GDPR & Data Protection

Records of Processing Activities (ROPA) at a Physiotherapy Practice - How to Fill It In

Author:

Even a small physiotherapy practice must keep a ROPA - the exemption for entities under 250 employees doesn't cover health data. See what to include in the register and check out sample completed rows.

Ania runs a one-person physiotherapy practice, and for two years she was convinced that a records of processing activities register was a formality for large clinics with an HR department and a dozen staff. After all, she has one person on the payroll -- herself. But when she was preparing for a data protection authority inspection after a former patient filed a complaint, it turned out that not having a ROPA is a standalone violation, regardless of whether any data breach actually occurred.

This misunderstanding repeats in almost every small practice. It comes from a misreading of the exemption for small entities -- an exemption that, in practice, almost never applies to physiotherapists, because they process health data. In this article we explain why a ROPA is essentially always mandatory, how to build one step by step, and what a sample completed row of the register looks like. We covered the GDPR basics for a physiotherapy practice in more depth in our article on GDPR at a physiotherapy practice.

What a ROPA is and where the obligation comes from

The Records of Processing Activities (ROPA, in Polish RCPD) is a document required under Article 30 of the GDPR. It is an internal "map" of every process in which the practice processes personal data -- from patients' medical records, through appointment scheduling, to HR and marketing. The register is not published or reported to any authority upfront, but that doesn't make it optional.

Small practices and the exemption in Article 30(5) GDPR

Many practice owners have heard that entities employing fewer than 250 people are exempt from keeping a register. That's only half true. The exemption in Article 30(5) GDPR does apply to small entities, but it does not cover situations where:

  • the processing is not occasional (i.e. it's carried out regularly -- and keeping patient records regularly at a physiotherapy practice is exactly that case),
  • the processing involves special categories of data under Article 9 GDPR -- including health data,
  • the processing is likely to result in a risk to the rights and freedoms of the data subjects.

A physiotherapy practice meets at least two of these three conditions simultaneously: it processes patients' health data regularly, at every visit. That's why, regardless of the practice's size -- a solo practice or one employing several therapists -- a ROPA is mandatory. This is one of the most commonly misread GDPR provisions in the physiotherapy sector, and a frequent source of inspection failings, which we cover in our article on mistakes during KIF and Sanepid inspections.

What every entry in the register must contain

Article 30(1) GDPR lists the mandatory elements for each processing activity entered into a controller's register. Each row of the register should include:

  1. Purpose of processing -- why the practice collects and uses the data (e.g. providing physiotherapy services, keeping medical records).
  2. Description of the categories of data subjects -- patients, staff, contractors.
  3. Description of the categories of personal data -- identification data, contact data, health data, billing data.
  4. Categories of recipients -- who the data is disclosed to, including processors (e.g. a medical software provider, an accounting firm) and recipients in third countries, if applicable.
  5. Envisaged time limits for erasure of the different categories of data -- e.g. in line with the statutory retention period for medical records.
  6. A general description of the technical and organisational security measures -- e.g. encryption, access control, backups, staff authorisations.

The controller also enters its own identification and contact details (and, if a data protection officer has been appointed, their details too).

Processing activities that need their own separate entry

The most common mistake when building a ROPA is entering one generic line, "processing of patient data," instead of breaking real processes down into separate rows. Each process has a different purpose, a different legal basis, and a different retention period, so it should be described separately. At a typical physiotherapy practice, these usually include:

  • Patients' medical records -- intake interviews, therapy cards, treatment plans.
  • Appointment scheduling and calendar -- contact data, booking history.
  • Marketing -- newsletters, appointment-reminder texts, ad campaigns.
  • Staff HR and payroll -- data on employees and collaborators.
  • CCTV monitoring -- if cameras are installed at the practice.
  • Accounting and invoicing -- billing data for clients and contractors.
  • Complaint and inquiry handling -- correspondence with patients on disputed matters.

Breaking these into separate rows also makes it easier to answer questions during a data protection authority inspection -- an inspector usually asks about a specific process, not about "data processing" in general.

Processing activity Categories of data Legal basis Recipients Retention period
Patient medical recordsIdentification data, contact data, health dataArt. 9(2)(h) GDPR + the Patient Rights ActMedical software provider (processor), NHF (if applicable)20 years from the last entry (Patient Rights Act)
Marketing (newsletter, texts)Name, email, phone numberConsent -- Art. 6(1)(a) GDPRMailing/SMS system providerUntil consent is withdrawn
Staff HR and payrollIdentification data, HR and payroll dataLegal obligation / contract -- Art. 6(1)(b) and (c) GDPRAccounting firm, social insurance institutionPer employee-records regulations

The legal basis is the element that most often causes trouble, because at a physiotherapy practice two legal regimes overlap -- the general GDPR rules and the rules on health data.

