Are AI chatbots handling patient enquiries GDPR-compliant?
A chatbot that collects patient enquiries is processing personal data, so UK GDPR applies. Done properly it is entirely compliant. Here is what "properly" means.
The moment a chatbot on your site collects a name, an email, or a health-related enquiry, it is processing personal data, and UK GDPR applies. That is not a reason to avoid chatbots. It is a reason to build them properly. Done right, a chatbot is no more risky than a contact form, and often more transparent.
The principles that apply
- Lawful basis. You need a reason to process the data. For an enquiry the person started, that is usually consent or taking steps to enter into a contract or service.
- Data minimisation. Collect only what you need to help them. A booking enquiry needs a name, contact detail, and reason. It does not need a medical history typed into a chat window.
- Transparency. People should know they are talking to an automated assistant, what happens to what they type, and where to read your privacy policy.
- Storage and security. Enquiries should land somewhere secure with proper access controls, and be kept only as long as you genuinely need them.
Special-category (health) data
Health information gets extra protection under UK GDPR. The safe design is simple: the chatbot handles logistics (who you are, what you want, when you are free) and does not invite people to type detailed health information. Anything clinical happens in your normal, secure clinical process, not in the chat.
Do you need a data protection impact assessment?
A data protection impact assessment (DPIA) is a short, structured check of the privacy risks before you launch something new. The ICO expects one whenever you process special-category data, such as health information, on any meaningful scale, or use new technology in a way that could be high-risk. For a simple logistics chatbot that deliberately avoids clinical detail, a full DPIA may not be triggered, but running a lightweight version is good practice and takes an afternoon: what data you collect, why, where it goes, what could go wrong, and how you have reduced each risk. The moment the bot strays into health specifics, a DPIA stops being optional.
Consent that actually counts
If consent is your lawful basis, it has to be real consent, not a pre-ticked box or a wall of text nobody reads. Under UK GDPR that means it is freely given, specific, informed, and as easy to withdraw as it was to give. In practice: tell people plainly what they are agreeing to, do not bundle enquiry consent together with marketing sign-up, and give a clear way to opt out later. Cookie-banner theatre — "by using this site you agree to everything" — does not meet the standard.
Where the data goes: processors and transfers
Most chatbots rely on third-party services behind the scenes, and each one that touches personal data is a processor you remain responsible for. Two practical checks: make sure there is a data processing agreement in place with each provider, and know which country the data is actually processed in. If personal data leaves the UK, you need a lawful transfer mechanism. Favour reputable providers with clear UK or EU processing and documented security, and avoid piping enquiries through tools nobody can vouch for. The same secure, access-controlled storage principle applies whether the enquiry arrives from a chatbot or a form — the plumbing behind it is what a good build gets right, which is exactly the point we made in whether AI chatbots actually work for clinics.
Practical rules for a compliant build
- Tell users up front it is an automated assistant, with a link to your privacy policy.
- Ask for the minimum, and avoid prompting for health detail.
- Store enquiries in a secure system with row-level access, not a random inbox forever.
- Have a clear retention period and honour data requests (access, deletion).
- Use reputable providers and know where the data is processed.
One caveat: this is a practical overview, not legal advice. If you handle health data at any scale, run your setup past your data protection lead or a qualified adviser. Getting the design right up front is far cheaper than fixing it after a complaint.
The bottom line
A well-built chatbot is fully compatible with UK GDPR. The risk comes from lazy builds that hoover up more than they need and store it carelessly. We build enquiry capture on secure, access-controlled storage and keep data collection to the minimum. For the detail on how we handle data, see our privacy policy, and for a review of your current setup, get a free Lead Leak Audit.
Find your lead leak in 48 hours
We review your site and send a personal video showing exactly where you are losing enquiries, and what to fix first. Free, no pitch.
Get your free Lead Leak Audit