
Police, a Patient, or an Insurer Asks for
Police demand footage, a patient wants proof of a fall, an insurer wants the parking-lot recording - learn who a physiotherapy practice can actually disclose.
Privacy notice, consents, privacy policy - GDPR in a physiotherapy clinic. Ready-made templates and checklists to download.

Police demand footage, a patient wants proof of a fall, an insurer wants the parking-lot recording - learn who a physiotherapy practice can actually disclose.

When and why the Polish DPA inspects a physiotherapy practice, how the inspection unfolds.

A complete map of the 7 GDPR documents every physiotherapy practice needs - policy, ROPA, information clause, authorizations, processing agreement.

A lost laptop, an email sent to the wrong patient, a ransomware attack - when it counts as a data breach, when you must report it to UODO within 72 hours.

Who at a physiotherapy practice needs written authorization to process personal data, how it differs from a data processing agreement.

The 11 mandatory elements of a GDPR information notice under Art. 13, the layered model, and whether patients need to sign it (spoiler: they don't).
Does an SMS appointment reminder require patient consent? When a message becomes marketing.

Even a small physiotherapy practice must keep a ROPA - the exemption for entities under 250 employees doesn't cover health data.
Who at a physiotherapy practice needs GDPR training, what scope makes sense.

Who a physiotherapist must sign a data processing agreement with - booking software, accounting firm, hosting.

An insurance company called Anna's practice asking for a patient's records after an injury. Anna emailed a copy of the file, thinking "the patient wants the…

Michał built a nice website for his practice with a "Book an appointment online" form. Patients entered their name, phone number, email, and sometimes a…

A mother brings her 8-year-old son to Mr Marcin's practice after a sprained ankle. She fills in the consent form, everything seems fine.

RODO is the Polish name for GDPR (the General Data Protection Regulation) -- the EU tells you how to safely store your patients' data.

The minimum IT security measures a physiotherapy practice must implement without an IT specialist: named accounts, passwords, disk encryption, 3-2-1 backups.

A patient file on the desk, a monitor visible from the waiting room.

An internal data protection policy is not the same as a website privacy policy - without this document a practice cannot demonstrate GDPR compliance to UODO.

Is CCTV at a physiotherapy practice legal? Where you may install cameras, where it's forbidden, the legal basis, retention limits and required signage.
Regulatory changes and practical tips for physiotherapy practices. No spam.