Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

TRUST CENTER

Personal Data Protection

Personal Data Protection explains the supported user journey, operating responsibility and verifiable service status.

Scope verifiedDeployment boundary disclosed

Purpose and operational value

PAINFragmented, hard-to-trace integration
TRUSTED CAREOne governed flow
DAILY BENEFITFewer repeats, clear status
TRUST BOUNDARYAuthorization, consent and audit

Business flow

  1. Use case
  2. Identity & authorization
  3. Data / resource
  4. Workflow
  5. Testing
  6. Production boundary
  7. Evidence
Public status reflects evidenced capability; integrations remain configuration-dependent.

Responsibility boundary

Responsibility boundary
Layer Responsibility Status
Trusted Care Initiation, orchestration, role mapping, audit Available
Mobile-ID Identity Layer Identity linking, assurance, evidence Integration-dependent
RAR / VNeID Transaction authentication or information sharing Per approved integration

Evidence and support

Every production claim must be reconciled with the integration register and publication approval. No certification or clinical outcome is implied.

PUBLIC CONTROL STATEMENT

Personal data protection across the lifecycle

The following states control boundaries; specific obligations depend on data roles, agreement and deployment scope.

01

Data scope

Identity, contact, health records, observations, appointments, medication, laboratory results, consent, device data and access logs are processed only within configured service scope.

02

Roles and responsibilities

Controller and processor roles depend on deployment relationships and applicable agreements; Trusted Care does not automatically determine purposes for healthcare customers.

03

Purpose and minimization

Only fields necessary for approved care, operations, safety, support or evidence purposes are collected.

04

Access, sharing and delegation

Access follows role, organization scope and context; sharing requires authority, consent or another applicable basis and is recorded.

05

Data-subject rights

Channels support applicable access, correction, restriction, objection, withdrawal, deletion and portability requests after identity and authority verification.

06

Retention and deletion

Retention depends on record type, customer policy, contract and applicable obligations; expiry triggers approved deletion, anonymization or hold handling.

07

Transfers and subprocessors

International transfers and subprocessors depend on configuration, contract, safeguards and applicable disclosures.

08

Security and incidents

Access control, configured encryption, logging, monitoring, backup and incident response support classification, containment, investigation, remediation and notification.

Privacy contact

info@mobile-id.vn · Requests should identify organization, role and relevant data scope.

Healthcare data matrix by source and purpose

Controller/processor roles depend on the deployment and contract. This matrix describes data categories and does not assign Mobile-ID a universal legal role.

Healthcare data matrix by source and purpose
Data category Typical source Purpose Consumer Retention / deletion
Identity & contact User, VNeID/RAR, organization Onboarding, authentication, communication Authorized applications, IAM and workflows Contract/policy-specific; deletion or restriction when applicable
Health data Patient, HIS, devices, applications Care, monitoring, coordination Authorized care roles and integrations Depends on record type and deployment policy
Kiosk / device data D1078, D1007, DeviceKit Measurement session, quality, Observation Kiosk, care team, integration Session/record policy with offline-queue cleanup
Laboratory data LIS/lab workflows Order, specimen, QC, result Lab, clinician and patient according to authorization Lab record and customer policy
Imaging data PACS/DICOM Diagnosis, consultation, integration Authorized roles Imaging retention and legal/operational holds
TeleHealth data Appointment, uploads, consultation Remote consultation and follow-up Patient, clinician, care team Metadata/content per configuration and policy
Caregiver / delegated access Delegation, task, consent Care on behalf of another person Caregiver and care team Delegation revocation/expiry is a key trigger
Audit & evidence IAM, app, API, consent, device Accountability, investigation, proof Authorized security/compliance/admin roles Separate audit/evidence retention policy

Data-subject request lifecycle

  1. Receive request
  2. Verify identity/authority
  3. Identify controller/processor and affected systems
  4. Access / correct / restrict / withdraw / delete where applicable
  5. Check backups, holds and downstream sharing
  6. Record evidence and respond
Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access