UK GDPR Special Category & Caldicott Principles

Data Sovereignty &
The Edge-Privacy Shield

Older adults deserve complete safety without surrendering personal dignity. Learn how CuraWave's patented radio-frequency sensing architecture achieves 100% optical privacy, ephemeral RAM computation, and strict UK GDPR Article 9 compliance.

The Safeguarding Dilemma

Why Bedroom Cameras Trigger Rejection

Optical and infrared cameras record visual silhouettes and video feeds of residents undressing, sleeping, or in acute bathroom distress. This triggers profound ethical concerns:

  • × Severe Resident Distress: Dementia residents frequently experience paranoia or agitation when observing camera lenses mounted in their rooms.
  • × Family Pushback: Families and safeguarding leads resist camera surveillance under Human Rights Act 1998 (Article 8: Right to respect for private life).
  • × Bathroom Exclusion: Cameras are legally and ethically prohibited inside en-suite bathrooms—where >40% of critical falls happen.
The CuraWave™ Edge Shield

Physically Anonymous RF Biometrics

CuraWave does not possess optical lenses, image sensors, or audio microphones. Our technology operates on radio-frequency physics:

  • No Reconstructible Imagery: Wi-Fi 6 Channel State Information measures sub-carrier wave attenuation. It is physically impossible to render an image or face.
  • Volatile RAM Ephemerality: Signal processing happens in temporary local memory and is overwritten within 80ms. Zero raw radio waveforms are stored.
  • En-Suite Through-Wall Protection: Safe radio waves penetrate drywall, protecting residents in bathrooms with complete visual privacy.
National Caldicott Guardian Standards

The Caldicott Principles 1–8 Compliance Audit

CuraWave's technical architecture is built to satisfy every one of the eight Caldicott Principles governing confidential patient data across the NHS.

Principle 1 & 2: Justification & Necessity

Strictly Necessary Emergency Data Only

CuraWave only processes the minimum telemetry required to detect life-threatening falls and acute respiratory distress. No extraneous personal profiling is captured.

Principle 3 & 4: Minimum Identifiable Data

Zero Pseudonym Mismatches

Nodes are referenced solely by cryptographic hardware IDs (e.g. CW-NODE-104). Resident names and medical history are never ingested or stored on sensing devices.

Principle 5 & 6: Need-to-Know & Legal Compliance

Role-Based Emergency Dispatch

Alert frames are dispatched exclusively to authorized care personnel and registered Alarm Receiving Centres (ARCs) under UK GDPR Article 6(1)(d) (Vital Interests) and 9(2)(h) (Health & Social Care).

Principle 7 & 8: Duty to Share & Patient Voice

Transparent Patient Information

Clear, non-technical resident information leaflets are provided to residents and families, ensuring transparency under the Mental Capacity Act 2005.

Download Official Data Protection Impact Assessment (DPIA)