Skip to main content
Close-up of a hand holding a smartphone displaying a VPN app, with a laptop in the background, emphasizing digital security.
Medical Marketing,  Healthcare Marketing

GDPR for Medical Practice Websites: What You Actually Need to Do

15 min read

Introduction

GDPR for Medical Practice Websites is more than a line on a checklist; it is the framework that governs how your site collects, uses, and protects patient information. For dental, GP, and allied-health practices, your website is often the first point of contact, and it routinely handles personal, and sometimes health‑related, details. Under UK GDPR and the Data Protection Act 2018, health information is “special category data”, which needs extra protection and a clear reason for processing. Getting this right builds trust, reduces risk, and supports good governance.

A common misconception is that publishing a privacy policy is sufficient. In reality, compliance touches the consent you ask for on forms, how tracking and cookies are set, where data goes after submission, who can access it, how long you keep it, and how you respond to rights requests. It also includes your contract terms with booking platforms and email providers, your security settings, and the way you explain choices to patients in plain English.

This guide offers practical, jargon‑free steps you can apply yourself this week.

Understanding GDPR and PECR for Medical Websites

Want this done for your practice?

We'll review your site and tell you exactly what's costing you enquiries.

UK GDPR and the Data Protection Act 2018 set the rules for how your site collects and uses personal information. As a practice, you are usually the “controller”, meaning you decide why and how data is processed. Website forms, enquiry chat, and booking tools often capture health details, which count as “special category data” and need extra protection. You must have a clear reason for processing, tell people what you do with their data, keep only what you need, and protect it with appropriate technical and organisational measures.

For UK GDPR healthcare website compliance, document your lawful basis (the legal reason to process) and, for health details, the extra Article 9 condition. Common examples in a clinical context include providing health or social care, or explicit consent for specific purposes; marketing usually relies on consent. The ICO’s guidance on special category data explains these routes and the safeguards expected. Reflect these choices in a clear privacy notice, maintain records of processing, and have written contracts with any provider handling data on your behalf.

PECR sits alongside UK GDPR and governs cookies, tracking technologies, and electronic marketing. In short, you need prior consent before setting non‑essential cookies (for example, analytics, advertising, or social media pixels). Consent must be a clear, affirmative choice; pre‑ticked boxes are not valid. The ICO’s guidance on the use of storage and access technologies sets out what counts as “strictly necessary” and what needs consent. You may see the phrase PECR cookies guidance NHS in supplier paperwork; it points to the same legal standard.

PECR also covers email and SMS. Marketing messages to individuals usually require consent and must identify your practice and include an easy way to opt out. Service messages related to a patient’s booking are different from marketing, but you should still minimise content, send securely, and respect preferences. Transparent notices, honest cookie controls that do not drop tags until chosen, and swift responses to data requests all help maintain confidence.

Good data stewardship is part of patient care. Clear language on your forms, a privacy notice that matches reality, and consent flows that are easy to understand typically build trust and reduce complaints. If you want a practical checklist to follow, our GDPR Compliance Guide for Healthcare Websites summarises the steps most practices take to get the basics right. It also helps your team answer patient questions with confidence and consistency every day.

Creating a GDPR-Compliant Privacy Notice

A clear, accurate privacy notice sets expectations and reduces complaints. It should explain, in plain English, what data you collect, why you collect it, how long you keep it, who you share it with, and the rights people have. The ICO’s guidance sets out what to include and how to write it clearly; it is the safest reference point for small practices How to write a privacy notice and what goes in it. As health information is “special category data”, you also need an appropriate condition for processing under UK GDPR, in addition to a lawful basis Special category data.

