DPIA template for clinic AI
A data protection impact assessment template for UK clinics introducing AI scribes or phone agents. Vendor-neutral, structured on the ICO's DPIA steps, with prompts, example wording and starter risks. No sign-up.
Replace everything in [square brackets]. Version . Practical starting point, not legal advice.
1. Why a DPIA is needed
Explain what the project is and why it needs a DPIA. For clinic AI the usual reasons are innovative technology combined with special category health data.
- What AI tool are you introducing, and what will it do?
- Which ICO high-risk indicators apply (innovative technology, special category data, large scale, vulnerable people)?
[Clinic name] plans to use [tool name], provided by [vendor], to [draft clinical notes from consultations / answer and record patient phone calls] for clinician or staff review. The processing uses innovative technology (AI) and special category health data, so we have completed this DPIA before go-live.
2. Describe the processing
Set out the nature, scope, context and purpose of the processing, including the full data flow from capture to deletion.
- What data is captured (audio, transcripts, draft notes, call recordings, metadata)?
- Whose data is it (patients, carers, staff, callers)? Roughly how many people a month?
- Where is each type of data processed and stored, including AI model providers and backups?
- Who can access it, at the clinic and at the vendor?
- How long is each type of data kept, and how is it deleted?
- What is the purpose, and what benefit do patients and the clinic get?
Audio is captured on [device] with the patient's agreement, sent encrypted to [vendor] and processed in [country/region] to produce a transcript and draft note. The clinician reviews and edits the draft before saving it to [patient management system]. Audio is deleted after [period]; transcripts after [period]; approved notes follow our clinical record retention schedule. Sub-processors are listed in the vendor's data processing agreement dated [date].
3. Consultation
Record who you asked for views: clinicians, reception staff, your data protection officer, the vendor, and where appropriate patients.
- Who did you consult, when, and what did they raise?
- What information did the vendor provide (DPA, sub-processor list, security and clinical safety evidence)?
We consulted [clinical lead], [practice manager] and [DPO or adviser] on [date]. [Vendor] supplied its data processing agreement, sub-processor list, security documentation and clinical safety evidence.
4. Necessity and proportionality
Show that the processing is necessary for the purpose and that you keep it to the minimum.
- What is your UK GDPR Article 6 lawful basis and Article 9 condition?
- Could you achieve the purpose with less data, or without recording (for example dictation)?
- How will you tell patients and let them object? (Privacy notice, signage, asking in the room.)
- How will you handle access, correction and erasure requests?
- Does the vendor act only on your documented instructions, with no use of data for its own purposes such as model training?
- Are any transfers outside the UK covered by an appropriate safeguard?
Lawful basis: [Article 6 basis]. Article 9 condition: [condition, for example health or social care]. Patients are told before recording and can decline at no cost to their care; clinicians use dictation instead. Our privacy notice was updated on [date]. The vendor's DPA states that patient data is not used to train AI models.
5. Identify and assess risks
List the risks to patients and others, with likelihood and severity before mitigation. A starter list is below; add risks specific to your clinic.
- What could go wrong for a patient if the data was inaccurate, lost, misused or seen by the wrong person?
- Are any patient groups at higher risk (for example people who may lack capacity, or speakers of other languages)?
| Risk | Likelihood | Severity |
|---|---|---|
| AI draft contains an error (wrong dose, side or finding, or content that was not said) that enters the clinical record. | Possible | Severe |
| Patient is recorded without knowing or without a real choice. | Possible | Significant |
| Patient data is transferred outside the UK without safeguards, including to an AI model provider. | Possible | Significant |
| Vendor or its sub-processors use patient data to train or improve AI models. | Possible | Significant |
| Audio, transcripts or recordings are kept longer than needed. | Probable | Significant |
| Unauthorised access to recordings or notes, at the clinic or the vendor. | Remote | Severe |
| Service outage during clinic leaves notes or calls unhandled. | Possible | Significant |
6. Measures to reduce risk
For each risk, record the measures you will take and the residual risk after them.
- Which measures are contractual, technical, or about how staff work?
- Who owns each measure, and by when?
- Is any residual risk still high? If so, UK GDPR requires you to consult the ICO before starting.
| Risk | Measures |
|---|---|
| AI draft contains an error (wrong dose, side or finding, or content that was not said) that enters the clinical record. | Clinician reviews and edits every draft before saving; documentation audit; incident reporting to the vendor. |
| Patient is recorded without knowing or without a real choice. | Ask at the start of each session and record the answer; privacy notice and signage; dictation for patients who decline or may lack capacity. |
| Patient data is transferred outside the UK without safeguards, including to an AI model provider. | Confirm storage and processing locations in the DPA and sub-processor list; require notice before changes. |
| Vendor or its sub-processors use patient data to train or improve AI models. | Contractual no-training commitment covering the vendor and all sub-processors. |
| Audio, transcripts or recordings are kept longer than needed. | Written retention periods for each data type; automatic deletion; check deletion on a sample basis. |
| Unauthorised access to recordings or notes, at the clinic or the vendor. | Role-based access with two-factor authentication; access logging; encryption at rest and in transit; leavers removed promptly. |
| Service outage during clinic leaves notes or calls unhandled. | Fallback to typing or dictation; calls divert to staff; outage procedure known to the team. |
7. Sign-off and review
Record who approved the residual risk and when the DPIA will next be reviewed.
- Who approved the measures and the residual risk?
- What advice did your data protection officer give, and was it followed?
- When will you review this DPIA (and what changes trigger an earlier review)?
Approved by [name, role] on [date]. DPO advice: [summary]. Next review: [date], or sooner if we add an AI tool, the vendor changes hosting or sub-processors, or an incident reveals a new risk.
Next: update your privacy notice with our AI privacy notice builder, and read the UK compliance hub for the rules behind each section. Source: ICO guidance on data protection impact assessments.
FAQ
About this template
Yes. Copy it or download it as a text file, adapt it to your clinic and keep it with your data protection records. You do not need to give us your email address.
Yes. It is vendor-neutral. Anything specific to your vendor, such as where data is processed, retention periods and sub-processors, is a placeholder for you to fill in from the vendor's data processing agreement.
No template can do that on its own. A DPIA is your clinic's assessment of your own processing. This template gives you the structure, prompts and starter risks; the answers, measures and sign-off are yours. Take advice from your data protection officer where you are unsure.
You can cover both in one DPIA if you describe each processing operation and its risks separately. A phone agent records callers and processes different data from a scribe, so it needs its own data flow, risks and measures.
Before go-live, then at a set review date, and sooner if you add an AI tool, the vendor changes hosting or sub-processors, you change how the tool is used, or an incident reveals a new risk.