For PI & clinical-negligence fee-earners and their DPOs · ~5 min read
1. Treat it as special-category data
Health data is “special category” under Article 9 of the UK GDPR. That means two things must be in place at once: an ordinary lawful basis for processing (Article 6) and a separate Article 9 condition that permits handling health data. One without the other is not enough. For a firm running a claim, the everyday basis is usually legitimate interests, and the Article 9 condition is typically the one for the establishment, exercise or defence of legal claims. Record which you are relying on.
2. Write it down before you request records
Your privacy information and Article 30 record of processing should already cover claimant health data. In practice that means being able to answer, on any file: why you hold the records, the basis you rely on, who you share them with (counsel, experts, the defendant), and how long you will keep them. If a claimant asks, you should be able to give a straight answer.
3. Minimise — request what the claim needs
Data minimisation is a principle, not a nicety. Blanket “all records, all time” requests pull in decades of unrelated history you then have to hold, secure and eventually destroy. Where the injury and issues allow, scope the request to the relevant period and providers. A tighter record set is also a faster, cheaper bundle.
4. Keep it secure in transit and at rest
- Move records over encrypted channels — secure portals or encrypted email, not an open attachment to a general inbox.
- Restrict access to the people who actually need it on the matter.
- If you use a third-party tool to summarise or paginate records, it is a processor: you need a processor agreement, and you should know where the data is processed and that it is not used to train anyone’s models.
5. Have a retention position
Health data should not be kept indefinitely “just in case”. Set a retention period tied to the limitation position and your regulatory obligations, and destroy securely at the end of it. A written schedule is far easier to defend than an ad-hoc decision years later.
6. Be ready for a subject access request
A claimant can ask for a copy of the personal data you hold about them. Knowing where the records live, who they have been shared with, and being able to produce them within a month is much easier when the file is organised — a paginated, indexed record set is a subject access response almost by itself.
Where Med-Legal fits. Records are processed only to produce your summary and bundle, on infrastructure under a processor agreement, and are never used to train models. The reading and assembly are automated; the file, and the judgement, stay with you.
This is general information for legal professionals, not legal advice, and does not create a client relationship. Check your own obligations with your DPO or compliance lead.