As soon as someone writes in your contact form what's troubling them, or you hold initial consultations by email, you are processing health data — the most sensitive data category in European law. The standard privacy policy from a WordPress plugin or from eRecht24 usually doesn't mention Article 9 GDPR with a single word. This is not a marginal issue but a structural risk.
What is Article 9 GDPR — and why does it concern you?
The General Data Protection Regulation distinguishes between ordinary personal data (name, email, address) and special categories. The latter enjoy special protection — because their unwanted disclosure can cause people particular harm.
Article 9 (1) GDPR explicitly lists these specially protected categories: health data come first, even before biometric data, religious affiliation or political beliefs. For practitioners, therapists and coaches this means:
This is health data under Article 9 GDPR
Descriptions of physical or psychological complaints in the contact form
Information about diagnoses, illnesses or medications in emails
Booking requests that name the reason for the treatment
Intake forms and case histories — digital or scanned
Notes from initial or follow-up consultations that you store digitally
Photos of clients in a therapeutic context
This concerns not only your practice software. It concerns your website — as soon as there is a contact form on it through which clients describe why they want to come to you.
Why isn't a standard privacy policy enough?
A generic privacy policy — as produced by generators from eRecht24, Datenschutz.org or the legal-notice plugin for WordPress — typically covers the following points: hosting provider, Google Fonts, contact form, cookies, social-media links.
That is sufficient for an online shop or a service company. For a practitioner, the decisive part is missing:
| Standard template contains | What practitioners additionally need |
|---|---|
| General note about contact-form data | Explicit mention of Article 9 GDPR and health data as a special category |
| "Data is not passed on to third parties" | Legal basis for processing health data (Article 9 (2) (a) or (h) GDPR) |
| General retention period | Erasure concept for treatment data (GoBD, retention periods in healthcare) |
| Hosting details | Proof of EU-compliant hosting without third-country transfer |
| — | Note on the duty of confidentiality as a data-protection supplement |
The core legal problem
The processing of health data is in principle prohibited under Article 9 (1) GDPR — unless one of the exceptions in paragraph 2 applies. Without explicitly naming this legal basis in your privacy policy, you have no documented legitimacy for the processing. That is a gap — not a trivial matter.
The contact form as a data-protection weak point
The contact form is present on every practitioner website. It is also the most common point at which Article 9 GDPR is breached — often unnoticed.
The problem with free text fields
A form with a free text field like "Your concern" or "What brings you to me?" invites clients to enter health information. As soon as that happens, you are processing health data under Article 9 GDPR — whether you wanted to or not.
The legal basis for this must be transparent before submission: in a mandatory field with a consent declaration that explicitly refers to the processing of health data. A simple "I agree to the privacy policy" is not sufficient.
Correct wording of the consent
This is what a legally compliant consent could look like
"I agree that the information I provide, including possible health information, may be stored and processed to handle my enquiry. This is done in accordance with Article 9 (2) (a) GDPR on the basis of my explicit consent. I can withdraw this consent at any time."
This consent must appear as a separate, actively tickable checkbox in the form — not pre-filled, not integrated into the general data-protection notice.
Hosting: why the server location matters
Many cheap hosting offers run on servers in the USA — or use US content delivery networks. For ordinary websites this is a grey area. For practitioner websites with health data it is a concrete risk.
The reason: Article 44 ff. GDPR governs data transfer to so-called "third countries" — i.e. states outside the EU/EEA. For the USA, a transitional arrangement has existed since the Schrems II ruling (CJEU 2020) and the subsequent EU-US Data Privacy Framework agreement, but legal uncertainty remains.
Concretely for practitioners
Hosting in Germany or the EU avoids this uncertainty entirely. For health data — the most sensitive data category — EU hosting is the only truly risk-free choice. This also applies to your email provider if you receive health-related enquiries by email.
