GDPR at Your Practice Without a Lawyer or IT Specialist - a Complete System in 7 Documents

A complete map of the 7 GDPR documents every physiotherapy practice needs - policy, ROPA, information clause, authorizations, processing agreement, breach procedure. Ready-made templates instead of PLN 2-5k for a lawyer.
"I have a small practice, just me, a dozen or so appointments a day -- GDPR is a problem for corporations, not for me." We hear this sentence at almost every training session, in every professional Facebook group, in every conversation about the paperwork side of running a practice. And every single time it needs correcting, because it rests on a false assumption that can end up costing far more than a complete set of documents.
The size of your practice has nothing to do with it. What matters is the type of data you process -- and data about a patient's health, their medical history, past injuries, or the course of their therapy falls under the so-called special category of personal data within the meaning of Article 9 GDPR. That provision makes no exception for sole proprietorships. A solo practice running manual therapy for ten patients a week is subject to exactly the same obligations as a large rehabilitation clinic -- only the scale differs, not the scope of responsibility. In this article we show exactly what documents make up a complete GDPR system for a physiotherapy practice, how they support one another, and how to implement them yourself over the course of a single weekend.
Why "I have a small practice" doesn't exempt you from GDPR
GDPR doesn't recognize a size threshold below which the rules stop applying. There's no clause saying "if you process fewer than a hundred patients, you're exempt." What there is, is Article 9 GDPR, which explicitly classifies health-related data as requiring heightened protection -- and every physiotherapist, regardless of how their business is structured, processes that kind of data by the very nature of their profession. A patient interview, a description of symptoms, a therapy plan, treatment notes -- all of that is health data.
The consequence is simple: as a data controller (which every practice is, regardless of size) you must meet the full catalogue of obligations under GDPR -- from informing patients about the processing of their data, through maintaining a record of processing activities, to a procedure for responding to data breaches. We describe these obligations in detail in the article GDPR at a physiotherapy practice -- here we focus on translating them into a concrete set of documents that actually exists in your practice, not just in theory.
The map of 7 documents -- a complete GDPR system for a physiotherapy practice
What a UODO inspector looks for during an inspection isn't a single document -- it's a coherent system. Each of the seven elements below covers a different piece of the puzzle, and together they form a complete picture of how your practice processes data -- from general principles, through specific relationships with patients and staff, to the response to crisis situations.
1. Data protection policy
This is the overarching document -- it defines who at the practice is the data controller (ADO), what processing principles apply, and how roles and responsibilities are divided. Every other document should be consistent with it -- if the policy states that the practice owner is the controller, but the information clause names a different entity, that's exactly the kind of inconsistency an inspector catches first.
2. Record of processing activities (RCPD / ROPA)
The record is an inventory of every process in which you process personal data -- maintaining patient files, running the appointment calendar, invoicing, marketing. The obligation to keep it stems from Article 30 GDPR and applies to practically every practice processing health data, regardless of headcount. You'll find a full step-by-step guide to filling out the record in the article record of processing activities in physiotherapy.
3. Information clause for patients
This is the document a patient must receive (usually at their first visit), informing them who processes their data, for what purpose, on what legal basis, and what rights they have -- access, rectification, erasure, data portability. The information obligation stems from Article 13 GDPR and is one of the most frequently checked elements, because it's easy to verify -- an inspector just has to ask a patient whether they received it. We cover the details in the article GDPR information clause for a physiotherapy practice.
4. Data-processing authorizations for staff
Every person with access to patient data -- physiotherapist, receptionist, trainee -- must have a formal authorization to process data, issued by the controller. Without this document, that person processes data without a legal basis, even if it's part of their normal job duties. This is the document most often missing from one-person practices that employ even a single contractor -- we cover it in detail in the article data-processing authorization for staff.
5. Data processing agreement (with suppliers)
The calendar app, the accounting firm, the website host, the IT company servicing your equipment -- each of these, if it has access to patients' personal data, is a processor within the meaning of Article 28 GDPR and requires a signed data processing agreement. We cover the full list of typical processors at a physiotherapy practice and the requirements for such an agreement in the article data processing agreement -- who a physiotherapist must sign one with.
6. Data breach procedure + breach register
A lost USB drive full of patient files, a computer infected with ransomware, an email with patient data sent to the wrong address -- these are all data breaches, and GDPR gives you 72 hours to report them to UODO. A practice without a written procedure loses that time figuring out what needs to be done, instead of actually doing it. We walk through this step by step in the article data breach -- 72 hours to respond.
7. Video surveillance policy (optional, if the practice has cameras)
If cameras are running in the waiting room or at reception, that's a separate area of regulation -- you need to define the purpose of the monitoring, the retention period for recordings, and inform patients about it with a dedicated sign and information clause. Not every practice has cameras, but those that do often forget that surveillance requires its own, separate document -- a general information clause isn't enough.
| Document | What it governs | What obligation it stems from | Status at your practice |
|---|---|---|---|
| Data protection policy | Roles, principles, overarching processing framework | Art. 24 GDPR (controller accountability) | [ ] |
| Record of processing activities | Inventory of data processing operations | Art. 30 GDPR | [ ] |
| Information clause for patients | Information obligation towards patients | Art. 13 GDPR | [ ] |
| Staff authorizations | Legal basis for staff access to data | Art. 29 GDPR, Art. 32(4) GDPR | [ ] |
| Data processing agreement | Relationship with suppliers (processors) | Art. 28 GDPR | [ ] |
| Breach procedure + register | Response to security incidents | Art. 33-34 GDPR | [ ] |
| Video surveillance policy (optional) | Rules for recording in waiting room/reception | Art. 13 GDPR combined with specific regulations | [ ] |
How much this costs if you outsource it to a lawyer
Before comparing a ready-made set with preparing documents from scratch yourself, it's worth pricing out a third option -- hiring a lawyer who specializes in GDPR for healthcare providers to put together the full set. A realistic estimate for a small practice is PLN 2,000-5,000 for a complete set of seven documents tailored to your specific practice, depending on whether the firm prices it as a package or as separate engagements per document.
