Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
Compliance and security

Questionnaire privacy statement: Free healthcare practice template

Avatar photo Anja Dodevska
Last Updated: September 18, 2026

A questionnaire privacy statement tells the person filling in your form how their personal data will be collected, used, stored, and protected. It sits on the form itself, at the moment data is collected, which is what separates it from the privacy policy published on your website. Data protection law treats it as mandatory: GDPR in the UK and EU, HIPAA in the US, and equivalent rules elsewhere.

Ten elements make a statement compliant, and three of them are required by GDPR but not by HIPAA. This guide walks through each one and shows where the statement belongs on paper and digital forms. There is a worked example for an aesthetic practice further down. The free template below is ready to customize.

Found our content helpful?

Download your free questionnaire privacy statement

A two-page statement with bracketed fields for your practice name, data protection officer, data categories, retention period, and complaint contact. It covers the lawful basis, participant rights, sharing, and the limits of confidentiality in a clinical setting.

Download template
Key takeaways

Key takeaways

A privacy statement informs; a consent form records agreement. Your questionnaire needs both.

Ten elements make a statement compliant, and the named legal basis is the one practices leave out most often.

GDPR requires the legal basis, the data categories, and the retention period on the form. HIPAA does not.

Confidential means identifiable but protected. Anonymous means no identifier was ever collected. Promise only the one you deliver.

UK clinical records are kept for 8 years after treatment ends, under the NHS Records Management Code of Practice.

The statement has to sit above the questions, in the same font size as the rest of the form.

What is a questionnaire privacy statement?

A questionnaire privacy statement is a disclosure that explains how personal data will be handled on one particular form. You may also see it called a survey privacy notice or a data collection notice. It sits at the point of collection. On paper that means the top of the form, above the first question. On a digital survey it sits behind a checkbox, or on a screen shown before anyone answers.

Your general privacy policy covers the whole organization. This statement is narrower. It speaks to one data collection, one purpose, and one set of participants. The reader knows what they are agreeing to before they start typing.

A consent form asks the participant to agree to an action, such as treatment, research participation, or photography. A privacy statement explains what happens to the data that action produces. The two often print on the same sheet, but they answer to different law. Data protection law makes the privacy statement mandatory, while clinical and research ethics rules make the consent form mandatory. Your questionnaire needs both.

Why healthcare practices need one

Every time a practice collects personal data, data protection law requires you to tell the person what you are doing with it. That covers intake questionnaires, health history, contact details, and treatment notes. In the UK and EU, the obligation comes from GDPR Articles 13 and 14. In the US, covered entities under HIPAA must provide a Notice of Privacy Practices.

Skipping the statement has consequences beyond a paperwork failure. Inspectors look for it, so it can surface as a finding during a CQC inspection in England or an ICO audit in the UK. It also draws patient complaints, costs you trust, and exposes the practice to financial penalties.

Those penalties are steep on both sides of the Atlantic. UK GDPR caps fines at £17.5 million or 4% of global annual turnover, whichever is higher. EU GDPR uses the same structure, with the fixed cap set at €20 million. In the US, HHS civil money penalties are adjusted for inflation each year.

The 2026 tiers start at $145 to $73,011 per violation where the practice did not know of the breach. The top tier, for willful neglect left uncorrected, runs from $73,011 to $2,190,294 per violation. Repeat violations of the same requirement are capped at $2,190,294 a year.

Patient trust and transparency

Compliance is the floor, not the reason. A clear statement reassures patients that sensitive health information is handled carefully, which matters most in aesthetic medicine, mental health, and sexual health practices. Those patients are already weighing how much to disclose before they pick up the pen.

What to include

A compliant statement covers the ten elements below. Use them as a checklist when you draft your own, or when you customize the template above.

  • Identity of the data controller: Your practice name, address, and contact email or phone. If you have a Data Protection Officer, known as a DPO, include their details too.
  • Purpose of collection: Why you are collecting the data. For example, to provide clinical assessment, to evaluate treatment outcomes, or to send appointment reminders.
  • Legal basis for processing: The lawful reason you are collecting it, usually consent, legal obligation, or legitimate interest. Under GDPR you must name the specific basis.
  • Data categories: The types of information you collect, such as name, contact details, health conditions, medication history, and photographs.
  • Data retention period: How long you keep the data. For example, for the duration of treatment plus 8 years, or for two years after the questionnaire is completed.
  • Recipients and sharing: Whether data goes to third parties such as insurers, referring physicians, or payment processors, and under what conditions.
  • Participant rights: The right to access their data, correct inaccuracies, request erasure, object to processing, and withdraw consent where that applies.
  • Voluntary participation statement: Whether answering is compulsory or optional. If it is optional, say that refusing will not affect their care.
  • Confidentiality and anonymity statement: How the data is protected, through encryption, access controls, and staff training. Say whether responses are confidential or anonymous.
  • Limited confidentiality disclaimer: In clinical settings, explain that confidentiality has limits. Mandatory reporting duties can require disclosure without consent.

