A treatment room in a modern private clinic, an examination couch and dark matte cabinetry

Private clinics

Patient data and AI tools: who stays responsible, and when a DPIA is required

Your practice stays the controller for patient data whichever supplier touches it, and clinical information is special category data, so you need a lawful basis and a separate Article 9 condition. A DPIA is required before processing that is likely to result in a high risk, and the ICO's own criteria make that likely in a clinic.

Last checked 20 September 2026

What the data is #

The ICO defines data concerning health as personal data related to the physical or mental health of a person, including the provision of health care services, which reveals information about their health status. It lists medical histories, diagnoses, test results and appointment details as examples, and it makes clear that this covers past, current and future health status.

Two consequences follow immediately, and they are the ones most often missed in a clinic. The first is that the sensitive category is much wider than the clinical note: a reminder text, a recall list, an insurance claim code and a missed appointment report are all health data about identifiable people.

The second is that processing it lawfully needs two things rather than one, a lawful basis under Article 6 and a separate Article 9 condition. Having a lawful basis is not enough on its own.

Who stays responsible #

The practice does. The controller is the organisation that decides why and how personal data is processed, and accountability under UK GDPR sits with the controller. A supplier acting on your instructions is a processor, and engaging one does not move the obligation across.

What that means in practice is that the contract between you carries real weight, because it is where the instructions live. The general version of that point is on what a data processing agreement is, and it applies to a clinic without modification.

When a DPIA is required #

A DPIA is required where a type of processing is likely to result in a high risk to people's rights and freedoms. Article 35(3) makes three cases automatic:

  • Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where decisions are based on it that produce legal effects.
  • Processing special category data on a large scale.
  • Systematic monitoring of a publicly accessible area on a large scale.

The ICO then adds ten further types of processing that call for one. Its own rule of thumb is that in most cases a combination of two of these factors indicates the need for a DPIA.

The further types the ICO lists

They include using innovative technology, automated decisions that deny somebody a service, large scale profiling, biometric or genetic data, matching data from several sources, invisible processing where the data was not obtained from the person, tracking location or behaviour, processing about children or vulnerable individuals, and processing where a breach could jeopardise someone's physical health or safety.

Read that list with a clinic in mind and the answer arrives quickly. Introducing something new that touches health data will often hit innovative technology, special category data and, if you treat children or vulnerable adults, a third. Our general page on whether you need a DPIA walks the same test for any business, and the honest summary for a clinic is that the assessment is normally the starting point rather than a formality to be dodged.

The decision line #

UK GDPR sets a separate restriction that matters more here than anywhere else on this site. Where a decision is based solely on automated processing and has a legal or similarly significant effect on the person, it is restricted unless a narrow condition applies. The ICO is precise about the word solely: it means there is no meaningful human involvement in the decision.

Where such processing does take place, people have to be told about it, and be able to make representations, obtain human intervention and contest the outcome.

That is the legal expression of the line this whole cluster holds. Nothing in a clinic should be set up so that a system decides something about a patient's care.

What the ICO actually publishes #

Rather than paraphrase the law, use the source. The ICO maintains guidance and resources on artificial intelligence, including detailed guidance on AI and data protection, guidance on explaining decisions made with AI, and an AI and data protection risk toolkit for assessing risks to individual rights and freedoms. Those documents, not a supplier's assurance page, are what an assessment should be built on. We summarise the regulator's general position on what the ICO says about AI.

Where clinics actually get caught #

In our experience the failures are governance failures rather than technical ones, and they look like this:

  • A tool is used quietly by one member of staff because it is useful, and nobody decided it was allowed.
  • A free consumer product is used on real patient information because it was to hand.
  • Identifiers are stripped from a record and everyone assumes it is now anonymous, when the combination of condition, age and town picks out exactly one person on the list.
  • A supplier's compliance claim is treated as the practice's compliance.
  • Recordings or transcripts of patient calls accumulate somewhere nobody has named an owner for.
  • A DPIA is written after the thing went live, which is the one timing the regulation explicitly rules out.

What this leaves you able to do #

A great deal, because most clinic admin is not about the contents of a record at all. Noticing that a letter was signed and never sent, that a claim has had no response, that an appointment has no reminder against it, or that a recall interval has elapsed does not require anything to read or interpret clinical information.

That distinction runs through every page in this cluster, from referral letters to results and follow ups, and it is the reason those pages stop where they do.

None of the above is legal advice and this page does not interpret the law for your practice. It points at the regulator, which is where the answer for your circumstances has to come from.

Questions people ask

Is patient information special category data?
Yes. The ICO defines data concerning health as personal data related to the physical or mental health of a person, including the provision of health care services, which reveals information about their health status. That covers medical histories, diagnoses, test results and appointment details. Processing it lawfully needs both a lawful basis under Article 6 and a separate Article 9 condition.
If a supplier processes the data, do they become responsible for it?
No. The practice that decides why and how patient data is processed is the controller, and accountability sits with the controller. A supplier acting on your instructions is a processor. Choosing a processor does not transfer the obligation, which is why the contract between you matters more than the marketing did.
When is a DPIA required?
A DPIA is required where processing is likely to result in a high risk. Article 35(3) names three automatic triggers, one of which is processing special category data on a large scale. The ICO adds ten further types, including using innovative technology, matching data from several sources, invisible processing and processing about vulnerable individuals, and says that in most cases a combination of two of those factors indicates the need for a DPIA.
Can a system make a decision about a patient on its own?
Not where the decision is based solely on automated processing and has a legal or similarly significant effect on the person, unless one of the narrow conditions applies. The ICO stresses that solely means there is no meaningful human involvement, and that people must be told, be able to make representations, obtain human intervention and contest the decision.
Does any of this stop a clinic using AI at all?
No, and that is not the argument. It says which jobs are sensible candidates. The admin around the care, where the question is whether a record exists rather than what it says, sits a long way from a decision about a patient. The care itself is not a candidate at all.

Where these numbers come from

  1. ICO, What is special category data? , read 20 September 2026 . Defines data concerning health and sets out the need for both a lawful basis and an Article 9 condition
  2. ICO, When do we need to do a DPIA? , read 20 September 2026 . Article 35(3) triggers plus the ICO list of ten further processing types
  3. ICO, Automated decision-making and profiling , read 20 September 2026 . Solely automated decisions with a legal or similarly significant effect, and the safeguards required
  4. ICO, Artificial intelligence guidance and resources , read 20 September 2026 . Includes AI and data protection guidance, Explaining decisions made with AI, and the AI and data protection risk toolkit

Last checked 20 September 2026.

Our workings are on the methodology page .

Free audit

A free audit for private clinics

One call, walking through a normal week. You get the tracker of every repeated job ranked by hours, a map of the top five, and the number of hours a month they could give back. Yours to keep either way.

Private clinics

Bookings, recalls, letters and the phone that rings all through a session.

All of private clinics

Read next