MSR-03 · Measurement and data

Data protection readiness assessment for clinic marketing

Twelve criteria for assessing how a clinic handles personal data in its marketing, from consent mechanisms to retention and supplier arrangements.

By the Rank My Clinic assessment desk· ·1664 words· 12 criteria

What this instrument establishes

This assessment covers how a clinic handles personal data in marketing: the basis for processing, consent mechanisms, privacy information, special category data, the mailing list, supplier arrangements, security, retention, subject rights, breach readiness, records of processing and staff awareness. Twelve criteria are scored 0 to 3. It is a structured self-check and not legal advice.

Marketing data in a clinical setting is not ordinary marketing data

The distinguishing feature of clinic marketing is that the data is rarely as innocuous as it looks. An enquiry form asking which treatment somebody is interested in has collected information about their health concerns. A tag on a mailing list recording that a subscriber is interested in a procedure has recorded the same thing. That information attracts additional protection, and it frequently sits in tools designed for retail email.

This is the finding that matters most in the lowest band, and it is why criterion four exists separately. A clinic can have functioning consent, an accurate notice and defined retention, and still be holding health information in a system nobody thought of as clinical.

The same point applies to imagery collected through marketing routes, which the imagery governance scorecard covers. The second distinguishing feature is provenance. Marketing lists in this sector accumulate: an old event, a competition, a previous owner, an imported spreadsheet. Each addition seemed reasonable at the time and none is documented, so the clinic cannot say how any given address arrived. Criterion five scores that, and it is the criterion clinics most often score 0 on while believing otherwise.

The reference points are the ICO's guidance for organisations and its guidance on direct marketing and electronic communications, both of which are written for people who are not lawyers.

How to score this assessment

Start by drawing the data flows. Where does personal data enter marketing systems, from which forms, into which tools, and who can see it. Most clinics find at least one flow nobody had documented, usually a form feeding a tool somebody set up and left.

For criterion two, look at the actual consent mechanism. Pre-ticked boxes, consent bundled with terms, and consent that is harder to withdraw than to give all score 0. Test the withdrawal route yourself.

For criterion five, take a sample of fifty addresses from your list and attempt to establish how each was obtained. Score by the proportion you can trace.

For criterion seven, list every tool and supplier that touches personal data and check that a written arrangement exists for each. Free tools count.

For criterion ten, run a test subject access request through your own process and time it. Clinics that have never tested this routinely discover the data is in more places than the process anticipated.

Common scoring errors

Treating treatment interest as ordinary contact data. It indicates a health concern. Criterion four scores whether that has been recognised.

Scoring consent by the presence of a checkbox. The criterion asks whether consent was freely given, specific, recorded and withdrawable. Most checkboxes fail at recorded.

Assuming the existing customer position covers the whole list. The rules on marketing to existing customers are narrower than generally assumed and do not cover addresses collected from competitions, events or purchased sources.

Excluding free tools from supplier arrangements. A free tool processing personal data is a processor.

Setting retention periods nobody enforces. A stated period with no deletion process scores 1 at most, because the statement misdescribes what is happening.

Cleaning a list you cannot account for

The finding clinics dread is a mailing list with untraceable provenance, because the remedy looks like deleting an asset. In practice the position is less painful than it appears.

Segment the list by what you can establish. Addresses collected through a documented route with a recorded basis stay. Addresses you can trace to a competition, an imported spreadsheet or an unknown origin form a second group.

For the second group, the practical options are to seek fresh consent through a single message that makes continuing easy and does nothing else, or to remove them. Clinics that do this consistently report that the remaining list performs better, because it consists of people who chose to be there.

Then close the source. New addresses arrive with a recorded route, a recorded basis and a date, so the problem does not rebuild. This is a form change and a habit, not a project.

Finally, look at where health-related data sits and reduce it. Recording that somebody enquired about a category of treatment is often unnecessary once the enquiry is handled, and data you do not hold requires no protection. Pair this with the measurement maturity assessment, which should be read as increasing your obligations rather than merely your insight.

MSR-03

Data protection readiness assessment

What it measures
Whether personal data used for marketing is collected on a clear basis, held securely, retained for a defined period and handled by suppliers under proper arrangements.
What it does not measure
It is not legal advice and does not establish compliance with data protection law.
Scoring method
Criterion referenced. 12 criteria, each scored 0 to 3 against the descriptor given. Maximum 36.
Evidence needed
Your forms, your consent mechanism, your mailing list, your supplier contracts and your privacy information.
Working time
Around 90 minutes.
Who should score it
Whoever is accountable for data protection, with whoever runs marketing.
Band scale
  • 0 Absent
  • 1 Emerging
  • 2 Established
  • 3 Embedded
  1. 01

    Basis for processing is identified

    For each marketing use of personal data, the lawful basis is identified and recorded. Score 0 if unexamined, 3 if documented per use.

  2. 02

    Consent mechanisms work

    Where consent is relied on, it is freely given, specific, recorded and as easy to withdraw as to give. Score 0 if pre-ticked or bundled, 3 if genuine and recorded.

  3. 03

    Privacy information is accessible and accurate

    The notice describes what actually happens, in plain terms, where people will see it. Score 0 if generic or absent, 3 if specific, current and linked at the point of collection.

  4. 04

    Special category data is identified

    Health data collected through marketing routes is recognised as such and handled accordingly. Score 0 if treated as ordinary contact data, 3 if identified and handled with the additional care required.

