GDPR Compliant AI for GP Practices: A Short DSPT Entry
Every year the practice answers, in the Data Security and Protection Toolkit, for where its data is processed and by whom. A cloud AI tool adds a processor to that answer. A machine in the surgery adds nothing.
£500 per month for the software and the hardware rental. You rent the machine — you don’t buy it.
GDPR compliant AI for GP practices means AI used in a way that meets the UK GDPR, the Data Protection Act 2018 and the practice’s DSPT obligations. A machine installed in the surgery means no third-party AI processor and no restricted transfer for the AI step, and the clinical system stays untouched; lawful basis and retention remain the practice’s.
Bring your DPO to the call
A short call with the practice manager and your DSPT lead. We will walk through the data flow before any hardware is ordered.
Model, documents and chat history on one machine in the practice office. Practice and patient information never leave the surgery.
Cloud Agents for the Phone, Local AI for Practice Documents
Appointment calls and the admin inbox suit a hosted agent; practice policies, complaints correspondence and hospital letters suit a machine inside the surgery. Many practices run both.
- ☁ Cloud-based AI Receptionist
- ☁ Cloud-based Email Manager
- ☁ Cloud-based Leads Outreach
- 🏢 On-premise Local AI
The Questions Your DPO Asks About AI and GDPR Compliance
Most of the hard work in an AI GDPR assessment is about the processor and the transfer. Here is what each looks like for GP practices.
| The question | Cloud AI service | A machine in the surgery |
|---|---|---|
| Who is the processor for the AI step? | The AI provider — appoint, assess, contract, review | Nobody — the model runs on your own machine |
| Is there a restricted transfer? | Often — IDTA or UK Addendum, plus a transfer risk assessment | No — the data never leaves the building |
| Is our data used to train models? | Depends on the plan, the settings and the small print | Never |
| What goes in the Article 30 record? | A new processor and, often, a new transfer | One fewer of each |
| Erasure requests | Your copy and theirs | Your copy only |
| Lawful basis, purpose, retention | Yours | Still yours |
What the Toolkit Asks, and What a Machine in the Surgery Answers
A GP practice’s data protection is not abstract: it is the Data Security and Protection Toolkit, submitted every year, with a Caldicott Guardian and an information governance lead who have to be able to name every system that processes patient or practice data and every organisation that touches it. A cloud AI tool used by the practice office — even for administrative documents like complaint responses and policies — is a processor to name, assess, contract with and, if it processes data outside the UK, to justify with a transfer mechanism.
A machine in the surgery keeps the entry short. The model runs on the practice’s own network in the practice office; policies, complaint files, reports, leaflets and chat history stay on it. No AI provider processes practice or patient information, so no processor to name for that step. Nothing leaves the building, so no transfer. Your content is never used to train models. The Caldicott question — is this use of identifiable information necessary and minimal — is answered the way it always was, by the practice, but with one fewer place the data could have gone.
What stays with the practice is what was always its own: lawful basis, retention under the practice’s existing policy, and who in the office can see what, set through the Microsoft 365 or Google Workspace sign-in staff already use. The clinical record is never touched: the machine is not connected to the clinical system, it is not for clinical decisions, and it is not a medical device.
We act as a processor only for the support access the practice grants us, under a data processing agreement, and we will help the DSPT lead word the entry. We would rather they and the Caldicott Guardian were on the first call; the data flow takes ten minutes to walk through.
What Is Installed, and What the Paperwork Looks Like
The machine, the software on it, the sign-in and the support — and the two documents your advisers will ask for.
No third-party AI processor
The model runs on your own machine, so your documents are never sent to an AI provider. Nothing to appoint, assess or keep under review for the AI step.
No restricted transfers
Your data never leaves the UK. The IDTA, the UK Addendum and a transfer risk assessment simply do not arise for the processing it does.
A shorter Article 30 record
One fewer processor and one fewer transfer to describe, review and keep current — and one less thing to explain if the ICO ever asks.
| Document | What the practice asks for | What stays where |
|---|---|---|
| Policies and procedures | Find it, check the review date, cite the page | On the machine, in the surgery |
| Complaint files | A draft response from the file and your complaints policy | On the machine, in the surgery |
| PCN and contract reporting | The quarterly report assembled from submissions | On the machine, in the surgery |
| Patient letters and leaflets | A draft in the practice’s wording | On the machine, in the surgery |
| National guidance and CQC evidence | A summary against what the practice already does | On the machine, in the surgery |
| Clinical records | Not used — stays in the clinical system | Your clinical system |
From the DSPT Lead’s Call to a Machine in the Office
Weeks, not months. Most practices start with the policies folder or the complaints process; PCNs usually start with one practice.
