GDPR & Data Protection

Your Practice Website and GDPR - Privacy Policy and Cookies

Author:

Michał built a nice website for his practice with a "Book an appointment online" form. Patients entered their name, phone number, email, and sometimes a…

Michał built a nice website for his practice with a "Book an appointment online" form. Patients entered their name, phone number, email, and sometimes a description of their complaint. The website had no privacy policy or cookie banner, and the form contained no information clause whatsoever. It only took one complaint from a dissatisfied patient to the Polish Data Protection Authority (UODO) for Michał to have to explain the legal basis on which he was processing data and why nobody had been informed of anything.

A practice website isn't just a business card -- it's a tool that collects personal data, often special category data (health data). In this article, we'll show you how to bring your website into line with the GDPR (General Data Protection Regulation): privacy policy, cookie banner, forms and newsletter, so you can avoid problems.

Why is a practice website subject to the GDPR?

The GDPR (EU Regulation 2016/679) applies whenever you process personal data. A practice website does this in several ways:

  • contact / booking form -- name, phone number, email
  • description of complaints -- this is health data, i.e. a special category of data (Article 9 GDPR)
  • cookies and analytics tools -- identifiers, IP addresses
  • newsletter -- email addresses
  • chat / messenger -- content of conversations

As the data controller, you're responsible for GDPR compliance, including fulfilling the information obligation (Article 13) and ensuring data security.

Privacy policy -- a mandatory element

A privacy policy is a document that fulfils the information obligation. It must include:

  • the identity and contact details of the controller (your practice)
  • the purposes and legal bases for processing
  • the categories of data processed
  • the recipients of the data (e.g. the booking system provider, hosting)
  • the data retention period
  • the data subject's rights (access, rectification, erasure, objection, portability)
  • information about the right to lodge a complaint with the President of UODO
  • information about profiling and cookies

The policy should be easily accessible from every subpage (usually via the footer).

Situation GDPR legal basis
Contact formlegitimate interest / steps prior to entering into a contract
Appointment booking (health data)consent or the provision of healthcare (Article 9(2) GDPR)
Marketing newsletterconsent
Analytics and marketing cookiesconsent
Cookies necessary for the website to functionlegitimate interest

Key point: don't collect health data in the form unless it's necessary. A name and contact details are enough -- you can discuss the details of the complaint during the visit.

Contrary to popular practice, a simple "This website uses cookies. OK" banner isn't sufficient. Under the GDPR and Article 399 of the Polish Electronic Communications Law (PKE, in force since 10 November 2024), a cookie banner should:

  • inform users about the types of cookies used (necessary, analytics, marketing)
  • allow consent and refusal on equal terms (a "Reject" button equal in prominence to "Accept")
  • not set any cookies other than necessary ones before consent is obtained
  • allow the user to change their decision later (cookie settings)

Cookies necessary for the website to function don't require consent, but analytics (e.g. statistics) and marketing cookies do.

Forms -- information clause and consents

Every form that collects data should have:

  • an information clause (a short version, with a link to the full policy)
  • consent checkboxes wherever consent is the legal basis (e.g. newsletter) -- unchecked by default
  • separated consents (contact consent kept separate from marketing consent)

Consent must be freely given, specific, informed, and unambiguous. You can't make booking an appointment conditional on marketing consent -- that breaches the principle of freely given consent.

CTA: Don't have a privacy policy or a proper cookie banner? The FizjoReady STANDARD package includes a privacy policy template for your practice, information clauses for forms, and a website GDPR compliance checklist. Deploy ready-made documents instead of writing them from scratch. See FizjoReady packages →

Newsletter and email marketing

Sending a newsletter requires consent to marketing communication (GDPR) as well as consent to receiving commercial information by electronic means -- since 10 November 2024 this is governed by Article 398 of the Polish Electronic Communications Law (PKE), which replaced the former telecommunications law and the act on providing services electronically in this respect. Make sure you have:

  • newsletter sign-up with separate, freely given consent
  • an easy way to unsubscribe (a link in every message)
  • a consent register (who consented, when, and to what)

Data processing agreements with providers

If you use external tools (a booking system, hosting, email marketing, chat), you're passing patient data to them. This requires a data processing agreement (Article 28 GDPR). Without one, you're responsible for a gap in your data protection system. Many providers make ready-made templates for such agreements available for you to accept.

Website security

Since your website collects data, including potentially health data, make sure you have:

  • an SSL certificate (https) -- the absolute minimum
  • up-to-date software (CMS, plugins)
  • strong passwords and restricted access to the admin panel
  • backups
  • protection of forms against spam and data leaks

Analytics tools and advertising pixels

Many practices install analytics tools (visit statistics) and advertising pixels (e.g. for social media campaigns) on their website. Such scripts process identifiers and IP addresses, so they require user consent obtained via the cookie banner. They must not be run before a visitor has given consent to marketing and analytics cookies. In your privacy policy, list which tools you use and for what purpose. If a tool provider transfers data outside the European Economic Area, check whether appropriate transfer mechanisms are in place -- this is something both users and supervisory authorities increasingly ask about.

The most common mistakes on a practice website

  • no privacy policy, or one that isn't accessible from the footer
  • a cookie banner with no real option to refuse
  • running analytics and pixels before consent is obtained
  • collecting health data in a form without an appropriate legal basis

Frequently asked questions

Does a small practice really need a privacy policy on its website?

Yes. The GDPR doesn't exempt small entities from the information obligation. If your website collects any data at all (even just through a contact form or analytics cookies), you must have a privacy policy and fulfil the information obligation. The size of the practice makes no difference here.

Is a "This website uses cookies. OK" banner enough?

No. Such a banner doesn't meet GDPR requirements, because it doesn't offer a real choice. A proper banner allows both acceptance and refusal of non-necessary cookies on equal terms, and doesn't set them before consent is obtained. It should also allow the user to change their decision at any time.

Can I collect a description of complaints in the booking form?

You can, but this is health data -- a special category requiring particular care and an appropriate legal basis. It's safest to limit the form to a name and contact details, and discuss the details during the visit. If you do collect such data, make sure you have an appropriate clause, a legal basis, and a high level of security.

Do I need an agreement with my hosting provider and booking system?

Yes. If an external provider processes patient data on your behalf (hosting, booking system, email marketing), you need a data processing agreement in line with Article 28 GDPR. Many providers have ready-made templates. Without such an agreement, you're responsible for the lack of proper safeguards in the processing chain.


CTA: Want a GDPR-compliant website without writing documents from scratch? The FizjoReady STANDARD package is a privacy policy, clauses and a checklist in a single file. See FizjoReady packages →

Related articles:
- GDPR in a physiotherapy practice
- Physiotherapy practice marketing and the law
- Medical records in physiotherapy

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.