Skip to main content
Version: 0.2 Draft 2

Appendix B — Controlled Purpose Vocabulary

The following values are defined as the standard controlled vocabulary for the allowed_purposes field. Implementers may use additional values expressed as URIs. Values are case-sensitive.

TermDefinition
clinical_analyticsProcessing for the purpose of analysing clinical or health data to derive insights, support diagnosis, or inform treatment pathways.
treatment_supportProcessing in direct support of delivering healthcare treatment to the data subject.
clinical_trial_protocol_{id}Processing within the scope of a specific, identified clinical trial protocol. Replace {id} with the trial identifier.
research_public_interestScientific or academic research conducted in the public interest, consistent with applicable ethical approvals.
fraud_preventionProcessing to detect, prevent, or investigate fraud or financial crime.
compliance_reportingProcessing required to fulfil a statutory reporting obligation.
service_deliveryProcessing necessary to deliver a contracted service to the data subject.
marketing_targetedProcessing to deliver targeted marketing communications where consent has been obtained.
marketing_generalProcessing to deliver general marketing communications on the basis of legitimate interests.
model_trainingProcessing to train, fine-tune, or evaluate a machine learning model.
model_inferenceProcessing as input to a deployed machine learning model for inference only, not training.
data_portabilityProcessing to fulfil a data portability request from the data subject.
legal_proceedingsProcessing in connection with legal proceedings or legal advice.
audit_internalProcessing for the purpose of internal audit, governance, or risk management.
audit_externalProcessing by an external auditor or regulator.
archiving_public_interestLong-term archiving in the public interest, consistent with applicable exemptions.