Retention is the element practices get wrong most often. There is no single rule, because the answer moves with the record type and the jurisdiction. Our guide to medical record retention sets out the periods by record type. Put a defensible number on the form rather than a vague promise.

A strong statement balances legal completeness with plain language. Avoid jargon, and explain terms like “data controller” and “legal basis” in words a patient would use.

GDPR and HIPAA requirements side by side

Regulatory rules differ by jurisdiction. If your practice operates in more than one country, the statement has to satisfy each regime it touches.

UK and EU GDPR (Articles 13 and 14)

Under the GDPR compliance checklist rules, you must provide a privacy notice at the point of data collection. Article 13 applies when you collect data directly from the person. Article 14 applies when you obtain it from somewhere else.

The notice must name the data controller, the processing purpose, the legal basis, the recipients, and the retention period. It must also set out the individual’s rights: access, correction, erasure, portability, objection, and protection from automated decision-making. Plain language is part of the standard, so dense legal text fails it just as marketing jargon does.

US HIPAA (45 CFR §164.520)

Covered entities and business associates must provide a Notice of Privacy Practices, or NPP. HIPAA does not require the notice on every form, the way GDPR does. It has to reach patients at first service and stay available on request. That is why many US practices publish a standalone notice of privacy practices and reference it from the questionnaire.

The NPP explains permitted uses and disclosures, the contact for privacy questions, and how to complain. It also sets out patient rights: access, amendment, and an accounting of disclosures. It must be written in plain language and offered in alternative formats for people with disabilities.

Put the two regimes next to each other and the overlap is larger than the difference. Four disclosures are required by both, three by GDPR alone, and one by HIPAA alone.

Matrix of privacy statement disclosures required by UK and EU GDPR versus US HIPAA.
Write to the GDPR column and you clear HIPAA on seven rows out of eight, so a practice serving both markets only needs one statement. Mapped from GDPR Articles 13 and 14 and 45 CFR §164.520.

How the two regimes compare on process

Aspect GDPR (UK and EU) HIPAA (US)
When to provide At point of collection (Article 13 or 14) At first service or on request
Legal basis required? Yes, and you must name the specific basis No, not required in the same way
Language requirement Plain language, concise, transparent Plain language, accessible format
Penalties for non-compliance UK: up to £17.5m or 4% of turnover. EU: up to €20m or 4% of turnover $145 to $2,190,294 per violation by tier, capped at $2,190,294 a year (2026)

Confidentiality vs anonymity: What’s the difference?

Confidential and anonymous are treated as interchangeable on a lot of clinical forms, and they are not. Promising the wrong one exposes your practice to a complaint you cannot answer.

Confidential responses

Confidential means the responses are identifiable but protected from unauthorized access. The person’s name sits on the form, linked to their health data, behind encryption, locked storage, and staff training. This is the standard for clinical questionnaires in medical and aesthetic practice. You need to know who answered, so the responses can be linked to their treatment record.

Anonymous responses

Anonymous means no identifier is collected at all. You do not ask for a name, a patient ID, or any detail that could link a response back to a person. It is rare in clinical practice and more common in research surveys and feedback forms, where you want opinions without attribution.

Your statement has to say which one applies. If a patient believes they answered anonymously while your statement promises confidentiality, you have told them two different stories about the same form.

Where to display it on the form

Placement decides whether the statement does its job. It has to be visible and understandable before the person hands over any data.

Paper forms

Print the statement at the top of the form, above the first question, under a clear header such as “Privacy information: please read before answering”. Keep the font size the same as the rest of the form. Small print reads as something you would rather the patient skipped. Add a checkbox so they can confirm they have read and understood it.

Digital forms and online questionnaires

Digital forms give you four workable options. Pick one and use it consistently across every questionnaire you send.

  1. An expandable “Privacy information” section at the top of the form.
  2. A mandatory checkbox reading “I have read and understand the privacy information”, which must be ticked before submission.
  3. A pre-survey screen that shows the statement with a “Continue” button.
  4. A linked notice that opens in a tooltip or modal beside the first question.

Never bury the statement at the bottom of the form or behind an unlabelled link. Build it into the flow so respondents meet it on the way in.

A worked example for an aesthetic practice

Below is a completed statement for a fictional aesthetic medicine practice in the UK. Use it as a model, replacing the bracketed fields with your own details.

Privacy information: Questionnaire responses

[Your practice name] collects information from this questionnaire to assess your health, plan treatment, and monitor outcomes. This privacy information explains how we handle your data.

  • Who we are: [Your practice name], located at [your address]. Our Data Protection Officer is [name and email].
  • Why we collect this data: To provide safe and effective treatment, comply with health and safety law, and evaluate treatment results.
  • What data we collect: Name, date of birth, contact details, medical history, medications, allergies, and photographs where they relate to treatment.
  • Legal basis: Your consent, for treatment and photographs, and our legal obligation to maintain safe clinical records.
  • How long we keep it: Questionnaire responses and photographs are stored for 8 years after the conclusion of your treatment, then securely deleted. That period is set by the NHS Records Management Code of Practice.
  • Who we share it with: Your GP if you consent, our payment processor, and emergency services where the law requires it.
  • Your rights: You can ask to see your data, correct inaccuracies, or request deletion, subject to our legal obligations. Contact us at [email or phone].
  • Confidentiality: Your information is encrypted and stored securely, and only staff involved in your care can access it. Confidentiality has limits, and we must report safeguarding concerns or threats to safety to the relevant authorities.
  • Questions: Contact [name] at [email] or call [phone].

