Rights are not a premium tier
Regulation (EU) 2016/679 — the GDPR — does not treat transmission as a grey area. Sending, sharing, or making personal data available is processing, and controllers remain accountable for the tools they choose. Article 32 requires appropriate technical and organisational measures; supervisory practice increasingly expects authorised channels, encryption, and documented choices — especially for special-category health data.
Parallel expectations under frameworks such as the NIS2 Directive reinforce the same point: secure communications are part of the baseline, not a bolt-on you buy only when budget allows. In the European Union, data safety, privacy, and security are regulatory duties — and duties that apply to startups, academic labs, and consortiums as much as to large vendors.
Compliance should not sit behind a paywall
Too often, organisations face a false choice: use consumer-grade email and messaging and hope auditors look the other way, or pay for sprawling platforms priced for enterprise procurement cycles. Neither outcome serves the EU’s intent — that individuals’ data is protected by design, and that accountability is practical, not theoretical.
We believe the minimum viable channel for GDPR-aligned clinical exchange — encrypted packages, controlled access, full audit tracing for both sides — should not be withheld behind a licence fee. Charging for baseline regulatory posture turns a legal obligation into a commercial barrier. That is the wrong incentive in a union built on enforceable privacy rights.
Therefore MDBS is free
Channel activation and data delivery is free for all packages meeting volume requirements.
MDBS is a secure data delivery service on clinicaldatavault.com: information travels in sealed, encrypted packages, and only the intended destination can open what is inside. While a package is in transit, the broker cannot read stored contents and does not hold the keys that unlock them. Both the clinical administrator and the technological processor receive a full audit log of handling — for their own documentation and supervisory readiness.
Zero setup, direct exchange between partners, structured feedback alongside data: the essentials regulators ask for, without asking you to fund a platform you do not need for this workflow.
Transmission treated as processing; encryption, access control, and trace documentation built into the channel — not added later.
Public-key encryption for packages; the broker stores ciphertext only. Partners retain control of decryption keys.
Complete lifetime tracing from reception through delivery and removal — documentation both partners can rely on.
Who this is for
MDBS fills the GDPR-compliant delivery gap between a clinical administrator and a technological processor — whether that processor is a MedTech startup, an academic department, a European project consortium, or a large-scale data-processing vendor. Different scales, same regulatory floor: privacy and security should not be priced out of reach.
- Define MDBS as an authorised transmission channel for partner clinical data and feedback.
- Document encryption in transit and access control as Article 32 measures in policies and DPIAs.
- Avoid habitual reliance on consumer messaging or unmanaged personal mail for medical data.
- Keep accountability direct between clinical partner and processor — clearer than opaque third-country routes.
Explore on clinicaldatavault.com
Everything about the service — architecture, regulatory posture, and how a data channel works — is published openly at www.clinicaldatavault.com. Read how it maps to your duties, request a walkthrough, or open the live broker when you are ready to exchange packages with your clinical partner.