All posts
Compliance 8 min read·

The UK GDPR checklist for adopting an AI receptionist

A practical checklist for clinics considering an AI answering system: DPA, lawful basis, patient notice, retention, and what to write in your privacy notice.

By Daniel O’ConnorData Protection Lead, ClincuePublished Updated
The UK GDPR checklist for adopting an AI receptionist

Bringing an AI receptionist online is not a huge GDPR undertaking, but it is not zero either. This is the checklist we walk every clinic through — the same one our own DPA is written to satisfy.

1. Confirm the controller / processor split

For patient conversations, the clinic is the controller and the AI receptionist vendor is the processor. That is the correct model under UK GDPR Article 28 and it is what our DPA documents.

2. Sign a written Data Processing Agreement

You need one before the first patient message flows through the system. It must name sub-processors, describe the categories of data, set retention limits, and cover international transfers.

3. Pick a lawful basis

  • Contract (Article 6(1)(b)) for the appointment booking itself.
  • Legitimate interests (Article 6(1)(f)) for the operational logging that keeps the service secure — with a documented LIA.
  • Consent is not required for the operational answering flow itself; it is required for any marketing follow-up.

4. Update the privacy notice

One paragraph is usually enough: what the AI does, that it is administrative not clinical, that no special-category data is requested, and the retention period. Point patients at the clinic's DPO or main privacy contact.

5. Set retention deliberately

The default in Clincue is 90 days for voice transcripts and indefinite (until deletion) for text conversations while the account is active. Shorter is fine, longer needs a reason.

6. Configure the agent's medical boundary

Do not let the agent diagnose or triage. Configure the greeting to remind patients that anything clinical goes to a human, and that emergencies go to 999. Our platform ships with these guardrails on by default.

7. Log staff access

Only reception and clinical leads should read conversation transcripts. Row-level security in the platform enforces this — turn on audit logging so subject-access requests can be answered quickly.


See it on your own clinic

Book a 20-minute Clincue demo

We show you the diary, the WhatsApp channel, and a live call — with realistic numbers for a clinic your size.

Book a demo