GDPR for healthcare professionals: a website guide
GDPR and websites for healthcare professionals: privacy policy, consents, contact forms and sensitive data. What you actually need to be compliant.
If you have a website and work in healthcare — psychologist, physiotherapist, doctor, nutritionist — GDPR for healthcare professionals isn’t a bureaucratic detail. It’s a concrete obligation covering every contact form, every field where a patient enters information about their health. Ignoring it exposes you to penalties from your data protection authority and, more importantly, undermines the trust of patients who are trusting you with sensitive data.
In this guide we look at what you actually need on the site, without oversimplification and without needless alarm.
Why health data has special protection
EU Regulation 2016/679 (GDPR) classifies data concerning health as a “special category of personal data”, subject to stronger protection than ordinary data. Supervisory authorities across Europe have issued sector-specific guidance for healthcare, reiterated and updated in 2024–2025.
What that means in practice: when a patient writes in your site’s form “I suffer from panic attacks” or “I need rehabilitation after knee surgery”, they’re sharing health data. That data requires a specific legal basis (normally explicit consent) and higher security measures than ordinary data.
The most common problem on healthcare professionals’ sites isn’t a missing privacy policy — it’s that the privacy policy present is a generic copy downloaded from the internet, not adapted to the reality of the practice. Regulators can penalise that too.
What the site’s privacy policy has to contain
A privacy policy isn’t a standard text. It has to describe precisely:
Who the data controller is. Name, practice address, direct contact details. If you have a designated DPO (Data Protection Officer), they have to be listed too — though for most solo practitioners one isn’t mandatory.
What data you collect and for what purpose. The contact form collects a name, an email, a reason for contact — and that reason may contain health data. The purpose is handling the appointment request. It has to be written explicitly.
How long you keep the data. Contact form data isn’t needed forever. A practical rule: data from people who don’t become patients should be deleted within 30–60 days. Patient data follows the timeframes set by healthcare regulations.
Whether you transfer data to third parties. Do you use an email marketing system? A CRM? An appointment management tool? Every tool that receives patient data is a “data processor” and has to be listed.
The contact form: the critical point
The contact form is where most healthcare sites fall short. Here’s what you need:
A separate consent checkbox for health data. General consent to the privacy policy isn’t enough. Before sending information about their health, the patient has to be able to give explicit, informed, separate consent. The checkbox text has to be clear: “I consent to the processing of the health data I provide in this message for the purpose of handling my appointment request.”
No unnecessary mandatory fields. If you don’t need someone’s national insurance number to handle an appointment request, don’t ask for it. The data minimisation principle requires collecting only what’s strictly necessary.
HTTPS. The site must only be accessible over HTTPS. A contact form on HTTP transmits data in the clear — a basic technical breach that regulators treat as serious.
Cookie banners and preferences
Since 2022, European regulators have adopted strict guidance on cookies. The banner can’t have only an “Accept all” button prominent: it has to give the user a real ability to refuse non-essential cookies as easily as they accept them.
For healthcare professionals’ sites using Google Analytics or tracking pixels (Facebook Ads, for example), the prior consent requirement is stricter still — tracking behaviour on a healthcare site is considered sensitive.
The practical solution: use a certified consent management platform (CMP). Iubenda, Cookiebot, Usercentrics: there are options at modest monthly cost that automatically handle a compliant banner.
What I often see people do: install a free WordPress cookie plugin that shows a banner, but doesn’t record consents and doesn’t distinguish between technical and profiling cookies. It’s enough to pass a distracted glance, but it doesn’t survive an inspection.
What compliance costs (and what happens if you skip it)
Making a healthcare professional’s site GDPR compliant requires: a bespoke privacy policy, a correct cookie notice, a CMP for consents, and a contact form with explicit consent for health data. These aren’t huge jobs — they’re jobs that need doing properly once.
The cost of not doing it is higher. Supervisory authorities can impose penalties up to €20 million or 4% of global annual turnover. For solo practitioners, penalties are proportionate, but even €5,000–15,000 for a medium-severity breach is a figure that hurts.
There’s a communication upside too: a site that handles data transparently conveys professionalism. For a patient about to share delicate information about their health, knowing the practitioner takes privacy seriously is a trust signal.
FAQ
Do I have to appoint a DPO as a solo healthcare professional? Generally, solo healthcare practitioners aren’t required to appoint a Data Protection Officer. The obligation applies to healthcare organisations processing data on a large scale. That said, having someone to turn to on privacy matters — even an external consultant — is good practice that many practices adopt.
Is a privacy policy downloaded from the internet good enough? No. Regulators have penalised sites with generic privacy policies not adapted to the actual processing. The policy has to describe the data your site collects, the specific purposes, the real retention periods and any processors. There’s no universally valid template.
Do I have to ask for consent every time a patient writes to me? Consent for processing health data is requested at first contact, via an explicit checkbox in the form. It doesn’t need repeating with every subsequent message within the same professional relationship. It does need renewing if you change the purpose or if a long period passes with no contact.
Is Google Analytics compatible with GDPR on a healthcare site? With the right consent system, yes. Without prior consent, no. For healthcare sites, the safest option is Google Analytics 4 with IP anonymisation, activated only after the user’s explicit consent through the cookie banner, or privacy-first alternatives such as Plausible or Fathom.
Every website for healthcare professionals I build includes a bespoke privacy policy, a compliant cookie notice and a contact form with correct GDPR consents — not as an extra, but as a standard part of the package. If you want to work out what you need in your specific case, book a free call.