Documented controls

Version 1.1 ยท reviewed 27 July 2026

Security and data handling rules

These rules explain how the MEDDEV Secure Client Room controls access to regulatory documents, protects transfers and records handling events.

01

Framework statement

Reference framework and scope

The Client Room was designed with reference to the confidentiality, integrity, availability and risk-management principles of ISO/IEC 27001:2022 and to the technical and organisational measures described in Article 32 of the General Data Protection Regulation.

This is a design and control statement. It does not state that MEDDEV, the Client Room or its information security management system is certified to ISO/IEC 27001 or has received independent conformity assurance.

02

Implemented safeguards

Controls operating in the Client Room

Controlled access

Each manufacturer receives a personal, expiring, one-time invitation. Invitation and session secrets are stored as cryptographic hashes. Access can be revoked.

Session protection

Sessions are time-limited. Cookies use Secure, HttpOnly and SameSite=Strict protections. State-changing client requests require an additional anti-forgery token.

Private encrypted storage

Documents are held in a non-public storage bucket in the European Union. Cloudflare R2 applies AES-256 encryption at rest and Transport Layer Security during transfer.

File handling checks

Permitted formats and file sizes are restricted. File signatures are checked against their declared type. Manufacturer uploads remain quarantined until MEDDEV completes handling checks.

Integrity and traceability

A SHA-256 digest is recorded for each accepted file. Room, session, upload, status and download events are entered in an audit log. Network addresses are pseudonymised before logging.

Browser safeguards

Responses are not cached and the portal is excluded from search indexing. Security headers restrict framing, content loading, referrer disclosure and browser permissions.

03

Manufacturer responsibilities

Rules for transferred documents

  1. 01

    Transfer only documents that relate to the manufacturer and regulatory scope displayed in the room.

  2. 02

    Do not upload patient-identifiable data, health records, unrelated personal data, executable files or malicious content.

  3. 03

    Remove special-category personal data unless MEDDEV has expressly agreed a lawful and necessary handling route in writing.

  4. 04

    Do not send a file password through the Client Room or in the same message as the protected file.

  5. 05

    Report a suspected incorrect disclosure, compromised invitation or security incident immediately to biuro@meddev.pl.

04

Access and retention

Automatic deletion after room expiry

By default, a room expires 30 days after it is created. A documented period from 7 to 90 days may be set for a specific case. Client access ends on the date displayed in the room and may be revoked earlier.

A daily retention process deletes expired-room documents from private storage and removes the room's sessions, invitations, document metadata and contact details. It retains only a minimal pseudonymised event recording when the purge occurred and the number and total size of objects removed. It does not retain file names or document contents.

The Client Room is a controlled transfer channel, not a long-term regulatory archive. Any record that MEDDEV is legally or contractually required to retain must be moved to the authorised record system before the room expires.

05

Privacy information

Data controller and individual rights

MEDDEV COMPLIANCE sp. z o.o., ul. Mydlarska 47, 04-690 Warsaw, Poland, KRS 0000900989, VAT PL9522216560, is the controller of personal data handled through the Client Room.

The purposes and legal bases for processing, categories of recipients, individual rights and complaint route are described in the MEDDEV Compliance Privacy Policy.