Health data -- Article 9 GDPR

A patient's medical record is special-category data. GDPR generally prohibits its processing, but provides for exceptions. For a physiotherapy practice, the key basis is Article 9(2)(h) GDPR -- processing necessary for the purposes of healthcare. This basis works together with national provisions, primarily the Patient Rights Act and the Act on Medical Activity, which spell out, among other things, the obligation to keep records and how long to retain them.

Newsletters and appointment-reminder texts (where they go beyond a purely organisational reminder of a scheduled appointment) are usually based on consent -- Article 6(1)(a) GDPR. Consent must be freely given, specific, and as easy to withdraw at any time as it was to give.

Data on employees and collaborators is processed mainly on the basis of legal obligation (Article 6(1)(c) GDPR) arising from labour and social-security law, and partly on the basis of contract performance (Article 6(1)(b) GDPR).

[SP] Example -- Solo practice: Ania runs her practice alone, with no employed staff. Even so, her ROPA has five separate rows: medical records, appointment scheduling, a newsletter with rehabilitation tips, accounting handled by an external accounting firm, and complaint handling. The register fits on one A4 page, but during an inspection the data protection authority checks exactly that -- whether the document exists and whether it reflects the practice's actual processes.

[GR] Example -- Group practice: At a practice employing four physiotherapists and a receptionist, the ROPA has nine rows -- adding staff HR and payroll, CCTV monitoring in the waiting room, and a separate entry for the recipients of B2B invoices. A designated person is responsible for keeping the register up to date, reviewing it every six months and after any significant change to the practice's processes, such as rolling out a new online booking system.

A ROPA is an internal document -- but that doesn't make it optional

The records of processing activities register is not published on the practice's website, nor reported to the data protection authority in advance -- it's an internal document of the data controller. How patients' data is presented externally, e.g. in a website privacy policy, is something we covered in our article on a practice website and GDPR.

That doesn't mean the ROPA can be skipped, though. Under Article 30(4) GDPR, the controller must make the register available to the supervisory authority on request. During an inspection, the inspector can ask to see the register at any point, and not having one is treated as a standalone GDPR violation, regardless of whether the practice has had any data-security incident at all. A missing register is one of the simplest failings to spot and one of the most clear-cut -- the inspector either sees the document or doesn't.

Updating the register -- when it needs revising

A ROPA isn't a "set it and forget it" document. It needs updating every time the practice:

  • introduces a new data processing activity (e.g. rolling out an online booking system, installing CCTV),
  • changes a data recipient (e.g. switching medical software provider or accounting firm),
  • changes a retention period due to a change in the law,
  • starts working with a new processor, which also requires signing a data processing agreement.

In practice, it's a good habit to review the register every six months, and every time a new tool or service is introduced at the practice.

Frequently asked questions

Does a one-person physiotherapy practice have to keep a ROPA?

Yes. The exemption in Article 30(5) GDPR for entities employing fewer than 250 people does not cover the processing of health data or regular processing, and a physiotherapy practice meets both of these conditions regardless of how many people it employs. That's why a ROPA is mandatory even at a practice run by a single person.

Does the records of processing activities register need to be reported to anyone or published?

No. A ROPA is an internal document of the data controller and isn't subject to reporting or publication. Under Article 30(4) GDPR, however, the practice must make it available to the data protection authority on request during an inspection. Not having such a document is treated as a standalone violation, even if the practice hasn't had any incident.

Which processes need a separate entry in the register?

Every processing activity should have its own row, since each differs in purpose, legal basis, and retention period. At a typical physiotherapy practice, these usually include medical records, appointment scheduling, marketing, HR and payroll, any CCTV monitoring, accounting, and complaint handling.

How long does data listed in the register have to be kept?

It depends on the category of data. Medical records are subject to the statutory retention period under the Patient Rights Act (generally 20 years from the last entry), marketing data is kept until consent is withdrawn, and HR data follows employee-records regulations. These time limits should be entered explicitly in the register for each processing activity.

CTA: Don't want to build a ROPA from scratch? The FizjoReady PREMIUM package (1297 PLN) includes a ready-made, editable records-of-processing-activities template -- complete with fill-in instructions and sample rows tailored to a physiotherapy practice. See FizjoReady packages →

Related articles:
- GDPR at a physiotherapy practice -- a practical guide for physiotherapists
- Register of medical records disclosures -- template
- A practice website and GDPR -- privacy policy and cookies

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.