Skip to content
HIPAA-Compliant Agency•BAA Signed Before PHI•NHS Digital Standards•WCAG 2.2 AA
HIPAA-Compliant Agency•BAA Signed Before PHI•NHS Digital Standards•WCAG 2.2 AA

UK GDPR Article 9 Health Data for Healthcare Websites

Understand how UK GDPR Article 9 applies to healthcare websites, including health data, Article 6 lawful bases, Article 9 conditions, website forms, patient journeys, analytics, and practical compliance checks.

UK GDPR Article 9 Health Data for Healthcare Websites
Qrolic Health Technical Team
10 min read
Article 9
UK GDPR
Health Data
Special Category Data
NHS Compliance
Table of Content

NHS Design System Manual

Reviewed and updated for the latest developments in nhs design system manual and related healthcare compliance standards.

Healthcare websites often collect information that goes beyond names, email addresses, and contact details. A symptom, diagnosis, treatment request, appointment detail, or patient registration record can reveal information about someone's health.

The primary question is therefore not simply whether your website collects personal data. You must determine whether the information reveals health data and, if so, whether the processing meets the additional requirements for special category data.

Under UK GDPR, health data receives additional protection under Article 9. You generally need an Article 6 lawful basis and a separate Article 9 condition, with further UK requirements applying in certain circumstances. According to the Information Commissioner's Office, these operate as separate layers rather than replacing one another.

What is health data under UK GDPR?

The Article 4(15) definition

Health data means personal data related to a person's physical or mental health that reveals information about their health status.

The ICO also makes clear that health information can include information collected when someone registers for healthcare or receives treatment. Health data can also arise through information that creates an inference about someone's health.

For a healthcare website, that means the assessment should focus on what the information reveals, why you collect it, and how you use it.

What health data can look like on a healthcare website

Common examples include:

  • Appointment information that reveals a medical service or condition.
  • Symptoms submitted through an enquiry form.
  • Condition-specific consultation requests.
  • Treatment information.
  • Medical history.
  • Diagnostic or test information.
  • Patient registration information.
  • Information submitted through a patient portal.
  • Referral information.
  • Information that intentionally reveals or infers a person's health status.

A free-text field can require particular attention because the user may enter considerably more information than the form designer expected.

What website data is not automatically health data

Not every piece of information collected by a healthcare website automatically becomes health data.

A person's name alone is not automatically special category data. A generic enquiry may also remain ordinary personal data if its content does not reveal information about the person's health.

Context matters. The ICO explains that inferred information can become special category data where processing intentionally makes an inference about health or treats someone differently because of that inference.

During healthcare implementations, we therefore recommend mapping individual fields rather than classifying an entire website as either sensitive or non-sensitive.

Need Help Identifying Article 9 Exposure?

A website can collect sensitive information through forms and integrations without the development team recognising the regulatory significance. A structured data-flow review can identify these issues.

Schedule a Data Flow Review →

Why Article 9 is different from Article 6

Article 6 answers one question

Article 6 addresses the general lawful basis for processing personal data.

Depending on the circumstances, an organisation may consider bases such as consent, contract, legal obligation, vital interests, public task, or legitimate interests.

The appropriate basis depends on the actual purpose and circumstances of the processing.

Article 9 answers another

Article 9 introduces an additional requirement when you process special category data.

The ICO states that organisations must identify both an Article 6 lawful basis and an Article 9 condition before processing special category data. The Article 9 condition does not replace the Article 6 basis.

Why healthcare websites need to assess both

A practical website assessment should follow this sequence:

  1. 1.Identify what information the website collects.
  2. 2.Establish the purpose for collecting it.
  3. 3.Determine the Article 6 lawful basis.
  4. 4.Assess whether the information is special category health data.
  5. 5.If it is, identify the relevant Article 9 condition.
  6. 6.Check whether DPA 2018 Schedule 1 requirements apply.
  7. 7.Document the decision.
  8. 8.Reflect the processing accurately in your privacy information.

For NHS teams, this distinction matters because website requirements should connect with the organisation's wider information governance framework.