Essential elements to include:

  • Who you are, contact details, and your data protection lead or DPO contact.
  • What personal data you collect, from whom, and how (forms, phone, referrals, cookies).
  • Why you collect it (purposes), and the lawful basis for each purpose.
  • The additional condition relied on for special category data, where relevant.
  • Who you share data with (categories of recipients), and why.
  • International transfers, and the safeguards if data leaves the UK.
  • How long you keep each category of data, stated in plain timeframes.
  • People’s rights (access, rectification, erasure, restriction, objection, portability), and how to exercise them.
  • How to withdraw consent for optional communications.
  • Whether decisions are automated, and how they work in simple terms.
  • How to complain to the ICO.

Use a privacy notice layered approach healthcare model to keep it usable:

  • Layer 1: Short notices at the point of collection (e.g., under each form), covering who you are, key purposes, a link to “learn more”.
  • Layer 2: An overview page with headings and accordions for each topic.
  • Layer 3: A full, searchable policy with tables for purposes, bases, retention, and processors.

Ensure it is readable on mobile, and accessible. If you need help presenting this cleanly across your site, our team can build it into your forms and footer as part of Healthcare Website Design.

GP practice privacy notice template — example sections:

  • Purpose and basis: “We use your information to provide GP services, manage appointments, and coordinate care, relying on public task or contract, and, for health data, the provision of health or social care condition.”
  • Sharing: “We share relevant data with NHS bodies, referral services, laboratories, and IT suppliers acting under our instructions.”
  • Retention: “We keep your GP medical record for the period required by applicable rules; non-clinical enquiry data is kept for defined, shorter periods.”
  • Marketing: “We only send practice news by email or SMS with your consent, and you can opt out at any time.”

Under UK GDPR and the Privacy and Electronic Communications Regulations (PECR), you need consent before setting any non‑essential cookies or similar technologies on a visitor’s device. “Essential” covers things like basic security and items strictly required to deliver a service the visitor has requested, such as keeping a form step active; analytics, advertising, and social media scripts are not essential. Consent must be freely given, specific, informed, and unambiguous; no pre‑ticked boxes, no nudging, and a clear “reject” option equal to “accept”. People should be able to withdraw or change their choice at any time, and you should keep records of consent.

In practice: audit your site for all scripts and plugins that store or read data. Categorise them as essential, analytics, marketing, or functional, then block all but essential by default. Add a banner with accept, reject, and settings of equal prominence, plus a preference centre in your footer. Renew consent periodically, and reflect cookie use in your privacy information, covering who sets them, purposes, and retention (ICO guidance on privacy notices). The ICO’s guidance on cookies explains these points in detail, with practical examples (ICO storage and access technologies guidance).

A cookie consent management platform (CMP) is software that displays the banner, blocks scripts until consent is given, and logs choices for audit. For a cookie consent management platform healthcare teams can run without technical support, look for: prior‑consent mode, automatic blocking for common tags, easy CMS and tag manager integration, an accessible interface, and a self‑service “change preferences” link. Accessibility matters; banners and settings must be keyboard‑navigable and screen‑reader friendly. If you need a refresher, see our guide on Ensuring Your Healthcare Website Meets ICO’s Accessibility Standards.

Common tools requiring consent on medical website cookie consent UK setups include:

  • Analytics and performance tags.
  • Advertising and social media pixels, including remarketing.
  • Heatmaps and session recording.
  • Video and map embeds.
  • Live chat widgets and feedback pop‑ups.
  • A/B testing and personalisation tools.
  • Appointment widgets, survey tools, and some spam‑prevention services.

Test with a private browser window: no non‑essential cookies should load before consent. Check that “reject” truly blocks them, and that withdrawal works on every page. Review your inventory quarterly, especially after adding new integrations or changing suppliers.

Avoid cookie walls that make access conditional on consent, except where a service genuinely depends on cookies. Document decisions, and brief admin staff on queries.

Data Retention and Subject Access Requests

A clear, written data retention policy reduces risk, cuts storage costs, and shows regulators that your practice treats patient and visitor data with care. Map every place data lands: enquiry and triage forms, booking systems, clinical letters sent via the site, email inboxes, chat tools, analytics, call recordings, and backups. For each, record what you collect, why, where it is stored, who has access, the retention trigger (for example, “last appointment” or “campaign end”), and how deletion happens. Avoid keeping data “just in case”; under UK GDPR you should only hold what you need for as long as you need it, especially where it includes health information.

