Policy

Data Protection, Privacy & PECR Marketing Consent Policy

Transparency to patients, lawful bases for processing health and image data, and compliant consent for electronic marketing in an aesthetic clinic

For Aesthetic ClinicRef BS-AES-POL-013See a sample (PDF) →
£54.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This policy is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Policy statement and data protection principles
  • 4. Definitions
  • 5. Lawful bases for processing patient data
  • 6. The privacy notice and the duty of transparency
  • 7. Direct marketing by electronic mail and text (PECR)
  • 8. Photographs, before and after images and testimonials
  • 9. Website cookies, pixels and analytics
  • 10. The rights of patients (data subjects)
  • 11. Children's data and consent
  • 12. Sharing data with prescribers, GPs and processors
  • 13. The ICO data protection fee and registration
  • 14. Roles and responsibilities
  • 15. Training and awareness
  • 16. Monitoring, audit and compliance
  • 17. Related policies
  • 18. Review and version control
  • Appendix A: Marketing and consent compliance checklist
  • Appendix B: Consent to use of images and testimonials (template)
  • 19. Disclaimer

Legislation & standards it maps to

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • Data Protection (Charges and Information) Regulations 2018 (the Information Commissioner's Office data protection fee)
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - Regulation 17 (Good governance)
  • Care Quality Commission (Registration) Regulations 2009 - Regulation 18 (Notification of other incidents)
  • Botulinum Toxin and Cosmetic Fillers (Children) Act 2021
  • Common Law Duty of Confidentiality
  • Information Commissioner's Office (ICO) guidance on direct marketing, on cookies and similar technologies, and on the right of access

Who it applies to

All directors, registered managers, prescribers, practitioners (medical, nursing, dental and non-medical injectors), reception and administrative staff, locums, students, contractors, third-party marketing agencies and social media managers, and any data processor acting on behalf of [Organisation Name]

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Adequacy decision
A formal finding that a country outside the United Kingdom protects personal data well enough for data to be sent there without extra safeguards.
Article 28 (UK GDPR)
The part of the data protection law that says what must be written into any contract with a company that handles personal data on your behalf.
Article 6 (UK GDPR)
The part of the data protection law that lists the lawful reasons an organisation is allowed to use someone's personal data.
Article 9 (UK GDPR)
The part of the data protection law that adds extra conditions before more sensitive information, such as health data, may be used.
Botulinum toxin
A prescription-only medicine injected to relax muscles and soften lines, commonly used in cosmetic treatments.
Botulinum Toxin and Cosmetic Fillers (Children) Act 2021
The law that makes it an offence to give botulinum toxin or cosmetic dermal filler treatment to anyone under 18 for cosmetic reasons in England.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Common law duty of confidentiality
The long-standing legal duty, built up through court decisions, to keep information given in confidence private and use it only for proper purposes.
Consent (UK GDPR)
Clear, freely given agreement to the use of one's personal data, shown by a positive action and just as easy to take back as to give.
Cookie
A small file or identifier a website places on a device to store or read information, for example to remember settings or track activity.
Data controller
The organisation that decides why and how personal data is used; here, the Clinic.
Data minimisation
The principle of collecting and keeping only the personal data that is actually needed for the purpose.
Data processor
A company that handles personal data on the controller's instructions, such as an email platform or booking system provider.
Data Protection Act 2018
The United Kingdom's data protection law that works alongside the UK GDPR, including extra rules for sensitive data.
Data protection by design and by default
Building privacy protections into new systems and processes from the start and setting them to the most protective option automatically.
Data Protection (Charges and Information) Regulations 2018
The law requiring most organisations that use personal data to register with, and pay an annual fee to, the Information Commissioner's Office.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data subject
The living individual that personal data is about, such as a patient or enquirer.
Dermal filler
A gel-like substance injected under the skin to smooth lines or add volume in cosmetic treatments.
Direct marketing
Advertising or promotional material aimed at particular individuals, for example a promotional email, text, call or letter.
Explicit consent
A stronger form of consent given by a clear, express statement, such as a signed form, needed for sensitive data like published clinical images.
General practitioner (GP)
A doctor who provides general medical care in the community and is often a patient's main point of contact for health matters.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting out the fundamental standards that providers of regulated care must meet, enforced by the Care Quality Commission.
Information Commissioner's Office (ICO)
The United Kingdom's independent regulator for data protection and privacy, which can investigate and fine organisations.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Intense pulsed light (IPL)
A skin treatment that uses broad-spectrum light to target conditions such as pigmentation, redness or unwanted hair.
International Data Transfer Agreement / UK Addendum
Standard legal documents used to protect personal data when it is sent to a country outside the United Kingdom.
Lawful basis
One of the legally recognised reasons an organisation must have before it may use someone's personal data.
Legitimate interests
A lawful basis allowing data use for a genuine business reason, provided it does not override the individual's rights and expectations.
Nominated Individual
The senior person responsible to the regulator for supervising how a service is provided.
Personal data
Any information that identifies or can identify a living person, such as a name, contact details or photograph.
Pixel (tracking pixel)
A tiny piece of code on a website or in an email that records when it is opened or viewed, often used for advertising and analytics.
Prescription-only medicine (POM)
A medicine that may lawfully be supplied only on the instruction of an appropriate prescriber.
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
The law governing electronic marketing, cookies and similar technologies, sitting alongside the UK GDPR.
Privacy notice
A clear statement telling people what personal data an organisation collects, why, and what their rights are.
Processing
Any action taken with personal data, including collecting, storing, using, sharing, publishing or deleting it.
Record of Processing Activities (ROPA)
A written record of all the ways an organisation uses personal data, including the purposes and lawful bases.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulated activity
A type of care or treatment the law requires a provider to register with the regulator to deliver.
Retention schedule
A documented timetable setting out how long different records are kept before they are securely destroyed.
Soft opt-in
A narrow exception that lets a business email or text existing customers about similar products, provided they were given a chance to opt out and can opt out in every message.
Special category data
More sensitive personal data, including information about health, that needs extra protection under the law.
Subject access request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
Suppression list
A record of people who have opted out of marketing, kept so that they are not contacted again by mistake.
Telephone Preference Service (TPS)
A register people can join to stop unsolicited live marketing calls; it is generally unlawful to call numbers listed on it for marketing.
UK General Data Protection Regulation (UK GDPR)
The United Kingdom's main data-protection law governing how personal information is collected and used.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyAdverse Event Management Policy£54.99
PolicySafeguarding Policy£54.99
PolicyComplaints Policy£54.99
PolicyConsent & Risk Disclosure Policy£54.99

Need the whole set?

Buy the full Aesthetic Clinic pack and save versus buying documents individually.

View the Aesthetic Clinic pack