This GDPR checklist UK practices can work through covers eight areas, from consent forms to before-and-after treatment photos. Each step maps a UK GDPR requirement to patient data your practice already handles. Work through them in order and you finish holding the documents the Information Commissioner’s Office (ICO) asks to see.
Most GDPR advice is written for businesses that hold email addresses and invoices. A health or aesthetic practice holds medical history, consultation notes, and treatment photos. That is special category data under Article 9, and it carries conditions the general advice skips over.
Below you will also find the seven data protection principles, the six lawful bases, and what to do in the 72 hours after a breach.
Key takeaways
A GDPR checklist for a UK practice has to cover patient data, not only customer contact details.
The ICO enforces UK GDPR, and the higher fine tier reaches £17.5 million or 4% of worldwide annual turnover.
Before-and-after treatment photos are special category health data under Article 9, so they need explicit consent and tighter access control.
You have 72 hours to report a notifiable breach to the ICO, counted from the moment you become aware of it.
A subject access request gets a response within one month, extendable by two months only where the request is complex.
A data protection officer is mandatory in three situations only, and most single-site private practices meet none of them.
Every supplier handling patient data needs a signed data processing agreement, plus a transfer safeguard if the data leaves the UK.
Your completed checklist is itself evidence, because accountability means showing the ICO how you reached each decision.
What is a GDPR checklist, and who checks it?
A GDPR checklist is a working list of the actions UK GDPR requires of you, with evidence attached to each one. In a health or aesthetic practice, every one of those actions points back at the patient record.
The Information Commissioner’s Office checks it. The ICO is the UK’s independent data protection regulator, and its powers run from an audit through to a fine. Three pieces of law sit behind those powers.
- UK GDPR sets the principles, the lawful bases, and the rights your patients hold over their own data.
- The Data Protection Act 2018 fills in the UK detail, including the extra conditions that apply to health data.
- The Data (Use and Access) Act 2025 updates both, with changes covering research, direct marketing, and automated decision-making.
The ICO publishes the GDPR guidance UK practices are measured against, so read its pages before you read a commercial summary of them. ICO guidance is free, and it is what the regulator will quote back at you.
Fines sit in two tiers. The standard maximum is £8.7 million or 2% of worldwide annual turnover, whichever is higher. The higher maximum is £17.5 million or 4%, and it covers the principles, consent, special category data, and patients’ rights.
That split matters more in a practice than in most businesses, because so much of what you hold is health data.

Maximum fines are rare for a small practice. Complaints are not. A single patient asking the ICO why their photo appeared on Instagram is enough to open a case.
The 7 UK GDPR principles
UK GDPR sets seven principles, and Article 5 makes you responsible for proving you follow all of them. They are the short version of the full list of GDPR requirements, and every step in this checklist traces back to one of them.
Six of the seven describe how you handle data. The seventh, accountability, is about proving it, and that is the principle a checklist exists to serve.
The GDPR checklist for UK practices
Eight steps cover UK GDPR for a practice, starting with the privacy notice and ending with staff training. Before you start any of them, settle your lawful basis, because it decides the wording of almost every document below.
UK GDPR gives six lawful bases, and you pick one per purpose rather than one for the whole practice.
- Consent — the patient has given clear, specific permission and can withdraw it.
- Contract — processing is needed to deliver the treatment the patient booked.
- Legal obligation — a law requires you to hold or disclose the data.
- Vital interests — someone’s life is at risk, as in a medical emergency.
- Public task — you carry out an official function, which rarely applies to private practices.
- Legitimate interests — you have a genuine business reason that does not override the patient’s rights.
Health data needs a second condition on top, taken from Article 9. In a practice that is usually explicit consent, or the provision of health care by a professional bound by a duty of confidentiality.
Treat the eight steps as a GDPR compliance roadmap rather than a one-off job. Vendors sell a GDPR compliance pack UK buyers can download in an afternoon, and the documents inside are written for no particular business.
A GDPR compliance checklist UK regulators would recognize names your own systems and your own suppliers. Generic GDPR compliance templates give you the structure, and the filling in is the work. Larger groups usually fold this into a wider data governance checklist that also covers clinical audit and records management.
Practices registered in England meet the same questions again at inspection, because secure, accurate records sit inside the CQC requirements for good governance.
The GDPR checklist template at a glance
Each step below produces one document, and those documents are what the ICO asks to see. Copy the table into your own records and add an owner’s name to every row. That turns the GDPR checklist template below into a working document rather than a reading list.
1. Draft or update your practice’s privacy policy
Your privacy policy tells patients what you hold, why you hold it, and what they can do about it. Write it in plain English, and describe the practice as it runs today rather than as it was set up.
