Zovi
All blog posts

GDPR-Compliant Patient Communication: What Clinics Must Get Right for Push, Email and WhatsApp

Push, email and WhatsApp are the most direct routes to a patient and the most heavily regulated. What consent, double opt-in, documentation and retention periods actually mean day to day in a clinic, plus the seven questions that let you check your own communication in an hour.

Guide
By Sam Chauhan9 min read
Share this article
DSGVOPatientenkommunikationWhatsAppEinwilligungCompliance

Push, email and WhatsApp are the most direct routes to a patient. They are also the most heavily regulated. Get the groundwork right and you can communicate without second-guessing every send. Get it wrong and the first consequence in Germany is usually not a regulator but a competitor's cease-and-desist letter. Here is what a clinic actually has to do, day to day.

Two rulebooks, not one

The most common mistake in clinics is the belief that a privacy policy settles the matter. In reality, every promotional message has to clear two separate sets of rules at the same time.

The GDPR answers whether you may process the data at all. Competition law, in Germany principally section 7 of the UWG, answers whether you may advertise with it. Both answers have to be yes. Austria handles this through section 174 of the TKG 2021, Switzerland through Article 3(o) of its own UWG alongside the revised Data Protection Act.

This matters commercially, because the expensive problem rarely arrives from a supervisory authority. It arrives from a competitor or a claims firm that received a marketing email you cannot prove consent for. And because treatment information in aesthetics is health data under Article 9 GDPR, you are working in the special-category tier with the higher bar that comes with it.

What counts as advertising and what does not

Not every message needs marketing consent. Anything you send to perform the treatment contract rests on Article 6(1)(b) GDPR:

  • Appointment confirmations and reminders
  • Cancellations and reschedules
  • Preparation and aftercare instructions for the booked treatment
  • Invoices, payment reminders, instalment schedules

Advertising is everything aimed at the next sale: offers, discounts, newsletters, birthday promotions, news about a treatment you have just added, an invitation to join the loyalty programme. German case law also treats review requests and satisfaction surveys as advertising, which surprises most clinic owners but is the safer assumption to work from.

The costliest everyday mistake is the mixed message. "Your appointment is Tuesday at 2pm. By the way, 20% off all filler treatments this month." That single sentence turns a permitted service notification into a marketing message you have no consent for. The fix is unglamorous and immediate: one message, one purpose.

A patient consent form being signed at a clinic reception desk
Consent is not a sheet in a binder. It is a record you can produce on demand.

Most clinics have consent of some kind. What they usually lack is consent that would survive scrutiny. Four requirements decide it.

1. Freely given

Booking an appointment must not depend on subscribing to the newsletter. That bundling undermines the consent. Offering a discount for signing up is fine. Making it a condition is not.

2. Informed

Before the box is ticked, the patient should know who is writing, on which channels, about what, roughly how often, and how to stop it. One sentence is enough if it is specific. The single word "marketing" is not.

3. Specific and separate

Push, email and WhatsApp are three channels, not one. Bundle them behind a single checkbox and you have defensible consent for none of them. Separate by purpose too, at minimum appointment service versus offers.

4. Actively given

Since the Court of Justice ruling in Planet49, a pre-ticked box is not valid consent. Neither is an opt-out buried in terms. It takes a deliberate action.

Withdrawal matters just as much. Article 7(3) GDPR requires it to be as easy as giving consent. If signing up takes two clicks and unsubscribing takes a phone call during opening hours, something is wrong.

One further point that gets missed: the moment your message names the treatment, you are processing health data. "Your filler top-up" is a different category from "your appointment". Neutral wording lowers your risk without costing the patient anything.

Double opt-in in practice

Double opt-in is the established German route to provable email consent. The flow is short: complete the form, receive a confirmation email, click the link, done. What matters is what you store along the way.

  • Timestamp of the sign-up and timestamp of the confirmation
  • The IP address or device identifier the sign-up came from
  • The channel and purpose consented to
  • The exact wording of the form, in the version that was live at that moment

That last item is where clinics routinely come unstuck. The consent text gets rewritten three times over the years, the old versions are overwritten, and when a dispute arrives you can no longer show what a patient agreed to in 2023. Version the text and store the version number on the record.

The confirmation email itself must carry no advertising. No offer, no discount code, no "while you're here". Just the confirmation link.

Paper forms at reception are acceptable, but they belong scanned and dated on the patient record. A binder where nobody can find the right sheet inside a week is not evidence.

On the existing-customer exception in section 7(3) UWG: it permits email marketing to existing customers without prior consent, but only under narrow conditions. The address must have been collected in connection with a paid service, the marketing must be for your own similar services, the right to object must be flagged at collection and again in every single message, and the customer must not have objected. It covers email only, never WhatsApp, SMS or phone. If you rely on it, be able to tick all four conditions literally.

Push: the underestimated special case

Many teams assume the iOS or Android system prompt is the consent. It is not. It grants technical permission to deliver. It says nothing about what content the patient expects.

The clean approach is two-stage. First an in-app screen of your own explaining what you will use push for, with separate toggles for appointment service and offers. Then the system prompt. As a side benefit, this is also the order that produces the highest opt-in rate, because the patient knows what she is agreeing to.

Three things get forgotten in day-to-day operation:

  • The lock screen is public. A push notification is readable by anyone sitting next to the patient. "Your appointment tomorrow at 10:30" is fine. "Your lip filler tomorrow" is not.
  • The push token is personal data. It belongs in your deletion policy and has to go when the app is uninstalled or the token expires.
  • Delivery runs through Apple and Google. That means a processor relationship and a possible international transfer sitting quietly in your stack.

