In 2025, controllers in Poland reported 22,435 personal data breaches to the supervisory authority, up from 14,842 a year earlier, while total fines climbed from PLN 13.9m to nearly PLN 64.5m. At the same time, the regulator put organisations processing health data, including medical practices and dental clinics, on its 2025 sectoral inspection plan. For an aesthetic clinic the implication is blunt: the client list you text about a botulinum toxin promotion is a health data set, and it sits under a stricter regime than a cosmetics shop's mailing list.
This is not legal advice. It is an operating tool: a matrix that settles what you may send, to whom, and on what basis, plus an audit you can run in half an hour.
Why an aesthetic clinic plays on a harder pitch
Three things separate a clinic from ordinary e-commerce.
- Health data. The fact that someone had a botulinum toxin treatment or an acne consultation is special category data under Article 9 GDPR. Processing it is prohibited by default, and the exemptions are narrow.
- A double consent regime. Marketing needs a GDPR basis and a separate channel consent under electronic communications law for SMS, email, messaging apps and phone calls.
- Two regulators. GDPR is enforced by the data protection authority, the channel by the telecom regulator. One campaign can breach both at once.
What changed on 10 November 2024
That is when Poland's Electronic Communications Law replaced the old telecom act. Its Article 398 bans sending commercial information, direct marketing included, by email, SMS, messaging apps or automated calling systems without the recipient's prior consent. The changes that hit clinics hardest:
| Item | Position after 10 Nov 2024 |
|---|---|
| Who is protected | Every recipient, companies included (previously mainly individuals) |
| Nature of consent | Express and active, never implied or inferred from silence |
| Scope of consent | Specific: channel and purpose consented to separately |
| Older consents | Still valid if they already met GDPR and the previous rules |
| Penalty | Up to 3% of annual revenue or PLN 1m, whichever is higher |
The practical takeaway: a single "I accept the terms and marketing" tickbox under your booking form is no longer a safe construction, if it ever was.
The consent matrix: purpose, channel, legal basis
This is the core. Most clinics think in terms of "we have consent or we don't". An inspector thinks in terms of "consent to exactly what, and who can prove it". Break your messaging into purposes and assign each one a basis.
| Message | Purpose | GDPR basis | Channel consent needed? |
|---|---|---|---|
| Appointment confirmation and reminder | Performance of a contract | Art. 6(1)(b) | No, it is not commercial information |
| Aftercare instructions, qualification form | Care and documentation | Art. 9(2)(h) | No |
| Newsletter with a treatment promotion | Marketing | Consent, Art. 6(1)(a) | Yes, email and SMS separately |
| "It has been 6 months since your treatment, time for a top-up" | Marketing based on health data | Explicit consent, Art. 9(2)(a) | Yes |
| Post-visit review request | Marketing | Consent or legitimate interest, depending on wording | Yes, if sent by SMS or email |
| Invoices, payments, complaints | Legal obligation | Art. 6(1)(c) | No |
Two rules follow from this table, and both are broken constantly:
- An appointment reminder is not marketing. You may send it without marketing consent. The moment you append "and by the way, 20% off mesotherapy this week", it becomes commercial information and needs channel consent.
- Segmenting by treatment is processing health data. A blast to your whole list on ordinary marketing consent is one thing. A campaign aimed at "clients who had treatment X" requires explicit consent to process health data for marketing. A generic marketing tickbox does not cover it.
A 30-minute consent audit
Seven questions. Answer each by opening your system, not from memory.
1.
Can I see the date and wording of consent on every record?
A bare yes/no in the client card is not accountability. You need a timestamp, the clause version and the source: form, front desk, landing page. 2.
Are consents split by channel?
Email and SMS are two separate consents. One combined tickbox is the most common post-reform defect. 3.
Do I hold separate consent for marketing based on treatment history?
If your automation segments by treatment name, that consent is mandatory. 4.
Is withdrawal as easy as giving consent?
An unsubscribe link in every send, STOP in SMS, and an immediate write-back to the client record. 5.
Does the Meta Lead Ads list land in the system with consent recorded?
A CSV import without a consent field is a data set you cannot defend. 6.
Who can open client records?
The 2025 sectoral inspection targeted precisely how health data is secured. A shared front desk login is the fastest way to fail that point. 7.
Do I keep a breach register?
The duty to document breaches covers the ones you do not report as well.
What inspections actually find
The EU-wide data is unambiguous. According to the GDPR Enforcement Tracker Report, authorities in 27 countries have issued 265 fines totalling roughly EUR 32.3m against healthcare organisations, and the number of new fines in 2025 ran 26% above the previous reporting period. The leading cause was not bad wording but insufficient technical and organisational measures: 100 fines worth EUR 22.8m in total, averaging over EUR 228,000 per case.
Translated to a clinic: a security policy in a binder protects nothing. Individual logins, restricted roles, encryption, backups and an access log of who opened which record do.
How to collect consent without killing conversion
The standard objection is that splitting one tickbox into three will shrink signups. In practice it shrinks list volume, not list value. Healthcare records the highest SMS opt-in rate of any industry at 49%, with average opt-out rates staying below 3.5% per send. People agree to hear from the clinic they trusted with their face. What they do not agree to is being surprised.
What works:
- Ask at the moment of value. After the visit, alongside aftercare notes, rather than on a cold landing page.
- Concrete wording instead of a legal block. "Text me when my treatment is due for a top-up and when slots open" converts better than "I consent to processing for marketing purposes".
- State the frequency. "Two messages a month at most" suppresses opt-outs, because it is over-sending rather than signup itself that empties a list.
- One source of truth. Consent captured at the desk and consent from the online form must land on the same record. Two parallel lists guarantee that somebody gets a message after unsubscribing.
FAQ
Can I send an appointment reminder without marketing consent?
Yes. A reminder about a booked appointment serves performance of the contract and is not commercial information. The condition is that it carries no offer, discount or prompt to buy again.
Are consents collected before 10 November 2024 still valid?
They remain valid if, when collected, they met GDPR and the rules then in force: freely given, specific, informed and unambiguous. A blanket "marketing" consent with no channel named is the weakest link and is worth refreshing.
Do I need consent to email business contacts, for example partners?
Yes. Since the reform, protection covers every recipient, legal persons included. A company domain is no longer a loophole.
What penalty does a small clinic realistically face?
Two tracks at once. The data protection authority can fine you for the GDPR breach, and the telecom regulator for marketing without consent, up to 3% of annual revenue or PLN 1m, whichever is higher. For a small operator the second figure is usually the binding one.
Do before-and-after photos need separate consent?
Yes. An image tied to information about a treatment is health data, and publishing it for marketing requires explicit, separate consent that can be withdrawn at any time.
Consent is a system feature, not a document
An inspection does not ask about your binder. It asks about the record: who consented, when, to what, through which channel, and who had access to it. If answering means searching through inboxes and paper cards, the problem is not the clause, it is the data architecture. In Palyri, consents are fields on the client record with change history and channel, and marketing automations read them before sending, so a "had treatment X" segment cannot reach anyone who never gave that consent. It is the cheapest way to make an audit a single view rather than a week of work.
Sources
Want to implement this in your clinic?
Book a free Palyri demo. We'll show how it works on your clinic's data.
Book demo via WhatsAppPaulina Zielińska
Konsultant w branży beauty
Ponad 4 lata doświadczenia w branży beauty: najpierw od środka jako manager kliniki, teraz jako niezależny konsultant. Wdrożyła systemy automatyzacji sprzedaży i CRM w kilkudziesięciu klinikach estetycznych w Polsce.