Does patient data have to stay in the UK when a clinic uses AI?
Short answer
No law says patient data must stay in the UK. UK GDPR allows transfers abroad with safeguards such as adequacy regulations or approved transfer clauses. Keeping storage and AI processing in the UK removes that transfer risk and simplifies your DPIA, so ask vendors exactly where data is stored, processed and backed up, including AI model calls.
What residency means
Data residency means data is stored and processed on servers in a particular country, under that country's law. For a clinic it is shorthand for two questions: which country's laws and authorities can reach your patients' data, and whether you are making international transfers that need extra safeguards under UK GDPR.
What UK GDPR actually requires
UK GDPR restricts transfers of personal data outside the UK unless they are covered by adequacy regulations, appropriate safeguards such as the International Data Transfer Agreement or the UK Addendum to EU standard contractual clauses, or a limited exception. The UK recognises the EU and EEA as adequate, so EU hosting is generally straightforward. Transfers to other countries need a documented mechanism and, usually, a transfer risk assessment.
Where hidden transfers happen
- AI model calls: a vendor may store data in the UK but send audio or text to a model hosted elsewhere for transcription or summarisation.
- Sub-processors: transcription engines, support tools and analytics services may sit in other countries.
- Backups and disaster recovery copies in a different region.
- Support access by staff based outside the UK.
Questions to ask, in writing
- Which region stores production data and backups? Name the region, not 'secure cloud'.
- Where does AI inference happen, including any third-party models you call?
- Which sub-processors are outside the UK, and under what transfer mechanism?
- Is the storage location committed in the data processing agreement?
- Will you tell us before changing hosting region or adding a sub-processor?
The sub-processor list attached to the data processing agreement is where the real answer lives. Record what you find in your DPIA.
What Motics does
- Data is stored and processed in-country by default. For UK clinics that means the UK, with other regions available on request.
- All backups remain within the same jurisdiction.
- Cross-border transfers do not occur without appropriate safeguards and your authorisation, as set out in our Data Processing Agreement.
- Motics is hosted on Google Cloud Platform data centres, which hold independent SOC 2 Type II certification.
- Our current sub-processor list is published on our Trust Centre.
Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.
Primary sources
- ICO: International transfers (UK GDPR guidance)
- ICO: Contracts and liabilities between controllers and processors
- ICO: Special category data (UK GDPR guidance)
- NHS England: Guidance on the use of AI-enabled ambient scribing products
Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.