GDPR in a Physiotherapy Practice - Practical Guide

RODO is the Polish name for GDPR (the General Data Protection Regulation) -- the EU tells you how to safely store your patients' data.
RODO is the Polish name for GDPR (the General Data Protection Regulation) -- the EU tells you how to safely store your patients' data. Many practising physiotherapists think: "Oh, that's some regulation for big companies, it doesn't apply to me." Wrong. It applies to you just as much as it does to a hospital or a pharmacy, because patient data is gold -- if you lose it or misuse it, you face financial penalties and a loss of trust.
In this article we'll show you exactly what GDPR is, why it's so important in physiotherapy, and specifically which documents you need to have in your practice.
Why GDPR is especially important in physiotherapy
Patient data in a physiotherapy practice isn't ordinary data. It's medical data -- a special category of personal data under Art. 9 GDPR. That means:
- Name and surname: ordinary data
- PESEL (national ID number): an identifier requiring heightened protection (although formally it is not a special category of data under Art. 9)
- Information that a patient has joint pain, has had surgery, has allergies -- this is a special category of data, more strictly protected
If you store this data badly, or unintentionally reveal that a patient visited you, you can receive a fine from the Personal Data Protection Office (UODO) -- the Polish data protection authority, operating at national level. UODO has already fined small medical entities, including for a lack of risk analysis and missing basic safeguards. GDPR makes no exceptions for small businesses.
Legal basis for processing data in physiotherapy
To be able to process a patient's data (collect it, store it, review it), you need a legal basis. In physiotherapy you have two:
Basis 1: Art. 6(1)(c) GDPR -- Compliance with a legal obligation
This is the main basis. You must collect and keep patient data because the law requires you to. Specifically:
- Art. 24 of the Act of 6 November 2008 on Patient Rights and the Patient Rights Ombudsman requires you to keep medical documentation
- The Ministry of Health Regulation of 6 April 2020 on the types, scope and templates of medical documentation requires you to collect specific data
- Health insurance regulations require data from you for settlement purposes
This basis allows you to collect: PESEL, medical history, diagnosis descriptions, treatment data.
Basis 2: Art. 9 GDPR -- Exception for health data
If you collect a special category of data (health information), you additionally need an exception permitting the processing of this data. In physiotherapy this is:
- Art. 9(2)(h) GDPR -- the "medical exception": you may process health data if it's necessary for medical/therapeutic purposes
- This means: you can collect information about diagnoses, pain, treatment, only if it's necessary for therapy
These two bases together give you the right to process patient data -- but conditionally. The patient must know you're collecting their data, and must give consent (where required).
The 7 GDPR documents you need to have in your practice
In practice, these 7 documents should be at your practice (on paper or electronically). Here they are:
Document 1: Privacy notice
This is a short text you give the patient before or during their first visit. It tells them:
- Who collects the data: you, [name, surname], physiotherapist, practice address
- What data you collect: PESEL, medical history, diagnosis descriptions, contact details
- For what purpose: therapy, NFZ settlement (if applicable), archiving
- How long you keep it: 20 years from the last entry (per the Ministry of Health Regulation)
- What rights they have: right to access, correct, delete (within legal limits)
- Your data protection officer's (DPO) details: only if you've appointed one -- a small or medium-sized practice generally has no such obligation (Art. 37 GDPR requires a DPO only where large-scale processing of health data is the core activity, and under EU guidance an individual medical practice does not count as "large scale")
The notice should be short and understandable, not 10 pages of legal text. The patient should be able to read it in 2 minutes.
[SP] Example -- Solo practice:
You work alone. Your privacy notice is one A5 page (half an A4) in a frame next to your desk, which the patient reads while waiting. At the bottom they sign to confirm they've read it.
[GR] Example -- Group practice:
You have three staff members plus two physiotherapists. The notice is the same for all patients. It's worth designating someone to coordinate data protection matters at the practice -- but that's not the same as a formal DPO, which a small group practice usually doesn't have to appoint. If you do decide to appoint a DPO, watch out for conflicts of interest: it shouldn't be a person who themselves decides on the purposes of processing (e.g. the owner or a manager in charge of the data). The notice is available both on paper and electronically (a QR code linking to the practice's website).
Document 2: GDPR consent form
This is the patient's explicit consent to processing their data beyond therapy. For example:
- Does the patient consent to receiving texts/emails as appointment reminders?
- Do they consent to their data being processed for statistical purposes (anonymised)?
- Do they consent to a newsletter (if you have one)?
- Do they consent to marketing contact?
For therapy itself you don't need consent -- the privacy notice is sufficient. But if you want to do anything more, you need explicit consent.
