UK compliance hubData protection

Does patient data have to stay in the UK when a clinic uses AI?

Short answer

No law says patient data must stay in the UK. UK GDPR allows transfers abroad with safeguards such as adequacy regulations or approved transfer clauses. Keeping storage and AI processing in the UK removes that transfer risk and simplifies your DPIA, so ask vendors exactly where data is stored, processed and backed up, including AI model calls.

What residency means

Data residency means data is stored and processed on servers in a particular country, under that country's law. For a clinic it is shorthand for two questions: which country's laws and authorities can reach your patients' data, and whether you are making international transfers that need extra safeguards under UK GDPR.

What UK GDPR actually requires

UK GDPR restricts transfers of personal data outside the UK unless they are covered by adequacy regulations, appropriate safeguards such as the International Data Transfer Agreement or the UK Addendum to EU standard contractual clauses, or a limited exception. The UK recognises the EU and EEA as adequate, so EU hosting is generally straightforward. Transfers to other countries need a documented mechanism and, usually, a transfer risk assessment.

Where hidden transfers happen

  • AI model calls: a vendor may store data in the UK but send audio or text to a model hosted elsewhere for transcription or summarisation.
  • Sub-processors: transcription engines, support tools and analytics services may sit in other countries.
  • Backups and disaster recovery copies in a different region.
  • Support access by staff based outside the UK.

Questions to ask, in writing

  • Which region stores production data and backups? Name the region, not 'secure cloud'.
  • Where does AI inference happen, including any third-party models you call?
  • Which sub-processors are outside the UK, and under what transfer mechanism?
  • Is the storage location committed in the data processing agreement?
  • Will you tell us before changing hosting region or adding a sub-processor?

The sub-processor list attached to the data processing agreement is where the real answer lives. Record what you find in your DPIA.

What Motics does

  • Data is stored and processed in-country by default. For UK clinics that means the UK, with other regions available on request.
  • All backups remain within the same jurisdiction.
  • Cross-border transfers do not occur without appropriate safeguards and your authorisation, as set out in our Data Processing Agreement.
  • Motics is hosted on Google Cloud Platform data centres, which hold independent SOC 2 Type II certification.
  • Our current sub-processor list is published on our Trust Centre.

Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.

Primary sources

  1. ICO: International transfers (UK GDPR guidance)
  2. ICO: Contracts and liabilities between controllers and processors
  3. ICO: Special category data (UK GDPR guidance)
  4. NHS England: Guidance on the use of AI-enabled ambient scribing products

Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.

FAQ

Common questions

No. UK GDPR permits international transfers with appropriate safeguards. Residency is a risk-reduction choice rather than a legal mandate, but it simplifies your DPIA, avoids reliance on transfer mechanisms, and is increasingly what patients and insurers expect for health data.

It can. If the vendor sends your data to a model hosted abroad, the data has left the UK wherever the vendor's own servers are. Ask specifically where AI inference happens and which sub-processors are outside the UK.

Generally yes. The UK has adequacy regulations covering the EU and EEA, so transfers there do not need extra transfer mechanisms. You should still record the location in your DPIA and privacy notice.

Sending personal data to, or making it accessible by, an organisation in another country. That includes remote access by overseas support staff, not just storage. The ICO's international transfers guidance explains the tests.

In the data processing agreement and its sub-processor list, not the marketing page. Ask for both, and for a commitment to notify you before hosting or sub-processors change.

Yes. Backup and disaster recovery copies are personal data too. Ask which region holds them and whether that is committed in the contract.

Running a compliance review?

We work with clinic owners, compliance leads and DPOs. Bring your DPIA or vendor questionnaire and we will come prepared.