How do you advertise as a physiotherapist without breaking the UK GDPR or the CAP Code?
Advertising and being visible online is allowed for a physiotherapist, as long as two sets of rules are kept apart. The first is data protection: health data is special category data under Article 9 of the UK GDPR, so you need a lawful basis and a separate Article 9 condition, and you report a personal data breach to the ICO within 72 hours. The second is advertising: every objective claim about what your treatment does has to be backed by evidence under rule 12.1 of the CAP Code, and the ASA keeps a list of the conditions a physiotherapist may claim to treat without further proof.
Get the first wrong and the penalty bands in section 157 of the Data Protection Act 2018 apply: 17.5 million pounds or 4 per cent of worldwide annual turnover for the higher tier, 8.7 million pounds or 2 per cent for the standard tier, whichever is higher in each case. Get the second wrong and the advert comes down.
What is the UK GDPR and why does it count twice in your clinic?
The UK GDPR sits alongside the Data Protection Act 2018 and governs how you collect, use and store personal data. For a physiotherapist the law counts twice. You work with health information, and that is special category data: the category with the highest protection, listed by name in Article 9.
If it goes wrong, there are two penalty bands. For breaches of the lawful basis and the principles the fine runs up to 17.5 million pounds or 4 per cent of your worldwide annual turnover, whichever is higher rather than a choice between the two. For duties such as the record of processing activities and breach reporting the maximum is 8.7 million pounds or 2 per cent, again the higher of the two. Both bands are set out in section 157 of the Data Protection Act 2018. Reason enough to get the basics right.
The six core principles of the UK GDPR
- Lawfulness, fairness and transparency: you use data only with a valid lawful basis and your patients know what for.
- Purpose limitation: you collect data for a specific, stated purpose, such as the course of treatment.
- Data minimisation: you ask for no more data than you need.
- Accuracy: you keep data current and correct.
- Storage limitation: you keep data no longer than necessary. There is no single statutory retention period for a private clinic in the United Kingdom, so write down the period you apply and where it comes from. The schedule most practices follow is the appendix to the NHS Records Management Code of Practice.
- Integrity and confidentiality: you protect data against unauthorised access.
Your duties as a physiotherapist under the UK GDPR
Keep a record of processing activities
This applies to practically every physiotherapist. The exemption in Article 30(5) of the UK GDPR for organisations with fewer than 250 staff falls away as soon as the processing is not occasional or includes special categories of data, and a patient record is both. In the record you set down which personal data you process, for what purpose, on which lawful basis and how long you keep it. The ICO can ask to see it. Source checked on 25 August 2026.
Put processor contracts in place
Do you use third parties who can reach patient data, such as your practice management supplier, your accountant or your IT contractor? Then a written contract under Article 28 of the UK GDPR sets out which data they may process and which security measures are compulsory.
Carry out a DPIA for new technology
A Data Protection Impact Assessment is a risk analysis that maps and reduces privacy risks. You carry one out for large scale processing of health data or for new technology, such as online intake forms or video consultations.
Data Protection Officer
Larger practices and partnerships that process special category data on a large scale must appoint a DPO. For a smaller clinic that is not always compulsory, but a named person who owns privacy is worth having anyway.
How you protect patient data in practice
Technical measures
- Encryption: choose a patient record system with encrypted storage and TLS connections.
- Strong passwords and MFA: use long unique passwords plus multi-factor authentication.
- Automatic updates: keep operating systems, software and anti-virus current.
- Backups: make regular encrypted backups and test that you can restore them.
- Network segmentation: keep clinical systems separate from the guest network.
Organisational measures
- Access control: staff see only the data they genuinely need.
- Awareness training: train your team regularly on privacy and on spotting phishing.
- Clean desk policy: never leave paper files or screens visible and unattended.
- Safe destruction: shred paper documents and delete digital files in a way that cannot be undone.
Tip: ask your supplier which security standard they work to, for example ISO 27001 or Cyber Essentials, and ask to see the certificate rather than the claim.
Consent and lawful bases
You may use patient data only with a valid lawful basis under Article 6, and for health data you need a condition under Article 9 on top of it. Three combinations cover almost everything in a physiotherapy clinic.
- Delivering the care itself: the treatment runs on the contract with your patient, with the Article 9 condition for health or social care purposes. You do not ask for separate consent to keep notes on the treatment you are giving.
