Skip to content
HIPAA-Compliant Agency•BAA Signed Before PHI•NHS Digital Standards•WCAG 2.2 AA
HIPAA-Compliant Agency•BAA Signed Before PHI•NHS Digital Standards•WCAG 2.2 AA

UK GDPR Healthcare Website Guide: What Your Website Specifically Must Do

A practical UK GDPR healthcare website guide covering lawful basis, Article 9 health data, third party processors, cookie consent, data subject rights, and website compliance responsibilities for healthcare organisations.

UK GDPR Healthcare Website Guide: What Your Website Specifically Must Do
Qrolic Health Technical Team
10 min read
UK GDPR
Data Protection
NHS Compliance
Healthcare Web Development
PECR
Table of Content

NHS Design System Manual

Reviewed and updated for the latest developments in nhs design system manual and related healthcare compliance standards.

A healthcare website can collect personal information long before a patient becomes a formal service user. Contact forms, appointment requests, newsletter subscriptions, analytics tools, chat functions, and embedded booking systems can all create data protection responsibilities.

A UK GDPR healthcare website therefore needs more than a generic privacy policy. Each processing activity needs an appropriate lawful basis, health information requires additional protection, and third party tools need proper governance.

Health is also the UK's most reported data breach sector. According to ICO data security incident trends, 3,820 personal data breaches were self-reported by the health sector between 2023 and Q1 2025.

The practical question is whether your website has been designed around these obligations. This guide focuses on the specific controls your digital team can review, document, and maintain.

Why "we are GDPR compliant" is not enough for a healthcare website

The gap between organisational compliance and website compliance

Saying that your organisation is GDPR compliant does not demonstrate that every website processing activity has been assessed correctly.

A healthcare organisation may have strong internal data protection policies while its website uses an undocumented booking tool, an incorrectly configured analytics platform, or a form with no clearly defined lawful basis.

The website needs its own data flow assessment. Map every point where information enters, leaves, or is stored, then connect each activity to its purpose, lawful basis, recipients, retention approach, and responsible owner.

During healthcare implementations, we have mapped website data capture points before development begins rather than applying one blanket privacy statement after launch.

For a wider view of organisational requirements, review our UK GDPR and data protection compliance guidance.

Why health is the UK's most reported data breach sector

The ICO's data security incident trends show health as the UK's most reported data breach sector, with 3,820 self-reported personal data breaches between 2023 and Q1 2025.

The figure matters because healthcare websites frequently handle information that can reveal something about a person's health, treatment, or care needs. A seemingly simple website form can therefore carry more sensitivity than a standard commercial enquiry form.

The regulatory ceiling also matters to leadership. According to the ICO's enforcement framework, UK GDPR breaches can attract fines of up to £17.5 million or 4% of global annual turnover, whichever is higher.

For organisations managing both UK and US operations, our guide to how UK GDPR compares with HIPAA can help clarify where the two frameworks differ.

Need UK GDPR & Data Protection Assistance?

Our compliance team helps healthcare organisations audit forms, data flows, cookie consent, and third-party DPAs.

Schedule a Data Protection Consultation →

Lawful basis for every type of data your website collects

Contact forms and general enquiries

A contact form should not simply sit under the website's general privacy policy. You need to establish why the organisation is collecting the information and identify the lawful basis that applies to that purpose.

For example, an enquiry from someone asking about a service may involve different processing considerations from a marketing subscription. The wording around the form should accurately communicate what information is requested and why.

A practical implementation starts with a form inventory. Record every field, identify whether it is necessary, document the purpose, and connect that purpose to the relevant Article 6 lawful basis.

Appointment booking and patient intake

Appointment booking can involve significantly more information than a general enquiry. Depending on the workflow, a patient may provide contact details, symptoms, medical history, treatment requirements, or other health information.

The processing purpose must be considered before selecting the lawful basis. Health information also creates separate Article 9 considerations, which means Article 6 alone is not enough.

For NHS-facing organisations, these website controls should also be considered alongside NHS digital compliance standards.

Newsletter and marketing sign ups

Marketing subscriptions require a clear purpose and appropriate consent management where consent is the chosen lawful basis.

A common implementation error occurs when marketing consent is bundled into an unrelated appointment or enquiry process. Patients should not be left unclear about whether they are requesting care information or agreeing to receive marketing communications.

Keep marketing subscriptions separate from operational forms where the purposes differ. That makes the consent record, withdrawal process, and subsequent suppression of marketing communications easier to manage.

Why 1 lawful basis rarely covers your whole website

A website can support several distinct processing activities at once. Applying one lawful basis across every form can therefore conceal important differences in purpose.

Create a simple processing register for the website that records:

  • Form or data capture point
  • Processing purpose
  • Categories of personal data
  • Article 6 lawful basis
  • Whether special category data is involved
  • Relevant Article 9 condition
  • Third party recipients
  • Retention requirements
  • Internal owner

The register becomes a practical governance document rather than another compliance file that nobody consults after launch.

