GDPR & Data Protection

A UODO Inspection at Your Physiotherapy Practice - Which Documents You Must Show

Author:

When and why the Polish DPA inspects a physiotherapy practice, how the inspection unfolds, and which GDPR documents the inspector will ask for - plus the realistic scale of fines for small entities.

Agnieszka has run a one-person physiotherapy practice for three years, and like most therapists, she thought about GDPR the way most do -- "I've got a clause on my website, that's probably enough." Then one day a letter arrived from the Polish Data Protection Authority (UODO). A patient she'd parted ways with on less-than-friendly terms had filed a complaint: he claimed he'd never been told who his data had been shared with, and that no one had responded to his request to access his records. Suddenly it turned out that one page with a privacy clause wasn't enough -- the inspector asked for the register of processing activities, staff authorisations, and agreements with any parties the practice shares data with.

This is a scenario that plays out at small physiotherapy practices more often than you'd think. The UODO doesn't inspect physiotherapy practices as systematically as the Sanitary Inspectorate or the National Chamber of Physiotherapists, but when it does show up, it means business -- and it checks exactly the things most small practices don't have. In this article we explain when the UODO comes knocking, what an inspection actually looks like, and which documents you need ready so it passes without consequences. This is the umbrella post for the entire GDPR module on our blog -- links to detailed articles on individual obligations follow below.

When does the UODO inspect a small physiotherapy practice

Unlike Sanepid or KIF inspections, the UODO rarely shows up at a small one-person practice as part of a routine plan. Far more often it opens an inspection for a specific reason:

  • A patient complaint -- the most common scenario. A patient reports that the practice failed to fulfil their right of access to data, didn't respond to a request to delete data, or that their data ended up with third parties without a legal basis (e.g. an employer, insurer, or another specialist).
  • A reported data breach -- if the practice itself reported a breach to the UODO under Article 33 GDPR (e.g. a lost laptop with patient records, a data leak from a booking system), the authority may open an investigation to check whether the report was complete and whether appropriate action was taken.
  • A planned sector inspection -- the UODO publishes an annual plan of sector-wide inspections that sometimes covers medical practices. A small physiotherapy practice being caught up in such a plan is uncommon, but not impossible, especially during sector-wide inspections covering the whole healthcare industry.
  • A tip-off from a third party -- e.g. a former employee, a competitor, or someone who noticed an irregularity (such as unsecured documents visible in the waiting room).

The most common trigger by far is a patient complaint -- which is why well-organised handling of patient requests (access, rectification, deletion of data) is the first line of defence against an inspection, long before any letter from the authority ever arrives.

How a UODO inspection unfolds

A UODO inspection differs from a KIF or Sanepid site visit -- it has a more formal, administrative character, though the underlying logic is similar: the inspector checks whether what actually happens at the practice day to day matches what the documentation says.

  1. Notice of inspection -- in most cases the practice receives written notice in advance, stating the scope and date of the inspection. In cases related to a reported data breach, the response time can be shorter.
  2. Identification of the inspectors -- on site, the inspector presents an authorisation to carry out the inspection and an ID.
  3. Right of access -- the inspector has the right to inspect documents, the premises where data is processed, and IT systems (the booking system, electronic medical records, email).
  4. Explanations -- the administrator (the person running the practice) or a designated staff member provides explanations about how data is processed.
  5. Inspection report -- a report is drawn up describing the course of the inspection, and objections can be raised against it. Based on it, the UODO may issue post-inspection recommendations or, in more serious cases, open a separate administrative proceeding.

The key difference compared with a KIF or Sanepid inspection: the UODO doesn't just look at whether a document exists, but whether it's actually applied in practice. A data protection policy sitting in a binder without staff authorisations, without a processing register, and without evidence that clauses are actually handed to patients won't protect the practice.

Which documents the UODO inspector will ask for

The table below shows the documents most commonly checked and exactly what the inspector looks for in each one.

Document What the inspector checks
Data protection policyWhether it describes the practice's actual processes, rather than being a generic template pulled from the internet and never adapted to physiotherapy
Register of processing activities (ROPA)Whether it covers all processes -- patient records, online bookings, monitoring (if any), invoicing
Staff authorisationsWhether every person with access to patient data (reception, collaborating therapists) has a written authorisation
Data processing agreements with vendorsWhether there are signed agreements with parties processing data on the practice's behalf -- the booking system, hosting, accounting, electronic records
Breach procedure / registerWhether there's a written procedure for handling breaches and whether any incidents that occurred are logged
Information clausesWhether there are template clauses (for patients, on the website, in forms) and evidence they're actually used, e.g. signed acknowledgements
Monitoring policy (if applicable)If the practice uses CCTV -- whether there's a policy, marked zones under surveillance, and a legal basis

Gaps typically show up not in one place but across several at once -- a typical picture is an information clause hanging on the wall, but no processing register, no authorisations, and no data processing agreement with the company running the online booking system. For more on the clauses themselves and how they should look in physiotherapy practice, see our article on GDPR at a physiotherapy practice.

