provided by the vendor InterSystems. The CCR programme will roll out in phases, starting with children's referrals and selected Specialist Palliative Care sites in in Q4 2026, followed by a phased regional roll-out in 2027, starting with the Mid-West.

How the CCR will be used (purposes of processing)

The purposes for processing personal data in the CCR are:

  • To allow healthcare staff to access patient information for patient care and service delivery
  • Appointment data will integrate with the HSE Health App; providing patients with access to their health data
  • Via the integration between the CCR and HSE Shared Care Record, a patient summary from SCR will be available on TrakCare, thus enhancing integrated care and safety.

Personal data processing in the CCR

Your personal data is 'processed' whenever it is used. For example, when it is collected or reviewed. The categories of personal data collected include the following:

1. Patient demographic data

  • Identifying information such as your name and PPSN to correctly identify you and ensure your records are linked to the right person.
  • Demographic information such your gender, ethnicity and date of birth in order to plan, manage and report on the services.
  • Contact information such as your address, phone number and emergency contact so that we can communicate with you.
  • Your preferences and individual needs, for example language needs, mobility requirements, sexual orientation, so that we can engage with you respectfully and effectively.
  • Care management information such as your GP contact details, private health insurance information

2. Health data

  • Details of your referral, appointments, treatment history and clinical information in order to provide care, manage waiting lists, follow-up on medication and treatment, etc.

3. Healthcare staff data

  • Professional and work information is processed to verify identity and manage access to the system.

Lawful basis for processing personal data

The CCR uses clear legal bases for data processing:

  • Article 6(1)(e) of the GDPR — processing necessary for tasks carried out in the public interest
  • Article 9(2)(h) of the GDPR — processing necessary to provide healthcare and manage health systems and services
  • Health Act 2004
  • Health Information Bill 2024
  • European Health Data Space (and amending Directive 2011/24/EU and Regulation (EU) 2024/2847): Art 7 and Art 19
  • Social Welfare Consolidation Act 2005

Assessment of necessity and proportionality

Necessity

Processing patient demographic and health data is necessary to:

  • Verify patient identity
  • Provide healthcare staff with access to the information needed to deliver care and manage services

Processing of healthcare staff data is necessary to:

  • Ensure safe and appropriate access
  • Support oversight and compliance

Proportionality (ensures that processing is not excessive)

  • Only the minimum demographic information is gathered to verify identity
  • All authorised users receive appropriate training on the correct and responsible use of the CCR.

The CCR technical solution

The CCR system is called TrakCare and provided by the vendor InterSystems. The vendor has completed all relevant HSE Data Protection Assessments and Security Questionnaire documentation.

Keeping the CCR secure

The CCR takes a proactive approach to managing risks and ensuring the security of personal data through a combination of comprehensive risk assessments and robust technical and organisational measures.

Risks such as illegitimate access to personal data, unwanted modification to personal data and personal data disappearance were assessed and mitigation measures are in place.

The organisational security measures include training, auditing and data breach processes. The technical security measures include secure log-in and Role-Based Access Control (RBAC). There will be no public path to the CCR system.

Data governance and the CCR

All data processing activities adhere to the core principles of GDPR, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

The HSE is the data controller for the Community Care Record Programme. The statutory sector organisations (section 38 and 39) are also data controllers. InterSystems B.V. is the processor of the HSE Data for the CCR.

The Community Care Record Oversight Group (CCROG) is the Design Authority for the Programme. Major changes to the CCR design and the associated data categories are escalated to the CCR Steering Committee. The Steering Committee provides reports to the Digital for Care Oversight Group (DfCOG).

Retention of data

Data retention will be in line with the HSE Data Records Retention Policy (2025). After the retention period, all clinical records will be destroyed.

HSE Data Protection Office opinion

Extensive consultation with the HSE National Data Protection Office was carried out, and their opinion on this document was obtained before approval. They will continue to review additional updates to the CCR DPIA.

This is a beta version - your feedback will help us to improve it

Data Protection Impact Assessment (DPIA) Summary - Community Care Record