- Who you are, including your role as data controller and a contact point for data questions.
- What you process and why, split by category: clinical records, photos, payments, marketing.
- Your lawful basis for each purpose, plus the Article 9 condition for health data.
- Who receives the data, naming the categories of supplier, lab, and insurer involved.
- How long you keep it, with the retention period for clinical records stated separately.
- How patients exercise their rights, and how to complain to you and then to the ICO.
Public GDPR statement examples are easy to find, and copying one wholesale is how a policy ends up describing systems you do not use. The policy and the GDPR consent form also have to agree with each other, because a patient who reads both should see one story.
2. Know your patients’ data rights
UK GDPR gives patients eight rights over their data, and six of them can arrive as a written request. The other two work quietly, through your privacy notice and through any automated decisions you make.
- To be informed about what you collect and why, which your privacy notice delivers.
- Of access to a copy of their data, known as a subject access request.
- To rectification of inaccurate or incomplete entries in the record.
- To erasure of data you no longer have grounds to keep.
- To restrict processing while a dispute about accuracy or lawful basis is resolved.
- To data portability, where you hold the data on consent or contract and process it digitally.
- To object, which is absolute for direct marketing and qualified elsewhere.
- To rights around automated decisions, including profiling that has a significant effect.
Responding to a subject access request
You have one month to respond to a subject access request, counted from the day you receive it. The deadline extends by up to two further months where the request is complex, or where one patient sends several.
Tell the patient inside the first month if you are taking longer, and say why. You cannot charge a fee unless the request is manifestly unfounded or excessive, or the patient asks for further copies.
In a practice the hard part is scope. A subject access request from a patient covers consultation notes, before-and-after photos, appointment history, and message threads. Every one of them is in scope unless an exemption applies.
Building a GDPR right to erasure response template
A GDPR right to erasure response template needs three versions: yes, no with a reason, and a partial deletion you can explain. Most practice requests land in the third version.
Erasure has limits. Where a legal or professional obligation requires you to keep a clinical record, that obligation wins, and your template should cite it plainly. State the retention period you follow, so the patient knows when the record will be deleted.
Marketing is different. A patient who withdraws marketing consent comes off the list straight away, even though the clinical record stays exactly where it is.
3. Run a GDPR compliance audit and data protection impact assessment
A GDPR compliance audit starts with a list of every place patient data lives. Write down the booking system, the records system, photo storage, email, the card terminal, and any paper folder still in use. That list is your record of processing activities, and an auditor asks for it first.
A data protection impact assessment is the forward-looking half of the same job.

Run one before you introduce a change to how sensitive data is handled, who can reach it, or how much of it you hold. In a practice that usually means:
- Facial recognition or fingerprint check-in, which turns a face into biometric data.
- Surveys covering mental health, weight, or fertility.
- Automated treatment or booking suggestions based on patient history.
- Any new store for before-and-after photos, including a shared drive.
- Moving records to a supplier that keeps them outside the UK.
Work through it in five moves. Describe the processing and its purpose. Ask whether you need all of it. Identify the risks to patients. Put controls against each risk. Then write down the decision and the reasoning behind it.
No official GDPR compliance test exists, so the ICO’s own self-assessment tools are the nearest you get to a score. Keep the reasoning in a folder, a spreadsheet, or audit-ready compliance software, so you can produce it later. If a high risk survives your controls, consult the ICO before you go live.
4. Develop a data breach response plan
You have 72 hours to report a notifiable breach to the ICO, counted from the moment you become aware of it. The clock runs through weekends, so the plan has to work without you.
Breaches in a practice rarely look dramatic. A treatment summary goes to the wrong email address. A laptop with unsynced photos goes missing. A receptionist opens the record of a neighbor out of curiosity.
Volume backs that up. Between 2023 and early 2025, healthcare organizations in the UK reported more than 3,800 breaches to the ICO, more than any other sector.
- Contain it. Withdraw access, change credentials, and recall the message if the system allows.
- Size it. Work out what data was exposed, how many patients are involved, and what harm could follow.
- Log it. Record every breach, including the ones you decide not to report, with the reason for that decision.
- Report it. Notify the ICO within 72 hours where there is a risk, and tell affected patients where the risk is high.
- Close it. Change the process that allowed it, and brief the team on what changed.
A breach involving treatment photos or medical history sits at the high-risk end by default, because the data itself is special category. That is the case to rehearse, not the lost spreadsheet of email addresses.
