For GP Practices

GDPR Compliant AI for GP Practices: A Short DSPT Entry

Every year the practice answers, in the Data Security and Protection Toolkit, for where its data is processed and by whom. A cloud AI tool adds a processor to that answer. A machine in the surgery adds nothing.

£500 per month for the software and the hardware rental. You rent the machine — you don’t buy it.

GDPR compliant AI for GP practices means AI used in a way that meets the UK GDPR, the Data Protection Act 2018 and the practice’s DSPT obligations. A machine installed in the surgery means no third-party AI processor and no restricted transfer for the AI step, and the clinical system stays untouched; lawful basis and retention remain the practice’s.

Bring your DPO to the call

A short call with the practice manager and your DSPT lead. We will walk through the data flow before any hardware is ordered.

The Data Flow
An on-premises AI machine keeping personal data inside the surgery

Model, documents and chat history on one machine in the practice office. Practice and patient information never leave the surgery.

AI and GDPR compliance for NHS GP practices and primary care networks across the UK

UK GDPR, the DSPT, Caldicott principles and the ICO. Here is what changes when the data stays in the surgery.

Also From Us · Cloud AI Agents

Cloud Agents for the Phone, Local AI for Practice Documents

Appointment calls and the admin inbox suit a hosted agent; practice policies, complaints correspondence and hospital letters suit a machine inside the surgery. Many practices run both.

See the Local AI product page →
The Difference

The Questions Your DPO Asks About AI and GDPR Compliance

Most of the hard work in an AI GDPR assessment is about the processor and the transfer. Here is what each looks like for GP practices.

The questionCloud AI serviceA machine in the surgery
Who is the processor for the AI step?The AI provider — appoint, assess, contract, reviewNobody — the model runs on your own machine
Is there a restricted transfer?Often — IDTA or UK Addendum, plus a transfer risk assessmentNo — the data never leaves the building
Is our data used to train models?Depends on the plan, the settings and the small printNever
What goes in the Article 30 record?A new processor and, often, a new transferOne fewer of each
Erasure requestsYour copy and theirsYour copy only
Lawful basis, purpose, retentionYoursStill yours
The DSPT Assessment

What the Toolkit Asks, and What a Machine in the Surgery Answers

A GP practice’s data protection is not abstract: it is the Data Security and Protection Toolkit, submitted every year, with a Caldicott Guardian and an information governance lead who have to be able to name every system that processes patient or practice data and every organisation that touches it. A cloud AI tool used by the practice office — even for administrative documents like complaint responses and policies — is a processor to name, assess, contract with and, if it processes data outside the UK, to justify with a transfer mechanism.

A machine in the surgery keeps the entry short. The model runs on the practice’s own network in the practice office; policies, complaint files, reports, leaflets and chat history stay on it. No AI provider processes practice or patient information, so no processor to name for that step. Nothing leaves the building, so no transfer. Your content is never used to train models. The Caldicott question — is this use of identifiable information necessary and minimal — is answered the way it always was, by the practice, but with one fewer place the data could have gone.

What stays with the practice is what was always its own: lawful basis, retention under the practice’s existing policy, and who in the office can see what, set through the Microsoft 365 or Google Workspace sign-in staff already use. The clinical record is never touched: the machine is not connected to the clinical system, it is not for clinical decisions, and it is not a medical device.

We act as a processor only for the support access the practice grants us, under a data processing agreement, and we will help the DSPT lead word the entry. We would rather they and the Caldicott Guardian were on the first call; the data flow takes ten minutes to walk through.

What You Get

What Is Installed, and What the Paperwork Looks Like

The machine, the software on it, the sign-in and the support — and the two documents your advisers will ask for.

🏠

No third-party AI processor

The model runs on your own machine, so your documents are never sent to an AI provider. Nothing to appoint, assess or keep under review for the AI step.

🇬🇧

No restricted transfers

Your data never leaves the UK. The IDTA, the UK Addendum and a transfer risk assessment simply do not arise for the processing it does.

📋

A shorter Article 30 record

One fewer processor and one fewer transfer to describe, review and keep current — and one less thing to explain if the ICO ever asks.

DocumentWhat the practice asks forWhat stays where
Policies and proceduresFind it, check the review date, cite the pageOn the machine, in the surgery
Complaint filesA draft response from the file and your complaints policyOn the machine, in the surgery
PCN and contract reportingThe quarterly report assembled from submissionsOn the machine, in the surgery
Patient letters and leafletsA draft in the practice’s wordingOn the machine, in the surgery
National guidance and CQC evidenceA summary against what the practice already doesOn the machine, in the surgery
Clinical recordsNot used — stays in the clinical systemYour clinical system
How It Works

From the DSPT Lead’s Call to a Machine in the Office

Weeks, not months. Most practices start with the policies folder or the complaints process; PCNs usually start with one practice.