The consent form should have:
- A list of purposes
- A tick box for "Yes, I consent" or "No, I don't consent"
- The patient's signature
- Date
[SP] Example -- Solo practice:
A patient visits you for the first time. You hand them a form: "Do you consent to text reminders about appointments?" The patient ticks YES or NO. That's it. No consent = you don't send texts.
[GR] Example -- Group practice:
On the form you ask: "Would you like to receive special offers from our practice?" and "Do you consent to (anonymous) progress photos being used to showcase patient results?" Patients choose. Those who ticked NO won't appear in any photos.
Document 3: Practice privacy policy
This is a complete document describing your data protection policy. It contains:
- Who you are (the practice's contact details)
- What data you collect and for what purpose
- How long you keep it (20 years)
- Who you share it with (the NFZ, insurers, if applicable)
- How you protect it (encryption, access limited to staff, etc.)
- What rights the patient has (access, correction, deletion, portability)
- The data breach handling procedure
- The procedure for objecting to processing
The policy should be available on your website (if you have one) or on paper at the practice. The patient should be able to read it before booking.
Document 4: Register of processing activities
This is a document for you, not for the patient. It's an inventory of what you do with the data:
- What data you process (PESEL, history, diagnoses)
- For what purpose (therapy, NFZ settlement)
- How you collect it (on paper at the practice, electronically)
- Where you store it (a cabinet at the practice, a server)
- Who has access (you, staff)
- How long you keep it (20 years)
- What security measures you have
The register doesn't need to be complicated. A single-page table is enough.
[SP] Example -- Solo practice:
| Data | Purpose | Source | Retention | Security |
|------|-----|--------|-----------------|-----------------|
| PESEL, history, diagnoses | Therapy, NFZ settlement | Patient questionnaire | 20 years, locked cabinet | I hold the key |
| Phone numbers | Appointment reminder texts | Notice + consent | Until the patient withdraws | Password-protected phone |
[GR] Example -- Group practice:
| Data | Purpose | Source | Retention | Security |
|------|-----|--------|-----------------|-----------------|
| All | Therapy, settlement | Form | 20 years, electronic system | Password + encryption, backups |
| Patient emails | Newsletter (optional) | Notice + consent | Until consent is withdrawn | Secured mailbox |
Document 5: Data processing agreement
This agreement is needed if someone else processes your data -- e.g.:
- An IT company managing your electronic documentation system
- An accountant to whom you give patient data for invoicing
- A cloud backup service (e.g. OneDrive, Google Drive)
- A laboratory to which you send data for analysis (if applicable)
The processing agreement states: "I (you) entrust you (the IT provider) with processing this data, and you will protect it just as well as I would."
[SP] Example -- Solo practice:
You use a cloud-based medical app for patient documentation. The app provider = a company that should sign a processing agreement with you. Check the app's website to see if the agreement is available for download. If not -- that's a red flag. Such an app doesn't have GDPR compliance.
[GR] Example -- Group practice:
You have an electronic patient system plus an accountant who handles NFZ settlements. You need:
1. A processing agreement with the system provider
2. A processing agreement with the accountant
If you're missing either, the procedure is incomplete.
Document 6: Data breach response procedure
Sometimes it happens -- a patient loses their card, or you as a physiotherapist accidentally reveal one patient's data to another patient. This is a data breach.
When a breach occurs, you must:
- Assess the risk -- could the breach result in a risk to the rights or freedoms of the people concerned?
- Report it to UODO within 72 hours -- but only where the breach is likely to result in such a risk (Art. 33 GDPR); if the risk is unlikely, no report is required
- Notify the patient without undue delay -- only where the breach is likely to result in a high risk to their rights or freedoms (Art. 34 GDPR)
- Document every breach internally -- regardless of whether you report it to UODO: what happened, how you discovered it, what the risk assessment concluded, and what you did to fix it
The procedure describes who assesses the risk and notifies UODO (it could be you, or a representative), and what data is sent (a notification in PDF).
[SP] Example -- Solo practice:
A patient leaves their record in a taxi. You find out the next day. Immediately:
1. You document it: "Mrs Zofia's patient record with medical data was lost on 10 April 2026, found on 12 April"
2. You assess the risk: a record containing medical data was out of your control -- the risk to Mrs Zofia's rights is real, so you report the breach to UODO (the form on uodo.gov.pl) within 72 hours
3. Since health data is involved, the risk may be high -- you call Mrs Zofia and tell her what happened
This is a procedure you should have prepared in advance.
[GR] Example -- Group practice:
One of two receptionists sends information about a patient (that Marek has back pain) to another receptionist via WhatsApp -- but sends the text to a third person by mistake. This is a breach. The procedure says: "The practice manager assesses the risk; if the breach is likely to result in a risk to the patient's rights, they report it to UODO within 72 hours." Regardless of whether you report it, you document the breach in your internal register.