For a broader overview, see our UK GDPR compliance for healthcare websites.

Which Article 9 condition applies to healthcare website data?

Article 9 contains 10 conditions for processing special category data. Healthcare websites should not select a condition simply because it sounds relevant to healthcare.

The condition must match the actual purpose and circumstances of the processing.

Article 9(2)(a): Explicit consent

Explicit consent is one possible Article 9 condition.

However, ordinary consent to submit a website form does not automatically establish explicit consent for special category processing.

The ICO distinguishes explicit consent from a general affirmative action. Where you rely on explicit consent, the consent must meet the applicable requirements and clearly address the processing concerned.

Healthcare organisations should therefore avoid adding a generic checkbox simply because health information appears on a form.

The better approach is to identify the processing purpose first, then determine whether explicit consent is genuinely the appropriate condition.

Article 9(2)(h): Health or social care

Article 9(2)(h) is particularly important for healthcare organisations.

It covers specified purposes including preventive or occupational medicine, medical diagnosis, provision of health or social care or treatment, and management of health or social care systems and services. Relevant UK-law safeguards also apply.

However, Article 9(2)(h) is not itself an Article 6 lawful basis.

You still need an appropriate Article 6 basis, and the Article 9 condition must satisfy its own requirements.

NHS England examples demonstrate this two-layer approach, with Article 6 and Article 9(2)(h) identified separately for relevant health-data processing.

Article 9(2)(i): Public health

Article 9(2)(i) concerns specified public health purposes.

It should not be treated as a general alternative for routine healthcare website processing. The purpose must genuinely fall within the relevant public health condition and associated legal requirements.

For an NHS website, this distinction becomes particularly important where information moves beyond direct patient service delivery into public health functions.

Other Article 9 conditions

Other conditions can apply in specific circumstances, including substantial public interest, legal claims, vital interests, and research, archiving, or statistical purposes.

The ICO identifies 10 Article 9 conditions overall. Five require additional conditions and safeguards under UK law, including relevant provisions in Schedule 1 of the Data Protection Act 2018.

The practical lesson is simple: document why the selected condition applies rather than treating Article 9 as a single healthcare exemption.

Did You Know ?

Health data processed through a UK healthcare website is special category personal data under UK GDPR. You generally need both an Article 6 lawful basis and an Article 9 condition, with additional DPA 2018 safeguards where applicable. The correct condition depends on the purpose and processing context.

How does Article 9 apply to common healthcare website features?

Appointment booking forms

Appointment information can reveal something about an individual's health depending on the service and context.

A booking request for a general administrative appointment may require a different assessment from a request that identifies a specific condition or treatment.

Limit the fields to information genuinely needed for the stated purpose. Avoid collecting detailed clinical information simply because the form technically allows it.

Contact and referral forms

Contact forms become more sensitive when they invite users to submit:

  • Symptoms.
  • Diagnoses.
  • Medication information.
  • Treatment history.
  • Referral details.
  • Clinical documents.
  • Free-text descriptions of health conditions.

A generic message box can therefore create a significant difference between the intended data flow and the actual data collected.

Patient registration

Patient registration can involve identity information alongside information concerning health, treatment, or healthcare needs.

The website architecture should distinguish registration data from unnecessary clinical information and establish where each category goes after submission.

Patient portals

A patient portal is materially different from a public information website because authenticated functionality can expose records, appointments, messages, prescriptions, or other sensitive information.

Access controls, authentication, session management, audit requirements, and integration boundaries should therefore form part of the compliance assessment.

Online consultation and telehealth journeys

Telehealth journeys can move a website from simple lead generation into direct healthcare service delivery.

Once information supports clinical assessment, diagnosis, treatment, or healthcare management, the organisation should assess the relevant Article 9 condition and wider governance requirements as part of the service design.

Website analytics and third-party tools

Analytics requires careful assessment rather than blanket assumptions.

Consider what URLs, events, form interactions, referrers, page paths, and other signals may reveal about a visitor's health. The assessment should cover the actual configuration, purpose, data flow, recipient, and processing relationship.