- Legal obligation: some processing is required of you, for example by an insurer or by a regulator. Write down which obligation applies, because that is what makes the processing lawful rather than the fact that somebody asked.
- Explicit consent: for everything that is not necessary for the treatment, such as sharing data with third parties, photographs and video, or a newsletter. Explicit consent under Article 9(2)(a) must be freely given, specific, informed and unambiguous, and a patient may withdraw it at any time.
This hits your marketing directly. Advertising your services and your expertise is fine, but the moment you want to use patient data, photographs or experiences, you need explicit consent. And a second rule applies to the marketing email itself: under regulation 22 of PECR you may not send unsolicited marketing email without consent, with a narrow soft opt-in for people whose details you took during a sale or negotiations for one.
These are the rights your patients have
- Right of access: patients may ask for all their personal data. You have one month to respond.
- Right to rectification: where data is wrong or incomplete a patient may ask for correction. With a clinical record you may make a professional judgement, but you take every request seriously.
- Right to erasure: in certain cases a patient may ask for deletion. The retention period you apply, and the reason you can give for it, limits that right.
- Right to data portability: patients can ask for their data in a structured, commonly used, machine readable format, for instance to move to another clinician.
- Right to restriction of processing: a patient can ask for a temporary restriction, for example while the accuracy of the data is disputed.
Tip: write an internal protocol for these requests and log every request with your response and how long it took.
Data breaches: prevention, and reporting within 72 hours
We are not going to put a national figure here that we cannot source properly. What you can look up yourself: the ICO publishes the numbers of reported data security incidents by sector in its data security incident trends, updated every quarter. Read that page once and you will see how ordinary the causes are. The list below is what a small clinic actually reports.
- A stolen or lost laptop with patient data on it.
- An email with clinical information sent to the wrong address.
- A member of staff sharing information over an unsecured channel.
- Ransomware that locks up your patient record system.
- A paper file that goes missing or is left lying around.
If you discover a breach, you report it to the ICO within 72 hours, unless a risk to the people affected is unlikely. If the risk is high, you also tell the patients concerned.
- 0 HOURS
- 24 HOURS
- 48 HOURS
- 72 HOURS
The clock never stops while you think. It starts at the moment you become aware and it keeps counting through a weekend, a bank holiday and a fortnight off. Discover something on a Friday and start working out who to ring on the Monday, and you watch this bar fill up without anything having happened.
What you are allowed to claim in an advert
The protected title and the HCPC register
Physiotherapy is regulated by statute in the United Kingdom. Physiotherapist is a protected title held by the Health and Care Professions Council, and under Article 39 of the Health Professions Order 2001 it is a criminal offence to use it with intent to deceive when you are not on the register. The HCPC states that this can extend to describing the service, not only the person, so an advert offering physiotherapy from someone who is not registered is the offence rather than a marketing mistake. Source: HCPC, misuse of title, checked 25 August 2026.
Rule 12.1: an objective claim needs evidence
The CAP Code governs what you may say in a non-broadcast advert, and that includes your own website and your Google Ads copy. Rule 12.1 requires objective claims to be substantiated, and for a health claim the ASA normally wants that evidence to come from trials conducted on people. Wording such as realigns, restores balance or corrects, without a study behind it, is exactly what gets rulings upheld against clinics.
The conditions the ASA accepts without further proof
The ASA and CAP keep a public list of conditions a physiotherapist may claim to treat: general aches and pains, arthritic and joint pain, backache, circulatory problems, cramp and muscle spasm, digestive problems, fibromyalgia, lumbago, neuralgia, minor sports injuries and tension. Anything outside that list has to be substantiated before you put it in an advert. Source: ASA and CAP, Health: Physiotherapy, checked 25 August 2026.
Reviews and testimonials
Since 6 April 2025 writing, commissioning or hosting fake reviews is a banned practice under the Digital Markets, Competition and Consumers Act 2024, and the Competition and Markets Authority enforces it directly. A paid review that is not clearly marked as paid falls in the same bracket. On top of that a testimonial is not evidence for a health claim: a patient saying it helped does not substantiate a claim under rule 12.1. Source: GOV.UK on the new consumer protection regime.
Tip: keep the evidence for every claim in one file, with the date you checked it. If the ASA asks, you have a week to produce it, and a week is not long enough to go looking.
