Skip to main content

NEUVIOR governance standard · 03

NEUVIOR Third Party Data Responsibility Standard

A NEUVIOR authored public governance principle. It is not a national, regulatory or certification standard. Use it to keep data responsibility visible when hosting, software or services are entrusted to another organisation.

Published by NEUVIOR · 2 August 2026 · Version 1.0

Document class | NEUVIOR governance principleAuthority | Duties remain attached to each party’s roleEvidence boundary | No certification or security performance claim

The principle

Outsource infrastructure. Never make responsibility disappear.

NEUVIOR treats external hosting, software and service providers as part of the operating system, not as responsibilities outside it.

The purpose of processing, legal role of each party, applicable lawful authority, binding instructions and contractual responsibilities should be established before sensitive information is entrusted to a supplier. Applicable law, regulation, professional duties, mandatory standards and binding contracts prevail.

01

Purpose and legal role assessment

Determine whether each party acts as a controller, joint controller, processor or in another role for the specific processing operation, and record the duties that follow.

Governance
02

Supplier responsibility

A hosting, software or service provider may occupy different legal roles in different contexts. Define its instructions, safeguards, evidence and incident responsibilities without assuming one category.

Delivery
03

Subprocessor and wider supply chain

Where subprocessors or subcontractors are used, keep them visible in the contractual, access, location, assurance and exit chain.

Extended supply chain

Before information is entrusted

The accountable organisations should establish:

The answers should be defined, approved and retained in the relevant legal, governance, security and operational records.

  • 01

    Information and location

    what categories of information are involved and where they are stored;

  • 02

    Access chain

    which individuals, systems and subcontractors may access them;

  • 03

    Monitored activity

    how access and privileged activity are monitored;

  • 04

    Detection and escalation

    who detects, investigates and escalates abnormal activity;

  • 05

    Evidence and affected parties

    how evidence is preserved and affected parties are identified;

  • 06

    Notification responsibility

    who owns regulatory, contractual and individual notification responsibilities, subject to applicable law and each party’s legal role;

  • 07

    Continuity and recovery

    how continuity, recovery and essential information availability will operate; and

  • 08

    End of relationship

    how information can be securely returned, transferred or deleted when the relationship ends.

Retained responsibility

Outsourcing infrastructure does not outsource responsibility.

Controllers, processors and other accountable parties retain the duties attached to their roles. A contract should allocate work and information flows clearly; it cannot erase a statutory duty.

This principle does not determine the legal role or lawful basis for a particular processing operation and is not legal, data protection or security advice.

The ICO material linked below provides wider accountability context. Accessed 2 August 2026, the ICO marks this material as under review following the Data (Use and Access) Act. Readers should check current official guidance and context specific advice. The link does not endorse NEUVIOR, certify any supplier or make this a regulatory standard.

01

Before the relationship

Map roles, information flows, locations, subprocessors, safeguards, evidence and approval conditions.

02

During the relationship

Monitor access, material changes, abnormal activity, incidents, continuity and the evidence needed for accountable decisions.

03

At exit

Evidence return, transfer, permitted retention and secure deletion across active systems, backups and relevant derived copies.

Publication and evidence boundary

This principle is not a security certificate or operating claim.

This standard describes a governance principle. It does not indicate cybersecurity certification, regulatory approval, NHS deployment, customer adoption or independently demonstrated security performance.

Publication is not evidence that NEUVIOR holds health data or has implemented, audited or independently validated this principle in an operating service.

Human decision requiredProceed only inside an evidenced and governed scope.
01

Publisher

NEUVIOR

Publication owner
02

Revision history

Version 1.0 · Initial publication · 2 August 2026

Current public version
03

Review trigger

Material change in applicable law, regulator guidance, supplier context, operating model or NEUVIOR’s public position.

Reassess and republish

Classified public record

ANALYSIS + EVIDENCE BOUNDARY

Read the argument. Verify the product separately.

Published analysis can explain why governance matters. It cannot evidence security, clinical authority, certification, product readiness or local approval. Use the dated NEUVIOR records for that.

  1. TechRadar ProContributed opinion

    Five questions to test whether an AI stack is truly under your control

    In TechRadar Pro, Varun Sharma sets out five tests for enterprise AI control across provenance, infrastructure, legal authority and safe exit.

    Test provenance, control and safe exit
  2. NEUVIOR InsightsNEUVIOR analysis

    From pilot theatre to financial grip: how NHS CFOs should evaluate AI in medicines optimisation

    NHS finance leaders do not need another AI pitch. They need a disciplined way to decide whether a technology can release value within the financial rules they are already being held to.

    See how a finance leader should test an AI claim

NEUVIOR Insights and After Publication reflections are company or founder analysis. Publisher records evidence publication, not endorsement, adoption, product readiness, savings or clinical outcomes.

The test

Can the organisation still see every duty across the supplier chain?

If roles, access, incident decisions, notifications, continuity and exit cannot be traced, the third party accountability record is incomplete.

QUESTIONS · ANSWERED DIRECTLY

The useful answers, in one place.

Browse every question
01Does using a cloud or software provider transfer accountability?

No. Controllers, processors and other accountable parties retain the legal and contractual duties attached to their roles.

02What should be established before information is entrusted to a supplier?

The purpose, legal roles, lawful authority, information flows, locations, access, subprocessors, safeguards, monitoring, incident responsibilities, continuity arrangements and exit process should be defined and recorded.

03Who reports a personal data breach?

That depends on the parties’ legal roles and the circumstances. Contracts and operating procedures should support prompt escalation. They should provide the information needed for the legally responsible party to assess regulatory and contractual notification, and whether affected people must be notified.

04What should happen when the supplier relationship ends?

Return, transfer, permitted retention and secure deletion arrangements should be defined and evidenced. This includes relevant backups and derived copies.

05Does this standard certify NEUVIOR’s security?

No. Publication is not cybersecurity certification, regulatory approval, evidence of NHS deployment or customer adoption, or proof of independently demonstrated security performance.