UODO fines for small medical entities -- a realistic scale

The fines the UODO has imposed on small medical entities in Poland are usually nowhere near the multi-million-złoty figures seen in high-profile cases involving large companies. In practice, for small practices, the numbers most often fall in the range of a few to a dozen or so thousand złoty -- and for failings that sound very familiar: no authorisations for staff with access to data, no risk analysis or data protection impact assessment, no appropriate technical and organisational measures, or failures in handling the rights of data subjects.

These aren't catastrophic sums on the scale of a large company, but for a one-person physiotherapy practice, a few thousand złoty in fines -- plus the time spent on the investigation and the stress of the whole process -- is a real cost. And it's a cost that's almost always avoidable simply by having the set of documents the UODO actually asks for in practice.

[SP] Example -- Solo practice: After receiving the letter from the UODO, Agnieszka completes her documentation within a week -- she implements a register of processing activities, has the part-time receptionist sign an authorisation, and adds the missing data processing agreement with the company running the online booking system. At the explanatory meeting she presents the complete set of documents and a timeline of the implementation -- the proceeding closes without a fine, only with a recommendation to complete one remaining item.

[GR] Example -- Group practice: At a practice with five physiotherapists and a reception desk, the risk grows because more people have access to patient data. The owner introduces a single shared authorisation register and a recurring review of data processing agreements with vendors -- so that, in the event of an inspection, every team member has a clearly defined scope of access and legal basis for processing.

How a complete set of documents changes the course of an inspection

The difference between a practice without documentation and one with a complete GDPR document set isn't cosmetic -- it's the difference between two entirely different inspection scenarios.

Without documentation, an inspection turns into an investigative proceeding with post-inspection recommendations: the inspector asks for documents that don't exist, sets a deadline to prepare them, and then checks whether the recommendations have been carried out. That means weeks of uncertainty, extra correspondence with the authority, and the risk that the next failing will be treated more severely.

With a complete document set, the same inspection can wrap up in 20 minutes -- the inspector asks for the ROPA, gets it on the spot; asks for authorisations, they're in a binder or in the cloud, ready to show; asks about data processing agreements, they're signed and up to date. There's no basis for recommendations, because there are no gaps to fill. That's the real difference between documentation kept up to date continuously and documentation prepared "for the inspection," which, in practice, never quite gets finished in time.

The same principle as at a KIF or Sanepid inspection

If you've read our article on mistakes during KIF and Sanepid inspections, you'll recognise the pattern here. The UODO is a different authority, with a different legal basis and different powers -- it oversees personal data protection, not professional standards or sanitary conditions. But the principle that decides the outcome of the inspection is identical: documentation kept up to date continuously turns an inspection into a formality, while documentation kept "for later" turns it into a proceeding with recommendations.

A practice with well-organised GDPR compliance usually also has well-organised medical and sanitary records -- that's not a coincidence, it's the result of the same habit: keeping all documents in one place and updating them continuously, instead of scrambling the week before an announced inspection.

Frequently asked questions

Can the UODO show up without notice?

In most cases the inspection is preceded by written notice given in advance, which gives you time to prepare your documents. The exception is cases related to urgently clarifying a reported data breach, where the authority's response time can be shorter. Regardless of the procedure, the safest approach is to keep your documentation ready on an ongoing basis rather than counting on having time to prepare after receiving notice.

What GDPR documents are the absolute minimum for a physiotherapy practice?

The minimum is a data protection policy, a register of processing activities, authorisations for everyone with access to patient data, data processing agreements with vendors (booking system, hosting, accounting), and information clauses actually used with patients. If the practice has ever experienced a data breach, you also need a written procedure and a register of such incidents.

Does a one-person physiotherapy practice also fall under UODO inspections?

Yes. The size of the entity doesn't exempt it from GDPR obligations -- a one-person physiotherapy practice processes sensitive data (patients' health data), so it's subject to the same rules as larger facilities, though the scale of documentation is proportionally smaller. Patient complaints target one-person practices just as often as larger ones.

What happens if an inspection finds gaps in the documentation?

Most often the UODO issues post-inspection recommendations with a deadline to implement them -- that's not yet a financial penalty. A fine tends to follow when the gaps are serious (e.g. a complete absence of documentation, an unreported data leak) or when the entity fails to implement the recommendations after the first inspection. A prompt response to recommendations is therefore key to avoiding further consequences.

CTA: Want a complete set of GDPR documents ready for any UODO inspection -- without hunting for templates or bolting them on at the last minute? The PREMIUM package includes a full GDPR module: a data protection policy, ROPA, information clauses, consent forms, a data processing agreement, a breach procedure, and staff authorisations. See FizjoReady packages →

Related articles:
- Complete GDPR documentation package for a physiotherapy practice
- Data breach -- 72 hours to report it
- Mistakes during KIF and Sanepid inspections -- how to avoid them
- GDPR at a physiotherapy practice -- what you must implement

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.