ICO / UK GDPR · Clinics

Health data on your clinic website: UK GDPR special-category rules in plain English

By Jordan Gilbert

In brief

The moment a patient names a condition in your enquiry form, you are processing special-category health data, and UK GDPR Article 9 raises the bar. You need two things at once: an Article 6 lawful basis and a separate Article 9 condition. For care delivery that condition is usually 9(2)(h) health or social care, not consent. For a newsletter it is consent, plus a PECR opt-in. The practical rule for a website is to collect less: a name, a contact detail, and a way to arrange a proper conversation, not a symptom history typed into a public form.

This briefing is general guidance, current at the time of writing. It is not legal or data-protection advice. Verify anything load-bearing with your DPO, your professional body, or the ICO before you rely on it.

A patient fills in the contact form on a clinic website. In the message box they write: “I have been getting migraines and my GP suggested I ask about your neurology service.” The form has done its job. It has also just collected special-category health data, and the rules that now apply are stricter than most agency-built forms were ever designed for.

This is the plain-English version of what UK GDPR requires of a clinic website that touches health data, why the obvious answer (ask for consent) is usually the wrong one, and what a form should quietly stop collecting.

What counts as health data

UK GDPR defines it broadly. Article 4(15) says “data concerning health” means:

“personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.”

Read that carefully. It is not only a diagnosis. It is anything that reveals health status. The fact that someone is a patient of a fertility clinic, a mental-health service, or an addiction service is health data on its own, before a single symptom is named. A mailing list of “our patients” is a list of health data. So is a testimonial that identifies the treatment someone received.

Health data is one of the “special categories” under UK GDPR Article 9. Article 9(1) starts from a position of prohibition:

“Processing of personal data revealing racial or ethnic origin … genetic data, biometric data … data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.”

That prohibition is then lifted only where one of the Article 9(2) conditions applies. The bar is the point: you begin from “not allowed” and have to earn your way to “allowed”.

The two-part test almost everyone gets half-right

To process health data lawfully you need two things at the same time, and they are separate questions:

  1. An Article 6 lawful basis - the same requirement as for any personal data (consent, contract, legitimate interests, legal obligation, public task, vital interests).
  2. A separate Article 9 condition - the extra key that unlocks the special-category prohibition.

The ICO is explicit that you need both, and that they do not have to be the same choice or linked to each other. A clinic that has thought about Article 6 but never identified an Article 9 condition has done half the job, and the missing half is the half that matters for health data.

The instinct is to reach for consent. For actual care delivery, the ICO’s guidance points the other way. Consent has to be freely given, and it “will not usually be appropriate if there is a clear imbalance of power” between the organisation and the individual. A patient who needs treatment is not in a position to freely refuse the data processing that treatment requires. You also cannot make care conditional on a data-processing consent and still call that consent freely given.

So for the provision of care, the condition that usually fits is Article 9(2)(h), health or social care:

“processing is necessary for the purposes of … medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services …”

Two things ride along with 9(2)(h) and are easy to miss:

  • It needs a basis in law. In the UK that means you must also meet a condition in Schedule 1 of the Data Protection Act 2018, specifically Part 1 paragraph 2 (health or social care purposes). The ICO also advises that in many special-category cases you should have an appropriate policy document in place setting out how you comply. Treat that as expected practice, not an optional extra.
  • It has a confidentiality gate. Under Article 9(3) and section 11 of the Data Protection Act 2018, processing under 9(2)(h) must be by, or under the responsibility of, a health or social-work professional owing a duty of confidentiality, or another person under an equivalent obligation. In plain terms: patient health data cannot be routed through a tool, or a person, that sits outside that duty of confidentiality.

Consent is not banished from the clinic website. It is the correct basis in exactly the place people forget to use it properly: marketing.

If you send a newsletter, an appointment-reminder marketing message, or a “our new physiotherapist starts in September” email, you are in marketing territory, and two rules stack up:

  • PECR (the Privacy and Electronic Communications Regulations) says you must not send marketing emails or texts to individuals without their consent - a clear, specific, positive opt-in that names your clinic and the type of message. A pre-ticked box is not consent.
  • Because you are marketing to people who are, by definition, your patients, the mailing itself reveals health status, so you are back in special-category territory. In practice that means the opt-in needs to be explicit consent under Article 9(2)(a), which the ICO treats as a higher standard than ordinary consent: an express statement, oral or written, that specifies the nature of the data.

The upshot is simple to state and often ignored: a patient newsletter needs a genuine, explicit, separate opt-in. It cannot be bundled into a booking, and it cannot be assumed because someone is a patient.

The Health-Data Minimisation Test

The strongest control on a clinic website is not a longer privacy notice. It is collecting less. Custodiance applies a four-question test to every field on every clinic form.

