16 September 2026 · 6 min read
AI notetaking tools in private practice: the UK GDPR questions to ask before you sign up
Practice management platforms are adding AI notetaking as standard: record the session, transcribe it, hand back a drafted note. If you've been offered one, or you're weighing up a standalone tool that does the same thing, the appeal is obvious. The data protection questions are less obvious, and they land on you, not the vendor selling you the feature.
This is general information about UK data protection law as it applies to a business decision, not legal advice, and it isn't a verdict on any particular product. Where the answer depends on your specific setup, that's a question for a solicitor, your professional body, or a data protection adviser, not this article.
Why the vendor doing the work doesn't change whose problem it is
You are the data controller for your client records: you decide why the data is collected and what happens to it, and that doesn't shift just because a third party's software does the transcribing. Under UK GDPR, a company that processes personal data on your instructions, rather than for its own purposes, is your processor, and using one doesn't transfer your obligations to them. If a transcript is mishandled, the regulator's first question is to you, not to the tool.
That's true whether the AI feature is bundled into practice software you already use or bought separately. The bundling changes how the invoice looks. It doesn't change who is accountable for the data.
The contract that has to exist before the first session
UK GDPR requires a written contract with any processor, covering things like what the data can be used for, who can see it, what security applies, whether sub-processors are allowed, and what happens to the data when the contract ends. A vendor who can't point you to this, or whose answer is a generic terms-of-service page rather than a document addressing UK GDPR processor obligations specifically, hasn't done the groundwork the law expects of them, and by extension, of you for choosing them.
For most therapists this isn't something you draft yourself. It's something you check exists, read, and keep a copy of, the same way you'd keep evidence of your indemnity insurance.
Health data needs a second lawful basis, not just the usual one
Session notes and recordings are special category data under UK GDPR, the same category as other health information, and processing it needs more than an ordinary lawful basis. You need a UK GDPR Article 6 basis and a separate Article 9 condition that specifically covers special category data, and the two aren't automatically the same thing. Several conditions could apply depending on how you've set up your practice and your relationship with the client, and which one genuinely fits isn't something this article can decide for you. It's worth working through with your professional body or a data protection adviser before you rely on a vendor's own assumption about which condition covers their product.
Where the recording and transcript actually go
A lot of AI transcription runs on infrastructure operated by US companies, which raises a separate question: is it lawful to send a UK client's session data there at all? UK GDPR restricts transfers of personal data outside the UK unless a recognised safeguard applies. One of those is the UK extension to the EU-US Data Privacy Framework, in force since October 2023, but it only covers transfers to the specific US organisations that have self-certified under it. A vendor using US-based AI infrastructure isn't automatically covered just because it's American; ask them directly whether the company actually processing the audio is on that list, and if not, what alternative safeguard, such as approved contract clauses, is in place instead.
The check the software can't do for you
Transcription tools mishear names, attribute the wrong speaker, and drop or garble details, and a garbled line in a clinical record is still your record once it's saved. UK GDPR's accuracy principle puts the responsibility for a correct record on you as the controller, not on the tool that produced the first draft. Building in a moment to read back and correct the transcript before it's filed isn't optional admin; it's the same principle that applies to notes you write yourself, just applied to a new source.
A working list of questions before you say yes to a vendor
- Is there a UK GDPR processor contract, and can you see it before you commit, not just after?
- What Article 9 condition does the vendor say applies, and have you checked that against your own setup rather than taking their word for it?
- Where does the audio and transcript actually get processed, and if it leaves the UK, what safeguard covers that specific transfer?
- How long is the audio kept after the transcript is produced, and can you set that retention yourself or is it fixed by the vendor?
- Can you export or delete a client's transcripts on request, at the same speed you'd need to answer a subject access request?
- If the vendor has a data breach, how and when do they tell you, given your own duty to consider notifying the ICO runs from when you become aware, not when they get round to mentioning it?
The gap between what MyOwnSession holds and what a scribe tool would
MyOwnSession doesn't transcribe or summarise sessions with AI. If you use a separate tool for that, it sits outside MyOwnSession as its own processor relationship, with its own contract and its own answers to the questions above; nothing about using MyOwnSession changes what you'd need to check with that vendor. What MyOwnSession does hold, your client and session records, stays governed by the data processing terms already in place, which is a narrower and more established question than the one a new AI feature raises.
This article describes UK data protection law as it applies to AI notetaking tools, as it stood in September 2026, and is general information, not legal advice. It doesn't assess any specific product, and the right answer for your practice depends on your setup and your client relationships. Take advice from a solicitor, your professional body, or a data protection adviser before relying on a vendor's own account of its compliance, and check current ICO guidance, since it continues to develop in this area.
MyOwnSession acts as a data processor for the therapists who use it and doesn't build AI transcription into that role. Read how we handle data.
Ready to talk to someone? Get matched with a verified therapist in minutes.
Find your therapist