Internal Data Protection Policy - the Document UODO Will Ask About

An internal data protection policy is not the same as a website privacy policy - without this document a practice cannot demonstrate GDPR compliance to UODO, even if it actually follows the rules in practice.
Tomasz, the owner of a solo physiotherapy practice, was asked by a client -- a lawyer who happened to be implementing GDPR at her own law firm -- "where do you have it written down how you actually manage patient data?" He replied that he already had a privacy policy on his website, so surely everything was in order. The lawyer shook her head. What she was asking about was an entirely different document -- one a patient will never see, because it isn't written for them.
That mix-up -- confusing a website's privacy policy with an internal data protection policy -- is one of the most common mistakes in GDPR documentation at physiotherapy practices. Both documents have the word "policy" in their name, both concern personal data, but they serve completely different purposes and reach completely different audiences. In this article we explain what an internal data protection policy actually is, why without it a practice cannot demonstrate GDPR compliance to an inspector, and exactly what it should contain.
Two documents, two completely different functions
This distinction is essential, so let's start there. A privacy policy published on a practice's website is a public, informational document -- its audience is the patient or website visitor, and its content answers questions like: what data do we collect through the contact form, how long do we keep it, who do we share it with, what rights does the data subject have. It's a document fulfilling the information obligation under GDPR Articles 13 and 14, aimed outward.
An internal data protection policy (sometimes also called a data security policy) is an internal document describing how the controller -- the practice -- actually manages personal data day to day: who has access to it, what rules apply to staff, what the procedure is in case of a breach, where documents are physically and electronically stored. Its audience isn't the patient -- it's the practice itself, its owner, its staff, and, in the event of an inspection, the Personal Data Protection Office (UODO).
A common mistake is for a practice to stop at just the website's privacy policy -- since that's the document most often discussed in a GDPR context -- and consider the topic closed. In reality it's only one of many elements of a data protection system, not its core. We cover the full documentation obligation of a practice more broadly in the article GDPR at a physiotherapy practice.
| Feature | Privacy policy (website) | Internal data protection policy |
|---|---|---|
| Audience | Patient / website user | Practice owner, staff, UODO during inspection |
| Nature | Public, informational | Internal, organisational |
| Legal basis | Art. 13-14 GDPR (information obligation) | Art. 5(2) GDPR (accountability principle) |
| Content | What data we collect, why, for how long | How we actually manage data day to day |
| Publication | Practice website | Internal documentation, not published |
The accountability principle -- why "we comply with GDPR" isn't enough
The legal basis for the obligation to have an internal data protection policy is Article 5(2) of the GDPR, which sets out the accountability principle. Under it, the data controller must not only comply with the data processing principles set out in Article 5(1) GDPR, but must be able to demonstrate compliance with them.
This distinction has fundamental practical significance. A practice may actually be processing patient data entirely correctly -- collecting only necessary information, protecting it against unauthorized access, deleting it once the retention period expires. But if those rules exist only "in the owner's head" and not in the form of a written document, the practice has no way to prove to an inspector that it actually operates this way. From UODO's point of view, missing documentation looks identical to actually failing to comply with the rules -- an inspector doesn't assess intentions, only evidence.
In practice, this means the data protection policy is the first document requested during an inspection or in response to a patient complaint. Its absence alone is grounds for a post-inspection recommendation, regardless of whether any actual data security breach has occurred.
What a data protection policy should contain
The policy isn't a document that describes everything from scratch -- it's rather an overarching document that ties together elements of the data protection system the practice should already have implemented separately. A well-constructed policy consists of several building blocks.
Roles and responsibility
The policy must clearly indicate who is the Data Controller -- at a solo practice this is usually the owner themselves; at a group practice it may be the entity running the business. If the practice employs staff with access to patient data, it's also worth describing who is responsible for day-to-day oversight of compliance with the rules -- this doesn't have to be a formally appointed Data Protection Officer, since most physiotherapy practices aren't required to appoint one, but someone should be accountable for ongoing supervision.
Data processing principles
This section describes how the practice implements, in practice, the principles from Article 5(1) GDPR:
- Lawfulness -- the legal basis on which each category of data is processed (e.g. contract performance, consent, legal obligation).
- Purpose limitation -- that data is collected for specific, explicit, and legitimate purposes, not "just in case."
- Data minimisation -- that the practice collects only the data actually necessary to achieve the purpose.
- Storage limitation -- how long each category of data is kept and when it must be deleted or anonymised.
- Integrity and confidentiality -- what technical and organisational measures protect the data against unauthorized access, loss, or destruction.
