GDPR and voice assistants: what a practice must check

In brief

GDPR and voice assistants meet at one point in your practice: the incoming call, which carries the caller’s number, their voice and often the reason for an appointment. That reason is health data, so the rules are stricter than for an ordinary enquiry line. Your practice remains the controller and ClinicAll processes call data on its behalf. Before the receptionist answers its first call, check four things in writing: the processing agreement, the sub-processors and where they process data, how long recordings and transcripts are kept, and what your privacy notice tells callers.

Who is the controller and who is the processor

Your practice decides why patient calls are handled and what happens to the details they contain, so it is the controller. A supplier that answers the phone for you, records the call and writes a summary does so on your instructions, which makes it a processor. That split matters because the controller answers to patients and to the supervisory authority, even when a supplier did the work.

With ClinicAll, the roles are set out on the security and data protection page: your practice is the controller, and EXIGE SARL in Luxembourg processes call data on your behalf, only to run the receptionist and your dashboard. Read that page before any meeting with a supplier, then hold every other vendor to the same level of detail. A supplier that cannot say who it is in this relationship is not ready to answer your patients.

Why a phone call counts as health data

A caller who asks for a smear test, a dental emergency slot or a follow-up after cataract surgery has told you something about their health. Article 9 of the GDPR (gdpr-info.eu) lists data concerning health among the special categories whose processing is prohibited unless an exception applies. The same article allows it for the provision of health care when the data is handled under professional secrecy.

That exception covers your practice and the people working under its responsibility. It does not make the supplier’s safeguards optional: the contract, the access controls and the deletion rules carry the professional secrecy into the systems that hear the call. The question for a voice assistant is therefore never whether it may handle health data, but how it keeps that data inside the circle of care.

The processing agreement to ask for first

Article 28 of the GDPR (gdpr-info.eu) requires a contract between controller and processor. It names the subject-matter and duration of the processing, its nature and purpose, the types of personal data and the categories of people concerned. It also binds the processor to act only on your instructions, keep its staff under confidentiality, help you answer patients’ requests and delete or return the data when the service ends.

Ask for that agreement before you sign anything else, not after go-live. ClinicAll makes its data processing agreement available on request before you commit, so your data protection adviser can read it alongside the written quote. If a supplier’s answer is a link to general terms of use, keep asking until you have a document that names your practice.

Where the call data goes

A voice assistant is rarely one company. Telephony carries the call, a voice platform turns speech into text and back, and a server keeps the call log your team reads. Each of these is a sub-processor, and Article 28 of the GDPR (gdpr-info.eu) says a processor may only engage one with the controller’s prior written authorisation, specific or general.

ClinicAll lists its sub-processors with their purpose, location and transfer safeguard. The voice platform and the telephony provider process call data in the United States, under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. The dashboard and call log are hosted in Germany, in Nuremberg, and your practice software vendor processes your appointments under its own contract with you.

A transfer outside the European Economic Area needs a legal footing. Article 46 of the GDPR (gdpr-info.eu) allows one where appropriate safeguards exist and patients keep enforceable rights, and the Commission’s standard data protection clauses are one of those safeguards. Your job is not to audit each data centre: it is to know the list, check that each transfer names its safeguard, and note it in your own records.

What the receptionist collects, and what it leaves alone

Data minimisation is easier to defend when the product’s scope is narrow. During a call, ClinicAll processes the caller’s phone number, the audio and its transcript, and the details a booking needs: name, date of birth and the reason for the appointment. Where the integration with your practice software is live, the appointment is written there; elsewhere the request arrives as a callback request in your dashboard.

What it does not do matters as much. The receptionist never looks up a patient’s record, gives no medical advice and follows the urgency rules your practice defines. A change of appointment is never made on the phone either: “It never moves or cancels an appointment itself: your team confirms.” Fewer actions mean fewer places where a wrong caller could learn something about someone else.

