📣 Heads up: Compliance is a shared responsibility. Jane provides the platform, features, and documentation to support your clinic's compliance, but your clinic is responsible for how you collect, use, and manage patient data in your day-to-day operations.
This guide is a general summary and is not intended as legal advice. For guidance specific to your practice, consult a legal professional or your regulatory body.
The EU and UK operate under separate but closely aligned data protection frameworks. EU clinics are subject to EU GDPR, while UK clinics are subject to UK GDPR and the Data Protection Act 2018. The principles below apply to both unless otherwise noted.
🌍 This guide applies to clinics based in the EU and UK only.
Why most EU and UK clinics don't need patient consent to collect data
Under GDPR, "consent" is a specific legal term. It's only appropriate when you can offer patients a genuine choice about whether their data is used. In healthcare, that's rarely the case. Clinics are required by local law and professional regulatory bodies to collect, store, and protect patient health data as part of delivering care.
Because data collection is legally required, asking for consent to collect it would be misleading. GDPR recognises this, which is why most EU and UK clinics document a legal basis for collecting and processing data instead of asking patients to consent.
Documenting a legal basis
EU and UK clinics document their legal basis for processing data under GDPR Article 6(f) and Article 9(1). This declaration explains what data is collected, why, and under what legal authority.
Here's an example of language a clinic might use:
The Village UK, located in London, England, fully complies with the UK's General Data Protection Regulation (GDPR) Article 6(f) and Article 9(1)(h). Lawful collection and processing (including the distribution of email and text message appointment confirmations and reminders) of personal health data of natural persons who are EU residents is only carried out where necessary for medical and health appointment confirmation, evaluation, diagnosis, and treatment purposes. All data collection and processing occurs for the legitimate medical and health interests pursued by The Village UK, the data controller. Personal data collected and processed includes but is not limited to full name, address, contact information, family relations, medical information, diagnosis, and other items as required by the General Chiropractic Council and laid out in The Chiropractors Act 1994.
You can read the relevant articles in full:
Once you've documented your legal basis, make sure your clinic policies and staff practices align with that declaration. Our guide on Is Jane GDPR Compliant? covers the broader steps for running a GDPR-compliant practice in Jane.
Do reminders require patient consent?
No. Appointment reminder notifications don't require patient consent under GDPR. While it's best to check in with your Supervisory Authority when in doubt, the UK Information Commissioner's Office notes that care providers will generally have a legitimate reason to process personal data when delivering medical care. Reminders fall into that category because:
- They're covered under your clinic's legal basis for processing data (most health clinics name GDPR Article 9(2)(h) as their legal basis for health-related processing)
- They serve a Legitimate Interest, patients rely on reminders to attend appointments, and receiving one from a health clinic is expected
- The privacy impact of processing personal data to send a healthcare reminder is minimal under GDPR
Before sending reminders, two things need to be in place:
- Document your lawful basis. Record the Lawful Basis under which you collect and process personal data. GDPR doesn't prescribe a format, so this can be a physical binder, an electronic document, or any accessible record, as long as it demonstrates that a lawful basis applies and can be produced if you need to prove compliance.
- Inform your patients. GDPR requires that patients know what data you collect, how you use it (including that you use email addresses to send reminders), and how long you retain it. Check with your Supervisory Authority whenever in doubt.
Setting up reminders in Jane
Once your lawful basis is documented and your patients are informed, configure reminders in Jane so that patients receive them by default but can opt out if they choose.
- Go to Settings > Reminders & Notifications.
- Under Notifications, select Set all to Enabled, then click Update Notification Settings.
- In the Reminders section, click Edit next to each reminder.
- Make sure the reminder is set to Enabled and Patient Selectable.
- Click Save and repeat the process for each reminder.
Patients will now receive reminders by default and can opt out if they prefer.
Treatment names
- Go to Settings > Treatments, Classes & Group Appointments.
- When naming treatments, use the most generic name or title that fits your purposes. Jane includes treatment names in certain email and text communications, so generic names help protect patient privacy.
Consent for marketing emails
Unlike reminders, marketing emails do require patient consent under EU and UK GDPR. Patients must be able to choose what marketing communications they receive. Configure the following settings in Jane to make sure patients opt in rather than being enrolled by default.
- Go to Settings > Online Booking and scroll to Display Preferences.
- Select Select All to Opted Out, then click Save.
Consent for treatment
Consent for treatment is separate from consent to collect data. How you handle it depends on the health services you provide and the requirements of your regulatory body.
In Jane, consent forms are fully customizable and built using Chart Templates. If you'd prefer not to start from scratch, the Chart Template Library includes forms you can adapt to your needs.