The Health-Data Minimisation Test. For each field a patient can fill in: (1) Does the clinic genuinely need this to respond, or is it convenience? (2) Could answering it reveal a condition, a service, or a health status? (3) If it were disclosed to a party the clinic never named, would that harm the patient? (4) Is there a lower-data way to get the same outcome, such as arranging a call rather than capturing a history? A field that fails questions two and three and passes question four should not be on a public web form.

Run it against a typical “tell us about your symptoms” box and it fails immediately. The clinic does not need a symptom history to book a first appointment. It needs a name, a way to make contact, and a route to a proper, confidential conversation.

What a clinic website form should and should not collect

Reasonable to collect on a public form:

  • Name and a single contact method (email or phone).
  • The service the person is enquiring about, kept general (for example “physiotherapy” rather than a free-text symptom account).
  • Preferred contact time or method.
  • An explicit, separate marketing opt-in, unticked by default.

Should not be collected on a public web form:

  • Free-text symptom or diagnosis histories. Provide a callback instead.
  • NHS numbers, dates of birth, or ID document details at the enquiry stage.
  • Anything that names another identifiable person’s health (for example a child or relative) without a clear, lawful reason and route.
  • Uploaded medical documents or images to a general contact form, unless the upload path is built for special-category data end to end.

None of this makes the clinic harder to contact. It moves the sensitive part of the conversation off the public form and into a channel built to hold it.

How a regulated-grade estate handles this

Custodiance runs a clinic’s web and email estate as a managed, in-jurisdiction service, so the two-part test is engineered into the forms rather than left to a privacy notice nobody reads. The controls that carry the special-category duty:

  • Forms designed to the minimisation test. Each field justified, symptom free-text replaced by a callback route, marketing opt-in kept explicit and separate.
  • A lawful-basis and retention block under every form, naming where the enquiry lands, how long it is kept, and the right to complain to the ICO.
  • An enquiry path that stays in jurisdiction and inside the confidentiality gate, so 9(2)(h) processing is not routed through a tool that sits outside a duty of confidentiality. The residency detail sits in the clinic GDPR briefing.
  • A privacy notice structured by Article 30 fields and an appropriate policy document, kept current, so the clinic can evidence its Article 9 condition on request.

This is the floor of a Growth engagement (£1,495/mo). Where a practice runs online booking, multiple sites, or wants a fractional CTO owning the compliance posture, that is an Embedded engagement (from £6,000/mo, bespoke).

Frequently asked questions

Is a patient’s name and email on its own health data?

Not by itself. A name and email in isolation are ordinary personal data. They become health data the moment they are combined with something that reveals health status, and on a clinic website that combination happens fast. A name on a fertility-clinic mailing list reveals a health status; a name attached to “enquiry about our addiction service” reveals one. Treat the context, not just the field, as the deciding factor.

No, and this is the most common mistake. Consent is the wrong basis for care delivery because of the imbalance of power, so a checkbox does not fix an enquiry about treatment. Consent is the right basis for marketing, but there it has to be an explicit, separate, unticked opt-in, not a bundled box. A single “I agree” checkbox usually satisfies neither case cleanly. The better fix is to collect less and route the sensitive conversation off the public form.

What lawful basis should we actually use for a booking enquiry?

For handling an enquiry that is part of arranging care, the Article 9 condition is usually 9(2)(h) health or social care, supported by the Data Protection Act 2018 Schedule 1 condition and an appropriate policy document, and processed inside a duty of confidentiality. Your Article 6 basis is commonly legitimate interests or steps toward a contract. This is exactly the kind of decision to confirm with your DPO, because the right pairing depends on your specific service and how the enquiry is handled.

Does this apply to a purely private clinic with no NHS work?

Yes. UK GDPR and the ICO regime apply to every organisation processing personal data in the UK, whether or not it does any NHS work. Being wholly private changes some things (the NHS Data Security and Protection Toolkit may not be mandatory, covered in the DSPT briefing), but it does not lower the Article 9 bar. Special-category health data is special-category health data regardless of who pays for the treatment.

Where this fits

The residency side of the same problem, where patient data physically lives and who can reach it, is set out in why your UK clinic’s website probably breaks GDPR. The NHS-facing checklist is the DSPT website-side checklist, and the DSPT decision guide is does your private clinic need the DSPT. The transparency-versus-privacy balance for published pages is covered in the CQC-ready clinic website briefing, and the booking-specific rules in online booking for clinics without breaking data rules. The published posture behind all of it, including the documented sub-processor list and the in-jurisdiction sovereignty position, is the Custodiance framework. The overview for practices is Custodiance for clinics. When a clinic is ready, the next step is to request a scoping call.

Sources & methodology

Regulatory text is quoted from the primary sources below. Where an ICO page is cited, the point is drawn from the ICO’s published special-category, consent, and PECR guidance.

Custody, not marketing.

Have a senior partner read your estate against this.

A scoping call is a measured conversation about your obligations, your current setup, and what it would take to run it to your regulator's standard. No obligation, and no pressure.

Request a scoping call More briefings