← All articles
Regulation

Medical Website GDPR Compliance: Forms, Chat and Patient Photos

Forms, chat, photo uploads, before/after galleries: medical website GDPR compliance is decided channel by channel. A practical audit to keep your clinic site legal.

NextmotionAugust 24, 20268 min read
Protecting health data on an aesthetic clinic website: forms, chat and patient photos under the GDPR.

Your medical website is a forgotten door into health data

When a practitioner thinks about compliance, they think about their clinical software, their consent forms, their patient records. Almost never about their website. Yet the moment a visitor fills in a form, opens a chat bubble or uploads a photo, your site starts collecting health data — the most protected category under the GDPR. Medical website GDPR compliance doesn't begin in your treatment room; it begins on the first line of your contact page.

This isn't a theoretical detail. A reason for booking, a question typed into a chatbot, a photo of an area to be treated: each of these reveals someone's health status or intention to seek care. This article walks through, channel by channel, the places where your website crosses the line, and what the regulation then requires. For the broader picture of patient data, see our GDPR and patient data guide — here, we stay strictly on the website.

Health data starts long before the medical record

The GDPR places health data in the "special categories" of its Article 9. These categories get heightened protection: processing them is prohibited in principle, unless a specific exception applies (explicit consent, provision of medical care, and so on). The European Commission is explicit that data revealing a person's health counts as sensitive personal data.

This is where many websites cross over without realising it. "I'd like an appointment for hyaluronic acid injections," typed into a form, is not a neutral message: the reason reveals an intention to seek care. A face photo sent before a consultation is health data, and potentially biometric. Once special-category data is involved, medical website GDPR compliance requires a clear legal basis, transparent information, and appropriate security. Nextmotion's GDPR and security page sets out the framework these data are handled in.

A channel-by-channel audit: where your site collects health data

The contact form and online booking

A single "reason for your request" field turns your form into health-data collection the moment a patient describes their concern. Three duties follow: minimisation (ask only for what you truly need — an open field inviting a detailed medical account is best avoided), information (purpose, retention period, rights of access and erasure), and the question of where the data lands. That last point — hosting — deserves its own decision, and we come back to it below.

Live chat and chatbots

A live chat or chatbot where a patient types "I have persistent redness, could laser help?" collects health data too. If the tool comes from a third-party provider, the conversation transits and is stored on their systems: you need a data processing agreement (DPA), a guarantee of appropriate hosting, and clear notice to the visitor. A chatbot isn't off-limits — it simply has to be treated as a health-data channel, not a marketing gadget.

Patient photo uploads

More and more sites invite patients to send a photo for an initial opinion. This is the most sensitive channel of all: an image of a body area is health data, and often identifying. A controlled, encrypted upload tied to the right record is far better than a link that dumps files into a generic inbox.

Before/after photos: the double filter of GDPR and professional rules

Publishing a before/after gallery is no longer collection but disclosure — and it stacks two requirements. Under the GDPR, publishing a patient's photo requires explicit, specific consent to that disclosure, separate from consent to treatment. On top of that, professional codes add their own layer. In France, for instance, Article 19-1 of the French medical ethics code (code de déontologie), enforced by the CNOM medical council, states plainly that patients must not be identifiable in published photos or videos, that before/after images must not imply a guarantee of results, and that patient testimonials are not allowed.

In practice, a compliant gallery means reliable blurring, neutral framing and a traceable consent record. That is exactly what a dedicated capture system solves: Nextmotion Capture automatically blurs eyes, removes the background and files each shot to the right patient, off your personal camera roll. For the photography method itself, see our article on standardizing before/after photos.

WhatsApp and email: the out-of-bounds reflex to fix

Receiving patient photos on WhatsApp or in a personal inbox is a common reflex — and it sits outside any controlled framework. These consumer messaging tools move and store health data on servers you don't control, often outside the European Union, with no isolation or audit trail, mixed in with your private conversations. Immediate convenience creates a lasting compliance debt.

The better practice is to bring these exchanges back into a controlled channel. A secure patient portal lets patients send questionnaires, documents and photos into a space tied to their record, rather than into a WhatsApp thread. Clinical images, meanwhile, belong in a capture system built for them — not in a phone gallery.

Where does hosting fit in?

As soon as your website collects health data, "where is this data hosted?" becomes an infrastructure decision in its own right, not a checkbox. Different jurisdictions frame this differently — in France, the HDS (health-data hosting) standard governs it, and a host can be certified against it. It's a big enough topic to deserve separate treatment, so we won't get into the technical detail here. Just know that your site, chat and photo uploads are better served by an infrastructure built to meet HDS requirements and the GDPR, with data kept in Europe. The European Data Protection Board's guidelines are the reference point for how these obligations are interpreted across the EU.

Your GDPR checklist for a medical website

  • Map every collection point: forms, chat, uploads, newsletter, online booking — list everything that can receive health data.
  • Legal basis and notice: for each channel, a purpose, a retention period and a clear statement of the patient's rights.
  • Minimisation: remove fields that invite a detailed medical account on the site; that level of detail belongs in the consultation.
  • Dedicated image consent: for any published photo, a specific, revocable, documented consent.
  • Processors under contract: a signed DPA with every provider (chat, form, host) that touches this data.
  • A secure channel for photos: a portal or dedicated system instead of WhatsApp and email.
  • Appropriate hosting: encryption in transit, data in Europe, infrastructure aligned with health-data requirements.

FAQ: medical websites and GDPR

Are patient photos considered health data under GDPR?

Yes. An image of a body area for a medical purpose reveals information about a person's health, and often identifies them, which places it in the GDPR's special categories. It calls for a legal basis, clear information, secure storage and — if published — explicit, specific consent.

Can patients send photos to my clinic by WhatsApp or email?

It's common, but it's outside a controlled framework. Consumer messaging tools store health data on servers you don't control, often outside the EU, with no isolation or audit trail. A secure patient portal or a dedicated capture system tied to the record is the compliant alternative.

What consent do I need for before and after photos on my website?

Explicit, specific consent to publication, separate from consent to treatment, and revocable. Professional rules add more: in France, the CNOM requires that patients not be identifiable and that images don't suggest a guarantee of results — so reliable blurring and documented consent are essential.

Is a contact form on a medical website special category data?

If the form captures information revealing health status — a reason for booking, for example — then yes, it processes special-category data. That triggers minimisation, clear notice, a proper legal basis and appropriate hosting for what the form collects.

Put your site right without losing your evenings

Getting medical website GDPR compliance right isn't one more burden: it's the assurance that the trust your patients place in your practice doesn't leak out between a misconfigured form and a WhatsApp thread. Forms, chat, photo uploads and before/after galleries — each channel is secured with the right tools and the right hosting. Request a demo to see how Nextmotion helps aesthetic clinics handle patient data within a controlled framework, from the patient portal to medical photography.

Also worth reading

Put it into practice with Nextmotion.

See the platform at work in a real clinic setting with one of our specialists.