This briefing is general guidance, current at the time of writing. It is not legal or compliance advice. CQC registration and the exact rules that apply depend on your regulated activities, so verify with your DPO, your professional body, or the CQC before you rely on it.
There are two questions a clinic website has to answer at once, and they pull in opposite directions. The first is a transparency duty: what must we publish so patients and the regulator can see how we perform? The second is a confidentiality duty: what must we never publish, because it belongs to a patient and not to the practice? A CQC-ready website gets both right. Many get the first half-right and the second badly wrong.
First, does CQC even apply to you?
Registration is triggered by carrying on a regulated activity, not by calling yourself a clinic. The regulated activities are listed in the Health and Social Care Act 2008 regulations, and for most clinics the relevant one is “treatment of disease, disorder or injury”, or “surgical procedures”. If your clinic carries on a regulated activity, you must register with the CQC. If none of your services is a regulated activity, you do not, and the display-of-ratings duty below does not apply to you.
This distinction is sharper than most cosmetic and aesthetic practices assume. As the position currently stands, surgical procedures and treatment by a healthcare professional are regulated, while a number of non-surgical cosmetic treatments, such as anti-wrinkle injections, dermal fillers, chemical peels, and laser hair removal offered on a purely cosmetic basis, sit outside CQC registration. Note the word “currently”: this area is under active reform, with separate licensing proposals for non-surgical cosmetic procedures in England, so treat “outside CQC registration” as the present position rather than a permanent one, and re-check it against the CQC scope-of-registration guidance. A clinic that is exempt for one service must still check whether any other service it offers is a regulated activity.
If you are registered, the publish-this duties below apply.
What you must publish: Regulation 20A, display of ratings
Once the CQC has rated your service, Regulation 20A of the 2014 regulations requires the rating to be displayed, and it is explicit that a website is in scope. The regulation says that on every website maintained by or on behalf of the provider there must be shown:
“(a) the Commission’s website address, (b) the place on the Commission’s website where the most recent assessment of the service provider’s overall performance … may be accessed, and (c) the most recent rating … in a way which makes it clear to which activities or premises a particular rating relates.”
Unpacked, that is three separate things on your site, not one:
- The rating itself (Outstanding, Good, Requires improvement, or Inadequate), shown clearly and mapped to the right service or location.
- The CQC website address.
- A link to where the CQC assessment can be accessed on the CQC site.
Two practical points. The duty applies where, and to the extent that, you have received a rating; a newly registered service awaiting its first inspection displays what it has. And when a rating changes, the updated rating must go up promptly. CQC’s guidance sets an expectation of display within 21 days of publication. The CQC provides a ratings widget you can embed, which is a convenient way to satisfy the requirement, but using the widget is recommended rather than mandatory; if you do not use it, your site must still carry the three elements above.
Breach of the display duty is enforceable, and CQC can move to prosecution, so this is not a soft nicety. It is a named legal requirement with your website explicitly inside it.
What the duty of candour adds
Regulation 20, the duty of candour, is not primarily a website rule, but it shapes the tone a CQC-ready site should strike. It requires registered persons to be open and transparent, and, when a notifiable safety incident occurs, to tell the affected person, apologise, and provide truthful information and support. Apologising is expressly not an admission of legal liability.
For the website, candour translates into two things: a genuine, easy-to-find complaints and feedback route, and copy that does not overclaim. A site that promises guaranteed outcomes sits awkwardly next to a duty built on openness about when things go wrong. A CQC-ready site makes it simple to raise a concern and is honest about what the service does and does not do.
What you must keep private: and why it is not a CQC rule
Here is the point that trips clinics up. The pressure to publish patient stories, testimonials, and before-and-after photographs is a marketing instinct, and nothing in the CQC regime requires any of it. CQC’s transparency duties are about the practice’s performance, not about exposing patients. In fact CQC’s own guidance points providers to UK GDPR, the Data Protection Act 2018, and the ICO for how to handle personal information, and states plainly that CQC does not directly assess GDPR compliance. So the limit on what you publish about patients does not come from CQC at all. It comes from UK GDPR and the common-law duty of confidentiality.
Under UK GDPR, anything that reveals a person’s health status is special-category data (Article 9). A testimonial that names a patient and their treatment reveals health status. A before-and-after photograph reveals it more vividly still. Publishing that content is processing special-category data for a marketing purpose, and for marketing the realistic lawful route is explicit consent under Article 9(2)(a): a specific, affirmative, documented statement, freely given, and capable of being withdrawn. On top of that sits the common-law duty of confidentiality a clinician owes the patient, which is a separate obligation from data-protection law.
Consent that is genuine and withdrawable is a high bar, and it is easy to get wrong:
- A consent buried in a treatment-form signature is not specific consent to marketing publication.
- Consent that cannot be withdrawn, so the photo stays up after the patient asks for it to come down, is not valid consent.
- A testimonial anonymised so thinly that the person is still identifiable to their own community is still their data.
The CQC-Ready Publishing Line
Custodiance builds every clinic estate to a single dividing line: publish what the regulator requires and what is genuinely the practice’s own; keep private anything that belongs to a patient.
The CQC-Ready Publishing Line. On the publish side sits everything about the practice: the CQC rating and link under Regulation 20A, the services offered, the clinicians’ professional credentials and registrations, fees where you choose to show them, the complaints route, and the compliance pages (privacy notice, cookies, security contact). On the keep-private side sits everything that reveals a patient: named testimonials, before-and-after images, case stories, and any content from which a patient could be identified, unless you hold specific, documented, withdrawable explicit consent and have satisfied the duty of confidentiality. When in doubt, a field or a page belongs on the private side.
