GDPR & Data Protection

GDPR Information Notice for Patients - What It Must Include and Where to Post It

Author:

The 11 mandatory elements of a GDPR information notice under Art. 13, the layered model, and whether patients need to sign it (spoiler: they don't).

Tomasz opened his physiotherapy practice six months ago. At the reception desk he keeps a printed sheet titled "GDPR" with a space for the patient's signature -- he copied it from a friend who runs a beauty salon. Every new patient signs this sheet at their first visit, and Tomasz files it away in a binder, feeling reassured. The problem is that the document he hands to patients doesn't contain a single one of the elements required by GDPR -- but it does have a signature field, which GDPR doesn't require at all.

This is one of the most common mistakes at small practices: confusing an information notice with a consent form. An information notice isn't a request for permission -- it's an obligation on the data controller to tell the patient who is processing their data, for what purpose, for how long, and what rights they have. In this article we explain exactly what it must include, when it needs to be provided, and why a patient's signature on it is unnecessary.

When the information obligation toward a patient must be fulfilled

Article 13 GDPR requires the controller to provide certain information at the time personal data is collected from the data subject. In practice, at a physiotherapy practice this means the information obligation must be fulfilled at the very first contact where the patient provides their data -- usually when booking the first appointment, not only during the treatment itself.

There is no transition period and no option to "sort it out later." If a patient calls to book an appointment and the receptionist writes down their name and phone number, the information obligation arises at that exact moment -- regardless of whether the patient ever actually shows up at the practice. We cover the general principles of implementing GDPR at a practice, including a map of all the controller's obligations, in the article GDPR at a physiotherapy practice.

The layered model -- how to convey a lot of information without overwhelming the patient

GDPR requires a fairly large amount of information to be provided, but that doesn't mean the patient has to read a page of legal text before sitting down for an intake interview. In practice, the layered model recommended by data protection authorities across Europe works well.

First layer -- the short-form notice

This is a brief, visible notice placed somewhere the patient will actually see it -- on a board in the waiting room, at reception, or in an online booking form. It contains the key points: who the controller is, for what purpose the data is processed, where to find the full text of the notice, and how to make contact regarding data protection matters. This isn't a shortened replacement for the full notice -- it's an entry point that directs the patient to the details.

Second layer -- the full text

The full notice, containing all 11 elements required by Article 13 GDPR, should be available somewhere easily accessible to the patient -- most often on the practice's website (in a privacy policy section) and physically at the practice, e.g. in a binder at reception, available on request. It's also good practice to place a link to the full notice directly beneath the short-form notice in the first layer.

This split serves two GDPR goals that might otherwise seem to conflict: the information must be concise and easily accessible (Article 12 GDPR), while also being complete (Article 13 GDPR).

The 11 mandatory elements of an information notice

Article 13(1) and (2) GDPR lists a specific set of information that must be included in the notice. The table below shows every element along with what its typical content looks like at a physiotherapy practice.

Element under Art. 13 GDPR How it looks at a physiotherapy practice
Identity and contact details of the controllerPractice/company name, address, email, phone number
Contact details of the DPO (if appointed)Small practices usually have no DPO -- this point is then omitted
Purposes and legal bases of processingE.g. keeping medical records (legal obligation), booking and providing the appointment (contract), contacting the patient about a scheduled visit (legitimate interest)
Legitimate interests of the controller (if applicable)E.g. pursuing claims, internal statistical purposes
Recipients of the dataAccounting firm, calendar software provider, cooperating labs/entities -- if applicable
Intention to transfer data to a third countryUsually none -- a statement that data isn't transferred outside the EEA, unless it actually is
Data retention period20 years for medical records under the Patient Rights Act, other periods for billing data
Rights of the data subjectAccess, rectification, erasure (within the limits of medical records regulations), restriction, objection, data portability
Right to lodge a complaint with a supervisory authorityThe President of the Personal Data Protection Office (UODO)
Whether providing the data is mandatory / a condition of the serviceA statement that providing the data is necessary to carry out the appointment and keep medical records
Automated decision-making, including profilingUsually absent at a physiotherapy practice -- a statement that the controller doesn't use automated decision-making

Missing even one of the elements above means the information obligation is not fully met -- no matter how detailed the rest of the document is.

Retention period -- 20 years, and why it needs to be spelled out

One of the elements most often skipped or stated only vaguely ("for as long as necessary") is the specific retention period for medical records. The Polish Patient Rights Act sets this at 20 years, counted from the end of the calendar year in which the last entry was made -- this is information the notice should state explicitly, rather than referring vaguely to "applicable regulations" without a specific figure. Patients have a right to know how long their data will be kept, and vague wording doesn't meet the transparency requirement of Article 12 GDPR.

Does the patient have to sign the information notice?

