Do I need a DPIA before using AI in my clinic?
Short answer
Almost certainly. UK GDPR requires a data protection impact assessment before processing that is likely to result in high risk. The ICO lists innovative technology such as AI as a risk indicator, alongside sensitive data like health records. An AI tool processing patient health data usually meets that bar, so complete the DPIA before go-live.
When a DPIA is required
Article 35 of UK GDPR requires a DPIA where processing is likely to result in a high risk to people's rights and freedoms, and it must be done before the processing starts. The ICO explains that large-scale use of special category data always needs one. It also lists innovative technologies, including AI, as a high-risk indicator that needs a DPIA when combined with another criterion, and sensitive data is one of those criteria. As a rule of thumb, two criteria together usually mean you need a DPIA.
The ICO also notes that an individual doctor is not processing at large scale in the way a hospital is. Even so, AI plus health data already ticks two boxes for most clinics. NHS England's ambient scribing guidance and CQC's mythbuster 109 both expect a DPIA. If in doubt, do one: a proportionate DPIA is a few pages, and it is the document you will be asked for first.
What goes in it
- The processing: what the tool does, what data it captures (audio, transcript, note, call recording), who has access, and the data flow from capture to deletion.
- Necessity and proportionality: why you need it, your lawful basis and Article 9 condition, and how you keep data to the minimum.
- Risks to patients: errors entering the record, transfers outside the UK, the vendor training on patient data, excessive retention, unauthorised access, and patients not knowing or not being able to object.
- Mitigations: clinician review, UK storage and processing, a no-training commitment in the DPA, deletion schedules, access controls, encryption, consent and patient information.
- Sign-off: who approved the residual risk, including your data protection officer if you have one, and when it will be reviewed.
Keep it current
A DPIA is not a one-off. Revisit it when you add a new AI agent (a phone agent processes different data from a scribe), when the vendor changes sub-processors or hosting, or when an incident shows a risk you had not considered. If you identify a high risk you cannot reduce, UK GDPR requires you to consult the ICO before starting the processing.
Our free DPIA template for clinic AI sets out these sections with prompts and example wording you can adapt.
What Motics does
- We sign a Data Processing Agreement that meets Article 28 requirements, and publish our sub-processor list on our Trust Centre.
- Facts for your DPIA: UK clinics' data is stored in the UK by default, encrypted with AES-256 at rest and TLS 1.3 in transit, and not used to train AI models.
- Scribe audio is deleted within 48 hours, and transcript and note retention is set per clinic. Deleted data is made unrecoverable by destroying its encryption keys.
- As your processor, we notify you without undue delay if we become aware of a personal data breach, with the detail you need for your own obligations.
- Our DCB 0129 clinical safety case is available on request to support the clinical risk section.
Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.
Primary sources
- ICO: When do we need to do a DPIA?
- ICO: Data protection impact assessments
- ICO: Guidance on AI and data protection
- NHS England: Guidance on the use of AI-enabled ambient scribing products
Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.