Staff Authorization to Process Personal Data - Who, When, How

Who at a physiotherapy practice needs written authorization to process personal data, how it differs from a data processing agreement, and how to keep a register of authorized persons under GDPR Article 29.
Krzysztof hired a new receptionist. On her first day, he showed her the patient booking system, handed over a password, and said "just enter appointments, you'll pick up the rest as you go." From her very first hour, the receptionist had access to patients' names, phone numbers, and fragments of visit history -- without a single signed document. A month later, when a lawyer friend asked him whether he had authorizations in place for his staff, Krzysztof replied: "she's not a physiotherapist, so why would she need one? Only the therapists see the data."
That assumption is one of the most common GDPR violations at physiotherapy practices. Authorization to process personal data is not a privilege or a formality reserved for people practicing a medical profession -- it applies to anyone who has actual access to patient data, regardless of job title. In this article we explain who at a practice needs an authorization, how it differs from a data processing agreement, what it must contain, and how to keep a register of authorized persons.
Who at a practice needs authorization to process data
The legal basis for this obligation is Article 29 of the GDPR, which states that a person acting under the authority of the controller or the processor, who has access to personal data, may process it only on instructions from the controller. In practice, this means one thing: anyone who has even occasional access to patients' personal data as part of their duties must have written authorization -- regardless of whether they work under an employment contract, a civil-law contract, or as an intern.
At a typical physiotherapy practice, the circle of people requiring authorization is broader than it may seem:
- Physiotherapists -- the obvious case: full access to medical records and patients' health data.
- Receptionist -- sees names, phone numbers, appointment schedules, and often the type of condition when booking a visit.
- Intern or trainee -- even if their access is limited in time and scope, simply looking at a patient's record under a supervisor's guidance requires authorization issued before the internship begins.
- Cleaning staff -- in principle they shouldn't need access to data, but if they clean the reception area where printed patient records are left out, or have access to an unlocked computer, the risk of access is real and should either be formally regulated or eliminated by changing how work is organized.
- Accountant or accounting firm -- this one is two-track. If the accountant only sees anonymized amounts and invoice numbers, they may not need authorization under Article 29 at all, just a separate data processing agreement (see below). But if they have access to patients' personal data beyond mere figures -- e.g. itemized billing by name -- the situation requires a careful look at the actual scope of their access.
The key question is always: does this person HAVE ACCESS to personal data, not: are they a physiotherapist. We cover the broader picture of GDPR implementation at a practice in GDPR at a physiotherapy practice, and staffing-related topics in Hiring a physiotherapist -- contract and qualifications.
Authorization vs. data processing agreement -- which one applies when
This is one of the most common sources of confusion. Both documents concern the lawful processing of data by people other than the controller itself, but they apply to entirely different relationships.
| Criterion | Authorization (GDPR Art. 29) | Data processing agreement (GDPR Art. 28) |
|---|---|---|
| Who it covers | People acting under the controller's direct supervision | Separate external entities |
| Example | Receptionist, physiotherapist, intern under contract with the practice | Accounting firm, software provider, IT company |
| Legal form | A one-sided document issued by the controller | A two-party agreement between controller and processor |
| Relationship | Internal, within the practice's own structure | External, between two separate entities |
| When to issue | Before the person is given access to data | Before starting cooperation with the supplier |
In other words: if a person works "under your wing", as part of your own team, and follows instructions within the practice's structure -- they need authorization. If, on the other hand, it's a separate entity that organizes its own work independently and processes data as part of its own business -- you need a data processing agreement with them. We cover agreements with external suppliers in detail in Data processing agreement -- who a physiotherapist must sign one with. Borderline cases do occur -- e.g. a physiotherapist working under a B2B contract -- in which case it's worth individually assessing whether the actual nature of the cooperation is closer to employment (authorization) or to an independent entity (processing agreement).
What an authorization must contain -- mandatory elements
The GDPR doesn't impose a rigid template for authorizations, but practice and supervisory guidance point to several elements without which the document doesn't fulfill its purpose.
Scope of authorization
The document must precisely specify which categories of data the person may process (e.g. identification data, health data, contact data) and which operations they may perform on them (e.g. viewing, entering, editing, sharing as part of patient service). An overly general phrase like "authorized to process personal data" without defining scope is a weak point during an inspection -- the authorization should genuinely reflect what that person actually has access to in their role.
Confidentiality commitment
The authorized person must be bound to keep the data confidential, including after their employment or cooperation ends. This can be part of the authorization itself or a separate confidentiality statement signed alongside it -- both approaches are acceptable, as long as the document actually exists and is signed.
Validity period
The authorization should state the period for which it's issued -- usually for the duration of employment or cooperation, expiring automatically when that ends. For interns or trainees, it's worth limiting the period to the actual duration of the internship.
Date and signature
The document must bear the date it was issued and the signature of the controller (or a person authorized by the controller to issue authorizations), as well as the signature of the authorized person confirming they've read and understood its content.