Based on our healthcare IT experience, website analytics should be reviewed as part of the wider information flow rather than treated as an isolated marketing decision.

When does Article 9(2)(h) make sense for a healthcare website?

Start with the purpose

Ask what the processing actually enables.

For example:

  1. 1.Is the information used for medical diagnosis?
  2. 2.Does it support healthcare or treatment?
  3. 3.Does it support management of healthcare services?
  4. 4.Is processing necessary for that purpose?
  5. 5.Could the same purpose reasonably be achieved with less sensitive information?

The ICO explains that necessity requires more than usefulness or established business practice. Processing should be targeted and proportionate to the purpose.

Check the professional secrecy requirement

Article 9(2)(h) has additional safeguards concerning professional secrecy and confidentiality.

A healthcare organisation should therefore consider who processes the information, under whose responsibility the processing occurs, and what legal or professional confidentiality obligations apply.

Article 9(2)(h) should never be treated as a universal healthcare exception.

Check the DPA 2018 Schedule 1 condition

Some Article 9 conditions require an associated condition in Schedule 1 of the Data Protection Act 2018.

The ICO specifically identifies additional UK-law requirements for conditions including Article 9(2)(h), (i), and (j).

That means the compliance record should show more than "Article 9(2)(h) applies". It should identify the relevant UK-law condition and applicable safeguards.

What should NHS and healthcare teams document before launch?

A website compliance record should connect legal decisions to actual technical implementation.

At minimum, document:

  • Processing purpose.
  • Data fields collected.
  • Whether each field is health data.
  • Article 6 lawful basis.
  • Article 9 condition.
  • DPA 2018 Schedule 1 condition where required.
  • Data minimisation rationale.
  • Retention requirements.
  • Data recipients.
  • Third-party processors.
  • Privacy notice wording.
  • Data-flow documentation.
  • DPIA assessment where appropriate.
  • Security and access controls.

The ICO recommends documenting the Article 9 condition before processing begins and considering DPIA requirements where processing is likely to create high risk.

For NHS-facing projects, website architecture should also align with the organisation's wider information governance requirements. The website should not become a separate compliance process maintained only by the marketing or digital team.

At Qrolic Health, we approach this as a website architecture issue as well as a governance issue. Forms, authentication, integrations, analytics, and third-party services all need to be considered within the same data-flow assessment.

For organisations planning a wider NHS-facing build, our NHS compliant website design and development service provides the implementation context for these requirements.

Common Article 9 mistakes on healthcare websites

Mistake 1: "We have consent, so we are covered"

Consent does not automatically establish the correct Article 6 lawful basis or Article 9 condition.

The processing purpose must determine which legal route is appropriate.

Mistake 2: "Healthcare means Article 9(2)(h) always applies"

Being a healthcare organisation does not automatically make every processing activity fall under Article 9(2)(h).

Purpose, necessity, applicable UK-law requirements, and safeguards still matter.

Mistake 3: Treating every website visitor as a patient

A person visiting a healthcare website is not automatically submitting health data.

Assess what the organisation actually collects and what the information reveals.

Mistake 4: Ignoring free-text fields

Free-text fields can collect detailed health information even when the surrounding form appears administrative.

Where clinical information is not required, consider whether the field should be restricted, removed, or redesigned.

Mistake 5: Writing the privacy notice after development

Privacy information should reflect the actual processing architecture.

If developers add fields, integrations, tracking, or data transfers late in a project, the privacy documentation may no longer accurately describe the website.

Article 9 healthcare website compliance checklist

Use this checklist before launching or materially changing a healthcare website:

  • Identify every website data collection point.
  • Determine whether each relevant field contains health data.
  • Document the Article 6 lawful basis.
  • Document the Article 9 condition.
  • Check DPA 2018 Schedule 1 requirements.
  • Apply data minimisation to forms and workflows.
  • Review third-party processors and integrations.
  • Assess whether a DPIA is required.
  • Update privacy information.
  • Confirm retention requirements.
  • Review access controls.
  • Test documented data flows before launch.

