A demo reference for the research roles and the exact commvita controls that carry a study from lawful basis through the Design → Publication → Archival lifecycle — anonymised, federated, and provable, so the answers travel while the records stay put.
Research on the live clinical record is built as a secondary use: separate purpose, separate lawful basis, separate people. The participant keeps their rights and their opt-out; the sponsor is accountable; the team only ever touches minimised, governed data.
Never re-keyed into research; their record is anonymised or pseudonymised first. They keep every right (Art.15 access, rectify, object) and can opt out — the National Data Opt-Out removes their confidential data from this secondary use.
Decides why and how the study runs. Holds the lawful basis (Art.6(1)(e) + Art.9(2)(j) with Art.89 safeguards), the HRA/IRAS approval, the DPIA and the DSA / contract register. Signs off each project before an extract can be taken.
Work only on minimised data at the approved tier — never the raw record, never the token vault. Build cohorts with a no-code filter builder; every extract they take is logged with an Extract ID + file hash to the ledger.
Six scoped roles keep the controls apart: data_custodian · ig_reviewer · project_approver · analyst · auditor · break_glass. Re-identification is possible for break_glass only, and every touch is auditable.
Research is not care. It needs its own basis and its own paperwork, and in commvita every link must be satisfied before an extract can be taken.
Public-body research runs on UK GDPR Art.6(1)(e) public task plus the special-category condition Art.9(2)(j) scientific research, together with the mandatory Art.89 safeguards (technical & organisational measures, data minimisation) — the basis that makes lawful research on health data possible.
The study is registered and approved through HRA / IRAS research information-governance review before recruitment opens. The approval reference is held against the study record — no approval, no extract.
A Data Protection Impact Assessment is required for this high-risk processing, and any onward sharing is bound by a Data Sharing Agreement in the contract register. The Data Governance tab holds the project approval pack, DPIA refs and re-identification risk register together.
This is a secondary use, so the National Data Opt-Out is applied — an opted-out patient's confidential data is removed from the cohort. The same enforcement point governs Caldicott-reviewed secondary access in the IG Spine.
The controls follow the ICO anonymisation / pseudonymisation guidance and NHS re-identification risk controls: minimise, generalise, and separate identifiers from the analysis dataset before anyone runs a query.
A commvita study moves through six governed stages — each is a status in the Study Library, and a study cannot skip a gate.
Define the research question, endpoints, cohort criteria and the anonymisation tier the study will run at. Lawful basis and DPIA are attached here.
The study is registered with its HRA / IRAS approval and lawful basis recorded — the project-approval workflow gates progress.
The cohort is assembled from the live record with a no-code filter builder, opt-outs removed, at the approved minimisation tier.
Analysts work only on the minimised extract; each extract is stamped with an Extract ID + file hash to the immutable ledger.
Outputs are aggregate and disclosure-controlled; the Evidence Pack assembles the IG artefacts that support the results.
The study is closed and retained per its retention schedule — provenance, extracts and governance pack preserved for audit.
The study picks the least-identifiable tier that answers its question. Identifiers are separated from analysis data before anyone runs a query.
Direct identifiers are replaced with stable tokens. Re-identification is possible by authorised break-glass only. Suitable for approved internal research that carries a DPIA and HRA approval.
Quasi-identifiers are generalised so each record is indistinguishable from at least k−1 others (k≥5). Suitable for broader internal analysis and approved cross-organisational datasets.
A statistically representative synthetic dataset with ε-differential privacy (ε=1.0) — a mathematical privacy guarantee. Safe for external sharing without a DSA requirement.
The reverse mapping lives in a separate key-management system with its own audit trail — analysts cannot access reverse mappings. Only the data_custodian / break_glass path can touch the vault, and every use is logged.
A live re-identification risk register tracks residual disclosure risk per dataset; data minimisation (Art.89) keeps each extract to the fields the study actually needs — nothing more.
Feasibility and cross-site questions are answered where the data lives. The counts come back; the records never leave the source.
Cohort Discovery runs a no-code criteria query across the federated network and returns an aggregate network count only, with small-number suppression (k≥5) — counts below five show as <5 per ICO anonymisation guidance. 0 rows leave the source.
Federated Query executes SQL/FHIR across independent sites and aggregates results without any data leaving its source; disclosure risk is surfaced on the result. Federated-by-design — the safe default for multi-site research.
| Research concept | Module | Route | Model / API | Standard |
|---|---|---|---|---|
| Study lifecycle & approvals (Design→Archival) | Clinical Studies | /clinical-studies | /studies/ · project approval · DPIA / DSA refs | HRA/IRAS · UK GDPR Art.6(1)(e)/9(2)(j)/89 |
| Cohort building | Cohort Builder · Population Health | /clinical-studies · /population-health | no-code filter builder · opt-out removal | ICO anonymisation guidance |
| Anonymisation & token vault | Clinical Studies — Anonymisation | /clinical-studies | 3 tiers · vault in separate KMS · break_glass | ICO · re-identification risk controls |
| Extract ledger (immutable provenance) | Clinical Studies — Extract Ledger | /clinical-studies | Extract ID · file_hash (SHA-256) · append-only | UK GDPR Art.5(2) accountability |
| Federated discovery (0 rows leave) | Cohort Discovery · Federated Query | /cohort-discovery · /federated-query | aggregate-only · k≥5 suppression | GDPR Art.89 · TriNetX-style federation |
| Synthetic data (ε-DP, external-safe) | Synthetic Data Generation | /synthetic-data | synthetic + differential privacy (ε=1.0) | ICO anonymisation guidance |
| External requests | Research Data Portal | /research-portal | /studies/data-requests · data catalogue | HRA/IRAS · DSA / contract register |
| IG basis (opt-out · Caldicott · WORM) | Confidential-IG Spine | /ig-spine | National Data Opt-Out · WORM hash-chain | Caldicott 8 · DSPT 2024/25 |