UK compliance hubData protection

Do I need a DPIA before using AI in my clinic?

Short answer

Almost certainly. UK GDPR requires a data protection impact assessment before processing that is likely to result in high risk. The ICO lists innovative technology such as AI as a risk indicator, alongside sensitive data like health records. An AI tool processing patient health data usually meets that bar, so complete the DPIA before go-live.

When a DPIA is required

Article 35 of UK GDPR requires a DPIA where processing is likely to result in a high risk to people's rights and freedoms, and it must be done before the processing starts. The ICO explains that large-scale use of special category data always needs one. It also lists innovative technologies, including AI, as a high-risk indicator that needs a DPIA when combined with another criterion, and sensitive data is one of those criteria. As a rule of thumb, two criteria together usually mean you need a DPIA.

The ICO also notes that an individual doctor is not processing at large scale in the way a hospital is. Even so, AI plus health data already ticks two boxes for most clinics. NHS England's ambient scribing guidance and CQC's mythbuster 109 both expect a DPIA. If in doubt, do one: a proportionate DPIA is a few pages, and it is the document you will be asked for first.

What goes in it

  • The processing: what the tool does, what data it captures (audio, transcript, note, call recording), who has access, and the data flow from capture to deletion.
  • Necessity and proportionality: why you need it, your lawful basis and Article 9 condition, and how you keep data to the minimum.
  • Risks to patients: errors entering the record, transfers outside the UK, the vendor training on patient data, excessive retention, unauthorised access, and patients not knowing or not being able to object.
  • Mitigations: clinician review, UK storage and processing, a no-training commitment in the DPA, deletion schedules, access controls, encryption, consent and patient information.
  • Sign-off: who approved the residual risk, including your data protection officer if you have one, and when it will be reviewed.

Keep it current

A DPIA is not a one-off. Revisit it when you add a new AI agent (a phone agent processes different data from a scribe), when the vendor changes sub-processors or hosting, or when an incident shows a risk you had not considered. If you identify a high risk you cannot reduce, UK GDPR requires you to consult the ICO before starting the processing.

Our free DPIA template for clinic AI sets out these sections with prompts and example wording you can adapt.

What Motics does

  • We sign a Data Processing Agreement that meets Article 28 requirements, and publish our sub-processor list on our Trust Centre.
  • Facts for your DPIA: UK clinics' data is stored in the UK by default, encrypted with AES-256 at rest and TLS 1.3 in transit, and not used to train AI models.
  • Scribe audio is deleted within 48 hours, and transcript and note retention is set per clinic. Deleted data is made unrecoverable by destroying its encryption keys.
  • As your processor, we notify you without undue delay if we become aware of a personal data breach, with the detail you need for your own obligations.
  • Our DCB 0129 clinical safety case is available on request to support the clinical risk section.

Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.

Primary sources

  1. ICO: When do we need to do a DPIA?
  2. ICO: Data protection impact assessments
  3. ICO: Guidance on AI and data protection
  4. NHS England: Guidance on the use of AI-enabled ambient scribing products

Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.

FAQ

Common questions

UK GDPR requires one before any processing likely to result in high risk. AI processing of patient health data usually meets that test, and NHS England and CQC guidance both expect one. Treat it as required unless you have a documented reason why the risk is not high.

Probably. The ICO says an individual doctor is not processing at large scale, so that particular trigger may not apply. But AI is an innovative technology and health data is sensitive, and those two criteria together usually point to a DPIA. A short, proportionate one is quick to write.

The clinic, as data controller. The vendor should give you the information you need, such as data flows, hosting, sub-processors, security controls and clinical safety evidence, but the assessment and the decision to proceed are yours.

Use it as an input, not a substitute. A vendor's document describes its product. Your DPIA has to cover your clinic: your patients, your consent process, your retention choices, who has access, and the risks in your setting.

Before you add a new AI tool or agent, when the vendor changes hosting or sub-processors, when you change how the tool is used, and after any incident that reveals a new risk. Set a review date as well.

UK GDPR requires you to consult the ICO before starting the processing. In practice, most risks from clinic AI can be reduced with contractual commitments, technical controls and clinician review, which is why the DPIA is worth doing early.

Running a compliance review?

We work with clinic owners, compliance leads and DPOs. Bring your DPIA or vendor questionnaire and we will come prepared.