Last updated: August 2026 (draft)
This is the plain-language version of our internal privacy and security assessment for the PCRA Caribbean Portal. PCRA Caribbean is operated by Primary Care Research Alliance Ltd (“PCRA UK”) as part of the PCRA Group, which hosts this website; the portal runs on its own dedicated infrastructure and database, separate from the UK members’ portal. Because PCRA UK is the operator, the UK GDPR and the Data Protection Act 2018 are the primary data-protection framework for the portal, alongside the local laws described below. The full assessment is maintained as a controlled document and is available to sponsors on request — contact us at info@pcralliance.uk.
1. Who the Portal is for
The PCRA Caribbean Portal is a workspace for three groups of people:
- Sponsor companies (pharma / CRO) — upload study protocols and review feasibility responses.
- Member sites — hospitals, polyclinics, health centres, GP/family practices, private specialist clinics, physiotherapy clinics, diagnostics labs, dental clinics, pharmacies, and dedicated research units — look at protocols, tell us how their site could contribute, collaborate with a sponsor on a specific study.
- PCRA Caribbean staff — run the platform.
The Portal is not a clinical system. It does not hold patient medical records and it does not process patient-identifiable data or individual health information. If anyone sends us a message that contains patient information, our system quarantines the message and asks them to resend it without the patient details.
2. What information we hold about you
If you have a Portal account, we hold:
- Your work name, work email, and the site or company you represent.
- Which projects, protocols, and documents you have been given access to.
- A record of each sign-in (time, IP address) and each document you have opened. This is our audit trail — it allows us to demonstrate to a sponsor (or an auditor) who saw what, and when.
- A timestamped record when you first accept the confidentiality terms (NDA) for a given project.
If you fill in one of our public forms (join request, sponsor inquiry, contact) we hold the content of the form and the contact details you provided.
3. What we never hold
- Patient-identifiable data. Patient names, dates of birth, national ID or social security numbers, medical record numbers. Our scanner actively looks for these patterns at ingest and blocks them.
- Your password. We only store a one-way hash that cannot be reversed.
- Financial account details. The public site and Portal do not collect payment card or bank account information.
4. Where the data lives
Personal data is stored in the United Kingdom — in a London-region database operated by PCRA UK on professionally managed cloud infrastructure. Where data is transferred internationally (for example, correspondence with sites and regulators in Caribbean territories), UK GDPR transfer safeguards apply — the UK adequacy regulations, the IDTA/Addendum, or other appropriate safeguards as applicable. The full list of service providers (sub-processors) will be published here before launch. [Sub-processor list to be confirmed.]
5. How long we keep it
- Regulated research audit trail (who signed which NDA, who opened which protocol): retained in line with ICH GCP record-keeping expectations and the regulatory requirements applicable to the studies concerned.
- Commercial correspondence (inquiries and join requests that didn’t lead to an account): a limited period, then deleted. [Exact retention periods to be confirmed with counsel in each participating jurisdiction.]
- Your account data: for as long as you have an active account, plus a short audit tail after closure.
6. Your privacy choices and rights
Because the portal is operated by PCRA UK, your rights under the UK GDPR and the Data Protection Act 2018 apply to the personal data we hold about you. You can ask us to:
- Access — tell you what information we hold about you and send you a copy.
- Rectify — correct anything that is wrong.
- Erase — delete your account and associated data, subject to our regulated audit retention.
- Restrict or object — stop using your information for a particular purpose.
- Portability — receive a copy of data you provided in a machine-readable format.
- Withdraw consent — where processing is based on consent (for example, the AI profile-enrichment opt-in), at any time.
Point of contact for all of the above: info@pcralliance.uk. We will respond within one month, as the UK GDPR requires. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk as lead authority. Member sites also operate under the laws of their own country or territory — for example Jamaica’s Data Protection Act 2020, Barbados’ Data Protection Act 2019, Trinidad & Tobago’s Data Protection Act, the Dominican Republic’s Law 172-13, and the EU GDPR in Guadeloupe, Martinique, Saint-Martin and French Guiana — and where those laws apply you may also complain to your local data-protection authority (or the CNIL for the French territories).
7. How we keep things safe
- Everything is encrypted in transit (HTTPS) and at rest (database-level encryption).
- Admin and member accounts require two-factor authentication.
- Every sign-in, document view, and NDA acceptance is recorded in an append-only audit log.
- Public forms and sign-in endpoints are rate-limited.
- Our Privacy Officer is notified automatically the moment our scanner detects anything that looks like patient data in inbound content.
- Dependencies are patched on a regular cadence; vulnerability status is reviewed each release.
8. When something goes wrong
If we detect (or are told about) a breach that is likely to affect you, we will notify the Information Commissioner’s Office where required by the UK GDPR (within 72 hours of becoming aware, where feasible) and contact you directly where the breach is likely to result in a high risk to you. Where the breach also engages the data-protection law of a participating Caribbean country or territory (or the EU GDPR for the French territories), we will notify the relevant local authority as that law requires. Our incident response runbook sits alongside our internal assessment as a controlled document.
9. Related documents
- Privacy Notice — the formal notice describing our data practices.
- Scraping Policy — what we do when we populate site profiles from public sources, and how to opt out.
- Full internal privacy and security assessment (controlled document) — available to sponsors on request.