A useful implementation test is to trace one piece of submitted information from the website form through storage, integrations, staff access, retention, and deletion.

If the team cannot clearly explain that journey, the governance documentation may not reflect the actual system.

When should you review your healthcare website's Article 9 position?

A review is particularly useful when your organisation:

  • Launches new patient-facing forms.
  • Introduces online appointment booking.
  • Adds patient registration.
  • Connects an EHR or CRM.
  • Introduces a patient portal.
  • Adds telehealth functionality.
  • Changes analytics or marketing technology.
  • Replaces a third-party processor.
  • Redesigns the website.
  • Expands clinical or healthcare services.

A redesign is often the right point to reassess these decisions because the data flow is already being reconsidered.

Conclusion

UK GDPR Article 9 health data requirements become much easier to manage when you treat them as part of website architecture rather than as wording added to a privacy policy.

The central distinction is critical. Article 6 provides the general lawful basis, while Article 9 adds a separate condition when your website processes special category health data. Some Article 9 conditions also require additional safeguards under the Data Protection Act 2018.

For NHS and private healthcare teams, the practical task is to connect each form, patient journey, integration, analytics service, and data flow to the correct governance decision.

That approach helps your digital team build requirements into the website before launch, rather than discovering gaps after implementation.

Need Help Reviewing Your Healthcare Website?

If your website is collecting health information or connecting with patient systems, Qrolic Health can help assess the relationship between your website architecture, data flows, and UK GDPR requirements.

Contact Qrolic Health →

Frequently Asked Questions

Is health data special category data under UK GDPR?

Yes. Information concerning an individual's health falls within the UK GDPR's special category framework. The ICO also recognises that health information can include inferred information where processing intentionally reveals or treats someone differently based on health-related inferences.

Do healthcare websites need both Article 6 and Article 9?

Generally, yes when processing health data. Article 6 provides the general lawful basis, while Article 9 requires an additional condition for special category processing. The two requirements operate separately and should both be documented.

What is Article 9(2)(h) in healthcare?

Article 9(2)(h) covers specified health and social care purposes, including medical diagnosis, healthcare provision, treatment, and management of health or social care services. Additional UK-law safeguards can apply through Schedule 1 of the DPA 2018.

Does collecting appointment information count as processing health data?

It can, depending on what the appointment information reveals. An appointment connected to a specific medical service or condition may reveal health information, so the organisation should assess the actual context rather than classify every appointment field automatically.

Does a healthcare website always need explicit consent to process health data?

No. Explicit consent is one Article 9 condition, but it is not the only option. The appropriate condition depends on the purpose and circumstances of processing, while the organisation must also identify an Article 6 lawful basis.

Does Article 9(2)(h) apply to private healthcare websites?

It can apply where the processing meets the relevant health or social care purposes and associated requirements. The organisation must still establish an Article 6 lawful basis and satisfy applicable safeguards, rather than relying solely on its healthcare status.

Does a healthcare website need a DPIA for Article 9 processing?

Not automatically. A DPIA is required where processing is likely to result in high risk. Healthcare organisations should assess the nature, scope, context, and risks of their processing before deciding whether a DPIA is required.

What should be included in a healthcare website's privacy notice?

The privacy information should accurately describe relevant purposes, personal data categories, lawful bases, applicable Article 9 conditions, recipients, retention, rights, and other information required for transparency. The notice should reflect the website's actual processing architecture.

Qrolic Health Technical Team

Qrolic Health Technical Team

Updated for 2026 Compliance Guidance
Qrolic Health - Healthcare Website Design Specialists

Qrolic Health works on healthcare websites and digital platforms where forms, integrations, patient journeys, analytics, and sensitive data flows must be considered together during implementation.

Qrolic Health - Healthcare Website Design Specialists

Ready to Build Your Healthcare Platform?

Work with a team that understands HIPAA, accessibility, and healthcare digital experiences from day one.

Service we offer:
HIPAA-Compliant Websites
Healthcare Website Design
Telehealth Platforms
Website Redesign & Migration
Healthcare SEO