On top of that comes time -- in practice, it typically takes 2-4 weeks from your first contact with a lawyer to receiving finished, signed documents, because the lawyer has to learn the specifics of your practice, prepare the documents, and then you have to review them and request corrections. That's a stretch of time during which your practice operates without complete documentation -- with a real risk that an inspection or a patient complaint lands exactly during that window.
A ready-made set of documents, prepared once for the entire physiotherapy industry and checked for GDPR compliance, costs a fraction of that amount and is available immediately -- the difference is that you have to fill in your own practice's details yourself, instead of waiting for a lawyer to do it for you.
A one-weekend implementation plan
A complete GDPR system doesn't have to take weeks to build. If you have ready-made templates, the whole job comes down to filling in your own details and adapting the content to your practice's specifics. Here's a two-day plan.
- Saturday morning -- policy and record. Fill in the controller's details in the data protection policy, then complete the record of processing activities -- list every process in which you process data (patient files, appointment calendar, invoicing, marketing).
- Saturday afternoon -- information clause and authorizations. Adapt the information clause to your practice (name, address, GDPR contact details) and issue authorizations for everyone who has access to patient data -- even if that's just you and one receptionist.
- Sunday morning -- data processing agreements. Make a list of every external supplier (calendar app, accounting firm, hosting, IT) and check which of them you already have a signed data processing agreement with, and which still need one.
- Sunday afternoon -- breach procedure and a final review. Fill in the breach-response procedure with contact details for reporting incidents, and finish by reviewing all seven documents for consistency -- checking that your practice name, address, and controller details are identical across every one of them.
After a weekend like that, your practice has a complete set of documentation ready to show during an inspection, instead of waiting weeks for a lawyer or -- worse -- putting the topic off "for later," which in practice never actually arrives.
What you can't buy ready-made
It's worth saying this plainly instead of promising something no ready-made set can deliver: GDPR documentation needs to be completed with details unique to your practice. No template will fill in the owner's details or your practice's address for you, and no template will figure out which suppliers actually process your data.
Three things always require your own work, no matter how good the template is:
- The controller's identifying details -- first and last name or business name, address, tax ID, GDPR contact details. This has to match reality, because it's exactly this information that goes into the information clause and the policy.
- The list of your actual processors -- the specific calendar or EDM app you use, your specific accounting firm, your specific hosting company. The data processing agreement template shows you what such an agreement should look like -- but you're the one who has to know who to sign it with.
- An accurate description of your processing activities -- whether you keep paper or electronic records, whether you have video surveillance, whether you employ staff -- all of this affects the content of the record of processing activities and needs to reflect how your practice is actually organized, not a generic description of a "typical practice."
[SP] Example -- Solo practice: Ania runs a one-person manual therapy practice in a rented room. Over the course of a weekend she works through all seven documents from the PREMIUM package, filling in her own details, her practice address, and a list of three suppliers (calendar app, accounting firm, website host). By Monday she has a complete, consistent set of documentation -- something she'd been putting off for two years because "she never had time to find a lawyer."
[GR] Example -- Group practice: The owner of a practice employing four physiotherapists and a receptionist goes through the same set, but additionally has to issue authorizations for each of the five staff members individually and include additional processes in the record of processing activities -- recruitment, staff scheduling, and possible waiting-room surveillance. Thanks to the ready-made document structure, extending the system to more staff members is just a matter of copying the authorization template, not building a new document from scratch.
Frequently asked questions
Does a one-person physiotherapy practice really need all seven documents?
Yes, as long as the practice processes patients' health data, which it does by the very nature of the business. The size of the entity doesn't exempt it from GDPR obligations -- a solo practice is subject to exactly the same rules as a large clinic; only the scope of individual documents differs (e.g. a shorter list of people in the authorizations), not whether they're required at all.
Can I implement these documents myself, without a lawyer?
Yes, if you use ready-made templates prepared specifically for the physiotherapy industry -- your job then comes down to filling in your own practice's details rather than drafting legal content from scratch. It's worth remembering, though, that no template knows your actual processes and suppliers -- those elements always need to be filled in yourself, accurately and in line with the facts.
What happens if I only have some of these seven documents?
A UODO inspector assesses the system as a whole, not individual documents in isolation. Missing even one element -- for example staff authorizations, while having a policy and a record in place -- is treated as a gap in the data protection system and can result in a post-inspection recommendation, even if the rest of the documentation is correct.
Is a video surveillance policy mandatory for every practice?
No -- this document only applies to practices that actually use video surveillance, e.g. cameras in the waiting room or at reception. If a practice doesn't have cameras, this element of the system simply doesn't apply, but it's worth keeping in mind for the moment you decide to install surveillance in the future.
CTA: You don't have to choose between an expensive lawyer and a risky "I'll get to it eventually." The PREMIUM package includes the complete set of GDPR documents described in this article -- the data protection policy, the record of processing activities, the information clause, staff authorizations, the data processing agreement, and the breach procedure -- ready to fill in over a single weekend, instead of waiting 2-4 weeks and paying a lawyer PLN 2,000-5,000. See the PREMIUM package →
Related articles:
- GDPR at a physiotherapy practice -- a complete guide
- Record of processing activities in physiotherapy
- GDPR information clause for a physiotherapy practice
- Data-processing authorization for staff
- Data processing agreement -- who a physiotherapist must sign one with
- Data breach -- 72 hours to respond