Jane's Guide

Here's all the help you need to use Jane.


Is Jane Compliant with GDPR in the EU and UK?

📣 Heads up: Compliance is a shared responsibility. Jane provides the platform, features, and documentation to support your clinic's compliance, but your clinic is responsible for how you collect, use, and manage patient data in your day-to-day operations.

This guide is a general summary and is not intended as legal advice. For guidance specific to your practice, consult a legal professional or your regulatory body.

Is Jane GDPR compliant?

Jane is compliant with both the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR). This guide outlines Jane's compliance framework and the built-in tools that help your clinic meet its ongoing UK and EU GDPR obligations.

How does Jane ensure GDPR compliance?

Data Protection Officer

Jane has an in-house Data Protection Officer (DPO) who oversees our compliance program. You can reach our DPO, Catharine Martin, at [email protected].

System and Business Assessments

Jane has conducted comprehensive system and business assessments to ensure the platform meets UK and EU GDPR requirements. We continuously monitor for compliance as regulations evolve.

Privacy Documentation

Our Privacy Notice and Terms of Use reflect UK and EU GDPR requirements and are kept up to date:

Data Processing Agreements

Jane provides Data Processing Agreements (DPAs) that outline our roles and responsibilities as a data processor, in line with Article 28 of the GDPR.

Breach Notification

Jane has established procedures to detect, report, and investigate personal data breaches in compliance with Article 33 of the UK and EU GDPR.

Data Security and Storage

Encryption

Your data is protected at every stage:

  • In transit: 128-bit encryption when data moves between your computer and Jane's servers.
  • At rest: 256-bit encryption for all stored data.

Data Storage Location

For clinics based in the UK or Europe, Jane stores your data on servers located in the UK. Jane maintains servers in multiple countries to comply with a range of international data protection laws, including the GDPR.

🩵 Jane Tip: If you have questions about which server holds your clinic's data, contact our Support Team or visit our Cloud Security White Paper for more information.

Cookie Consent and Management

Jane provides UK and EU GDPR-compliant cookie consent management, including opt-in requirements, information about the types of cookies used, and instructions for managing cookie preferences. See Jane's Cookie Policy for details.

Does GDPR apply to my clinic?

Both the EU and UK GDPRs apply to organizations and businesses handling data of EU and UK residents, respectively. It also applies to:

  • Any organization established in the EU/UK, regardless of whose data they process or where the data subject lives
  • An organization not established in the EU/UK but that offers goods/services to, or monitors, individuals who are in the EU/UK.

GDPR sets out the rules for how organizations collect, use, and disclose personal information, including employee information (with specific exceptions).

If you're unsure whether GDPR applies to your organization, contact your regulatory body or supervisory authority for guidance, or reach out to your organization's Data Privacy Officer.

How does GDPR apply to my clinic?

Below are a few common principles in GDPR that apply to businesses and clinics.

Lawfulness, fairness, and transparency

GDPR outlines that controllers must have a valid, legal reason to process data protected under GDPR. Fairness and openness with the individuals who the data is about is essential, particularly around how their personal information is being used.

Purpose limitation

Personal information should be collected for a clear and specific purpose, and for a legitimate reason. Data should not be used at a later date for reasons unrelated to the original purpose it was collected for.

Data minimization

Only the exact information needed should be collected and additional information not required should not be collected.

Accuracy

When collecting personal information, it should be validated as correct and should be kept current. If data is out of date or inaccurate, it should be erased, rectified, or purged.

Storage limitation

Personal information should not be retained for longer than necessary to fulfill the defined purpose and as allowable by an organization's data retention standards. Once no longer required, data should be deleted.

Integrity and confidentiality

Security safeguards are essential to protect data by preventing loss, inappropriate access, and so forth.

Accountability

Full responsibility of these rules is needed, and compliance should be able to be proven.

How does Jane enable my compliance with GDPR?

Jane includes tools to help you maintain GDPR compliance in your daily operations.

Access Control and Security

  • Unique user authentication: All staff require a unique username and password. Jane recommends against shared profiles to protect account security and maintain privacy settings. See Helping Staff Sign In.
  • Role-based access: Account Owners can assign Access Levels to restrict what data each user can view and edit.
  • Charting privacy: Practitioners control who can access their charts using Charting Privacy Options.
  • Password management: Staff can reset passwords directly from the main login page. See Log In Help.
  • 2-Step Verification: A one-time code is sent to the staff member's chosen verification method each time they log in. See 2-Step Verification.

Consent Management

Jane provides tools for obtaining and managing patient consent in accordance with applicable regulatory college and governing body requirements, including:

  • Consent to collect personal data
  • Consent to treatment
  • Marketing consent, with active opt-out options

See our guide on Intake Forms for details on how to configure consent in Jane.

Audit Trail and Documentation

  • Data export: Export charts, intake forms, or clinical notes to fulfill data subject access requests.
  • Chart integrity: Sign and lock charts with a permanent timestamp.
  • Error correction: The Amend function lets you correct charting errors while preserving the original sign and lock date and time.
  • Activity monitoring: The Activity Log tracks all user activity for accountability and compliance. Each user can also view their own session logs.

Data Subject Rights

Jane has tools to help you fulfill your patients' rights under the UK and EU GDPR:

  • Right of access: Export charts, intake forms, or clinical notes on request.
  • Right to rectification: Use the Amend function to correct errors while maintaining audit trails.
  • Right to erasure: Jane includes tools to support data deletion requests.
  • Right to data portability: Export patient data in accessible formats.

Still have questions?

Have questions about privacy or data protection at Jane? Reach out to our Support team or contact our DPO directly at [email protected].

Related Guides