In a clinic, GDPR is about people, not animals: the owner's name, phone, address, e-mail, payment history — all personal data you process daily. Below is the practical minimum worth having in order. This article organises the topic — it is not legal advice.
1. The legal basis
You do not need consent to keep records and settle bills — the basis is performing the contract (treating the animal) and the clinic's legal obligations. Consent is needed where you go beyond that: newsletters, marketing SMS, publishing photos of the pet on social media.
2. The information duty
At first contact the owner should learn who controls their data, why you process it and what rights they have. In practice: a short clause at registration and a full privacy policy on your website.
3. Consents — best signed electronically
Paper consents have two flaws: they get lost, and nobody knows which version applied on the signing day. Increasingly, consents — GDPR, marketing, treatment or surgery — are signed electronically on a reception tablet, and the document saves straight at the patient record, with its date and exact wording. That is how it works in VetiCloud: the reception consent tablet.
4. Data security
- Named accounts — every employee logs in as themselves; accounts are deactivated when someone leaves.
- Scoped access — reception does not need what the manager needs.
- Backups — regular and stored beyond one computer; in a cloud system the vendor does this.
- The reception computer — screen lock, and no open record facing the waiting room.
5. Do not collect more than you need
You do not need a national ID number for a vaccination visit. The less surplus data, the smaller the risk and the simpler the duties.
Good GDPR in a clinic is boring GDPR: named accounts, consents signed and stored at the record, backups nobody has to remember.