What the data is #
The ICO defines data concerning health as personal data related to the physical or mental health of a person, including the provision of health care services, which reveals information about their health status. It lists medical histories, diagnoses, test results and appointment details as examples, and it makes clear that this covers past, current and future health status.
Two consequences follow immediately, and they are the ones most often missed in a clinic. The first is that the sensitive category is much wider than the clinical note: a reminder text, a recall list, an insurance claim code and a missed appointment report are all health data about identifiable people.
The second is that processing it lawfully needs two things rather than one, a lawful basis under Article 6 and a separate Article 9 condition. Having a lawful basis is not enough on its own.
Who stays responsible #
The practice does. The controller is the organisation that decides why and how personal data is processed, and accountability under UK GDPR sits with the controller. A supplier acting on your instructions is a processor, and engaging one does not move the obligation across.
What that means in practice is that the contract between you carries real weight, because it is where the instructions live. The general version of that point is on what a data processing agreement is, and it applies to a clinic without modification.
When a DPIA is required #
A DPIA is required where a type of processing is likely to result in a high risk to people's rights and freedoms. Article 35(3) makes three cases automatic:
- Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where decisions are based on it that produce legal effects.
- Processing special category data on a large scale.
- Systematic monitoring of a publicly accessible area on a large scale.
The ICO then adds ten further types of processing that call for one. Its own rule of thumb is that in most cases a combination of two of these factors indicates the need for a DPIA.
The further types the ICO lists
They include using innovative technology, automated decisions that deny somebody a service, large scale profiling, biometric or genetic data, matching data from several sources, invisible processing where the data was not obtained from the person, tracking location or behaviour, processing about children or vulnerable individuals, and processing where a breach could jeopardise someone's physical health or safety.
Read that list with a clinic in mind and the answer arrives quickly. Introducing something new that touches health data will often hit innovative technology, special category data and, if you treat children or vulnerable adults, a third. Our general page on whether you need a DPIA walks the same test for any business, and the honest summary for a clinic is that the assessment is normally the starting point rather than a formality to be dodged.
The decision line #
UK GDPR sets a separate restriction that matters more here than anywhere else on this site. Where a decision is based solely on automated processing and has a legal or similarly significant effect on the person, it is restricted unless a narrow condition applies. The ICO is precise about the word solely: it means there is no meaningful human involvement in the decision.
Where such processing does take place, people have to be told about it, and be able to make representations, obtain human intervention and contest the outcome.
That is the legal expression of the line this whole cluster holds. Nothing in a clinic should be set up so that a system decides something about a patient's care.
What the ICO actually publishes #
Rather than paraphrase the law, use the source. The ICO maintains guidance and resources on artificial intelligence, including detailed guidance on AI and data protection, guidance on explaining decisions made with AI, and an AI and data protection risk toolkit for assessing risks to individual rights and freedoms. Those documents, not a supplier's assurance page, are what an assessment should be built on. We summarise the regulator's general position on what the ICO says about AI.
Where clinics actually get caught #
In our experience the failures are governance failures rather than technical ones, and they look like this:
- A tool is used quietly by one member of staff because it is useful, and nobody decided it was allowed.
- A free consumer product is used on real patient information because it was to hand.
- Identifiers are stripped from a record and everyone assumes it is now anonymous, when the combination of condition, age and town picks out exactly one person on the list.
- A supplier's compliance claim is treated as the practice's compliance.
- Recordings or transcripts of patient calls accumulate somewhere nobody has named an owner for.
- A DPIA is written after the thing went live, which is the one timing the regulation explicitly rules out.
What this leaves you able to do #
A great deal, because most clinic admin is not about the contents of a record at all. Noticing that a letter was signed and never sent, that a claim has had no response, that an appointment has no reminder against it, or that a recall interval has elapsed does not require anything to read or interpret clinical information.
That distinction runs through every page in this cluster, from referral letters to results and follow ups, and it is the reason those pages stop where they do.
None of the above is legal advice and this page does not interpret the law for your practice. It points at the regulator, which is where the answer for your circumstances has to come from.