1

A call with the practice manager

List size, PCN role, how many staff, which paperwork goes first. We specify the machine from that and walk through the data flow with your DSPT lead.

2

Install and import

The machine goes on the practice network. Sign-in connects to your Microsoft 365 or Google Workspace. Policies, templates and correspondence are imported into spaces.

3

Train the office, then support

We train the practice manager, reception and admin team on what it does and what it is not for, then keep the software and models current.

Straight Answers

Where Local AI Is the Wrong Answer

We would rather lose the enquiry than the trust. Three things we tell every prospect before they sign anything.

It is not a compliance certificate

No product can make GP practices UK GDPR-compliant on their own. A machine in the building removes the processor and transfer questions for the AI step. Purpose, lawful basis, retention and staff conduct remain yours, and we will not tell you otherwise.

It is slower than the big cloud models

Open-weight models on a single machine are capable for summarising, drafting and answering questions about your own documents. For frontier reasoning on hard, novel problems, the largest cloud models are still ahead. That is the trade.

It is a weeks-long install, not a sign-up

A cloud agent is live in days. Local AI needs the machine specified, delivered, installed on your network and your documents imported. Weeks, not months — but not tomorrow.

Why Business AI Agents

Built With the Regulator in Mind

Data never leaves the building

Open-weight model, documents and chat history on one machine in the surgery. The only outside connection is your own sign-in.

Never used for training

Your content is not used to train or improve any model. The models arrive trained and stay that way unless you ask.

One DPA, for one thing

We are a processor only for the support access you grant, and the agreement says so in plain terms.

Honest about the trade

Local models are capable and somewhat slower than the largest cloud services. We say so before you sign anything.

Which Page Answers Your Practice’s Question

If your question is…The short answerRead more
The general GDPR picture for AIThe processor and transfer questions, in fullGDPR compliant AI
We want the Local AI overview for GP practicesThe head page for surgeriesLocal AI for GP practices
What exactly is installed in the surgery?One machine in the office, supportedOn-Premises AI for gp practices
We want a private ChatGPT for the officeThat is the private chat assistantPrivate AI for gp practices
The 8am phone queue is the real problemA hosted agent, live in daysAI Receptionist
We are a dental practice, not a GPThe GDC and CQC questions, answeredGDPR Compliant AI for dental practices
Why on-premises at all?The case for Local AI, in fullLocal AI product page

AI and GDPR Compliance for GP Practices: Common Questions

Is there such a thing as GDPR compliant AI?

Not as a product label. Compliance is a property of how GP practices use a tool, not of the tool. What a product can do is make the assessment easier: a machine in the surgery removes the processor and transfer questions for the AI step entirely.

Do we need a DPIA for AI?

Often, yes, and we would rather you did one. A machine in the building makes it shorter: the questions about the processor, the transfer mechanism and the training use of your data have plain answers. Purpose, lawful basis, retention and access are still yours to answer.

How do we describe a machine in the surgery in the DSPT?

As processing on hardware the practice owns, at the practice, on the practice network, with no third-party AI processor and no transfer for the work it does. We act as a processor only for the support access you grant, under a data processing agreement, and we will help your DSPT lead word the entry.

Does it change our Caldicott obligations?

No. The Caldicott principles — justify the purpose, use the minimum identifiable information, restrict access — are still the practice’s to apply. What changes is that the AI step no longer sends identifiable information anywhere, which makes the “where did it go” part of the answer one word.

Does it connect to our clinical system?

No, and it should not. The clinical record stays in your clinical system. It works on the documents around the practice — policies, correspondence, reports, leaflets — which are imported into spaces on the machine.

How does it fit with the Data Security and Protection Toolkit?

The DSPT asks you to know where data is processed and by whom. With a machine in the surgery the answer is: here, by nobody else. There is no third-party AI processor and no transfer for the work it does. Bring your DSPT lead or Caldicott Guardian to the call.

How much does Local AI cost?

£500 per month for the software and the hardware rental. The dedicated machine is rented to your business, not sold: you never buy the hardware. It is installed in your building and runs the private chat, document spaces and assistants. Local AI is for business customers only.

Bring the DSPT Lead to the First Call

Tell us your list size and what is blocking AI sign-off in the practice. We will walk through the data flow with your DSPT lead and Caldicott Guardian.

Book a Consultation

Prefer email? sghaith@businessaiagents.co.uk