Special category data and Article 9: the condition most sites miss

Why health data needs a lawful basis AND an Article 9 condition

Health data is special category data under UK GDPR. Processing it therefore requires both an Article 6 lawful basis and an applicable Article 9 condition.

That distinction matters when websites collect symptoms, medical histories, treatment details, or other information that reveals health status.

A privacy notice stating that the organisation has a lawful basis does not, by itself, demonstrate that the additional Article 9 requirement has been addressed.

Common Article 9 conditions used by healthcare websites

Healthcare processing can involve different Article 9 conditions depending on the purpose and circumstances. The appropriate condition needs to be determined from the actual processing activity rather than selected as a standard website setting.

Clinical intake, direct care, employment related processing, public health activities, and explicit consent can involve different considerations.

For a healthcare website, the important control is traceability. Your records should show why a particular Article 9 condition applies to each relevant processing activity.

Our dedicated guide to Article 9 and special category health data provides further detail for teams reviewing this part of their compliance framework.

What happens when only Article 6 is documented

Documenting Article 6 without addressing Article 9 leaves the assessment incomplete when health information is processed as special category data.

The gap can occur because developers focus on the form's technical function while legal teams review the organisation's wider processing activities. Neither perspective alone provides the complete website assessment.

Build the Article 6 and Article 9 assessment into the same data mapping exercise. That keeps the legal analysis connected to the actual fields, workflows, integrations, and purposes implemented on the website.

Did You Know ?

A UK GDPR healthcare website needs a documented lawful basis for each processing purpose, an Article 9 condition for health data, appropriate Data Processing Agreements with processors, PECR compliant cookie consent, and a working process for handling data subject rights requests.

Data Processing Agreements for every third party tool on your site

Which tools typically need a DPA

Healthcare websites commonly depend on external services for analytics, appointment booking, forms, live chat, customer relationship management, email delivery, hosting, or other functions.

Where a third party processes personal data on your organisation's behalf as a processor, appropriate contractual arrangements need to be established.

A tool review should therefore happen before implementation. Record the provider, processing purpose, data categories, hosting arrangements, processor status, and relevant contractual documentation.

What to check before adding a new embedded tool

An embedded tool can introduce a new data flow without changing the visible appearance of your website.

Before approving one, establish:

  • What data the tool receives
  • When the data is transmitted
  • Whether cookies or similar technologies are involved
  • Where information is processed
  • Whether the provider acts as processor or controller
  • Whether a DPA is required
  • What retention provisions apply
  • Whether the tool is appropriate for the intended data

Across recent compliance projects, we have reviewed booking widgets, chat functions, forms, and other embedded services before they become part of the live healthcare workflow.

Processor liability, and why this is no longer a controller only risk

The ICO's enforcement activity demonstrates why organisations cannot treat third party processing as someone else's problem.

In March 2025, the ICO issued a £3,076,320 fine against a data processor under UK GDPR following a 2022 ransomware attack that exposed data belonging to 79,404 people and disrupted NHS 111.

The practical lesson for website owners is straightforward. Vendor selection and processor governance form part of your website's data protection risk management.

Cookie consent under UK GDPR and PECR

What PECR adds on top of UK GDPR

PECR creates specific rules around cookies and similar technologies used on websites. UK GDPR can then apply to personal data collected through those technologies.

The two frameworks should therefore be assessed together rather than treating cookie consent as a standalone banner design exercise.

Before implementation, identify every cookie and tracking technology, determine its purpose, and establish whether consent or another permitted approach applies.

What ICO's website compliance checks are actually looking for

The ICO expanded its national cookie compliance check to the UK's top 1,000 websites in January 2025. The initiative reflected concerns about whether organisations provide adequate user choice over tracking and personalised marketing.

That makes cookie configuration a live compliance issue rather than a minor website preference.

A practical review should test the actual behaviour of the website, not just the wording of the consent banner. Check what loads before consent, what happens when users reject tracking, and whether withdrawal remains possible.

Common cookie banner failures on healthcare sites

Healthcare sites often use multiple third party services, which can make cookie governance difficult.

Common problems include:

  • Non-essential tracking loading before consent
  • Consent options that are difficult to reject
  • Vague descriptions of tracking purposes
  • Marketing cookies grouped with essential functions
  • No practical withdrawal mechanism
  • New scripts added without updating consent controls

Our full breakdown of cookie consent requirements can help teams assess this area separately.

Implementing data subject rights through your website

Right of access, and how a website should route these requests

A patient may use a website contact route to request access to personal information. The website does not need to fulfil the request itself, but it should route the request into an established data protection process.

That distinction prevents website administrators from becoming accidental decision makers about identity verification, exemptions, disclosure scope, or clinical records.

Build a defined escalation route for access requests. Make sure staff know where requests go, who assesses them, and how the organisation tracks the response.

Right to erasure and its limits with clinical records

The right to erasure is not absolute. Healthcare organisations may have legitimate legal, clinical, public health, or other grounds that require certain information to be retained.

A website form should therefore avoid promising that every record can simply be deleted. Instead, it should route the request to the appropriate data protection or governance function.