No. This is one of the most common and widespread mistakes at practices -- collecting patient signatures on the information notice as if it were a consent to something. An information notice is not consent -- it is a one-sided obligation on the controller, who must provide the information to the patient regardless of whether the patient agrees with it or not. The patient has nothing to "give" here -- only the right to be informed.

Where does this mistake come from? Most often from confusing the information notice with marketing consent (e.g. for sending newsletters or SMS appointment reminders for purposes other than providing the service), which does actually require an active action from the patient -- ticking a checkbox or signing. Collecting signatures on the information notice itself is not required, and in practice it just creates extra, unnecessary paperwork that has to be stored and archived with no legal benefit.

If a practice wants proof that the information obligation was fulfilled, it's enough to document the fact that the notice was made available -- e.g. by keeping it permanently displayed in a visible location, published on the website, and referenced in the registration procedure. There's no need for every individual patient's signature.

[SP] Example -- Solo practice: Tomasz removes the sign-off sheet from his intake process and replaces it with a sign at reception carrying the first-layer notice and a link to the full text on the website. He keeps a binder with the full notice on the reception counter, available on request. He keeps the marketing consent for SMS appointment reminders as a separate, optional checkbox -- the only element that actually requires a signature or a tick.

[GR] Example -- Group practice: At a practice with five physiotherapists, each therapist previously had their own version of a "GDPR consent" form, differing in wording and format. The practice manager standardizes the documentation: one information notice applies across the whole practice, displayed in the waiting room, available on the website and at reception, with no signatures required. Marketing consents (if the practice collects them) are a separate, unified form with a checkbox.

Phone and online booking -- meeting the obligation without a physical signature

More and more patients book by phone or through a website form or booking app (e.g. Booksy). In both cases, the information obligation arises the moment the data is collected -- so before the first appointment -- and it has to be fulfilled without the patient being physically present at the practice.

For phone bookings, good practice is a short verbal notice from the receptionist ("Your data will be processed in accordance with GDPR for the purpose of your appointment; the full notice is available on our website at...") along with a reference to the full text available online. There's no need to read the entire notice over the phone -- it's enough to ensure the information is easily accessible and the patient knows where to find it.

For online bookings (website form, booking app), the obligation is met by placing a short-form notice directly next to the form fields, together with a link to the full notice -- most often as a line under the "Book" button ("The controller of your data is [practice name]. Full information about data processing is available [here]"). We cover website booking forms and GDPR compliance in more detail in the article Practice website and GDPR. It's also worth making sure the way data from the form is processed is consistent with what the practice has recorded in its record of processing activities -- the information notice and the record should describe the same purposes and legal bases, not diverge from each other.

How to implement an information notice step by step

  1. Gather all the elements from Article 13 GDPR and prepare the full notice text tailored to the actual processes at your practice -- don't just copy a template without checking it fits your situation.
  2. Prepare a short-form version (first layer) for the reception board, the online form, and phone notices.
  3. Post the full text in two places -- on the practice's website and physically at the practice, somewhere accessible to patients.
  4. Remove any signature field attached to the information notice itself, if one exists.
  5. Check consistency with the record of processing activities -- the purposes and legal bases must match across documents.
  6. Update the notice after any process change -- e.g. when switching calendar software providers or adding a new service.

Frequently asked questions

Does the GDPR information notice have to be posted at reception?

There's no requirement for the notice to physically hang on a wall, but it must be easily accessible to the patient at the moment their data is collected. In practice, the most effective solution is combining a short notice visible at reception or in the booking form with the full text available on the website and in a binder at the practice -- so the patient can review it without having to ask for it directly.

Do you need a separate notice for children and patients with a guardian?

Yes, it's worth including a statement in the notice that for minor or legally incapacitated patients, the information obligation is fulfilled toward their legal representative or guardian, who gives consents and receives information on their behalf. This doesn't need to be a separate document -- one paragraph in the full notice describing this situation is enough.

Yes, these are two different documents serving different functions. The information notice fulfills the obligation under Article 13 GDPR and requires no action from the patient beyond reading it. Processing health data at a physiotherapy practice is usually based on the performance of a healthcare services contract and the legal obligation to keep medical records, not on consent -- which is why a typical practice usually doesn't need separate consent for processing medical data.

What happens if a practice has no information notice at all?

Having no information notice is a violation of one of the controller's fundamental obligations under Article 13 GDPR, regardless of whether any security incident has occurred. During an inspection or in response to a patient complaint, the Personal Data Protection Office (UODO) can issue post-inspection recommendations or impose an administrative fine solely for failing to meet the information obligation, without needing to demonstrate any additional harm.

CTA: Don't have a compliant Article 13 GDPR information notice yet? The PREMIUM package includes a ready-made "GDPR Information Notice" -- implementation instructions together with a fillable template for your practice's details, ready to post at reception and publish on your website. See FizjoReady packages →

Related articles:
- GDPR at a physiotherapy practice -- a complete guide
- Patient records in physiotherapy -- what they must include
- Record of processing activities at a physiotherapy practice

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.