Build your schedule around the NHS England Records Management Code of Practice. Clinical records have statutory or recommended periods; website and marketing data usually do not, so set proportionate timeframes and stick to them. For GP surgeries, check the latest tables for the records management code GP retention schedules, and document any local departures with a reason. Make sure backups and archives are covered, so expired data is not quietly kept forever in old snapshots.

Subject Access Requests (SARs) are the rights requests where someone asks for a copy of their personal data. You normally have one month to respond, with the option to extend for complex requests. Prepare now so you can handle them without disrupting clinics:

  • Create a single route for requests (an email address or form), and signpost it in your privacy notice.
  • Log each request, the date received, the identity check you carried out, and deadlines.
  • Verify identity proportionately; do not store ID longer than necessary.
  • Scope the systems to search: website forms, booking platform, EPR or PMS, email, cloud drives, chat, analytics, and third-party processors.
  • Exclude third-party information and legally privileged notes; redact where needed.
  • Provide the data in a commonly used format and explain the sources, purposes, and retention periods.
  • Send the response securely, and record what you sent and when.

On the site, a small “subject access request GP website” page or link within your privacy notice makes life simpler for patients and staff. The ICO explains what a good privacy notice covers, including how people can exercise their rights and how long you keep data; see its guidance on writing notices (ICO privacy notices guidance). Health information is special category data, which demands stronger protection and a clear lawful basis for processing (ICO: Special category data). Align your security with practical outcomes-based advice (NCSC GDPR security outcomes), and consider using the NHS Data Security and Protection Toolkit to evidence your approach. If you would like a second pair of eyes on your retention map or SAR flow, you can book a free 20-minute website review.

Ensuring Security and Compliance with DPIAs

A Data Protection Impact Assessment (DPIA) is a structured process that helps you identify and reduce risks when your website processes personal data that could be high risk to individuals. For healthcare, that often includes special category data, such as information about health, collected through forms, bookings, or consultations. A DPIA supports UK GDPR compliance by evidencing necessity, proportionality, and safeguards, and by showing you have considered patients’ rights. It also produces a practical record of what you collect, why, who can see it, and how long you keep it.

How to run a DPIA for medical practice websites:

  1. Describe the processing. List every page, form, booking step, cookie, analytics tag, chat, and video tool involved, plus each supplier.
  2. Map data items and flows. Note every field and attachment, where each item is stored, who has access, and any transfers outside the UK.
  3. Set purposes and lawful bases, and select a special category condition where relevant. Record retention periods and controller/processor roles.
  4. Test necessity and proportionality. Could you meet the same purpose with fewer fields, less tracking, or shorter retention?
  5. Identify risks to people, not just to the practice: unauthorised access, misdirected emails/SMS, inappropriate profiling, third‑country transfers, or vendor changes.
  6. Rate likelihood and impact for each risk so you can prioritise.
  7. Define measures: encryption in transit and at rest, access controls, MFA, audit logs, data minimisation, staff training, processor contracts, and incident response.
  8. Consult stakeholders. Involve your DPO or adviser, reception and clinical leads, and your web and booking suppliers. Ask vendors for an “online consultation tool GDPR assurance” pack covering security, sub‑processors, and data location.
  9. Decide residual risk, get senior sign‑off, and schedule reviews. If risk remains high, consider consulting the ICO before going live.

Common scenarios that typically call for a DPIA include:

  • Online consultation, symptom checkers, or triage questionnaires.
  • Patient intake forms capturing health history, images, or ID.
  • Website‑embedded video, voice, or live chat used for care discussions.
  • Booking systems that collect clinical reasons and send reminders.
  • Patient portals or document upload features.
  • Behavioural tracking, remarketing, or AI chat that profiles visitors.
  • Any regular, large‑scale processing or overseas data transfer.