Document 7: Data processing authorisations + register
This document is for you and your staff. It says: "Who at the practice can view patient data?"
The register should contain:
- Employee's name
- Role (physiotherapist, receptionist, accountant)
- Which data they may view (physiotherapist: everything, receptionist: phone number and name, accountant: only invoicing data)
- Date of authorisation
- Validity period
The employee should sign to confirm they've read it and know how to protect the data.
Penalties for GDPR violations -- examples
If you ignore GDPR, you face concrete penalties:
Lower-tier fine (Art. 83(4) GDPR)
- Up to 10 million EUR (or 2% of annual turnover, whichever is higher)
- For lack of procedures, no register of processing activities, no processing agreements
Upper-tier fine (Art. 83(5) GDPR)
- Up to 20 million EUR (or 4% of annual turnover)
- For serious violations: disclosing data without a legal basis, processing without a legal basis, infringing data subjects' rights
For a solo physiotherapist
These are the statutory maximums -- in practice, UODO fines against small practices are rare and much lower (issued in PLN, proportionate to the scale of the violation and the entity's means). On top of that, however, comes civil liability if a patient sues you over disclosure of their data.
Even a "proportionate" fine plus the loss of patients' trust can destroy a small practice. That's why GDPR matters.
Differences between a solo practice and a group practice
Solo practice (SP)
- You alone collect and process data
- You don't need a data protection officer (DPO) -- under EU guidance, an individual medical practice doesn't process data "on a large scale"
- Procedures can be simpler (one person = easy oversight)
- Processing agreements -- only with those you give access to (IT provider, accountant)
Group practice (GR)
- Several people have access to the data
- A DPO is generally still not mandatory -- the obligation under Art. 37 GDPR arises only where large-scale processing of health data is the core activity (typically hospitals, large clinic networks); it's still worth designating someone to coordinate GDPR matters in the team
- Procedures must be stricter (what each person may do)
- More processing agreements (IT system, accountant, staff)
- The authorisation register must be precise
[SP] Example -- Solo practice:
You have a system: the notice on the wall, a printed patient consent form, a privacy policy on your website (if you have one), a register of processing on a sheet in the cabinet, a processing agreement with your system provider (if you use one). That's 4-5 documents. Done.
[GR] Example -- Group practice:
You have: everything above PLUS an authorisation register for every employee, a breach procedure (because more people = higher risk), someone coordinating GDPR matters in the team, staff training on how to protect data.
Frequently asked questions
Question 1: Do I need patient consent to process their medical data?
Answer: Not entirely. For therapy itself the privacy notice is enough (Art. 6(1)(c) -- legal obligation). The patient comes to you, you say "I'll be collecting your data because the law requires it of me," and that's sufficient.
But if you want to process the data for something more (texts, newsletter, photos for a portfolio) -- then you need explicit consent.
Question 2: If a patient asks me to delete their data, do I have to do it?
Answer: The patient has a right to "be forgotten" (Art. 17 GDPR), but it isn't unlimited:
- If you have a legal obligation to keep the data (e.g. documentation for 20 years) -- you can't delete it
- If the patient changes their mind in a year and wants access to their history -- but you've already deleted the data, that's a problem
You might want to tell the patient: "I can anonymise your data (remove your name/surname), but the medical documentation must be kept for 20 years under the law."
Question 3: What if I back up patient data to Google Drive?
Answer: The transfer of data to the USA is no longer the problem in itself -- since July 2023 the European Commission's adequacy decision (the EU-US Data Privacy Framework) has been in force, so transfers to certified providers such as Google are lawful. The real requirement is different:
- Use the business version (Google Workspace), not a personal account -- only then does Google enter into a data processing agreement (DPA) with you
- Configure access properly: a strong password, two-step verification, access limited to authorised staff
- Additionally encrypting files before uploading (e.g. password-protected 7-Zip) is good practice for medical data
You may not simply "dump" patient data into a personal Google Drive account without a processing agreement and safeguards.
CTA: See FizjoReady packages →
GDPR isn't simple, but it's an essential part of running a practice. The FizjoReady FULL COMPLIANCE package (799 PLN) includes all 7 GDPR documents ready to sign: a privacy notice, consent form, privacy policy, register of processing activities, processing agreement, breach procedure and authorisations. All tailored to physiotherapy. Check out the FULL package
Related articles:
- Medical documentation in physiotherapy -- what's mandatory
- How to correctly keep a patient record in physiotherapy
- 7 compliance mistakes in a physiotherapy practice and how to avoid them