The line is easy to apply and it resolves almost every real case. The rating goes up because the law requires it. The patient photo stays down unless a genuine, withdrawable consent exists, because the law of confidentiality and special-category data requires that.
A CQC-ready website checklist
Publish:
- The CQC rating, the CQC website address, and a link to the assessment (Regulation 20A), mapped to the right service or premises.
- Clear, honest descriptions of the regulated activities you provide.
- Clinicians’ names, roles, and professional-body registration numbers (GMC, GDC, HCPC, NMC as applicable).
- An accessible complaints and feedback route, in the spirit of the duty of candour.
- A current privacy notice, a cookies page, and a security contact.
Keep private, unless you hold specific, documented, withdrawable consent and have met the duty of confidentiality:
- Named patient testimonials and reviews that reveal treatment.
- Before-and-after photographs of identifiable patients.
- Case studies or stories from which a patient could be identified.
- Any patient document, image, or identifier.
Never do:
- Reuse a patient photo or story beyond the specific consent given.
- Leave a testimonial up after the patient has asked for it to come down.
- Treat a treatment-consent signature as consent to marketing publication.
How a regulated-grade estate handles this
Custodiance runs a clinic’s web estate as a managed, in-jurisdiction service, so the publishing line is built into the site and maintained, not left to whoever last edited a page. In practice that means:
- The Regulation 20A rating block placed correctly and kept current as ratings change, with the CQC link intact.
- A consent-gated route for any patient-derived content, so a testimonial or image cannot be published without the documented explicit consent on file, and can be removed cleanly when consent is withdrawn.
- The compliance pages (privacy notice structured to Article 30, cookies, security contact) present and carrying explicit last-updated dates.
- The whole estate kept in UK and EU jurisdiction, so the special-category content that does exist is not routed through infrastructure the practice cannot account for. The residency detail is in the clinic GDPR briefing.
This is the floor of a Growth engagement (£1,495/mo). Where a practice runs multiple sites or wants a fractional CTO owning the compliance posture, that is an Embedded engagement (from £6,000/mo, bespoke).
Frequently asked questions
Do we have to show our CQC rating on our website?
If you are CQC-registered and have been rated, yes. Regulation 20A requires the most recent rating to be displayed on every website you maintain, along with the CQC website address and a link to where the assessment can be accessed. The CQC ratings widget is a convenient way to do it but is not compulsory; without it, your site must still carry those three elements, mapped clearly to the right service.
Can we publish patient testimonials and before-and-after photos?
Only with care. Nothing in the CQC regime requires them, and they are special-category health data under UK GDPR. Publishing them for marketing needs explicit, specific, documented consent that the patient can withdraw, and you must also satisfy the common-law duty of confidentiality. A consent that is vague, bundled into a treatment form, or impossible to withdraw does not meet the bar. Many clinics decide the risk is not worth it and market on their services and credentials instead.
Is our website’s data handling something CQC will inspect?
Indirectly. CQC uses data-security assurance as evidence within its well-led assessment, but it says plainly that it does not directly assess GDPR compliance or make detailed technical assessments of data security. Your data-protection duties are enforced by the ICO under UK GDPR and the Data Protection Act 2018. So a CQC-ready website is really two things at once: CQC-compliant on the publish side, and ICO-compliant on the keep-private side.
We only do cosmetic injectables. Does any of this apply?
It depends on your specific services and can change. As the position currently stands, purely cosmetic non-surgical treatments such as anti-wrinkle injections and dermal fillers sit outside CQC registration, so the Regulation 20A duty would not apply. But this area is under active reform, and any service that crosses into a regulated activity brings registration with it. Your UK GDPR duties on patient data apply regardless of CQC status. Check your position against the current CQC scope-of-registration guidance.
Where this fits
The confidentiality side of this is the same special-category question set out in health data on your clinic website, and the residency side is why your UK clinic’s website probably breaks GDPR. If NHS work is involved, the DSPT decision guide and the DSPT website-side checklist apply. The booking-specific rules are in online booking for clinics without breaking data rules. The published posture behind all of it, including the documented sub-processor list and the in-jurisdiction sovereignty position, is the Custodiance framework, and the overview for practices is Custodiance for clinics. When a clinic is ready, the next step is to request a scoping call.
Sources & methodology
Regulatory text is quoted from the primary sources below. The point that CQC does not directly assess data protection is taken from CQC’s own personal-information guidance; the confidentiality limits on publishing patient content are UK GDPR and common law, not CQC rules.
- Regulation 20A - Requirement as to display of performance assessments - legislation.gov.uk - https://www.legislation.gov.uk/uksi/2014/2936/regulation/20A
- Regulation 20 - Duty of candour - legislation.gov.uk - https://www.legislation.gov.uk/uksi/2014/2936/regulation/20
- The fundamental standards - Care Quality Commission - https://www.cqc.org.uk/about-us/fundamental-standards
- Scope of registration: regulated activities - Care Quality Commission - https://www.cqc.org.uk/guidance-providers/scope-registration-regulated-activities
- Check the way you handle personal information meets the right standards - Care Quality Commission - https://www.cqc.org.uk/guidance-providers/all-services/check-way-you-handle-personal-information-meets-right-standards-0
- What is special category data? - Information Commissioner’s Office - https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-is-special-category-data/
- Methodology: primary CQC regulations and CQC scope and personal-information guidance, read against UK GDPR special-category rules. The cosmetic-registration position is current and under reform. General guidance, not legal advice. Last updated 3 July 2026.