If you are mapping your current site and suppliers, our UK Medical Practice Website Benchmark Report 2026 can help you compare common features before you scope your DPIA. Review your DPIA annually.

Conclusion and Call to Action

Bringing GDPR for Medical Practice Websites into focus starts with a clear map: what you collect, where it goes, who sees it, and why. For each activity, record your lawful basis, note if health information is involved, and minimise fields, retention, and access. Fix tracking and cookies with genuine choice, update your privacy notice, and make sure processor contracts, data locations, and deletion terms are written down. Strengthen security with HTTPS everywhere, strong passwords, role‑based access, encryption, backups, and audit trails. Run a DPIA for higher‑risk features, keep records of processing, train staff, and rehearse how you will handle requests and breaches.

Set aside one focused hour this week to review your website, booking flows, and third‑party tools against that list. Start with the pages that collect patient details, then check cookies, your privacy notice, and processor agreements and templates. If you would like a second pair of eyes, Aethus offers a quick, no‑obligation check of the basics. Book a free 20-minute website review, and we can highlight practical next steps you can take in‑house.

Frequently Asked Questions

Do GP practices need to appoint a Data Protection Officer (DPO) under UK GDPR?

Generally, yes. If your practice processes large amounts of special category data (which includes health information), a DPO is typically required. The DPO advises on your UK GDPR obligations, monitors data protection activities, oversees training and Data Protection Impact Assessments, and acts as a contact point for the ICO and patients. The role can be in‑house or outsourced, but must be independent, with appropriate expertise. Publish the DPO’s contact details in your privacy notice and make them easy to find on your website.

What should be included in a GP practice website privacy notice?

Set out what you collect (forms, booking tools, cookies), why you collect it, and your lawful bases. Explain who you share data with (your processors), where it is stored, retention periods, and patients’ rights, including how to object or withdraw consent where relevant. Include your identity and contact details, your DPO’s details, complaints routes, and whether data leaves the UK. Keep it clear, concise, and linked in your footer on every page. See the ICO’s guidance on how to write a privacy notice and what goes in it.

Yes, you need consent for non‑essential cookies, such as analytics and marketing. Your banner should block those cookies until consent is given, and offer Accept, Reject, and granular controls. Record consent, honour it on future visits, and let patients change their choice later. The ICO explains these expectations in its guidance on the use of storage and access technologies.

How should GP practices handle Subject Access Requests (SARs) submitted via the website?

Acknowledge and respond within one month (30 days). Have a documented process: verify identity proportionately, log the request, assign an owner, gather data from all systems, and respond securely. Do not charge a fee unless the request is manifestly unfounded or excessive. Offer a web form with secure upload, but provide email and postal routes as alternatives. Keep a record of decisions and deadlines.

What is the lawful basis for processing patient data in general practice?

For direct care and most core NHS activities, the lawful basis is typically public task. For marketing communications, consent is usually required. Because health data is special category data, you also need an Article 9 condition, commonly the provision of health or social care; see the ICO’s page on special category data. Record your bases in your privacy notice and internal registers, and match each basis to its specific purpose.

See more on Healthcare Practice Growth.

Healthcare growth — Book a Website Review

This article covers how a practice runs and markets itself. It is not clinical advice and does not replace guidance from your regulator or professional body.

Ready to improve your website?

Book a free 20-minute website review — no obligation, just a plain-English list of what to fix.

Book a Website Review

Compliance Scorecard. 12 questions on CQC display, UK GDPR/PECR, accessibility and advertising rules. Instant score and a plain-English action plan. Take the compliance scorecard →

Healthcare Website Design

5.0 on Google

Trusted by growing UK businesses and clinics

  • Universally Bedford
  • Bricking It
  • CranberryHome
  • K Vision Centre
  • Menassa Vision
  • Panthagani