These often-overlooked services on practitioner websites are also critical:
- Google Fonts (embedded directly): Transmits IP addresses to Google servers in the USA — subject to legal warnings since the Munich Regional Court ruling of 2022
- Google Analytics / Meta Pixel: Profiling services that do not belong on practitioner websites without explicit consent
- Calendar tools (Calendly, Acuity): US providers that store booking data including the enquiry text on US servers
- WhatsApp Business: End-to-end encrypted, but metadata flows into Meta's infrastructure
What are the consequences of GDPR violations?
GDPR violations have been penalised since 2018 — and the supervisory authorities have become more active. For small practices and individuals the fines remain manageable, but legal warnings from competitors or consumer-protection associations are possible at any time.
On top of that: every affected person — that is, every client who has ever transmitted data via your website — has a right of access (Article 15 GDPR), a right to erasure (Article 17 GDPR) and a right to data portability (Article 20 GDPR). Anyone without clean documentation can hardly meet these claims.
What a complete GDPR solution for practitioners includes
A truly GDPR-compliant practitioner website needs more than a generated text. It needs a well-thought-out system:
Checklist — GDPR-compliant practitioner website
✓ Privacy policy with an explicit Article 9 module (health data as a special category)
✓ Statement of the legal basis for processing health data (Article 9 (2) GDPR)
✓ Contact form with separate, active consent for health data
✓ EU hosting — verifiably in Germany or the EU, no US third-country transfer
✓ Google Fonts self-hosted (no direct call to Google)
✓ No tracking without consent (no Google Analytics, no Meta Pixel)
✓ Cookie notice only where technically necessary — no cookie banner as an "alibi"
✓ Erasure concept for contact enquiries and booking data documented
✓ Legal notice complete under § 5 DDG (incl. the competent supervisory authority)
✓ Record of processing activities kept under Article 30 GDPR
Want to check your own website point by point? The GDPR checklist for practitioner websites takes you through legal notice, privacy policy, Google Fonts, cookies, contact form and hosting in 20 steps — with an evaluation and concrete next steps.
Cookies and tracking — what is really allowed
Most practitioner websites don't need a big cookie banner. They need a clear concept. The difference:
Technically necessary cookies (session, form protection, language setting) may be set without consent. They need a notice, but no active opt-in.
Analytics and marketing cookies (Google Analytics, Meta Pixel, Hotjar, LinkedIn Insight Tag) require active, voluntary consent before the cookie is set. A banner that makes it hard for users to decline, or even hides the option, has been impermissible since the CJEU ruling (Planet49, 2019).
My advice for practitioners
Do without tracking tools that require consent. You don't need Google Analytics to know whether your website works. The number of initial-consultation enquiries is a clearer signal than any bounce rate. Less tracking means less legal risk — and more trust from clients who handle their privacy more sensitively.
Frequently asked questions about GDPR for practitioners
Yes. The GDPR applies to anyone who processes personal data of natural persons — regardless of business size or legal form. As a self-employed practitioner with a website you are fully subject to the GDPR. The only exception is for purely private, non-professional use.
For an ordinary service website yes, with limitations. For practitioners no. The eRecht24 template contains no module for processing health data under Article 9 GDPR and no specific legal basis for processing health data. This gap has to be added by hand — which requires a specialist lawyer or a specialised agency.
Under Article 30 (5) GDPR, companies with fewer than 250 employees are exempt from the recording obligation — but only if the processing poses no risk to data subjects and no special data categories are involved. Since practitioners process health data (Article 9 GDPR), the exemption does not apply. A record of processing activities is mandatory.
Practice software does not fall under your website privacy policy — it needs its own processing bases and possibly a data processing agreement (DPA) with the software provider under Article 28 GDPR. That is a separate topic you should clarify with your software provider. For the website: cleanly separate website data from treatment data.
GDPR-compliant from the start — not as an afterthought.
In a free initial consultation we look together at whether and how I can help you. No pressure, no obligation.
Book a free initial consultation