Withdrawal has to live inside the app, not in an email to reception. A toggle in settings, effective immediately.

A patient reading a clinic message on a smartphone
Someone is usually reading over the patient's shoulder. Write as though that is always true.

WhatsApp: the hardest channel

WhatsApp gets read, nobody disputes that. Legally it is the most demanding of the three channels, for a reason many clinics never consider.

The free WhatsApp Business app accesses the address book of the phone it runs on. If your clinic handset holds patient numbers, you are passing on the contact details of people who never agreed to it, including patients who do not use WhatsApp at all. German supervisory authorities have taken a dim view of this setup for years, and for a clinic it is close to impossible to resolve cleanly.

The workable route is the WhatsApp Business Platform, the API, run through a provider you sign a processor agreement with. On that basis:

  • Use a dedicated clinic number, never a member of staff's personal phone
  • Do not synchronise any address book
  • Capture opt-in before the first message and document it like any other consent
  • Outside the 24-hour window after the patient's last reply, only pre-approved template messages are permitted, which is Meta's own platform rule on top of the law
  • Automate opt-out, for example via a STOP keyword, so it lands in the system rather than on a sticky note at reception

On content, apply the strictest restraint. WhatsApp often runs on a shared family phone. No diagnoses, no treatment names, no before-and-after photos, no invoice detail.

Documentation that actually counts

Article 5(2) GDPR requires you not only to comply but to demonstrate compliance. This accountability duty is where well-run clinics separate from the rest. Five documents will take you a long way.

  • A record of processing activities under Article 30, with a separate entry per channel: purpose, legal basis, recipients, retention period.
  • Processor agreements under Article 28 with every supplier that sees patient data. That is more of them than you think: booking software, app provider, email tool, WhatsApp provider, cloud backup, review service.
  • A transfer overview under Articles 44 and following. Push runs through Apple and Google, and many email tools sit in the United States. Check whether the provider relies on the EU-US Data Privacy Framework and keep standard contractual clauses ready otherwise.
  • Article 13 privacy information at the point of collection, meaning right at the form, not only somewhere in the legal notice.
  • A deletion policy that names a period for each data type and names who executes it.

Add one organisational decision that costs nothing: one named person owns consent. Not "marketing" and not "reception", but a name.

Consent documentation being reviewed at a clinic desk
Five well-maintained documents beat a thick compliance folder nobody opens.

Retention and deletion

Deletion is the piece almost every clinic postpones, because deleting feels like loss. It is also the piece with the best effort-to-benefit ratio, because data you no longer hold cannot leak.

  • Treatment records: section 630f of the German Civil Code sets ten years after the treatment concludes, unless professional or radiation-protection rules require longer.
  • Consent evidence: there is no fixed statutory period. The workable approach is to keep the evidence for as long as you rely on the consent, plus the general three-year limitation period afterwards so you can defend a claim.
  • Withdrawals: the withdrawal itself has to stay documented while the marketing data goes. What you need is a genuine suppression list. Clinics that simply delete withdrawn contacts happily reimport them at the next data sync, and that is where it gets expensive.
  • Campaign data: open and click logs need a period too. A few months is ample for analysis.

Then there is the case aesthetics sees most often: the patient who came once years ago, never opens, never responds. Either you run one clean re-permission message and she signs up again, or she should be deleted. A list that is one third dead weight damages your deliverability as much as your compliance.

The everyday clinic check

If you only have an hour, work through these seven questions.

  • Does every marketing message from the past twelve months have documented, timestamped consent?
  • Can push, email and WhatsApp be consented to and unsubscribed from separately?
  • Does no appointment reminder contain an offer?
  • Does no message name a treatment where "your appointment" would do?
  • Is there a processor agreement for every tool that touches patient data?
  • Is there a suppression list for withdrawals that applies on every import?
  • Does a named person know where the consent records live?

Answer yes to all seven and you have removed most of the risk from your communication without giving up a single channel.

One practical note: little of this survives in a spreadsheet. It belongs in the system that actually sends the messages. What to look for when choosing one: consent recorded separately per channel and per purpose, with a timestamp and the version of the form that was agreed to, and a withdrawal that is as easy for the patient as the opt-in was. Check that concretely with any vendor rather than assuming it.

Please note: this article is practical orientation for clinic owners, not legal advice. For your specific situation, particularly with multiple sites or locations in Austria and Switzerland, have your processes reviewed by a qualified lawyer or an external data protection officer.

Frequently asked questions

Do I need consent for a plain appointment reminder?

Generally no, as long as it relates to the booked appointment and carries no advertising. It rests on performance of the treatment contract. The moment an offer travels with it, the classification changes.

Is a signature on the intake form enough for marketing consent?

Only if that form contains a clearly separated section naming channels and purposes, ticked actively. A blanket signature at the end of a multi-page form does not cover advertising.

Can we use WhatsApp at all?

Yes, but in practice only through the WhatsApp Business Platform with a processor agreement, no address book synchronisation and documented opt-in. The free Business app on the clinic handset is the problematic route.

How long may I keep an email address for marketing?

For as long as the consent holds and you genuinely use it. An address that has not responded in years should be re-permissioned or deleted. Keep the consent evidence itself for the general limitation period beyond that.

What happens on withdrawal?

Marketing stops immediately, the contact goes on a suppression list, and the withdrawal is documented. Appointment and billing communication is unaffected, because it rests on a different legal basis.

Try Zovi

Klarna, memberships, and AI campaigns, all in one app for your clinic.

Book a demo
GDPR-Compliant Patient Communication: What Clinics Must Get Right for Push, Email and WhatsApp | Zovi Blog