Legal compliance · GDPR · Data protection

GDPR for Practitioners:
What Article 9 means — and why
standard templates aren't enough.

sandhan-design.com

As soon as someone writes in your contact form what's troubling them, or you hold initial consultations by email, you are processing health data — the most sensitive data category in European law. The standard privacy policy from a WordPress plugin or from eRecht24 usually doesn't mention Article 9 GDPR with a single word. This is not a marginal issue but a structural risk.

What is Article 9 GDPR — and why does it concern you?

The General Data Protection Regulation distinguishes between ordinary personal data (name, email, address) and special categories. The latter enjoy special protection — because their unwanted disclosure can cause people particular harm.

Article 9 (1) GDPR explicitly lists these specially protected categories: health data come first, even before biometric data, religious affiliation or political beliefs. For practitioners, therapists and coaches this means:

This is health data under Article 9 GDPR

Descriptions of physical or psychological complaints in the contact form

Information about diagnoses, illnesses or medications in emails

Booking requests that name the reason for the treatment

Intake forms and case histories — digital or scanned

Notes from initial or follow-up consultations that you store digitally

Photos of clients in a therapeutic context

This concerns not only your practice software. It concerns your website — as soon as there is a contact form on it through which clients describe why they want to come to you.

Why isn't a standard privacy policy enough?

A generic privacy policy — as produced by generators from eRecht24, Datenschutz.org or the legal-notice plugin for WordPress — typically covers the following points: hosting provider, Google Fonts, contact form, cookies, social-media links.

That is sufficient for an online shop or a service company. For a practitioner, the decisive part is missing:

Standard template contains What practitioners additionally need
General note about contact-form data Explicit mention of Article 9 GDPR and health data as a special category
"Data is not passed on to third parties" Legal basis for processing health data (Article 9 (2) (a) or (h) GDPR)
General retention period Erasure concept for treatment data (GoBD, retention periods in healthcare)
Hosting details Proof of EU-compliant hosting without third-country transfer
Note on the duty of confidentiality as a data-protection supplement

The core legal problem

The processing of health data is in principle prohibited under Article 9 (1) GDPR — unless one of the exceptions in paragraph 2 applies. Without explicitly naming this legal basis in your privacy policy, you have no documented legitimacy for the processing. That is a gap — not a trivial matter.

The contact form as a data-protection weak point

The contact form is present on every practitioner website. It is also the most common point at which Article 9 GDPR is breached — often unnoticed.

The problem with free text fields

A form with a free text field like "Your concern" or "What brings you to me?" invites clients to enter health information. As soon as that happens, you are processing health data under Article 9 GDPR — whether you wanted to or not.

The legal basis for this must be transparent before submission: in a mandatory field with a consent declaration that explicitly refers to the processing of health data. A simple "I agree to the privacy policy" is not sufficient.

Correct wording of the consent

This is what a legally compliant consent could look like

"I agree that the information I provide, including possible health information, may be stored and processed to handle my enquiry. This is done in accordance with Article 9 (2) (a) GDPR on the basis of my explicit consent. I can withdraw this consent at any time."

This consent must appear as a separate, actively tickable checkbox in the form — not pre-filled, not integrated into the general data-protection notice.

Hosting: why the server location matters

Many cheap hosting offers run on servers in the USA — or use US content delivery networks. For ordinary websites this is a grey area. For practitioner websites with health data it is a concrete risk.

The reason: Article 44 ff. GDPR governs data transfer to so-called "third countries" — i.e. states outside the EU/EEA. For the USA, a transitional arrangement has existed since the Schrems II ruling (CJEU 2020) and the subsequent EU-US Data Privacy Framework agreement, but legal uncertainty remains.

Concretely for practitioners

Hosting in Germany or the EU avoids this uncertainty entirely. For health data — the most sensitive data category — EU hosting is the only truly risk-free choice. This also applies to your email provider if you receive health-related enquiries by email.

These often-overlooked services on practitioner websites are also critical:

What are the consequences of GDPR violations?

