
Sharing CCTV Footage: Who Can Receive It
Police demand footage, a patient wants proof of a fall, an insurer wants the parking-lot recording - learn who a physiotherapy practice can actually disclose.
Privacy notice, consents, privacy policy - GDPR in a physiotherapy clinic. Ready-made templates and checklists to download.

Police demand footage, a patient wants proof of a fall, an insurer wants the parking-lot recording - learn who a physiotherapy practice can actually disclose.

When the UODO inspects a small physiotherapy practice, how the inspection unfolds, which documents the inspector asks for and the realistic scale of fines.

A complete map of the 7 GDPR documents every physiotherapy practice needs - policy, ROPA, information clause, authorizations, processing agreement.

A lost laptop, an email sent to the wrong patient, a ransomware attack - when it counts as a data breach, when you must report it to UODO within 72 hours.

Who at a physiotherapy practice needs written authorization to process personal data, how it differs from a data processing agreement.

The 11 mandatory elements of a GDPR information notice under Art. 13, the layered model, and whether patients need to sign it (spoiler: they don't).
An appointment reminder needs no marketing consent, but one extra sentence can turn it into one. What may go into an SMS and how to email records safely.

Even a small physiotherapy practice must keep a ROPA - the exemption for entities under 250 employees doesn't cover health data.
Where the GDPR training duty comes from, who at a physiotherapy practice has to be trained, what scope makes sense and how to document that it took place.

Who a physiotherapist must sign a data processing agreement with - booking software, accounting firm, hosting.

Who can access a patient's medical records, in what form and by when, plus a template for the mandatory disclosure register in a physiotherapy practice.

How to make a physiotherapy practice website GDPR-compliant: privacy policy, cookie banner, booking forms, newsletter, processor agreements and analytics.

A mother brings her 8-year-old son to Mr Marcin's practice after a sprained ankle. She fills in the consent form, everything seems fine.

RODO is the Polish name for GDPR (the General Data Protection Regulation) -- the EU tells you how to safely store your patients' data.

The minimum IT security measures a physiotherapy practice must implement without an IT specialist: named accounts, passwords, disk encryption, 3-2-1 backups.

A patient file left on the desk, a monitor visible from the waiting room: clean desk and clean screen rules that close the most common leaks at reception.

An internal data protection policy is not the same as a website privacy policy - without this document a practice cannot demonstrate GDPR compliance to UODO.

Is CCTV at a physiotherapy practice legal? Where you may install cameras, where it's forbidden, the legal basis, retention limits and required signage.
Regulatory changes and practical tips for physiotherapy practices. No spam.