Speed of detection is what keeps the cost down. IBM’s 2025 UK breach report put the average breach cost at £3.11 million for organizations using AI and automation. Those without it averaged £3.78 million.

5. Finalize third-party and data processing agreements
Your booking system, your records system, your accountant, and the lab that runs a sample all touch patient data. Each one acting on your instructions is a data processor, and each needs a written contract before it starts.
A GDPR data processing agreement has to commit the supplier to six obligations.
- Processing only on your written instructions, and never beyond them.
- Confidentiality obligations on every member of staff who can reach the data.
- Security measures matched to how sensitive the data is.
- Help with subject access requests, audits, and breach notification.
- Return or deletion of the data when the contract ends.
- Your right to audit or inspect, and to approve any sub-processor.
Then check where the data physically sits. If a supplier stores patient records outside the UK, that transfer needs a safeguard of its own, and post-Brexit there are three routes.
- UK adequacy regulations cover some countries outright, and no extra paperwork is needed.
- Appropriate safeguards, meaning the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
- Article 49 exceptions, which are narrow and should not be your default.
If you rely on a safeguard rather than adequacy, you also owe a transfer risk assessment. Cloud photo storage and overseas laboratories are the two places a practice usually finds this applies.
Referrals deserve the same care. Sending a patient’s history to a lab, an insurer, or another practitioner is a disclosure. The lawful basis for it belongs in your privacy notice rather than in an email.
6. Implement secure technical controls
Treat the five items below as your data security checklist, and write down the setting you chose for each. These are the GDPR controls an auditor can see evidence of, which is why the configuration matters more than the policy describing it.
- Access. Give each role the minimum it needs, enforce strong passwords, and switch on two-factor authentication for everyone.
- Encryption. Encrypt records at rest and in transit, so a lost device does not become a disclosure.
- Backup. Run backups on a schedule, keep a copy off site, and restore one occasionally to prove it works.
- Network. Keep the firewall on, patch on time, and treat ransomware as a data breach as well as an outage.
- Physical. Lock paper files away, angle reception screens away from the waiting area, and keep visitors out of staff areas.
Your website counts too. The GDPR cookie consent examples worth copying give reject and accept equal weight, and set no non-essential cookies until the visitor has chosen.
One control carries more weight than the rest in a practice. Photos and medical history are special category data, so they need stricter access rules than a contact list. Neither belongs on a device that syncs to a personal account.
7. Assign or evaluate your data protection officer
A data protection officer is mandatory in three situations only, and most single-site private practices meet none of them. Work through the three before you appoint anyone, and write down the answer either way.
- Are you a public authority or body? NHS organizations are. A private practice is not, even when it treats NHS-funded patients.
- Is large-scale, regular and systematic monitoring a core activity? Routine appointment records do not count. Continuous tracking of individuals does.
- Is large-scale processing of special category data a core activity? Treating patients is a core activity, so this one turns entirely on scale.
Scale is the word that decides it. Regulatory guidance has long treated an individual practitioner’s records as outside large scale, and a hospital’s as inside it. A multi-site group with tens of thousands of patient records should assume it is closer to the second.
Answer yes to any of the three and appointment is mandatory. Answer no to all three and you still name an owner, because accountability needs a person attached to it.
Either way, keep a one-page note recording which trigger you considered and why it did or did not apply. That note is the evidence, and it takes about twenty minutes to write.
Whoever holds the role carries four standing jobs.
- Owning the audit cycle and the schedule it runs on.
- Acting as the contact point for patients and for the ICO.
- Advising on data protection impact assessments before a change goes live.
- Keeping the training records current across the team.
8. Train your team on data protection
Reception and clinical staff meet different risks, so give them different training and date both records. Generic annual e-learning satisfies nobody, least of all an ICO caseworker reading it after an incident.
- Reception. What to say when a caller asks about someone else’s appointment, how to log a request, and why screens face away from the waiting area.
- Clinical staff. How photo consent is captured, what belongs in a note, and why a personal phone is not storage.
- Everyone. How to recognize a breach and who to tell inside the first hour, because the 72-hour clock has already started.
Record the date, the content, and who attended. A training log is the cheapest evidence on this checklist, and it is the first record a caseworker asks for after a staff error.
Protecting patient data: photos, consent, and medical records
Before-and-after treatment photos are special category health data under UK GDPR Article 9, so they need explicit consent and a tighter standard of care. A photo qualifies because it shows a physical condition and its treatment.
Those photos are not automatically biometric data. An image only becomes biometric data when you run technical processing on it to identify someone, such as facial recognition at check-in.
The distinction changes what you have to do. Health data needs an Article 9 condition and explicit consent for any use beyond treatment. Switching on facial recognition would add biometric processing, and that needs an impact assessment before it goes live.