  5. 05

    The mailing list has provenance

    Every address on the list can be traced to how it was obtained. Score 0 if provenance is unknown for any portion, 3 if traceable throughout.

  6. 06

    Electronic marketing rules are followed

    Marketing messages comply with the rules on unsolicited electronic communication, including the position on existing customers. Score 0 if unexamined, 3 if the position is documented per list.

  7. 07

    Supplier arrangements are documented

    Every supplier processing personal data does so under a written arrangement. Score 0 if any is informal, 3 if all are documented.

  8. 08

    Security is proportionate

    Access to marketing data is limited, protected and reviewed. Score 0 if lists circulate by email or live on personal devices, 3 if access is controlled and reviewed.

  9. 09

    Retention is defined and applied

    How long each category is kept, and why, with deletion actually happening. Score 0 if data is kept indefinitely, 3 if defined and enforced.

  10. 10

    Subject rights can be honoured

    Requests for access, erasure or objection can be met within the statutory period. Score 0 if untested, 3 if a process exists and has been exercised.

  11. 11

    Breach readiness

    Somebody knows what to do, whom to tell and within what period if data is lost or exposed. Score 0 if unaddressed, 3 if documented and rehearsed.

  12. 12

    Records and awareness

    A record of processing activities exists and staff who handle data know the basics. Score 0 if neither, 3 if the record is current and staff have been briefed.

Total score 0/ 36 Not yet scored

Scoring runs in your browser and nowhere else. Nothing is saved, nothing is sent to us, and closing the page clears it. Print this page to fill the instrument in on paper.

Band interpretations

0 to 12Absent

Personal data is being used for marketing without a clear basis, with unknown provenance and no retention limit. Health information may be sitting in ordinary marketing systems.

Next action. Establish where health data sits in your marketing systems and deal with that first. It is the most serious finding this assessment produces.

13 to 21Emerging

Basic mechanisms exist and the detail does not. Consent is collected but not recorded, notices exist but do not describe what happens, retention is intended rather than applied.

Next action. Record consent properly, rewrite the privacy information to describe reality, and set retention periods you will actually enforce.

22 to 30Established

Practice is sound. Gaps are usually supplier documentation, subject rights testing and breach readiness.

Next action. Document supplier arrangements, run a test subject access request, and write the breach procedure down.

31 to 36Embedded

Bases are identified, consent is genuine and recorded, health data is handled appropriately, suppliers are documented, retention is enforced and rights can be honoured.

Next action. Re-assess annually and whenever a new tool, supplier or data flow is introduced.

Measurement and data instrument MSR-03. Bands are criterion referenced: they describe your operation against the descriptors above, not against any other clinic. No comparative benchmark for UK aesthetic clinics is published, so this instrument does not pretend to one.

What this instrument does not tell you

  • Whether you comply with data protection law. This is a structured self-check, not a legal assessment.
  • Whether your privacy notice is legally sufficient. It scores whether the notice describes what actually happens.
  • What your retention periods should be. That depends on your clinical and legal obligations.
  • Whether a specific processing activity is lawful. Specific questions need specific advice.
  • How other clinics handle this. Common practice includes several arrangements this assessment scores 0.

Every instrument on this site carries this block. An assessment that will not state its own limits is a sales document with a scale printed on it.

Questions about this instrument

Is treatment interest really health data?

Information indicating a person's health concerns generally attracts the additional protections that apply to health data, and an enquiry naming a procedure usually indicates one. This instrument scores whether the clinic has recognised the question rather than offering a legal conclusion on any specific field.

Can we email past patients about new treatments?

There are rules covering marketing to existing customers, and they are narrower than commonly assumed. The criterion scores whether you have examined and documented your position per list rather than assuming it, because the answer depends on how and when the address was obtained.

How long should we keep enquiry data?

The instrument does not prescribe a period, because clinical record obligations and marketing purposes point in different directions. What it scores is whether periods are defined per category and actually applied.

Do we need a data protection officer?

That depends on your activities and scale, and the question should be resolved against the regulator's guidance rather than by a scorecard. What every clinic needs regardless is somebody named who is accountable, which criterion twelve touches.

Our marketing is outsourced. Does that reduce our obligations?

No. The clinic remains responsible for personal data processed on its behalf, which is why criterion seven asks for written arrangements with every supplier. Outsourcing distributes work, not accountability.

Sources

  1. Information Commissioner's Office: UK GDPR guidance and resources
  2. Information Commissioner's Office: guide to PECR
  3. Information Commissioner's Office: direct marketing and privacy
  4. Care Quality Commission: guidance for providers

Disclosure. This instrument contains no commercial links of any kind. Rank My Clinic is published by Northbank Media. We do not rank clinics, we do not rank suppliers, and no organisation can pay to influence any criterion, band or interpretation. Nothing here is medical, legal or regulatory advice.

Related instruments

The full library
MSR-01 · Measurement

Marketing measurement maturity assessment

Measures: Whether the clinic records what it needs to record, whether the record is trustworthy, and whether anybody uses it to …

12 criteriaMax 368 min
MSR-02 · Measurement

Attribution integrity checklist for clinics

Measures: Whether the method used to assign an enquiry to a source is defined, applied consistently, and understood by the peopl…

10 criteriaMax 308 min