Insights

Data Protection•14 May 2026
The difference between a privacy policy and a proper DPIA, and why it matters
Most digital health companies have a privacy policy. Far fewer have a properly conducted DPIA. Conflating the two is one of the most common governance gaps surfaced in NHS procurement.
6 min readRead article

Governance•22 April 2026
What is an Ethical, Social and Legal Impact Assessment, and does your product need one?
The term appears in EU funding bids and procurement requirements but is rarely explained in plain terms. Here is what an ESLIA covers, when it is expected, and how to scope one proportionately.
7 minRead

Buyer & Funder Readiness•9 March 2026
Five questions buyers, funders and partners will ask about your AI product
Health systems, public sector buyers, investors and research funders are asking sharper questions about AI-enabled tools. Here are five that come up most often, and how to prepare.
6 minRead

Regulation•18 February 2026
What the EU AI Act means for small digital health companies, and what to do now
The first comprehensive AI law in the world is rolling out in phases. For small digital health teams, the window to prepare is closing. Here is what applies, when, and where to start.
7 minRead
