Sample policy · Private clinic

Before-and-after photography and data protection policy (private clinic)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). The real primary for clinical-image data protection is the UK GDPR and the Data Protection Act 2018, alongside GMC and ICO guidance. · primary source

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) ... assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity. (Reg 17(2)(a) and (b): quality and risk)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. The data-protection duties that govern clinical images sit in the UK GDPR and the Data Protection Act 2018; their full text is at https://www.legislation.gov.uk/eur/2016/679/contents and https://www.legislation.gov.uk/ukpga/2018/12/contents. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.

Clinical photography is health information and potential special category data under the UK GDPR. Good governance of those images means consent is obtained and recorded, storage and access are controlled, and use, withdrawal, deletion and breach are all managed against current data-protection law and professional image guidance.

3. Purpose

This policy sets out how the Clinic obtains consent for before-and-after photography, stores clinical images and controls use of images for records, teaching, audit and marketing.

It treats clinical photography as health information and potential special category data under UK GDPR.

4. Scope

This policy applies to:

This policy applies to staff-owned phones and cameras as well as Clinic devices. Staff do not store patient images on personal devices.

5. Photography consent process

The Clinic separates procedure consent from photography consent.

5.1 Clinical-record photography

Clinical-record photography is used where it supports assessment, treatment planning, progress review, complication review or continuity of care.

The clinician explains:

The Clinic records whether the patient agreed or refused. Refusal of non-essential photography does not prevent clinically appropriate care.

5.2 Marketing and advertising photography

Marketing use needs separate explicit consent.

The Clinic does not rely on clinical-record consent for:

The consent record states the specific uses the patient agreed to. The Clinic does not bundle marketing image consent into procedure consent.

5.3 Special category data wording

UK GDPR Article 9 says processing of "data concerning health" is prohibited unless an Article 9 condition applies.

Where the Clinic relies on explicit consent for marketing images, Article 9(2)(a) says "the data subject has given explicit consent to the processing of those personal data for one or more specified purposes".

The Clinic verifies the current Article 9 wording and the relevant Data Protection Act 2018 condition before adoption.

6. Image capture and storage

The Clinic uses approved devices, approved storage and controlled access.

6.1 Capture standards

Staff record:

Images are taken respectfully. Staff explain positioning, privacy and what will be visible before taking an image.

6.2 Storage and access control

The Clinic stores clinical images in the approved clinical record or secure image store.

The local procedure covers:

Staff do not send patient images through personal messaging apps, personal email accounts or unapproved cloud storage.

6.3 Withdrawal and deletion

Patients may withdraw consent for optional uses such as marketing images.

The Clinic records:

Where a patient requests deletion, Staff follow the Clinic's data-protection procedure and record the Article 17 decision.

7. Breach and unauthorised use response

If Staff identify unauthorised image access, loss, disclosure or use, they record an incident immediately.

The Registered Manager and data-protection lead:

The Clinic does not wait for a complaint before removing unauthorised image use.

8. Responsibilities

9. Recording requirements

The Clinic keeps the following records:

Records are kept in the clinical record or governance record according to local procedure.

10. Audit cadence

The Clinic uses the following Verivius default audit rhythm unless current source material requires a different rhythm:

Audit findings are recorded as improvement actions with an owner and review date.

11. Version control and review date

The Clinic keeps a controlled copy of this policy. The footer or document-control table records:

12. Related records

Review cadence: annual or on regulatory change, whichever sooner. Owner: Registered Manager.

13. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

14. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

15. Document control

Version Date Author Changes
v1 2026-06-10 Verivius (sample) Conformed to the Verivius policy standard: added statutory anchor, verbatim Reg 17 quotes, plain-English summary, standard sources, advice and document-control blocks; existing operational sections preserved and renumbered.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

A before-and-after photograph in an aesthetic clinic does two jobs at once, and that is exactly where it goes wrong. The same image of somebody's face, abdomen or breasts is both a clinical baseline for spotting an asymmetry or a developing filler complication, and a commercially valuable marketing asset the clinic has a direct financial interest in publishing. Where the photograph never reaches the clinical record, the clinician assessing swelling or a suspected vascular occlusion weeks later has nothing to compare against, and the patient carries the cost of that missing baseline. Where it reaches the gallery on the strength of a procedure consent nobody talked through, the patient discovers their own body advertising a clinic they may have long since left, and the trust that made them agree to treatment in the first place is gone. Getting consent, storage and the withdrawal trail right is what keeps a clinical photograph a tool used with somebody rather than something done to them.

  1. Marketing use of a before-and-after image carries its own explicit, specified consent, not the clinical-record consent carried over. What goes wrong is a website or gallery image whose only authority is the procedure or clinical-record consent, so nobody can show the patient agreed to being published.

