All articles

GDPR & Data Protection

Privacy notice, consents, privacy policy - GDPR in a physiotherapy clinic. Ready-made templates and checklists to download.

Sharing CCTV Footage: Who Can Receive It

Police demand footage, a patient wants proof of a fall, an insurer wants the parking-lot recording - learn who a physiotherapy practice can actually disclose.

A UODO Inspection at Your Physiotherapy

When the UODO inspects a small physiotherapy practice, how the inspection unfolds, which documents the inspector asks for and the realistic scale of fines.

A Data Breach at Your Practice

A lost laptop, an email sent to the wrong patient, a ransomware attack - when it counts as a data breach, when you must report it to UODO within 72 hours.

GDPR Information Notice for Patients

The 11 mandatory elements of a GDPR information notice under Art. 13, the layered model, and whether patients need to sign it (spoiler: they don't).

SMS and Email to Patients under GDPR

An appointment reminder needs no marketing consent, but one extra sentence can turn it into one. What may go into an SMS and how to email records safely.

GDPR Training for Practice Staff

Where the GDPR training duty comes from, who at a physiotherapy practice has to be trained, what scope makes sense and how to document that it took place.

Data Processing Agreement

Who a physiotherapist must sign a data processing agreement with - booking software, accounting firm, hosting.

Register of Medical Records Disclosures

Who can access a patient's medical records, in what form and by when, plus a template for the mandatory disclosure register in a physiotherapy practice.

Your Practice Website and GDPR

How to make a physiotherapy practice website GDPR-compliant: privacy policy, cookie banner, booking forms, newsletter, processor agreements and analytics.

Paediatric physiotherapy

A mother brings her 8-year-old son to Mr Marcin's practice after a sprained ankle. She fills in the consent form, everything seems fine.

GDPR in a Physiotherapy Practice

RODO is the Polish name for GDPR (the General Data Protection Regulation) -- the EU tells you how to safely store your patients' data.

IT Security at Your Practice

The minimum IT security measures a physiotherapy practice must implement without an IT specialist: named accounts, passwords, disk encryption, 3-2-1 backups.

Clean Desk Policy

A patient file left on the desk, a monitor visible from the waiting room: clean desk and clean screen rules that close the most common leaks at reception.

Internal Data Protection Policy

An internal data protection policy is not the same as a website privacy policy - without this document a practice cannot demonstrate GDPR compliance to UODO.

CCTV at a Physiotherapy Practice

Is CCTV at a physiotherapy practice legal? Where you may install cameras, where it's forbidden, the legal basis, retention limits and required signage.

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.