GDPR violations have been penalised since 2018 — and the supervisory authorities have become more active. For small practices and individuals the fines remain manageable, but legal warnings from competitors or consumer-protection associations are possible at any time.

up to €20 million GDPR fine (Article 83 GDPR)
500 – 3.000 € typical legal-warning costs for small businesses
100 – 1.000 € damages per affected person (Article 82 GDPR)

On top of that: every affected person — that is, every client who has ever transmitted data via your website — has a right of access (Article 15 GDPR), a right to erasure (Article 17 GDPR) and a right to data portability (Article 20 GDPR). Anyone without clean documentation can hardly meet these claims.

What a complete GDPR solution for practitioners includes

A truly GDPR-compliant practitioner website needs more than a generated text. It needs a well-thought-out system:

Checklist — GDPR-compliant practitioner website

✓ Privacy policy with an explicit Article 9 module (health data as a special category)

✓ Statement of the legal basis for processing health data (Article 9 (2) GDPR)

✓ Contact form with separate, active consent for health data

✓ EU hosting — verifiably in Germany or the EU, no US third-country transfer

✓ Google Fonts self-hosted (no direct call to Google)

✓ No tracking without consent (no Google Analytics, no Meta Pixel)

✓ Cookie notice only where technically necessary — no cookie banner as an "alibi"

✓ Erasure concept for contact enquiries and booking data documented

✓ Legal notice complete under § 5 DDG (incl. the competent supervisory authority)

✓ Record of processing activities kept under Article 30 GDPR

Want to check your own website point by point? The GDPR checklist for practitioner websites takes you through legal notice, privacy policy, Google Fonts, cookies, contact form and hosting in 20 steps — with an evaluation and concrete next steps.

Cookies and tracking — what is really allowed

Most practitioner websites don't need a big cookie banner. They need a clear concept. The difference:

Technically necessary cookies (session, form protection, language setting) may be set without consent. They need a notice, but no active opt-in.

Analytics and marketing cookies (Google Analytics, Meta Pixel, Hotjar, LinkedIn Insight Tag) require active, voluntary consent before the cookie is set. A banner that makes it hard for users to decline, or even hides the option, has been impermissible since the CJEU ruling (Planet49, 2019).

My advice for practitioners

Do without tracking tools that require consent. You don't need Google Analytics to know whether your website works. The number of initial-consultation enquiries is a clearer signal than any bounce rate. Less tracking means less legal risk — and more trust from clients who handle their privacy more sensitively.

Frequently asked questions about GDPR for practitioners

Yes. The GDPR applies to anyone who processes personal data of natural persons — regardless of business size or legal form. As a self-employed practitioner with a website you are fully subject to the GDPR. The only exception is for purely private, non-professional use.

For an ordinary service website yes, with limitations. For practitioners no. The eRecht24 template contains no module for processing health data under Article 9 GDPR and no specific legal basis for processing health data. This gap has to be added by hand — which requires a specialist lawyer or a specialised agency.

Under Article 30 (5) GDPR, companies with fewer than 250 employees are exempt from the recording obligation — but only if the processing poses no risk to data subjects and no special data categories are involved. Since practitioners process health data (Article 9 GDPR), the exemption does not apply. A record of processing activities is mandatory.

Practice software does not fall under your website privacy policy — it needs its own processing bases and possibly a data processing agreement (DPA) with the software provider under Article 28 GDPR. That is a separate topic you should clarify with your software provider. For the website: cleanly separate website data from treatment data.

Sandhan Jürgen Westphal
Sandhan Jürgen Westphal

Web designer for holistic practitioners, coaches and therapists across the German-speaking region (DACH). All websites are built with complete GDPR documentation — including the Article 9 GDPR module, EU hosting and a legally compliant contact form. As standard, at no extra charge.

GDPR-compliant from the start — not as an afterthought.

In a free initial consultation we look together at whether and how I can help you. No pressure, no obligation.

Book a free initial consultation