KI Praxis Tools

Processing agreements for AI documentation: a checklist before the pilot

If a provider processes conversation content on the practice's behalf, a contract under Art. 28 GDPR is needed before the first appointment. It has to set out the subject matter, duration, nature and purpose of the processing and cover the eight duties in paragraph 3 — and it does not answer the criminal-law question under § 203 StGB.

Abstract checklist on a card: six ticked rows and two open boxes rendered in jade green
Redaktion KiPT Voice · J Medical GmbH

Reviewed editorially against product behaviour and the stated primary sources; not individual medical or legal advice.

When a practice needs a processing agreement

A processing agreement becomes due as soon as a service provider processes personal data for the practice and on its instructions. With AI documentation the question is whether conversation content leaves the practice computer — and for which of the three paths of audio, transcript and draft that is true.

Art. 28 paragraph 1 GDPR puts the selection before that: the practice may only work with processors that provide sufficient guarantees for appropriate technical and organisational measures. That is a duty to check before signing, not an assurance that sits inside the contract.

The data in question is health data, a special category under Art. 9 paragraph 1 GDPR. Processing for the purposes of treatment is possible via Art. 9 paragraph 2 point (h) together with paragraph 3, where it is carried out by or under the responsibility of a professional subject to an obligation of professional secrecy.

What Art. 28 paragraph 3 GDPR requires in the contract

The contract first fixes the frame: the subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the obligations and rights of the practice. The processor's duties follow.

  • Processing only on the practice's documented instructions.
  • Persons on the provider's side committed to confidentiality.
  • The security measures required under Art. 32 GDPR.
  • Compliance with the conditions for engaging another processor.
  • Assistance with requests from data subjects exercising their rights.
  • Assistance with the obligations in Art. 32 to 36 GDPR.
  • Deletion or return of the data at the end of the service, at the practice's choice.
  • Making information available for audits and allowing inspections.
  • Telling the practice if, in the provider's view, an instruction infringes data protection law.

Sub-processors, and why they are the real question

Under Art. 28 paragraph 2 GDPR the provider may not engage another processor without the practice's prior specific or general written authorisation. Where the authorisation is general, it must inform the practice of any intended change so the practice can object.

With AI tools more hangs on that clause than usual, because the provider of the application and the provider of the language model are often not the same organisation. So the practice should ask not only who is named in the contract, but who actually gets to see text.

What Art. 28 GDPR does not require

The provision does not require the contract to name a processing location. A practice that wants to know where processing happens — and many do — has to agree it; it is not there by default. Transfers to third countries additionally follow Chapter V of the GDPR.

Nor does the contract replace the criminal-law assessment. § 203 StGB requires the practice to ensure that contributing persons are placed under an obligation of secrecy. Covering both in one document is common; confusing the two is the frequent mistake.

On form: under Art. 28 paragraph 9 GDPR the contract has to be in writing, and an electronic format is enough.

Checklist before the pilot

The order is deliberate: first it is settled which content leaves the computer, then it can be judged whether the contract describes the right operation. The other way round, contracts are written about processing that does not happen.

  • Is it settled in writing which content leaves the practice computer and which does not?
  • Does the contract describe exactly that operation, with subject matter, duration, nature and purpose?
  • Are all sub-processors named, and how is the practice told about changes?
  • How long does the provider keep content, and how is it deleted?
  • What evidence does the provider make available if the practice wants to check?
  • Is there, beside the contract, an obligation of secrecy under § 203 StGB?
  • Has it been settled whether processing takes place inside the EU only?

When no text leaves the practice

If the draft is produced by a model running on a computer in the practice, there is no processor for that step, because nobody outside the practice processes anything. The other duties remain: a legal basis, informing patients, the measures under Art. 32 GDPR and the practice's own deletion schedule.

With KiPT Voice the audio file stays on the practice computer in every case. Whether transcript text goes to an external provider is decided by the configuration in the settings — and that decision is what determines whether, and with whom, a contract under Art. 28 GDPR is needed.

Frequently asked questions

Do I need a processing agreement if a local model runs?

Not for the step that runs locally: nobody outside the practice processes anything. For every other service that processes content on the practice's behalf, the contract under Art. 28 GDPR still applies.

Must the contract name the processing location?

Art. 28 GDPR does not require it. If the practice wants to know the location or limit it to the EU, that belongs expressly in the contract; transfers to third countries additionally follow Chapter V of the GDPR.

Is the processing agreement enough to cover professional secrecy?

No. § 203 StGB additionally requires the practice to ensure that contributing persons are placed under an obligation of secrecy. The contract can cover that too, but does not do so automatically.

In what form must the contract be concluded?

Under Art. 28 paragraph 9 GDPR in writing, where an electronic format is sufficient.

Who is the controller, the practice or the provider?

The practice decides on the purposes and means of the processing and is therefore the controller. The provider processes on instruction and is the processor, as long as it does not use the content for its own purposes.

Read on