Data is the compliance area where an aesthetics clinic's exposure most exceeds its awareness, because the material at issue is also the material the business most wants to publish.
UK data protection law requires a lawful basis for processing personal data, and for special category data, which includes data concerning health, a separate condition must also be satisfied. Clinical records held by an aesthetics clinic will generally engage both requirements.
Photographs are personal data where the individual is identifiable. Where an image is taken for the purpose of recording a clinical condition or its treatment, it is capable of being health data, which places it in the special category tier with everything that follows.
ObservedThe Information Commissioner's Office publishes guidance on lawful basis, on special category data and on photography, and it is directly applicable to this setting.AnalysisThe common structural error is treating clinical images as a marketing asset with a consent tickbox attached, rather than as health data that happens to be useful in marketing.Separate the two consents completely: consent to clinical photography for the record, and a distinct, specific, withdrawable consent for any publication. One document doing both jobs will fail at the moment it matters.
Before and after imagery is the sector's highest performing content type and its most exposed. Every published image is a data processing operation with an identifiable person at the other end of it.
The exposure compounds over time. Images published years ago remain indexed, are copied to third party sites, and are now ingested by systems that will reproduce them in contexts the patient never contemplated. Withdrawal of consent does not un publish what has already been copied.
ObservedConsent under UK data protection law must be as easy to withdraw as to give, and withdrawal must be actionable by the controller.AnalysisA clinic that cannot locate every published copy of a patient image cannot honour a withdrawal, which means the consent it obtained was not really withdrawable.SpeculationAs image provenance and content scraping become more visible issues generally, we would expect patient willingness to consent to publication to decline. That is a reasoned expectation, not a measurement.Keep a register of every published patient image: where it was published, when, under which consent, and where else it has been syndicated. If you cannot produce that register, you have a data problem you have not yet been asked about.
Professional regulators address confidentiality and the use of patient images in their standards, and the requirements are generally stricter than the data protection floor.
For a registered practitioner, therefore, there are two overlapping obligations with different enforcement mechanisms: the regulator, which can affect registration, and the information regulator, which can affect the organisation. A practitioner can satisfy the second and breach the first.
ObservedProfessional regulators publish standards on confidentiality and on the use of images of patients, separate from and additional to data protection law.If you are registered, your regulator's standard is the binding one, because it is the one attached to your ability to practise. Compliance with data protection law is not a defence to a professional standards question.
The question appearing now is what happens to my photographs, asked at the point of clinical photography rather than at the point of publication.
It is a well informed question and most clinics answer it badly, because a complete answer requires knowing the retention period, the storage location, who has access and what happens if the clinic is sold. Those are four facts and most businesses hold none of them in writing.
AnalysisThe sale question is the one nobody has considered. Patient records and images are an asset in a transaction and their transfer is a processing operation requiring its own analysis.SpeculationAs consolidation continues, the transfer of patient data on acquisition is an obvious area for scrutiny. We are not aware of it being tested in this sector and it looks untested rather than settled.Write a one page patient facing note answering the four questions: how long, where, who can see it, and what happens if the business changes hands. It takes an afternoon and it answers the question better than any privacy policy.
"Your data is safe with us." Not a statement with content. "GDPR compliant." Not a certification, not awarded by anyone, and not verifiable. "Anonymised before and after photographs." Cropping a face is not necessarily anonymisation. Identifiability is a practical test, and distinguishing features, backgrounds, tattoos and context all bear on it.
Reviews and testimonials reproduced with a patient's first name and treatment. That is health data about an identifiable person published for marketing purposes, and it needs its own basis.
ObservedAnonymisation is assessed on whether an individual can be identified by reasonably likely means, taking account of all information available, not on whether a face is visible.The test for an image is not whether you can see the face. It is whether anyone who knows the person could recognise them. That is a much lower bar than most clinics assume.
Data compliance is a pure cost with no revenue attached, which is why it is chronically underinvested in across every small business sector, not only this one.
The asymmetry is that the cost of getting it right is small and bounded, while the cost of getting it wrong is unbounded and lands at the worst possible time, usually alongside a clinical complaint from the same patient.
AnalysisData complaints in this sector rarely arrive alone. They arrive as the second front in a dispute that started as a clinical or a refund issue, which is why the data position matters most exactly when everything else has already gone wrong.SpeculationThe most likely trigger for a data complaint against an aesthetics clinic is a patient asking for an image to be removed and not receiving a satisfactory response. That is a mechanism we would expect to dominate, though we have no complaint statistics for this sector.Practise the removal request. Have someone ask for an image to be taken down and time how long it takes and how completely it can be done. That exercise will tell you more about your exposure than any audit.
The direction is towards more patient awareness rather than towards more enforcement, and patient awareness is the more consequential of the two for a small business.
A regulator acts on a complaint. A patient acts on a Google search. The volume of the second is orders of magnitude higher and the response time expected is far shorter.
SpeculationSubject access requests and erasure requests in consumer facing health adjacent businesses appear to be rising as awareness spreads. We cannot quantify it for this sector.AnalysisA clinic that can answer a subject access request within a month, completely, without disruption, has effectively demonstrated that its record keeping is in order. Most cannot, and the request is how they find out.Run a subject access request against your own clinic as an exercise. Whatever you find is what a patient would find, and you would rather find it first.