Who this is for
- Private healthcare providers using AI with patient data
- Practice managers and clinic owners responding to DPO queries
- DPOs and governance leads preparing AI evidence reviews
What your DPO may ask for
Checklist
- AI tool and use-case inventory
- Purpose of processing
- Categories of personal data
- Special category health data indicators
- Lawful basis and Article 9 condition indicators for review
- DPIA screening record
- DPIA readiness information
- Records of Processing Activities indicators
- Controller/processor mapping
- Data Processing Agreements
- Data residency and hosting information
- Sub-processor list
- International transfer indicators
- Privacy notice and patient transparency wording
- Staff guidance and training evidence
- AI incident records, where relevant
When a DPIA may be likely required or strongly indicated
A DPIA is required under UK GDPR Article 35 where processing is likely to result in high risk. In a healthcare AI context, risk indicators may include special category health data, new technology, voice or audio processing, automated evaluation, large-scale processing, vulnerable data subjects or significant effects on patients. ELSA AI does not make the final legal determination. We identify DPIA indicators and prepare a structured readiness position for DPO/legal review.
Common evidence gaps
Checklist
- AI tools not recorded in a register
- Free or personal AI tools used without a patient-data boundary
- Vendor DPAs missing
- Sub-processors unknown
- Privacy notice not updated
- No evidence of staff guidance
- No clear DPIA status
Next step
If a DPO has already asked for AI evidence, use the scenario page for the immediate response path. The Diagnostic produces a structured evidence pack for DPO review.
ELSA AI provides advisory governance support only. It does not provide: legal advice or legal sign-off; CQC, ICO or NHS approval; insurer coverage or underwriting decisions; MDO indemnity decisions; a completed or signed DPIA; clinical safety case sign-off, DCB0160 authorship or appointment as Clinical Safety Officer; medical device or SaMD classification; certification or any guarantee of compliance. Final legal, data protection, clinical safety, regulatory, insurer and indemnity decisions remain with the client's DPO, legal counsel, Clinical Safety Officer, accountable officers and clinicians.