Adapt the wording to your practice type, the data you actually collect, and the jurisdiction you work in. A US practice would swap the retention line and the rights list for their HIPAA equivalents.

Common mistakes to avoid

Seven problems account for most of the statements that fail an audit:

  • Jargon without explanation: Define “data controller”, “legitimate interest”, and “data subject rights” for readers who are not lawyers.
  • Conflating confidentiality and anonymity: Do not promise anonymity if you collect names. Be specific about which protections apply.
  • Forgetting voluntary participation: If the questionnaire is optional, say so. People can refuse without penalty.
  • No contact information: Readers need to know who to approach with questions or complaints. Give a name, an email, and a phone number.
  • Hidden or unreadable text: Tiny fonts, pale colors, and text buried at the foot of the page all read as concealment.
  • Overly long statements: If yours runs past a page, break it into sections or add a short summary at the top.
  • Omitting limited confidentiality: Clinical and mental health settings carry mandatory reporting duties. State them so participants know where confidentiality stops.

Most practices maintain their privacy statement as a Word file, paste it into each form by hand, and reprint the lot whenever the wording changes. A version then lingers on the old intake pack in reception, and nobody can say which patient saw which text.

Practice management software like Pabau handles that differently. Compliance management software lets you attach a privacy statement field to every questionnaire and set it to display before any data is collected. Change the wording once and it updates across all your locations. Digital intake forms carry pre-built consent checkboxes, so each acknowledgment is recorded at the point of collection.

Responses are encrypted at rest, and retention policies delete them on the schedule you set rather than when someone remembers. So when an inspector asks which patients received the current statement, you answer from the record instead of from memory.

HIPAA compliance Pabau
Pabau’s compliance settings log every privacy acknowledgment against the patient record, so you can show an auditor who saw which version of your statement.

Record every privacy acknowledgment automatically

Pabau attaches your privacy statement to every questionnaire, captures the patient’s acknowledgment at the point of collection, and keeps the audit trail for you. Update the wording once and every form across every location follows.

Pabau practice management dashboard

Conclusion

Write the statement for the stricter of the two regimes you work under and you will rarely need a second version. GDPR asks for three disclosures HIPAA leaves out, so a GDPR-shaped statement travels well. Then decide the two things the law leaves to you: your retention period, and whether responses are confidential or anonymous.

The part that quietly fails is not the drafting. It is proving, months later, that a specific patient saw the current wording before they answered. Paper forms cannot show that, which is why the acknowledgment belongs in the same system as the questionnaire.

Book a demo to see how Pabau records each acknowledgment against the patient file and keeps your retention schedule running without a reminder.

Continue your research

Continue your research

Need the organization-wide version too? HIPAA privacy policy template gives you the practice-level policy that sits behind every form-level statement.

Building a compliance program from scratch? HIPAA compliance for medical offices walks through the policies, training, and safeguards a practice needs in place.

Worried about where the data lives? EHR security covers the encryption, access controls, and audit logging your privacy statement is promising patients.

Something already went wrong? What to do if you violate HIPAA sets out the reporting timeline and the steps that limit the damage.

Frequently asked questions

Is a questionnaire privacy statement legally required?

Yes. Under GDPR in the UK and EU, and under HIPAA in the US, you must tell people how their data is collected and used. Skipping it can bring regulatory penalties and patient complaints.

What is the difference between a privacy statement, a consent form, and a privacy policy?

A privacy statement informs, a consent form records agreement to an action, and a privacy policy covers your whole organization. Your questionnaire needs the statement and the consent form. The policy is separate and published on your website.

How long must I keep questionnaire responses?

Retention depends on jurisdiction and context. In the UK, adult clinical records are kept for 8 years after the conclusion of treatment under the NHS Records Management Code of Practice. Research data may be held longer for validation, and satisfaction survey responses can usually go after one or two years. State your period on the form.

What does ‘limited confidentiality’ mean?

Limited confidentiality means you protect data normally, but some disclosures are compulsory. In healthcare and mental health that covers child abuse, elder abuse, threats to safety, communicable diseases, and in some cases substance dependence. State these limits so participants know when you must disclose.

Can one statement cover all my questionnaires?

Yes, as long as every form collects the same data types, keeps them for the same period, and shares them with the same recipients. Where an aesthetic consultation and a mental health intake differ on any of those, write a form-specific statement for each.

Do online questionnaires need one too?

Yes. Online and paper forms answer to the same data protection rules. Digital forms have a practical advantage. You can display the statement as a mandatory checkbox, a pre-survey screen, or an expandable section before anyone can submit.

Found our content helpful?
×