{"id":3075,"date":"2026-03-24T08:39:42","date_gmt":"2026-03-24T08:39:42","guid":{"rendered":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/?p=3075"},"modified":"2026-04-13T11:56:51","modified_gmt":"2026-04-13T11:56:51","slug":"kivicare-gdpr-integration","status":"publish","type":"post","link":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/kivicare-pro\/documentation\/advanced-feature-pro\/kivicare-gdpr-integration\/","title":{"rendered":"KiviCare GDPR Integration"},"content":{"rendered":"<div class=\"nolwrap\">\n<h2 class=\"wp-block-heading\"><strong>1. Overview<\/strong><\/h2>\n\n\n\n<p>KiviCare&#8217;s GDPR (General Data Protection Regulation) functionality is designed to help clinics and healthcare providers comply with data protection laws. It offers comprehensive tools for managing patient consent, maintaining a detailed audit trail of data-related activities, and supporting data subject rights requests.<\/p>\n\n\n\n<p>The GDPR module is integrated into the KiviCare ecosystem to ensure accountability, transparency, and regulatory compliance when handling sensitive patient health data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>2. Core Features<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Consent Management<\/strong>: Enables clinics to obtain, record, and manage patient consent for various data processing activities.<\/li>\n\n\n\n<li><strong>Audit Trail<\/strong>: Provides a secure and comprehensive log of all GDPR-relevant actions, including data access, creation, modification, and deletion.<\/li>\n\n\n\n<li><strong>Data Subject Rights Support<\/strong>: Assists clinics in responding efficiently to patient requests such as the right to access their data and the right to be forgotten (data erasure).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>3. Consent Management<\/strong><\/h2>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>3.1. Consent Configuration<\/strong><\/h4>\n\n\n\n<p>Clinics can configure GDPR consent settings directly from the KiviCare dashboard. Key configuration options include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enabling or disabling the GDPR module.<\/li>\n\n\n\n<li>Setting and updating the consent version number.<\/li>\n\n\n\n<li>Providing links to the clinic\u2019s Privacy Policy and Terms of Service.<\/li>\n\n\n\n<li>Defining which types of consent are mandatory for patients.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>3.2. Patient Consent Process<\/strong><\/h4>\n\n\n\n<p>During new patient registration, the system prompts patients to review and provide consent according to the clinic\u2019s configured settings. All consents are recorded securely.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>3.3. Re-consent Mechanism<\/strong><\/h4>\n\n\n\n<p>When a clinic updates its privacy policy, terms of service, or other consent-related documents, the consent version can be incremented. This automatically triggers a re-consent request for existing patients, ensuring they review and agree to the latest terms before continuing to use the system.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"521\" src=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/Screenshot-from-2026-04-13-17-25-37-1024x521.png\" alt=\"\" class=\"wp-image-3176\" srcset=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/Screenshot-from-2026-04-13-17-25-37-1024x521.png 1024w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/Screenshot-from-2026-04-13-17-25-37-300x153.png 300w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/Screenshot-from-2026-04-13-17-25-37-768x391.png 768w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/Screenshot-from-2026-04-13-17-25-37.png 1534w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>4. Audit Trail<\/strong><\/h2>\n\n\n\n<p>KiviCare employs a high-security logging service that records activities based on user-defined sensitivity levels.<\/p>\n\n\n\n<p>The GDPR audit trail is a chronological record of all activities involving personal data. It plays a critical role in demonstrating compliance, investigating incidents, and maintaining accountability.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>4.1. &nbsp;Activity Log Modes<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Disabled<\/strong>: No logging (Not recommended for compliance).<\/li>\n\n\n\n<li><strong>Preview<\/strong>: Logs basic CRUD actions and Authentication.<\/li>\n\n\n\n<li><strong>Significant Events<\/strong>: (Recommended) Records mutations (Create\/Update\/Delete) and&nbsp;<strong>Security Incidents<\/strong>, but skips passive &#8220;Viewing&#8221; to save server space.<\/li>\n\n\n\n<li><strong>All Events<\/strong>: Forensic-level logging of every single interaction, including every time a record is opened.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>4.2. Logged Activities<\/strong><\/h4>\n\n\n\n<p>The following categories of events are automatically recorded:<\/p>\n\n\n\n<p><strong>Patient Data Activities<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Creation of a new patient record<\/li>\n\n\n\n<li>Viewing\/accessing a patient\u2019s record<\/li>\n\n\n\n<li>Updating patient information<\/li>\n\n\n\n<li>Deleting a patient record<\/li>\n<\/ul>\n\n\n\n<p><strong>Authentication Events<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Successful user login<\/li>\n\n\n\n<li>User logout<\/li>\n\n\n\n<li>Failed login attempts<\/li>\n<\/ul>\n\n\n\n<p><strong>Appointment Activities<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Creation of a new appointment<\/li>\n\n\n\n<li>Viewing an appointment<\/li>\n\n\n\n<li>Updating an appointment<\/li>\n\n\n\n<li>Deleting an appointment<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>4.3. Viewing the Audit Trail<\/strong><\/h4>\n\n\n\n<p>Clinic administrators can access the audit trail through the KiviCare dashboard. The interface supports filtering, searching, and exporting logs for easy review and reporting.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1010\" src=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/activitylog-1024x1010.png\" alt=\"\" class=\"wp-image-3083\" srcset=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/activitylog-1024x1010.png 1024w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/activitylog-300x296.png 300w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/activitylog-768x758.png 768w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/activitylog.png 1479w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>5.Managing Data Subject Rights<\/strong><\/h2>\n\n\n\n<p>GDPR grants patients the right to access their data and the right to have it completely erased. KiviCare manages these requests through a secure, multi-step verification process.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Processing Data Export Requests (Right to Access)<\/strong><\/h4>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Patient Request:<\/strong> The patient logs into their KiviCare profile and clicks <strong>Export Personal Data<\/strong>. The system sends them a verification email.<\/li>\n\n\n\n<li><strong>Patient Verification:<\/strong> The patient opens the email and clicks the secure link to confirm they are the account owner. The request is now marked as &#8220;Confirmed.