CP PACS privacy notice
Development notice — requires controller approval before production. CP PACS processes identifiable health information to receive, archive, retrieve, display, correct, route, audit, secure and administer medical imaging. The deploying health agency must publish its legal name, privacy officer, contact details, lawful purposes, legal bases, recipients, overseas disclosures and approved retention schedule here before production use.
Information and purposes
Account identity, professional details, tenant/site entitlement, security and audit information are used to administer access and protect the service. Patient demographics, identifiers, DICOM images and associated clinical metadata are used only for authorised healthcare, archive, quality, correction and distribution purposes.
Essential browser technologies
Keycloak authentication cookies provide login, SSO, MFA and session security. CP PACS session storage holds short-lived OIDC tokens and PKCE state for the current browser tab. Local storage records only the version and time of this essential-cookie choice. No advertising or analytics cookies are configured.
Access, correction and complaints
Individuals may request access to or correction of their information and may raise a privacy complaint with the deploying health agency's privacy officer. Identity and authority must be verified before health information is released or corrected. The production notice must include the privacy officer's contact channel and explain escalation to the New Zealand Office of the Privacy Commissioner and, where applicable, an EU supervisory authority.
Security, disclosures and retention
Access is role- and tenant-scoped and important actions are audited. Information must not be disclosed overseas without an approved Rule 12/IPP 12 and GDPR transfer assessment where applicable. Health information and audit records are retained only under an approved clinical, legal and business schedule; legal holds override disposal. Suspected privacy incidents must be reported immediately through the deploying agency's approved breach process.
Notice version: 2026-08-01. This notice describes the development build and is not a substitute for the deploying organisation's approved privacy statement.
