Data protection that begins before the first recording
When using KiPT Voice, your practice remains the controller under data protection law, and the application is built so that you can fulfil that role. The recording is created and stays on the practice computer; for the note draft, the transcript text goes to the provider you have configured, with whom your practice signs its own data processing agreement, or it does not leave the practice at all if you choose a local model. Recording only begins after the patient's explicit, timestamped consent. A privacy package with templates for your own advice comes with every start.
Reviewed editorially against product behaviour and the cited primary sources; not individual medical or legal advice.
Roles: the practice remains the controller
Your practice decides when to record, who reviews the note, and how the data is handled afterwards. Under data protection law, the practice therefore remains the controller within the meaning of the GDPR. KiPT Voice and the provider you choose support this process technically but make no decisions of their own about the purpose and means of the processing.
- The practice decides on the start, scope, and retention of the recording.
- The practice reviews the note draft and adopts it into the practice software itself.
- Providers that process on behalf of the practice act on the practice's instructions.
The three data paths: recording, transcript, draft
Within one session, three different data states arise. The audio recording stays encrypted on the practice computer and is deleted as soon as the note is confirmed. A transcript is created from it there; unless a local model is configured, this text goes to the provider to produce a draft of the note. The draft comes back to the practice computer for review. Transcript and note text remain in the application for an adjustable period, 90 days by default, and are removed afterwards.
- Recording: created and stays encrypted on the practice computer, deleted once the note is confirmed.
- Transcript: created on the practice computer; the text goes to the configured provider, or stays there as well with a local model.
- Draft: comes back from the provider, reviewed by the practice, and adopted into the practice software by the practice itself.
Consent before the recording
Unauthorised recording of the spoken word not intended for the public is a criminal offence under § 201 of the German Criminal Code (StGB). KiPT Voice responds to this with a blocking, timestamped consent prompt directly in the application: without explicit confirmation, no recording begins. Tell the patient beforehand, in your own words, that the conversation is being recorded, what the draft is used for, and that declining is possible.
If someone declines, recording simply does not happen; the conversation proceeds as usual, without a recording.
- Consent is obtained before recording begins and recorded with a timestamp.
- Without confirmation, recording does not start.
- A refusal has no further consequences for treatment.
Data processing and professional confidentiality
Anyone bound by medical confidentiality under § 203 of the German Criminal Code (StGB) may make use of so-called assisting persons where these are necessary to provide the service and are involved accordingly. The provider you configure receives the transcript text on this basis; the practice signs its own data processing agreement (AVV) with that provider under Art. 28 GDPR.
Anyone who instead uses a local model processes the transcript text solely on their own practice computer and needs no external data processing agreement for this step. This information is general and does not replace legal advice for an individual case.
- The configured provider is typically a data processor for the practice, with its own contract under Art. 28 GDPR.
- A local model keeps the transcript text on the practice computer.
- General information, not legal advice for an individual case.
The privacy package
KiPT Voice includes a privacy package with four documents you can present to your own data protection adviser: an entry for the record of processing activities (VVT), a patient information sheet, a conversation guide for obtaining consent in the consultation room, and an overview of technical and organisational measures (TOM). It does not replace the advice but prepares the documents for it. A data protection impact assessment is the practice's own assessment; the package supplies the description of the data flows for it, not the assessment. The draft data processing agreement is deliberately not public; it goes to the practice after review.
- Record of processing activities (VVT): the entry for KiPT Voice.
- Patient information sheet and conversation guide for consent.
- Overview of technical and organisational measures (TOM).
Frequently asked questions
Do I need to carry out a data protection impact assessment?
This needs to be checked; with health data and new technology the answer is often yes. Clarify this question with your own data protection officer; the assessment itself is the practice's to make. The privacy package supplies the description of the data flows for it (the VVT entry and the TOM overview).
What do I tell patients?
That the conversation is being recorded, what the draft is used for, and that declining is possible at any time, in your own words, before the recording begins. The conversation guide in the privacy package is the template for this.
What happens if someone declines?
No recording is made. Without consent, KiPT Voice does not start recording; the conversation proceeds as usual, without a technical recording.
Who is the data processor?
Typically the provider you have configured, with whom your practice signs its own contract under Art. 28 GDPR. With a local model, this step does not apply.
How long does the recording stay stored?
The audio recording is deleted as soon as you confirm the note. Transcript and note text remain for an adjustable period, 90 days by default, and are removed from the application afterwards.