How do I stay GDPR-compliant when emailing patients?
Sound familiar?
You would email your patients more if you weren't half-braced for a fine. GDPR was introduced with so much consultant-fuelled fear that many clinics simply stopped communicating with their own patients. The reality is far simpler: be clear, be transparent, respect people's control over their data, and you are on safe ground 🛡️.
What's happening
Privacy law — GDPR in the UK and EU, and its cousins elsewhere — asks three things of your emails: tell people what you'll send them, actually send what you said, and let them opt out easily. Co-Kinetic handles the mechanical parts (sign-up forms link to your privacy policy, and emails carry an unsubscribe route); the part that belongs to you is a clear privacy-policy statement about what subscribers can expect.
Why it works this way
The law was never designed to stop a clinic emailing recovery advice to people who asked for it — it was designed to stop hidden data use and inescapable spam. That is why transparency is the whole game: a subscriber who was told what to expect, gets what they were told, and can leave at any time has nothing to complain about, and neither does a regulator 🙂.
What to do now
Add this paragraph to your clinic's privacy policy (copy and paste, then adjust to taste):
"When you sign up to receive information from us, we will use your details to send you resources, updates and guidance related to the campaign or topic you registered for (for example, advice on managing a specific condition). From time to time, we may also share other health and wellbeing information that we believe will be useful to you, such as injury prevention tips, recovery advice, or seasonal guidance. Occasionally, we may include updates about our services or special offers. These emails are designed to be supportive and informative rather than purely promotional, and you can unsubscribe at any time using the link in our messages."
Link that policy in Settings — Business Settings → Legal & compliance holds your privacy policy URL, which your sign-up forms point to.
Do what the paragraph says — mostly useful content, occasional offers. Consistency is the compliance.
Honour opt-outs instantly and everywhere — never re-add someone who unsubscribed, including via imports.
Why this wording travels well: UK/EU GDPR asks for transparency, fair use and control — covered. Australia and New Zealand (Privacy Act, Spam Act, Unsolicited Electronic Messages Act) ask for consent, clarity and unsubscribe — covered. Canada (CASL) is strictest on consent, but transparency plus unsubscribe with clear sign-up expectations satisfies it. For the US (CAN-SPAM), add your clinic's postal address to your emails.
The question behind the question
"Can I email my existing patients about services, or only people who signed up?" The honest answer: it depends on what they were told when you collected their details, and rules differ by country. Past patients who gave you their email in a treatment context haven't automatically consented to marketing. The safe pattern is to invite them once to join your list (a genuinely useful resource works well as the invitation) and market only to those who do. This article is practical guidance, not legal advice — if your situation is unusual, a quick check with a local advisor settles it ⚖️.
The next question is usually...
- How do I create an email collection form and add it to my website?
- How do I add contacts and create audiences in Co-Kinetic?
- How do I create a nurture email workflow?
Still stuck? This usually means...
- You have no privacy policy to paste into. Free generators produce a serviceable base policy; add the paragraph above and host it on your website, then link it in Settings.
- Someone asked what data you hold on them. Their contact record in Audience → Manage Contacts is the answer — export or transcribe it for them, and delete on request.
- You are worried about a specific import or audience. If you can't say where the consent came from, don't email that group — invite, don't assume.