[SP] Example -- Solo practice: Ewa runs a one-person practice and hires a part-time receptionist. Before her first day, Ewa prepares a short authorization specifying the scope of access (patients' contact and scheduling data, without access to full medical records) plus a separate confidentiality statement. They sign both together before the receptionist gets her login to the system.
[GR] Example -- Group practice: At a practice employing eight physiotherapists and two receptionists, the owner notices that one therapist left six months ago, but his authorization was never formally revoked -- on paper, he's still listed as an authorized person. She introduces a procedure: every new hire gets an authorization issued before their first day of work, and every departure triggers immediate revocation of the authorization, logged in the register the same day.
Register of authorized persons
Issuing authorizations isn't the end of the obligation -- the controller should keep a register of persons authorized to process personal data. Such a register is typically a simple list containing the person's name, the scope of their authorization, the date it was granted, and (where applicable) the date it was revoked.
The register matters especially during staff turnover, which is not uncommon at physiotherapy practices -- interns rotate every semester, receptionists are sometimes hired seasonally, and physiotherapists sometimes cooperate only for a fixed period. Two rules are essential here:
- A new person means a new authorization. Every new hire, even a short-term one, requires its own document -- you cannot simply "carry over" a predecessor's authorization to a new person.
- A departure means revocation. When someone stops working at the practice, their authorization should be formally revoked and their access to systems physically blocked (password change, account deactivation). Without this step, that person technically remains "authorized" even though they no longer have any connection to the practice.
A register that hasn't been updated in two years is just as problematic as having no register at all -- during a UODO inspection, a mismatch between actual staffing and the register's contents is easy to spot and treated as a sign that the practice's GDPR documentation is fictional rather than a real access-management tool.
Connection to the Patients' Rights Act
The obligation to authorize staff doesn't come from the GDPR alone. Article 24(2) of the Polish Act on Patients' Rights and the Patients' Rights Ombudsman states that the head of an entity providing healthcare services determines the manner and scope in which medical records are made available to staff for the performance of their duties. For a physiotherapy practice, this means that a formal GDPR authorization alone isn't enough -- it's worth having internal regulations or a security policy that also specifies who has access to medical records as such, and to what extent, independent of the general authorization to process personal data. At small practices these two obligations most often merge into a single document, but it's worth being aware they rest on two separate legal bases.
Onboarding a new employee -- order matters
The most common mistake practices make is treating the authorization as a formality "to sort out at some point," sometimes weeks after the person has actually started working. But the order should be reversed: the authorization must be signed BEFORE the person is given any access to data at all -- a system login, a key to the cabinet with paper records, a password to the reception computer.
A practical onboarding checklist for authorizations looks like this:
- Before the first day of work, prepare an authorization tailored to the role (reception, physiotherapist, intern).
- On the first day, before handing over logins, sign the authorization together with the confidentiality statement.
- Enter the person into the register of authorized persons with the date granted.
- Only then hand over access to the system, paper records, or rooms containing data.
- When the cooperation ends, revoke the authorization, block access, and log the revocation date in the register.
This order eliminates the most common violation scenario: a new person working "on trust" for the first few days or weeks without any formal basis for processing the data they're seeing every day regardless.
Frequently asked questions
Does cleaning staff need authorization to process data?
It depends on their actual level of access. If cleaning takes place outside reception hours and records are always secured (locked cabinet, locked computer), formal authorization usually isn't necessary. But if the cleaning staff has access to a room with unsecured data -- e.g. cleaning happens during reception hours while printed patient records are lying out -- the risk of access is real, and you should either issue an authorization or reorganize work so data is always secured before cleaning takes place.
Does an intern need authorization if they're only observing a physiotherapist's work?
Yes, if during the observation they have any access to a patient's personal data -- e.g. they see the patient record on which the therapist notes the course of the visit. An intern's authorization should be limited in time to the internship period and in scope to what they actually observe, and it should be issued before their first day, not after the fact.
What's the difference between an authorization and a confidentiality statement?
An authorization defines the scope within which a given person may process personal data -- in other words, what they're allowed to do with the data. A confidentiality statement is a commitment not to disclose that data to third parties, including after the cooperation ends. Both elements can appear in a single document or be signed separately -- the GDPR doesn't dictate the form, it only requires that both obligations actually exist and are documented.
What happens if a practice doesn't have authorizations for its staff?
Missing authorizations is a violation of GDPR Article 29, which UODO treats as an independent basis for issuing a post-inspection recommendation or, in more serious cases, an administrative fine -- regardless of whether a data leak occurred. In practice, it's one of the first things checked during an inspection of a healthcare entity, because verification is simple: just ask for a staff list and compare it against the register of authorized persons.
CTA: The PREMIUM package includes a ready-made instruction and template for staff authorization to process personal data -- just fill in the employee's details and scope of access to have a complete set of documents compliant with GDPR Article 29 for every person on your team. See FizjoReady packages →
Related articles:
- Onboarding at a physiotherapy practice -- which documents to prepare
- Hiring a physiotherapist -- contract and qualifications
- GDPR at a physiotherapy practice -- a complete guide