Data Protection Impact Assessment (DPIA)
Organisation: PharmaMate Limited
Website: https://PharmaMate.co.uk
Date of assessment: 17 March 2026
1. Project Description
PharmaMate is an independent United Kingdom pharmacy price comparison website for GLP-1 medications, including Mounjaro, Wegovy, and Ozempic. The platform enables consumers to compare prices, delivery options, and service features across GPhC-registered online pharmacies.
PharmaMate is not a pharmacy and is not registered with the General Pharmaceutical Council (GPhC). We do not sell, supply, prescribe, or dispense any medicines. Revenue is generated through affiliate commissions when users visit pharmacy websites via links on our platform.
2. Data Processing Activities
2.1 Medication Request Forms
| Field |
Detail |
| Data collected |
First name, email address (AES-256-CBC encrypted at rest), medication interest |
| Special category data |
Yes — medication interest constitutes health data under UK GDPR Article 9 |
| Storage |
WordPress posts in the site database |
| Retention |
Automatically deleted after 12 months via scheduled cron |
| Legal basis |
Explicit consent (Article 6(1)(a) and Article 9(2)(a)) — obtained via consent checkbox on the form |
2.2 Success Story Submissions
| Field |
Detail |
| Data collected |
Name, email address (AES-256-CBC encrypted at rest), before/after photographs (EXIF metadata stripped on upload), story text |
| Special category data |
Yes — health-related narratives and photographs |
| Consent mechanisms |
Explicit health data consent checkbox and separate photo publication consent checkbox |
| Storage |
Custom database table |
| Legal basis |
Explicit consent (Article 6(1)(a) and Article 9(2)(a)) |
2.3 Affiliate Click Tracking (Aggregate)
| Field |
Detail |
| Data collected |
Daily aggregate counters per link type, provider, medication, and page |
| Personal data |
No — no personally identifiable information is recorded |
| Legal basis |
Legitimate interest (Article 6(1)(f)) — business analytics and commission verification |
2.4 Affiliate Redirect Tracking
| Field |
Detail |
| Data collected |
Session hash (SHA-256 of IP address + User-Agent string), timestamp, provider, discount code used |
| Personal data |
Pseudonymised — raw IP address is not stored |
| Condition |
Only collected when the user has given tracking consent via cookie banner |
| Retention |
Automatically deleted after 90 days via scheduled cron |
| Legal basis |
Consent (Article 6(1)(a)) |
2.5 Cookie Consent Preferences
| Field |
Detail |
| Data collected |
Consent choices across categories: essential, functional, analytics, health-related tracking |
| Storage |
Browser localStorage (client-side only) |
| Legal basis |
Essential for compliance with PECR and UK GDPR — no separate consent required |
2.6 Newsletter Subscriptions
| Field |
Detail |
| Data collected |
First name, email address, medication interests (health data) |
| Special category data |
Yes — medication interests |
| Processor |
MailerLite (Data Processing Agreement in place) |
| Legal basis |
Explicit consent (Article 6(1)(a) and Article 9(2)(a)) — obtained via health data consent checkbox |
3. Special Category Data Assessment
Medication interests (e.g. selecting “Mounjaro” or “Wegovy”) constitute health data under UK GDPR Article 9. This applies to:
- Treatment suggestion form submissions
- Newsletter medication interest selections
- Success story health narratives and photographs
- Health-related cookie tracking (browsing medication-specific pages)
Safeguards: Explicit consent is obtained via clearly labelled checkboxes before any health data is collected. The cookie consent banner includes a separate “Health-Related Tracking” category that is off by default and requires affirmative opt-in.
4. Necessity and Proportionality
| Processing Activity |
Why It Is Necessary |
| Medication request forms |
Enables users to express interest in specific treatments and receive tailored pharmacy comparisons. Without medication interest data, the service cannot provide relevant recommendations. |
| Success story submissions |
User-generated content that helps prospective patients make informed decisions. Health narratives and photos are voluntarily submitted and published only with explicit consent. |
| Aggregate affiliate tracking |
Required for business operation — verifying affiliate commissions and understanding which pharmacy services are most useful to users. Contains no personal data. |
| Redirect tracking |
Enables fraud detection and commission dispute resolution with pharmacy partners. Uses pseudonymised session hashes rather than raw identifiers. Only active with consent. |
| Cookie consent preferences |
Legal requirement under PECR to record and respect user cookie choices. |
| Newsletter subscriptions |
Enables users to receive updates about pharmacy pricing and availability for medications they are interested in. Medication interest is necessary to send relevant rather than generic communications. |
5. Risk Assessment
Risk 1: Unauthorised access to encrypted email addresses
| Likelihood |
Low |
| Severity |
Medium |
| Mitigation |
Email addresses are encrypted using AES-256-CBC with the WordPress authentication salt as the encryption key. Database access requires server-level credentials. WordPress admin access is restricted and protected by strong passwords. |
| Residual risk |
Low |
Risk 2: Health data inference from browsing behaviour
| Likelihood |
Medium |
| Severity |
Medium |
| Mitigation |
Default tracking is aggregate-only with no personal identifiers. Health-related tracking (which could link browsing to a pseudonymous session) requires explicit opt-in via a dedicated cookie consent category. Aggregate counters cannot be traced to individuals. |
| Residual risk |
Low |
Risk 3: Misuse of success story photographs
| Likelihood |
Low |
| Severity |
High |
| Mitigation |
EXIF metadata (including GPS coordinates) is stripped from all uploaded photographs. Explicit photo publication consent is required via a separate checkbox. Users may request removal of their story and photos at any time by contacting hello@pharmamate.co.uk. Stories are moderated before publication. |
| Residual risk |
Low |
Risk 4: Data processor breach (MailerLite, hosting provider)
| Likelihood |
Low |
| Severity |
High |
| Mitigation |
Data Processing Agreements (DPAs) are in place with all processors. MailerLite operates under Standard Contractual Clauses for international transfers. Hosting provider access is restricted to necessary operational personnel. Processor security practices are reviewed annually. |
| Residual risk |
Low–Medium |
Risk 5: Stale personal data retained beyond necessity
| Likelihood |
Low |
| Severity |
Low |
| Mitigation |
Automated WordPress cron jobs delete medication request form submissions after 12 months and affiliate redirect tracking records after 90 days. Newsletter unsubscribes are processed within 30 days by MailerLite. Retention schedules are documented in the Privacy Policy. |
| Residual risk |
Low |
6. Measures to Reduce Risk
- Encryption: AES-256-CBC encryption for stored email addresses
- IP hashing: SHA-256 hashing of IP + User-Agent for redirect tracking; raw IP never stored
- EXIF stripping: All photo metadata removed on upload to prevent location disclosure
- Automated deletion: Cron-based cleanup at 12-month and 90-day intervals
- Consent-gated tracking: Health-related tracking disabled by default; requires explicit opt-in
- K-anonymity threshold: Journey-level analytics are only reported when the aggregate count meets a minimum threshold, preventing identification of individuals through small datasets
- Data minimisation: Only data strictly necessary for each processing purpose is collected
- Access controls: WordPress role-based access; database credentials restricted to server administrators
7. Decision
Based on this assessment, the identified data processing activities may proceed with the safeguards described above. The residual risks are acceptable given the measures in place. This DPIA should be reviewed annually or when significant changes are made to data processing activities.
8. Sign-Off
| Role |
Name |
Date |
Signature |
| Data Protection Officer / Reviewer |
____________________ |
____________________ |
____________________ |
| Project Owner |
____________________ |
____________________ |
____________________ |
Last updated: 17 March 2026