The website's role is to capture the request accurately and trigger the correct internal process. The substantive decision belongs with the organisation responsible for the relevant records.

Building a request process that does not rely on 1 person's inbox

Health recorded 910 completed ICO complaint cases in Q3 2025/26, making it the second highest sector in the dataset behind finance, insurance and credit.

The figure reinforces why patient-facing data protection processes need defined ownership rather than depending on informal handling.

Based on our healthcare IT experience, website request routes work better when they connect to an internal workflow with clear ownership, verification, escalation, and auditability.

A practical UK GDPR checklist for healthcare websites

Data collection and processing

  • Map every website form and data capture point.
  • Document the purpose of each processing activity.
  • Identify the relevant Article 6 lawful basis.
  • Identify Article 9 conditions where health data is processed.
  • Review every field for necessity and proportionality.
  • Keep privacy information aligned with actual website behaviour.

Third party services and cookies

  • Inventory analytics, booking, chat, form, and marketing tools.
  • Confirm processor or controller status for each provider.
  • Establish required Data Processing Agreements.
  • Review international processing arrangements where relevant.
  • Test cookie behaviour before and after consent.
  • Maintain a process for approving new website integrations.

Data subject rights and governance

  • Provide a clear route for data subject requests.
  • Define identity verification and escalation procedures.
  • Route erasure requests to qualified reviewers.
  • Assign ownership for website privacy controls.
  • Review website processing after significant feature changes.

The strongest implementation model treats this checklist as part of the website release process. New forms, scripts, integrations, and account features should trigger a data protection review before production deployment.

Conclusion

A UK GDPR healthcare website requires more than a privacy policy placed in the footer. Your forms, booking workflows, health data collection, embedded tools, cookies, and data subject request routes all need to reflect the organisation's actual processing activities.

The most effective approach starts with data mapping. Identify what each website function collects, why it collects it, which lawful basis applies, whether Article 9 is relevant, which third parties receive information, and how requests are handled.

The regulatory environment also reinforces the need for practical governance. ICO breach reporting, processor enforcement, cookie compliance checks, and data protection complaints all demonstrate why website controls deserve active ownership.

For healthcare organisations, compliance works best when legal requirements become part of website architecture, development, testing, and ongoing change management.

Review Your Healthcare Website Before It Becomes a Data Protection Risk

UK GDPR fines can reach £17.5 million or 4% of global annual turnover, whichever is higher. A website scoped review can identify gaps across forms, health data, third party tools, cookies, and data subject rights.

Talk to our data protection team →

Frequently Asked Questions

Does a healthcare website need a separate lawful basis for each form?

Often, yes. Different forms can support different processing purposes, so they may require different lawful bases. A contact enquiry, appointment request, and marketing subscription should be assessed separately rather than automatically sharing one basis.

What is the difference between UK GDPR and PECR for cookies?

PECR specifically governs cookies and similar technologies in relevant circumstances. UK GDPR governs personal data processing associated with those technologies. Healthcare websites therefore need to consider both frameworks when implementing analytics and tracking.

Do healthcare websites need a Data Processing Agreement with every tool?

Where a third party processes personal data on your organisation's behalf as a processor, appropriate contractual arrangements are required. Review each tool's role, processing activities, and contractual terms before placing it on the website.

What is an Article 9 condition, and why is a lawful basis not enough?

Article 6 provides the general lawful basis for processing personal data. Health information is special category data, so processing it also requires an applicable Article 9 condition. Both assessments should be documented together.

How should a website handle a right to erasure request involving clinical records?

The website should capture and route the request rather than promise deletion. Erasure rights have exceptions, including circumstances where information must be retained for applicable legal, clinical, public health, or other obligations.

Can a healthcare website rely on consent as its only lawful basis?

Not necessarily. Consent may be appropriate for particular activities, but it can be withdrawn. Processing connected with providing healthcare services or meeting other obligations may require a different lawful basis.

Who is responsible for a data breach caused by a third party website tool?

Responsibility depends on the circumstances and the roles of the organisations involved. Controllers and processors have distinct UK GDPR responsibilities, and the ICO's processor enforcement action demonstrates that processors can face direct regulatory consequences.

What happens if a healthcare website ignores cookie consent requirements?

The ICO actively monitors cookie compliance, including national website checks. Non-compliant tracking can create regulatory exposure, particularly where users are not given appropriate choices before non-essential cookies or similar technologies operate.

Qrolic Health Technical Team

Qrolic Health Technical Team

Updated for 2026 Compliance Guidance
Qrolic Health - Healthcare Website Design Specialists

Qrolic Health supports healthcare organisations with compliance-focused website architecture, data handling workflows, accessibility, and healthcare platform development across UK and NHS-facing services.

Qrolic Health - Healthcare Website Design Specialists

Ready to Build Your Healthcare Platform?

Work with a team that understands HIPAA, accessibility, and healthcare digital experiences from day one.

Service we offer:
HIPAA-Compliant Websites
Healthcare Website Design
Telehealth Platforms
Website Redesign & Migration
Healthcare SEO