    Strong evidence: Marketing-use consent record stating the specific uses the patient agreed to (website, social media, printed marketing, paid advertising, before-and-after gallery), kept separate from procedure consent and never bundled into it (sections 5.2, 9 marketing image register).

    Weak evidence: One consent form with a single tick-box reading "I consent to photography", or wording such as "for clinical and promotional purposes" that never names website, social media, printed marketing, paid advertising or gallery use. The marketing image register lists images whose only paper trail is the procedure consent signed on the day of treatment, when the patient was focused on the procedure rather than on where their photograph would later be published.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 9(2)(a), read with Article 4(11), Article 7(2) and Article 5(1)(b)

  2. Withdrawal of image consent actually reaches the platforms the image sits on, not just a line in the file. Where it breaks down, a patient who has withdrawn consent still finds their own photograph live on social media or in a gallery.

    Strong evidence: Withdrawal record showing date of withdrawal, image uses affected, platforms or materials to update, action taken and any lawful reason the image must remain in the clinical record (section 6.3).

    Weak evidence: A line in the record saying "patient withdrew consent for photos" with no date, no list of the platforms and materials the image actually sits on, and nothing confirming the post came down. The give-away is finding the withdrawn image still in the social-media grid, in an old gallery page or in a printed leaflet at reception, because nobody held a list of where it had been published.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 7(3) and Article 17(1)(b), with Article 17(2)

  3. Patient images live in the approved clinical record or secure image store with access by role, not on personal phones, messaging apps or unapproved cloud storage. In practice it fails when a treatment photograph is still in a staff member's camera roll after upload, on a device the clinic does not control.

    Strong evidence: Storage and access-control procedure covering access by role, deletion from the capture device after upload, encryption and an audit trail, alongside the standing rule that staff do not store patient images on personal devices or send them via personal messaging or email (sections 4, 6.2).

    Weak evidence: A policy sentence saying staff must not use personal devices, with no evidence anyone has ever checked, no record of deletion from the capture device after upload, and treatment photographs still sitting in a practitioner's camera roll or in a staff group chat. Shared logins to the image store are another sign, because access by role cannot be demonstrated when everyone signs in as the same user.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 32(1) and 32(4), read with Article 5(1)(f)

  4. A breach or unauthorised use is acted on the moment staff spot it, not when a complaint arrives. It goes wrong when unauthorised marketing use is left live while the clinic waits to be challenged, and the patient is the last to know.

    Strong evidence: Incident record with breach assessment, a recorded decision on whether to report the breach to the Information Commissioner's Office (ICO) and a separate recorded decision on whether to tell the affected patient, neither standing in for the other, with unauthorised marketing or social-media use removed without waiting for a complaint (sections 7, 9).

    Weak evidence: An incident register with no image entries at all, or an entry closed as "resolved" with no breach risk assessment, no recorded Information Commissioner's Office (ICO) notification decision and no patient notification decision. The clearest sign of a reactive clinic is a takedown dated after the patient's complaint email rather than after the day staff first spotted the unauthorised use.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 33(1) and 33(5), and Article 34(1)

  5. Each clinical image is captured with its identifying and consent details recorded alongside it, so an image traces to a patient, a purpose and a consent status. The common failure is an anonymous image with no recorded purpose or consent, leaving the next colleague to open the folder unable to say whether it may be used at all.

    Strong evidence: Capture record holding patient identity, date, treatment area, image purpose, photographer, device used, consent status and any requested restrictions (section 6.1).

    Weak evidence: Image folders named only by date or by a shorthand such as "patient 3", or a clinical photography log where identity and date are filled in but image purpose, consent status and requested restrictions are blank. Nobody can say from the record which images the patient asked to be kept out of any gallery, so the restriction only exists in the memory of whoever took the photograph.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  6. The image-governance audit rhythm actually runs and produces owned actions, rather than sitting dormant in the policy. The drift to watch for is nobody reviewing consent, access or marketing use between incidents, so the first time anyone looks is after something has already gone wrong for a patient.

    Strong evidence: Monthly Registered Manager review of open image-consent issues, withdrawal requests and image incidents, plus quarterly data-protection lead audit of image access, marketing image consent and storage controls, recorded as improvement actions with an owner and review date (section 10).

    Weak evidence: An audit template whose last completed entry sits well behind the monthly and quarterly rhythm the clinic set for itself, or findings written up as "no issues identified" with no note of how many images or consent records were sampled, no named owner and no review date. Access reviews that never actually remove a leaver's login to the image store show the rhythm is being recorded rather than run. The intervals are the clinic's own operational default, so the question is whether the rhythm it chose is actually happening.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.

Last verified 20 July 2026

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 10 June 2026