Is It Safe to Use AI for Veterinary Practices?
Yes for drafting, no with the client record: never paste an owner's name, contact or card number into a consumer AI. Anonymise the record first.
The short answer: yes for drafting, no with the client record. AI can prepare a note, summarise a case or write a letter to the owner. But never hand it the owner's details. In a veterinary file, the sensitive data is the human's, not the animal's. Their name, address, phone, email, payment history. Under the GDPR, these are personal data. Your practice is the controller of them. Pasted into a consumer ChatGPT, that record goes to a third party. The fix is one rule: anonymise the owner's identifiers before the prompt.
The sensitive data is the owner — not the animal
One point is often misread. The treatment record is about the animal. But the personal data belongs to the owner. Name, address, phone, email, payment history. Once it is linked to an identifiable human, the record becomes personal data under the GDPR.
Clinical detail about the animal is not, on its own, personal data. It becomes so the moment it is tied to an identifiable client. Watch a common error too: the GDPR's 'special categories', such as health data, protect the person, not the animal. A dog's health condition is therefore not sensitive data on that basis. The heightened tier is triggered by sensitive info about the human, not by the animal's condition.
Your practice is the data controller
The GDPR (Regulation (EU) 2016/679) names a central role: the controller. It is the party that decides why and how personal data is processed. A veterinary practice that holds client records plays that role. Article 5(2) makes it an explicit duty: the controller must comply and be able to demonstrate it.
That duty has a direct consequence. Pasting a client record into a consumer AI hands it to a third party. That party sits outside your controls. Often outside any data processing agreement. And often with no guarantee of no-training on your data. The text can be retained or reviewed there. Yet you remain accountable for that processing.
Card data: never in a chatbot (PCI DSS)
Deposits, invoices and card payments add a separate frame. PCI DSS (the Payment Card Industry Data Security Standard) sets baseline controls. It applies to any organisation that stores, processes or transmits card data. Merchants of any size are in scope, including your clinic.
The rule is simple: a card number is never typed into a general chatbot. A consumer AI is not a compliant cardholder-data environment. It sits outside your practice's payment controls. PCI DSS is maintained by the PCI Security Standards Council, the body founded by the card networks. It is a payment standard, separate from the GDPR, covering card data specifically.
Confidentiality, professional duty and clinical judgement
Client confidentiality is also a professional duty. Veterinary bodies expect records kept securely and disclosed only on a proper basis. Guidance from the Royal College of Veterinary Surgeons (RCVS), in the UK, illustrates this approach. It frames clinical and client records around confidentiality and data protection. Pasting a full record into a consumer AI clashes with that duty.
A case can also be delicate beyond the law. A valuable animal. A live dispute. Such details are commercially or personally sensitive. Finally, keep a clinical reserve. AI can be confidently wrong on a medical detail. Treat its notes as a first draft. The diagnostic and treatment decision stays with the clinician.
| You assume | The reality |
|---|---|
| “The record is about the animal, not a person” | Tied to an identifiable owner, it becomes personal data under the GDPR |
| “Pasting a client record into an AI is harmless” | It hands personal data to a third party, outside your controls |
| “I can copy the card number for the invoice” | No: PCI DSS covers card data, never a chatbot |
| “AI reviews the record better than I do” | It can be wrong on clinical detail; the decision stays with the vet |
The fix: anonymise before you send
Good news: AI is still useful in the clinic. It can draft a note, a case summary or a client letter. For that, it does not need to identify the owner. The safe move is to de-identify before the prompt. Strip the owner's name, contact, address and any identifier. The AI then works on anonymised text. You re-insert the real values afterwards, locally.
Two guardrails round out the method. Card numbers are never pasted, full stop. And if you move to a real AI vendor, require a data processing agreement. Its terms should exclude training on the practice's data.
- Anonymise the owner's name, contact and address before the prompt.
- Never paste a card number into a chatbot (PCI DSS).
- Choose a tool under a data processing agreement, with no-training terms.
- Keep every diagnostic and treatment decision with the clinician.
In practice, the steps fit in four moves.
- 1Spot the owner's identifiers: name, contact, address, payment.
- 2Replace them with reversible tokens, in the browser.
- 3Send only the anonymised text to the AI.
- 4Restore the real values in the reply, locally.
That's what ONYRI Sanitize is for. The engine detects sensitive data — owner name, contact, address, amounts — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. The AI sees only tokens, never your client's real record. You get the drafting help, without handing the owner's data to a third party.
Frequently asked questions
- Is it safe to use AI for veterinary practices?
- Yes for drafting, no with the client record. AI can prepare a note, a case summary or a letter to the owner with no personal data at all. But never paste the owner's name, contact, address or card into a consumer ChatGPT. Under the GDPR, your practice is the controller of that data. Anonymise the identifiers before you send.
- Is the animal's health record personal data?
- It becomes so once linked to an identifiable owner. Clinical detail about the animal, on its own, is not personal data. But tied to the owner's name, address or payment, it falls under the GDPR. Note: the animal's health condition is not a 'special category' — that heightened protection covers the person, not the animal.
- Can I paste a card number into a chatbot for an invoice?
- No. Card data falls under PCI DSS, the payment-security standard maintained by the PCI Security Standards Council. A general chatbot is not a compliant environment and sits outside your practice's payment controls. A card number should never be typed there, even to prepare an invoice.
Sources & references
- Regulation (EU) 2016/679 (GDPR) — full text on EUR-Lex (controller definition and accountability, Articles 4, 5 and 24) — EUR-Lex (Publications Office of the European Union)
- PCI DSS — official standard page (baseline controls for card data, merchants of any size) — PCI Security Standards Council
- Clinical and client records — guidance on confidentiality and data protection for veterinary practices — Royal College of Veterinary Surgeons (RCVS)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.
Anonymize my prompt