&#8221;<\/li>\n\n\n\n<li><strong>Admin Generation:<\/strong> The Clinic Administrator goes to <strong>Tools<\/strong> &gt; <strong>Export Personal Data<\/strong> in the WordPress backend, locates the confirmed request, and clicks <strong>Send Export Link<\/strong>.<\/li>\n\n\n\n<li><strong>Data Delivery:<\/strong> The system compiles the patient&#8217;s profile, appointment, and billing data into a secure ZIP file and automatically emails the patient a temporary download link.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"540\" src=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdprexportdata-1024x540.png\" alt=\"\" class=\"wp-image-3086\" srcset=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdprexportdata-1024x540.png 1024w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdprexportdata-300x158.png 300w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdprexportdata-768x405.png 768w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdprexportdata.png 1445w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"564\" src=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-export-ttools-1024x564.png\" alt=\"\" class=\"wp-image-3087\" srcset=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-export-ttools-1024x564.png 1024w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-export-ttools-300x165.png 300w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-export-ttools-768x423.png 768w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-export-ttools.png 1479w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"564\" src=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/send-export-link-1024x564.png\" alt=\"\" class=\"wp-image-3088\" srcset=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/send-export-link-1024x564.png 1024w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/send-export-link-300x165.png 300w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/send-export-link-768x423.png 768w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/send-export-link.png 1479w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Processing Data Erasure Requests (Right to Be Forgotten)<\/strong><\/h4>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Patient Request:<\/strong> The patient logs into their KiviCare profile and clicks the <strong>Request Account Deletion<\/strong> button.<\/li>\n\n\n\n<li><strong>Immediate Data Scrubbing:<\/strong> The system instantly and permanently deletes the user account and scrubs all personal identifiers from associated appointments and medical records. This action happens immediately upon the patient&#8217;s request, requiring no email verification or administrator approval.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"544\" src=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/account-deletion-1024x544.png\" alt=\"\" class=\"wp-image-3089\" srcset=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/account-deletion-1024x544.png 1024w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/account-deletion-300x159.png 300w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/account-deletion-768x408.png 768w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/account-deletion.png 1442w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>6. Setup and Configuration<\/strong><\/h2>\n\n\n\n<p>Follow these steps to enable and configure the GDPR functionality in KiviCare:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Access KiviCare Settings<\/strong><br>Log in to your WordPress dashboard and navigate to the KiviCare settings area.<\/li>\n\n\n\n<li><strong>Enable the GDPR Module<\/strong><br>In the Modules or Add-ons section, activate the GDPR feature.<\/li>\n\n\n\n<li><strong>Configure Consent Settings<\/strong><br>Go to the GDPR Consent settings page and configure the following:\n<ul class=\"wp-block-list\">\n<li>Enable GDPR compliance<\/li>\n\n\n\n<li>Set the current consent version (e.g., 1.0, 1.1)<\/li>\n\n\n\n<li>Enter the Privacy Policy URL<\/li>\n\n\n\n<li>Enter the Terms of Service URL<\/li>\n\n\n\n<li>Select mandatory consent types<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Configure Activity Log Settings<\/strong><br>Navigate to the GDPR &amp; Activity Log settings page to define log retention periods and select specific events to track.<\/li>\n\n\n\n<li><strong>Save All Changes<\/strong><br>Ensure all settings are saved to activate the configured GDPR features.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"908\" src=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-setting-1024x908.png\" alt=\"\" class=\"wp-image-3167\" srcset=\"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-setting-1024x908.png 1024w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-setting-300x266.png 300w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-setting-768x681.png 768w, https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-content\/uploads\/sites\/18\/2026\/03\/gdpr-setting.png 1260w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>7. Best Practices for GDPR Compliance with KiviCare<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Regularly review and update consent versions when policies change.<\/li>\n\n\n\n<li>Monitor the audit trail periodically for unusual activity.<\/li>\n\n\n\n<li>Document all data subject requests and how they were handled.<\/li>\n\n\n\n<li>Ensure privacy policy and terms of service links are always up-to-date.<\/li>\n\n\n\n<li>Train staff on using the GDPR tools within the KiviCare dashboard.<\/li>\n<\/ul>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>1. Overview KiviCare&#8217;s GDPR (General Data Protection Regulation) functionality is designed to help clinics and healthcare providers comply with data protection laws. It offers comprehensive tools for managing patient consent, maintaining a detailed audit trail of data-related activities, and supporting data subject rights requests. The GDPR module is integrated into the KiviCare ecosystem to ensure [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":0,"parent":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32,51],"tags":[],"class_list":["post-3075","post","type-post","status-publish","format-standard","hentry","category-kivicare-pro","category-advanced-feature-pro"],"featured_image_src":null,"author_info":{"display_name":"wordpressadminiq","author_link":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/author\/wordpressadminiq\/"},"_links":{"self":[{"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/posts\/3075","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/comments?post=3075"}],"version-history":[{"count":13,"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/posts\/3075\/revisions"}],"predecessor-version":[{"id":3178,"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/posts\/3075\/revisions\/3178"}],"wp:attachment":[{"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/media?parent=3075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/categories?post=3075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/documentation.iqonic.design\/kivicare-wordpress\/wp-json\/wp\/v2\/tags?post=3075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}