Consent is where practices most often come unstuck. GDPR consent has to be freely given, specific, informed, and unambiguous, which rules out one tick box covering several purposes.
- Consent to treat is a clinical decision, recorded against the appointment.
- Consent to photograph for the clinical record is a separate question with its own answer.
- Consent to publish a photo on social media or a website is a third, and the most often assumed.
Withdrawal has to be as easy as giving it. A patient who asks you to take a photo down should not have to put the request in writing. The takedown should happen that day, not the next time the practice opens.
Consultation notes carry more than the treatment. A note recording a mental health condition, a pregnancy, or a medication is special category data as well. That note sits in the same record as the appointment time.
In practices we onboard, before-and-after photos are usually the last records to leave a personal phone. The camera roll is fast, and it syncs to a personal cloud account by default. Neither the practice nor the patient can then see who else has access.
The lasting fix changes where the photos live. Photos, consent, and notes belong in one patient record with role-based access, which is what medical records management is for. If you are rebuilding the paperwork, start from a consent for medical treatment template and add the photo and publication permissions as separate questions.
How Pabau helps UK practices stay GDPR compliant
By the time a practice works through this checklist, its patient data is usually scattered. Consent forms sit in a filing cabinet, photos on a phone, notes in one system, and marketing preferences in another. Each split is a separate place to search when a patient makes a request.
Pabau’s practice software brings those four into one patient record. Consent is captured digitally before the appointment, so the signed form attaches to the visit it belongs to rather than to a scanner queue.
Photos are taken inside the record instead of on a camera roll. Role-based permissions decide who can open them, and access is logged, so a subject access request or a breach review has an answer ready.
Pabau handles the administrative half of the checklist too. Marketing preferences update from the patient’s own record, and two-factor authentication and encrypted storage are built in. Full audit trails log every action, so a breach review can show who opened or changed a record.
Every Pabau subscription includes every feature, so the compliance tools are not held back for a larger plan. That matters on a checklist like this one, where the weakest step decides the outcome.

Keep consent, photos, and records in one place
Pabau captures patient consent before the appointment, stores treatment photos inside the patient record, and logs who opened what. Your team answers a subject access request from one screen instead of four systems.
Conclusion
None of these eight steps is difficult on its own. What makes them hard is that they sit outside the appointment. Each one gets done once, then drifts away from how the practice works day to day.
If you only have an afternoon, pick two. Photo consent and the breach plan are the steps tested under pressure, and they are the ones a patient complaint reaches first.
The trade-off worth remembering is scope. A checklist built around your own systems takes longer to write than a downloaded one. It is also the version that holds up when the ICO asks how your practice handles patient data.
Book a demo to see how Pabau keeps consent, treatment photos, and patient records in one place your team can evidence.
Continue your research
Registering a new practice? How to get CQC registered walks through the application step by step.
Wondering what the CQC expects? CQC requirements sets out what every provider has to prove to the regulator.
Preparing for a visit? CQC inspection explains what happens on the day and how to prepare for it.
New to the regulator? The CQC and its role covers what the Care Quality Commission does and who it regulates.
Frequently asked questions
What is the GDPR checklist?
A GDPR checklist is the list of actions UK GDPR requires of you, together with the document each action produces. In a practice it runs from the privacy notice through to dated staff training records. The point of the list is evidence, because accountability means showing how you reached each decision.
What are the 7 GDPR requirements?
The seven requirements are the data protection principles in Article 5. They are lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. The table earlier in this article shows what each principle looks like inside a practice.
Who checks GDPR compliance?
The Information Commissioner’s Office checks GDPR compliance in the UK. The ICO can investigate a complaint, run an audit, and order you to change how you process data. Its higher fine tier reaches £17.5 million or 4% of worldwide annual turnover, whichever is higher.
How to prepare a compliance checklist?
List every place patient data lives, then name the requirement that applies to each one. Turn each requirement into a single action with an owner, a document, and a review date. Work through the actions in order rather than all at once, and keep the completed list as your accountability record.
What documents are needed for GDPR compliance?
You need a published privacy notice, a record of processing activities, and a signed data processing agreement for every supplier. Add a data protection impact assessment for each high-risk change, a breach plan and breach log, and response templates for access and erasure requests. Dated staff training records complete the set.
How to prove GDPR compliance to patients?
Show the evidence rather than the policy. Share your privacy notice, name the lawful basis you rely on, and confirm your processor agreements and where data is stored. Offer your most recent training records and breach log on request, since documents carry more weight than a compliance badge.