Appendices -- the document that ties the whole system together
This is the element most often skipped, yet it's key to the policy's practical usefulness. Rather than duplicating the content of other documents, the policy should reference them as appendices or related documents: the record of processing activities (RCPD), information clauses for patients, template staff authorisations for data processing, and the data breach procedure. We describe the full set of these elements in the article on the record of processing activities in physiotherapy, and we discuss the staff authorisation template in the GDPR information clause for physiotherapy practices.
Structured this way, the policy isn't just another standalone document -- it's a table of contents for the practice's entire data protection system, easy to present to an inspector since it immediately shows that all the elements are consistent with one another.
[SP] Example -- Solo practice: After his conversation with the lawyer-client, Tomasz sits down to organize his documentation. It turns out he already has an RCPD and information clauses in place separately, but has never written them into one overarching document. He creates a data protection policy describing himself as the controller, sets out the principles for processing patients' health data, and attaches the documents he had already prepared as appendices.
[GR] Example -- Group practice: At a practice employing four physiotherapists and a receptionist, each staff member had their own way of handling paper documentation -- some locked the cabinets, others left patient cards on the desk between appointments. The owner introduces a data protection policy with a clear section on physical and electronic access rules for documentation, which the entire staff signs to confirm they've read and understood the rules.
Does a solo practice also need one
Yes -- and this is one of the most common misconceptions. The size of the entity does not exempt it from the obligation arising from the accountability principle. The GDPR does not provide an exception for sole proprietorships, nor a patient-count threshold below which documentation stops being required.
What's more, for physiotherapy practices this argument actually works the other way around. Physiotherapists process data concerning patients' health, which is data belonging to a special category under Article 9 GDPR. That provision requires additional safeguards and separate legal bases for processing (e.g. the patient's explicit consent or a healthcare-related basis), and a well-written data protection policy should address this directly -- specifying what additional security measures the practice applies precisely because of the nature of the data it processes. The smaller the entity, the easier it is to overlook the formalities -- and the easier it is for UODO to demonstrate a lack of documentation during an inspection, since a small practice has no legal department to flag the obligation.
How long implementation takes -- ready-made template vs. starting from scratch
The time needed to prepare a data protection policy depends mainly on whether the practice starts from scratch or uses a ready-made template.
Writing a policy from the ground up -- without a template, analysing the requirements of Article 5(2) and Article 9 GDPR on your own -- usually takes several to a dozen or so hours of work if done properly: you need to analyse your own processes, determine what data you actually process, describe security measures, and ensure consistency with the other documents (RCPD, clauses, authorisations). The risk here isn't just the time involved -- someone without GDPR experience can easily miss important elements that only surface later, during an inspection.
With a ready-made template tailored to the specifics of a physiotherapy practice, the process comes down mainly to filling in your own details and checking that the described procedures actually match how the practice operates day to day -- typically a matter of one, at most two afternoons of work, instead of a drawn-out project.
Frequently asked questions
What's the difference between a data protection policy and a website privacy policy?
A website privacy policy is a public document aimed at patients and website visitors -- it fulfils the information obligation under GDPR Articles 13-14 and describes what data the practice collects through the forms on its website. A data protection policy is an internal document describing how the practice actually manages data day to day -- roles, processing principles, security procedures. These are two different documents serving different purposes, and having one does not replace the other.
Does a solo physiotherapy practice need a written data protection policy?
Yes. The accountability principle under Article 5(2) GDPR applies regardless of the size of the entity or the number of patients served. In addition, physiotherapists process health data, which is special category data under Article 9 GDPR, making the case for written documentation describing how it is protected even stronger.
Does patient health data require additional safeguards in the policy?
Yes. Data concerning health belongs to the special category of personal data under Article 9 GDPR, which means additional security measures are required along with a separate legal basis for processing. A well-written data protection policy should explicitly describe what specific measures the practice applies because of the nature of the health data it processes, rather than relying on general statements.
What happens if a practice follows GDPR rules in practice but hasn't written them down in a policy?
From the perspective of the accountability principle, having no written document means the practice cannot demonstrate GDPR compliance to UODO, even if it actually complies with the rules in practice. During an inspection, evidence is assessed, not declarations -- a missing data protection policy is grounds on its own for a post-inspection recommendation, regardless of whether any security breach has occurred.
CTA: Organizing a practice's GDPR documentation -- from the data protection policy to the record of processing activities and patient information clauses -- is easier to start with ready-made templates than a blank page. FizjoReady packages include a full set of documentation supporting GDPR compliance, including a related website privacy policy as one element of the overall system. See FizjoReady packages →
Related articles:
- GDPR at a physiotherapy practice -- a complete guide
- Record of processing activities in physiotherapy
- GDPR information clause at a physiotherapy practice