Using the App

Non-Conformance and GDPR Simulator

Premium tool. Open directly at /nonconformance-gdpr-simulator. The simulator has its own page and is also listed on the Training Dashboard, which records your attempts.

Data-protection breaches in pathology are common — wrong report sent, sample misidentified, results discussed inappropriately, system access mistake. The simulator drills the breach-classification and Article 33 notification decisions that laboratory staff must make, alongside laboratory non-conformance handling.

What it does

Article 33 — Notification to ICO

The ICO must be notified within 72 hours of becoming aware of a personal data breach UNLESS the breach is unlikely to result in a risk to the rights and freedoms of the data subject.

The simulator drills the judgement calls:

Article 34 — Notification to the data subject (background)

The simulator does not cover Article 34, but you should know it for interview: notifying the data subject is required when the breach is likely to result in a high risk to their rights and freedoms, without undue delay and in plain language, unless the data was rendered unintelligible, notification would involve disproportionate effort, or it would prejudice the public interest.

Internal workflow

For every incident, parallel to the ICO/Article 34 decisions:

  1. Initial incident log — Datix (see article 49)
  2. Confidentiality / Data Protection Officer (DPO) notification — most trusts have a named DPO
  3. Information governance committee review
  4. Root cause analysis (see article 48)
  5. CAPA to prevent recurrence

Common scenarios

Standards alignment

Bands and competency mapping

Common interview question themes

Pair with Incident Reporting Simulator (article 49) for the operational side, RCA Simulator (article 48) for root-cause, and the GDPR / Data article (article 24) for your own personal data rights.