A practical compliance checklist for your clinic
Walk through these eight points and the basics are in place.
- Record of processing activities written
- Privacy notice on the website
- Processor contracts in place
- Security measures implemented
- Staff trained
- Breach response plan written
- Consent forms up to date
- Backup strategy tested
Two of these eight are worth doing with a colleague rather than alone: the privacy notice and the breach response plan. The ICO publishes free templates and a self assessment for small organisations, and using theirs is faster and safer than writing your own from scratch. Want the checking work to run alongside your own systems instead of on a Friday afternoon, then that is what our service AI and automation is for. It stays a checklist and not legal advice; for a clinic that handles special category data a solicitor should give the final word.
Frequently asked questions about advertising and data protection for physiotherapists
Do I need a record of processing activities as a sole practitioner?
Yes, in practice. The exemption for organisations with fewer than 250 staff in Article 30(5) of the UK GDPR falls away as soon as the processing is not occasional or includes special categories of data, and a patient record is both. Source checked on 25 August 2026.
May I claim in an advert that I treat sciatica or headaches?
Only with evidence. The ASA and CAP list of conditions accepted for physiotherapy without further proof covers general aches and pains, arthritic and joint pain, backache, circulatory problems, cramp and muscle spasm, digestive problems, fibromyalgia, lumbago, neuralgia, minor sports injuries and tension. A condition outside that list needs substantiation under rule 12.1, normally from trials on people, before it goes into the advert.
How long do I have to keep patient records?
There is no single statutory period for a private clinic in the United Kingdom, which is why the honest answer is: write down the period you apply and the reason for it. The schedule most practices follow is the appendix to the NHS Records Management Code of Practice, and your indemnity provider may set its own expectation. What the UK GDPR requires of you is the storage limitation principle: a stated period, applied consistently, that you can justify.
May I use WhatsApp for patient communication?
Strongly discouraged for clinical information. We are not going to tell you that WhatsApp is by definition unlawful, because that depends on what you send and what you have agreed with the provider; what you do know with an ordinary chat service is that you cannot see who can reach the data and that you have no processor contract covering healthcare. Use a secure platform built for clinical use or the patient portal in your practice system, and put the question to your own data protection adviser.
What if a patient asks me to delete their record?
You assess the request rather than refuse it by reflex. The right to erasure is not absolute: where you can show that keeping the record is necessary, for instance for a legal claim or under the retention period you have written down and can justify, you may keep it. Document the request, your decision and the reason.
Do I need a Data Protection Officer?
For large scale processing of special category data it is compulsory. For a small clinic usually not, but a named internal privacy contact is worth having.
Does my website have to be compliant?
Yes. Make sure there is a current privacy notice, a lawful approach to anything you store on a visitor device under regulation 6 of PECR, a TLS certificate and contact forms that ask for no more than they need. If you want to know what else a good clinic website needs, read how to build your own website.
What if my practice system supplier does not secure things properly?
You stay accountable. Check the certification, check the Article 28 contract and ask for regular audits. If it stays inadequate, consider moving.
Rules in order? Then work on being found
A clinic that keeps data protection and advertising claims straight has the base in place, but you also want to be found by new patients. That works perfectly well without breaking any rule: you advertise and publish about your services and your expertise, not about individual patients, and every claim about what treatment does stays inside what you can evidence. To get going with all of that yourself, have a look at our service improving SEO.
More and more people also look for a clinician through an AI assistant. So read how to make content for ChatGPT, Perplexity and Google Gemini, or find more practical explanation in our knowledge base. What that costs is set out openly on our pricing page.
One thing we should say plainly, because this page deals with two sets of rules and one of them carries fines. We are not your lawyer and we are not your data protection adviser. Whether a particular processing operation has a lawful basis, and how long you keep a record, is a decision for you and your own adviser, and this page is written to help you ask that adviser the right question rather than to replace them.
What we can do is the marketing side: check the wording of an advert against rule 12.1 of the CAP Code before it goes live, keep the claims on your website inside what the ASA list allows, and set up a contact form that asks for no more than it needs.
If that is the part you want help with, take half an hour and bring one advert and one page from your website. We go through both against the two rule sets on this page while you watch, and you leave with a list of what to change, whether or not you take anything further. You can also just write to us through the contact page, and if you would rather see the advertising side first, our SEA specialist page sets out how the campaigns are run.