A call with the practice manager
List size, PCN role, how many staff, which paperwork goes first. We specify the machine from that and walk through the data flow with your DSPT lead.
Install and import
The machine goes on the practice network. Sign-in connects to your Microsoft 365 or Google Workspace. Policies, templates and correspondence are imported into spaces.
Train the office, then support
We train the practice manager, reception and admin team on what it does and what it is not for, then keep the software and models current.
Where Local AI Is the Wrong Answer
We would rather lose the enquiry than the trust. Three things we tell every prospect before they sign anything.
It is not a compliance certificate
No product can make GP practices UK GDPR-compliant on their own. A machine in the building removes the processor and transfer questions for the AI step. Purpose, lawful basis, retention and staff conduct remain yours, and we will not tell you otherwise.
It is slower than the big cloud models
Open-weight models on a single machine are capable for summarising, drafting and answering questions about your own documents. For frontier reasoning on hard, novel problems, the largest cloud models are still ahead. That is the trade.
It is a weeks-long install, not a sign-up
A cloud agent is live in days. Local AI needs the machine specified, delivered, installed on your network and your documents imported. Weeks, not months — but not tomorrow.
Built With the Regulator in Mind
Data never leaves the building
Open-weight model, documents and chat history on one machine in the surgery. The only outside connection is your own sign-in.
Never used for training
Your content is not used to train or improve any model. The models arrive trained and stay that way unless you ask.
One DPA, for one thing
We are a processor only for the support access you grant, and the agreement says so in plain terms.
Honest about the trade
Local models are capable and somewhat slower than the largest cloud services. We say so before you sign anything.
Which Page Answers Your Practice’s Question
| If your question is… | The short answer | Read more |
|---|---|---|
| The general GDPR picture for AI | The processor and transfer questions, in full | GDPR compliant AI |
| We want the Local AI overview for GP practices | The head page for surgeries | Local AI for GP practices |
| What exactly is installed in the surgery? | One machine in the office, supported | On-Premises AI for gp practices |
| We want a private ChatGPT for the office | That is the private chat assistant | Private AI for gp practices |
| The 8am phone queue is the real problem | A hosted agent, live in days | AI Receptionist |
| We are a dental practice, not a GP | The GDC and CQC questions, answered | GDPR Compliant AI for dental practices |
| Why on-premises at all? | The case for Local AI, in full | Local AI product page |
AI and GDPR Compliance for GP Practices: Common Questions
Is there such a thing as GDPR compliant AI?
Not as a product label. Compliance is a property of how GP practices use a tool, not of the tool. What a product can do is make the assessment easier: a machine in the surgery removes the processor and transfer questions for the AI step entirely.
Do we need a DPIA for AI?
Often, yes, and we would rather you did one. A machine in the building makes it shorter: the questions about the processor, the transfer mechanism and the training use of your data have plain answers. Purpose, lawful basis, retention and access are still yours to answer.
How do we describe a machine in the surgery in the DSPT?
As processing on hardware the practice owns, at the practice, on the practice network, with no third-party AI processor and no transfer for the work it does. We act as a processor only for the support access you grant, under a data processing agreement, and we will help your DSPT lead word the entry.
Does it change our Caldicott obligations?
No. The Caldicott principles — justify the purpose, use the minimum identifiable information, restrict access — are still the practice’s to apply. What changes is that the AI step no longer sends identifiable information anywhere, which makes the “where did it go” part of the answer one word.
Does it connect to our clinical system?
No, and it should not. The clinical record stays in your clinical system. It works on the documents around the practice — policies, correspondence, reports, leaflets — which are imported into spaces on the machine.
How does it fit with the Data Security and Protection Toolkit?
The DSPT asks you to know where data is processed and by whom. With a machine in the surgery the answer is: here, by nobody else. There is no third-party AI processor and no transfer for the work it does. Bring your DSPT lead or Caldicott Guardian to the call.
How much does Local AI cost?
£500 per month for the software and the hardware rental. The dedicated machine is rented to your business, not sold: you never buy the hardware. It is installed in your building and runs the private chat, document spaces and assistants. Local AI is for business customers only.
Bring the DSPT Lead to the First Call
Tell us your list size and what is blocking AI sign-off in the practice. We will walk through the data flow with your DSPT lead and Caldicott Guardian.
Prefer email? sghaith@businessaiagents.co.uk
