Guide

Care Robot Data Protection and Privacy in the UK

A companion or monitoring robot in a care setting can see, hear and record a great deal about a vulnerable person. This guide explains, in plain terms, what these devices tend to collect, how UK data protection law applies, and the questions a provider or family should put to any supplier before a device is switched on.

Published September 2026 | Humanoid Robot Care

Data protection is one of the most important and most overlooked questions in care robotics. A device introduced to reduce loneliness or support a routine can also become, in effect, a microphone and sometimes a camera in the room of a person who may not fully understand what is being recorded. Getting this right is both a legal duty and a matter of dignity. This guide sets out the considerations without inventing figures or overstating what any particular product does; always check the specifics with the supplier.

A note on scope: this is general information, not legal advice. Data protection duties depend on the exact device and how it is used, and a care provider should take advice from someone with UK data protection competence, and consult the Information Commissioner's Office guidance, before deploying technology that collects personal data about residents.


What these devices can collect

The starting point is to understand what a specific device actually captures, because this varies widely. Depending on the product, a care robot or companion device may record or process voice and conversation, video from calls or built-in cameras, movement and presence in a room, daily routine and activity patterns, responses to medication or wellbeing prompts, and the contact details of family members. Some of this is processed on the device itself, and some is sent to the supplier's servers, which may be located outside the UK.

Much of this information can reveal something about a person's health, cognition or care needs. Under UK data protection law, health-related information is special category data and attracts extra protection, which means it cannot simply be collected because it is convenient.


How UK data protection law applies

Where a device collects information about identifiable people, UK GDPR and the Data Protection Act 2018 apply. In practice this creates several obligations for a care provider deploying the technology.

These duties sit alongside the provider's regulatory obligations. Our CQC regulation guide explains how data protection connects to the wider quality and safeguarding expectations a care home must meet.


The surveillance question

There is a genuine and reasonable worry that care robots can slide from companionship into surveillance. A device that watches, listens and reports can make a care home safer in some respects, but it can also erode the privacy and dignity that residents are entitled to in what is, after all, their home. The concern is sharper where a resident cannot fully consent, for example because of advanced dementia.

The right approach is to be deliberate rather than to let monitoring creep in by default. Recording should be limited to what is genuinely necessary for the stated purpose, residents and families should understand it, and there should be a clear reason why any camera or always-on microphone is proportionate. Where the aim is companionship, a device does not need to be a covert monitoring tool, and it should not quietly become one. The ethics of this are covered further in our ethics of robots in care homes guide.


Consent and mental capacity

Consent is central and often complicated in a care setting. Where a resident has the capacity to decide, they should be given clear information and a genuine choice, and they should be able to say no or to change their mind. Where a resident may lack the capacity to consent to a device that records them, the Mental Capacity Act framework applies, and any decision has to be made in that person's best interests, involving those close to them, and properly documented. Consent should never be assumed simply because a family member agreed on the resident's behalf.


Questions to ask a supplier

Before deploying a device, a provider or family can protect themselves and the person in their care by asking the supplier direct questions and getting the answers in writing.

A credible supplier will answer these clearly. Vague or evasive answers are themselves a warning sign.


Get in touch

If you are a care provider, commissioner or NHS technology lead working through the data protection implications of a companion or assistive robot, write to us at hello@humanoidrobotcare.co.uk. We are an independent information service rather than a vendor, so our aim is to help you ask the right questions and understand the UK context. Our For Providers page explains the enquiry route for organisations at the research or planning stage.


Common questions

Frequently Asked Questions

What data do care robots collect?

It depends entirely on the device, which is why you should always ask the supplier for specifics rather than assume. Companion and monitoring devices used in care can capture some or all of the following: voice recordings and transcripts of conversations, video from calls or cameras, movement or presence data, routine and activity patterns, medication or reminder responses, and account details for family contacts. Some processing happens on the device and some in the supplier's cloud, sometimes outside the UK. Because much of this can reveal a person's health or care needs, it may count as special category data under UK data protection law and carries extra protection.

Does UK GDPR apply to robots used in care homes?

Yes. Where a robot or companion device collects information about identifiable people, UK GDPR and the Data Protection Act 2018 apply. A care provider using such a device is normally a data controller and must have a lawful basis for processing, must handle any special category health data under an appropriate condition, must tell people what is collected and why through a clear privacy notice, and must keep the data secure and only as long as necessary. Depending on the scale and sensitivity, a Data Protection Impact Assessment may be required. The supplier is usually a processor, and a written data processing agreement should be in place.