Named accountability
Controller, processor, product owner, rule owner and operational decision-maker are identified for the real deployment.
NHS Sovereign Federated Data Platform · 03 — Governance, Migration & Supplier Exit
Governance stays under public authority. Exit is planned before award and accepted only after replacement operation, verified data return, access revocation and deletion.
Public authority
Controller, processor, product owner, rule owner and operational decision-maker are identified for the real deployment.
Purpose, lawful basis, minimum data, retention, sharing route and permitted users are declared before processing.
Processing records, contracts, rules, source authority, decisions, audits, incidents and limitations remain reviewable.
Users and affected people have routes for correction, complaint, independent review and security reporting.
The platform does not infer diagnosis, treatment or readiness unless the authorised clinical workflow supplies or confirms it.
Legal, safety, security, accessibility and operational compliance are verified in the actual organisation and environment.
Assurance map
| Control area | Required evidence | Release position |
|---|---|---|
| Data protection | UK GDPR, Data Protection Act 2018, processing record, DPIA, purpose, minimisation, retention and rights route. | Framework and templates; organisation-specific completion required. |
| Confidentiality | Common-law confidentiality, purpose-bound access, sharing agreements and disclosure controls. | Architectural controls defined; live authority not claimed. |
| Clinical safety | DCB0129/0160 ownership, clinical safety case, hazard log, mitigations and residual-risk acceptance. | Templates only; accountable clinical safety officers required. |
| Cyber security | Threat model, identity, secrets, network, dependency, monitoring, incident, backup and recovery evidence. | Controls specified; penetration and production environment tests outstanding. |
| Accessibility | WCAG 2.2 AA, keyboard, screen-reader, zoom, contrast and representative-user evidence. | Accessible shell designed; independent testing still required. |
| National onboarding | DTAC, DSPT, HSCN, PDS, CIS2 and API onboarding evidence where each applies. | No live NHS connection or production approval is claimed. |
Migration evidence
An export request, a dispatched archive and an accepted migration are not the same event. The platform records the whole chain and prohibits inference from an earlier state.
Datasets, schemas, mappings, pipelines, rules, products, users, roles, schedules, licences, keys and operational knowledge are recorded.
Files are preserved, hashed, opened, decrypted, schema-validated, counted, sampled, related and repeatedly imported.
Equivalent inputs are compared at dataset, record, field, calculation, rule, workflow, dashboard, export and audit levels.
Each material difference receives both outputs, inputs, versions, cause, resolution, reviewer and corrective action.
Final synchronisation, write freeze, open work, user activation, monitoring, rollback threshold and decision owner are fixed.
Data return, credentials, accounts, routes, licences, supplier access, deletion and residual risk are independently verified.
Evidence-led progression
| Stage | Required outcome | Progression gate |
|---|---|---|
| Reference release | Runnable synthetic product, contracts, tests, deployment files and limitations. | Independent reconstruction and repeatable evidence. |
| Department / trust pilot | Representative data, real user journeys, governance owners, integration and recovery. | Accepted safety, security, accessibility, performance and rollback evidence. |
| Regional federation | Controlled cross-organisation products with registered purpose and routes. | Data-sharing, identity, failure isolation, withdrawal and continuity proven. |
| National coordination | Accepted scale, resilience, support, public control, portability and supplier exit. | Independent operation without hidden technical or contractual dependency. |