Can a UK clinic use an AI scribe under UK GDPR?
Short answer
Yes, if you set it up properly. Consultation audio, transcripts and notes are health data, which UK GDPR treats as special category data. You need an Article 6 lawful basis plus an Article 9 condition, a data processing agreement with the vendor, an updated privacy notice and a DPIA completed before go-live.
Why scribe data is special category data
Everything an AI scribe touches is about a patient's health: the consultation audio, the transcript and the draft note. Under UK GDPR, health data is special category data. Processing it needs two things, not one: a lawful basis under Article 6 and a separate condition under Article 9. For clinical care the health or social care condition is the usual fit. Most clinics already rely on both for their clinical records. The real question is whether the AI processing fits within that existing purpose, and your DPIA is where you record the answer.
Controller and processor: who is responsible for what
Your clinic is the data controller. It decides why and how patient data is processed. The scribe vendor is your processor and may only act on your documented instructions. UK GDPR Article 28 requires a written contract (the data processing agreement, or DPA) that sets out those instructions, confidentiality, security, sub-processors, help with patient rights requests, and what happens to the data at the end of the contract. If a vendor won't sign one, you cannot lawfully use it for patient data.
Four things to have before go-live
- A signed DPA with the vendor, including its current sub-processor list.
- An updated privacy notice telling patients an AI tool is involved, what it does, where data is processed and how long it is kept. See patient consent and transparency.
- A record of the data flow: what is captured, where it is processed and stored, and what is deleted when.
- A DPIA, completed before the first patient is recorded.
Where clinics usually go wrong
The common failures are not exotic. Clinicians use a free consumer app or a personal chatbot account with no DPA. Nobody asks where the AI model actually runs, so data quietly leaves the UK (see UK data residency). The contract allows the vendor to 'improve its services' with your data (see AI training and retention). Or audio is kept indefinitely because no one set a retention period. Each of these is fixable in writing before go-live, and very hard to fix afterwards.
Accuracy is a data protection issue too. UK GDPR requires personal data to be accurate, so an AI draft that mishears a dose or invents a finding is a data quality problem as well as a clinical one. That is why clinician review before anything is filed is not optional.
What Motics does
- Motics acts as your data processor and your clinic stays the data controller. We sign a Data Processing Agreement that meets Article 28 requirements.
- Motics is designed and operated to meet UK GDPR and EU GDPR. The current status of our GDPR controls and our sub-processor list are published on our Trust Centre.
- Patient data is not used to train, fine-tune or improve AI models, ours or any sub-processor's.
- Every AI-generated note is a draft. A clinician reviews and approves it before it is saved.
- Data is encrypted with AES-256 at rest and TLS 1.3 in transit, and UK clinics' data is stored in the UK by default.
Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.
Primary sources
- ICO: Special category data (UK GDPR guidance)
- ICO: Contracts and liabilities between controllers and processors
- ICO: The right to be informed
- ICO: Guidance on AI and data protection
- NHS England: Guidance on the use of AI-enabled ambient scribing products
Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.