How long recordings and transcripts are kept

Retention is where many practices find out they never asked. At the voice platform, recordings and transcripts are deleted after a retention period set for each practice, so the period is a decision you make with the supplier rather than a default you inherit. Choose one long enough for your team to handle the day’s callback requests and short enough that old calls do not pile up.

The call log in your dashboard keeps the caller’s number, a summary and the transcript, so the desk can follow up. ClinicAll deletes it at your practice’s request. Appointments and records created in your practice software stay under your own rules, as they did before the receptionist arrived.

What callers must be told

Article 13 of the GDPR (gdpr-info.eu) lists what a person must be told when their data is collected from them. That includes who the controller is, the purposes and legal basis, the recipients, any transfer to a third country with its safeguards, and how long the data is kept. Add the voice assistant to your practice’s privacy notice, on your website and at the desk, with the sub-processors in general terms and the retention you agreed.

Callers also deserve a straight answer about who they are speaking to. ClinicAll answers as your front desk and, whenever a caller asks, says it is “the practice’s virtual receptionist”; it never claims to be a person. Brief your team on that sentence, so the desk gives the same answer when a patient asks about it later.

A caller who wants a human gets one only when someone can take the call. The receptionist “transfers to the desk when it is staffed and a transfer line is configured; otherwise it takes a callback request”. Write that rule into your notice too, so nobody expects a transfer at an hour when the desk is closed.

When an impact assessment is needed

Article 35 of the GDPR (gdpr-info.eu) requires a data protection impact assessment before processing that uses new technologies and is likely to result in a high risk. It names processing on a large scale of special categories of data as one case where the assessment is mandatory. Whether one practice’s phone line counts as large scale is a judgement your data protection adviser should make and write down.

Even where it is not strictly required, a short assessment is a useful document. It describes the call flow, the data at each step, the sub-processors, the risks you considered and the measures that answer them. When a patient or an authority asks how you chose the supplier, that page is your answer.

Your record of processing and patient requests

Article 30 of the GDPR (gdpr-info.eu) asks each controller to keep a record of processing activities. For the phone line, the entry names the purpose, the categories of patients and data, the recipients, the transfers outside the EU with their safeguards, the deletion periods and a general description of the security measures. Most of it can be copied from the supplier’s sub-processor list and the processing agreement.

Patients will occasionally ask for a copy of a call or for its deletion. They should contact your practice first, and ClinicAll helps the practice answer; the team that handles those requests “works in French, from Luxembourg”. Decide in advance who at the desk receives such a request and how quickly you pass it on.

A checklist before go-live

Before the first call is answered, your file should hold the signed processing agreement, the list of sub-processors with their locations and safeguards, and the retention period you chose. It should also hold the updated privacy notice, the entry in your record of processing and, where your adviser asks for one, the impact assessment. Each of these is a document you can show, which is what an inspection looks for.

Then test the line as a patient would. The demo line lets you hear how the receptionist answers, asks for details and replies when you ask whether it is a person. If you are still comparing options, the comparison with a medical answering service sets out who hears your patients’ calls in each model.

The how it works page describes the call flow step by step, which is the material your impact assessment starts from. The website privacy policy covers only the data collected by the ClinicAll website itself, and the pricing page explains how the price is quoted in writing after a 30-minute call. For other questions about the practice phone, the guides cover opening hours, transfers and medical confidentiality.

Sources

  1. GDPR, Article 9 (gdpr-info.eu)

  2. GDPR, Article 13 (gdpr-info.eu)

  3. GDPR, Article 28 (gdpr-info.eu)

  4. GDPR, Article 30 (gdpr-info.eu)

  5. GDPR, Article 35 (gdpr-info.eu)

  6. GDPR, Article 46 (gdpr-info.eu)

See it answer a call for your practice

A 30-minute demo by video. We show the assistant live and look at how it would fit your practice, your software and your rules.

Book a demo