Privacy notice for a clinic or therapist

A privacy notice for a clinic, private practitioner or therapist, drafted for the practice with the cookie notice and consent guidance, for a fixed fee of £595 in five working days.

Share

Privacy notice for a clinic or therapist

Buy now, £595

A clinic or a therapist processes health data about everyone who walks through the door, which is special category data that most practices wrongly think they process on the basis of consent. The privacy notice has to state the health care condition that applies, explain the duty of confidence that sits alongside data protection, describe the records the practice keeps and for how long the professional body requires, deal with sharing (the GP, the insurer, the specialist, the family member the client names), cover the booking system and the reminders, and address children and clients who cannot consent for themselves. For £595, fixed, with delivery in five working days, I draft the privacy notice and the cookie notice for the business and set out how the consent mechanism should work.

Who this is for

Private clinics, physiotherapists, osteopaths, chiropractors, counsellors, psychotherapists, dentists, aesthetic practitioners, nutritionists and other health and wellbeing practitioners in England and Wales.

What matters in a clinic or therapist privacy notice

Information about a client's physical or mental health is special category data under Article 9 of the UK GDPR, and a clinic providing care processes it under Article 9(2)(h) (processing necessary for medical diagnosis, the provision of health or social care or treatment, or the management of health care systems) with the condition in Schedule 1 to the Data Protection Act 2018 for health or social care purposes, by or under the responsibility of a health professional or someone owing an equivalent duty of confidentiality, rather than under explicit consent, which can be withdrawn and which a client needing treatment cannot give freely; the lawful basis under Article 6 is the contract for the treatment under Article 6(1)(b) or legitimate interests, and the notice should state both correctly, because a notice that relies on consent for clinical records has told the client they can require the records to be deleted.

The duty of confidence that sits alongside the law

Being the controller, the business is required by Article 13 of the UK GDPR to tell clients what it does with their data, and a clinic also owes the common law duty of confidence and the professional body's confidentiality rules, which the notice should explain: that clinical information is shared only with the client's agreement, where the law requires it (safeguarding, a court order, notifiable diseases) or where the public interest justifies it, with the practitioner's professional judgement engaged; the notice should name the professional body whose rules the practitioner follows and should say where the practice is registered with the Care Quality Commission under the Health and Social Care Act 2008 for regulated activities.

Records, retention and the professional body's requirements

The notice should describe the records the practice keeps (consultation notes, assessments, treatment plans, consent forms, images, correspondence, test results), the systems they are held in, and the retention period, which for clinical records is set by the professional body's guidance and the Department of Health and Social Care's records management code rather than by the practice's convenience (commonly a period of years after the last treatment, longer for children and for certain treatments), and should say that records are not deleted on request where the retention is required, with the right to erasure limited accordingly; a practice that promises to delete records on request has promised something its professional body forbids.

Sharing with GPs, insurers, specialists and the people the client names

The notice should explain the sharing the practice carries out and the basis for each: with the client's GP or other clinicians involved in their care (with the client's agreement, or in an emergency), with private medical insurers paying for treatment (with the client's authority, and only what the claim requires), with specialists on referral, with laboratories and imaging providers, with the client's nominated contact or family member where the client has agreed, with regulators and the authorities where the law requires, and with the practice's processors (the practice management system, the booking platform, the accountants); the client should be told that the insurer and the GP are separate controllers with their own notices.

Booking systems, reminders, marketing and the practice's suppliers

The booking platform, the practice management software, the payment processor and the email and messaging tools are processors under Article 28 of the UK GDPR with agreements the practice should hold, and the notice should describe them; appointment reminders and treatment follow-ups are service messages rather than marketing, but promotions and newsletters are marketing, and email and text marketing to individuals is permitted by regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 only with consent or the soft opt-in, with the notice and the sign-up implementing whichever the practice relies on; the website's cookies and any booking widget's tracking need the consent mechanism the pack provides guidance on, under regulation 6 of those Regulations.

The notice should address children (a child with sufficient understanding may consent to treatment and to the processing that goes with it, with the practitioner assessing competence; below that the parent consents, and the records remain the child's), adults who lack capacity (where the Mental Capacity Act 2005 governs decisions in their best interests and the practice records who was involved), and clients who nominate someone to deal with the practice on their behalf; it should also cover the rights the individual has (to access, correct, erase, restrict, port and object), the way to exercise them, the month the business has to respond, and the route to the Information Commissioner's Office, and the Data Protection (Charges and Information) Regulations 2018 require registration with the Information Commissioner's Office where the fee applies, and the notice can give the number.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Consent is not needed and is the wrong basis: the health care condition applies, with the contract or legitimate interests under Article 6. Consent is for the optional things, such as marketing. The notice states the right basis so that a client cannot require clinical records to be deleted.

A client has asked us to delete all their records. Do we have to?

Not where the professional body's retention requirements apply, which for clinical records they do. The notice explains the retention and the limit on erasure, so that the request can be answered by pointing to it.

Can we share records with a client's insurer?

With the client's authority and only what the claim requires, treating the insurer as a separate controller. The notice explains the sharing and the basis.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.