Guides

Booking Systems and Privacy Law: The Owner's Version

What privacy law requires of a small business taking bookings online: lawful basis, what to tell clients, health data, retention, and six checks for your tool.

5 min read
GuidesBooking SystemsPrivacy
952 words5 min read

This is the version of privacy law a business owner needs to run a booking system responsibly, written by people who set booking systems up, not by lawyers. It tells you what the questions are and what the usual answers look like. For your specific situation, especially if you handle health data or operate in several countries, a short conversation with a privacy professional is money well spent.

The laws in one paragraph each

GDPR (EU) and UK GDPR apply to any business handling personal data of people in those regions. They require a lawful basis for each use of data, transparency about what you do with it, security proportionate to the risk, limits on how long you keep it, and rights for individuals to access and delete their data. Health data is a "special category" with stricter rules. Fines exist; for small businesses the realistic risk is a complaint, a regulator's letter and the work of responding.

HIPAA (US) applies to "covered entities" (healthcare providers who bill insurance electronically, plans, clearinghouses) and their vendors. If you are a dentist, physio or therapist who bills insurance, you are likely covered, and your booking tool holding patient names and appointment types is holding protected health information. It must sign a Business Associate Agreement with you. Many general-purpose booking tools will not; healthcare-specific ones will.

Other regimes: Australia's Privacy Act, Canada's PIPEDA, various US state laws (California's CCPA/CPRA and others). Similar principles: tell people, keep it secure, do not over-collect, honour requests.

If you take bookings from people in Europe, GDPR applies regardless of where you are.

What a booking involves, legally

When someone books, you collect their name, contact details, the service and time, possibly payment details (usually held by the payment processor, not you), possibly notes or an intake form. Each piece has a purpose. The law asks you to be able to say what each is for and on what basis you hold it.

Lawful basis. For the booking itself, name, contact, appointment, the basis is "contract": you need it to provide the service. You do not need consent for that, and asking for it is a common mistake that makes consent meaningless. For marketing messages, you need consent (or, in some regimes, an existing-customer exemption for similar services, with an easy opt-out). For health information, you need explicit consent or another special-category basis.

Transparency. A privacy notice, linked from the booking form and your website, saying what you collect, why, who processes it (your booking tool, your payment processor, your email service), how long you keep it, and how people can ask for it or have it deleted. Plain words, one page. Templates from your national regulator are fine.

Security. A booking tool with encryption, access controls and a sensible security posture. Strong passwords and two-factor on your accounts. Not emailing client lists around. Not storing intake forms in a shared inbox.

Retention. Decide how long you keep client records and stick to it. Appointment history for regulars is legitimately kept while they are clients. Records for someone who came once in 2019 are not. Health records have their own statutory periods in most countries, often years, and those override the general principle.

Rights. Someone can ask what you hold and ask you to delete it. Know how to export and delete a client in your booking tool before anyone asks.

The processor agreement

Your booking tool processes personal data on your behalf. Under GDPR that makes it a "processor" and you need a written agreement (a Data Processing Agreement) with it. Under HIPAA, a Business Associate Agreement. Reputable tools publish theirs and it is accepted as part of their terms; check that it exists and that the tool's handling of health data, if relevant, is stated. A tool that has no DPA and will not sign a BAA is not one to hold health data in.

Health data specifically

Booking a "consultation" is not health data. Booking "sports massage for lower back injury" arguably is. Intake forms asking about conditions, medications and allergies certainly are.

Practical rules:

  • Keep the booking form itself free of health questions; collect those in a separate intake form with its own consent.
  • Use a tool designed for health practices (Cliniko, Jane, Nookal, Dentally, the practice management systems) for intake and notes, or a form tool that explicitly handles health data.
  • Never let health information sit in email.
  • Limit who on your team can see it.
  • Say on the form why you are asking and that it is used only to deliver the treatment.

Six things to check in your booking tool today

  1. It has a published DPA (and a BAA if you are HIPAA-covered), and you have accepted it.
  2. Two-factor authentication is on for every staff login.
  3. The marketing consent box is separate, unticked by default, and clearly worded.
  4. Your privacy notice is linked from the booking page.
  5. You know how to export and delete one client's data.
  6. Intake forms with health questions live somewhere built for that, not in the general booking notes.

Most of these take a few minutes each. Together they are the bulk of what a regulator would ask a small business.

Where this sits

When we set up booking for a client the checklist above is part of it, because a booking system is the largest store of personal data most small businesses have, and the tool choice is the moment to get it right. It is not a large burden. It is a privacy notice, a few settings, and the habit of not over-collecting.

All writingSee packages and prices