Skip to main content
UK REGULATION3 September 2026

GDPR for Aesthetic Clinic Marketing: What You Can Actually Send

Surinder Ahitan By Surinder Ahitan
GDPR for Aesthetic Clinic Marketing: What You Can Actually Send

I sat with a clinic owner last year who had 3,800 patient records in her booking system and hadn’t emailed a single one of them in two years. Not because she didn’t want to. Because someone at a conference told her that GDPR meant she needed fresh written consent from every patient before she could send anything, and the job looked so big she never started.

That list was worth somewhere north of £40,000 a year in repeat treatments. It sat there doing nothing.

At the other end of the same week I looked at a clinic that had bought a list of 12,000 “beauty-interested females aged 30-55” and was blasting it weekly with filler offers. That one is genuinely a problem. The first clinic was scared of a rule that didn’t apply to her. The second was breaking one it never checked.

Most clinic owners are somewhere between those two, guessing. So here’s the plain-English version of what UK rules actually let you send to your own patients.

One caveat before we start: I run marketing, not a law firm. This is how I’ve handled it across nine clinics and what the ICO’s own guidance says. If you’re doing something unusual, take proper advice.

Why this matters more than the fine

The fine is the thing everyone talks about and the thing least likely to happen to you. The ICO tends to act on complaints and on volume. A clinic sending relevant emails to its own patients is not who they’re looking for.

The real cost is the one the first clinic paid. Your patient list is the single cheapest source of revenue you own — no ad spend, no agency, no competing against a clinic down the road. Every month you leave it dormant because you’re not sure what’s allowed, you’re funding someone else’s Google Ads instead. That’s the Reactivate stage (R5) of the flywheel sitting idle.

The second cost is trust. Patients who feel their data has been passed around, or who get an offer for a treatment they quietly had done in confidence, don’t complain to the ICO. They just stop coming.

1. There are two rulebooks, not one

This is the bit nobody explains, and it’s the source of most of the confusion.

UK GDPR governs how you hold and use personal data at all — collecting it, storing it, being fair about it, deleting it when you no longer need it.

PECR — the Privacy and Electronic Communications Regulations — governs the actual sending of marketing by email, text, or phone. This is the one that decides whether you can press send.

When people say “GDPR means I need consent for everything”, they’re usually half-remembering PECR. And PECR has an exception that covers most of what a clinic wants to do.

Ink consent form with two tick boxes, the upper one ticked in brand green

2. The soft opt-in is the rule most clinics have never heard of

Under PECR, you can send marketing emails and texts without a separate consent tick if all of the following are true:

  • You got their contact details in the course of a sale, or negotiations for a sale — so, they booked a treatment, or enquired about one
  • You’re marketing your own similar products or services — more treatments, not a partner’s supplement range
  • You gave them a simple way to opt out when you collected the details, and you give them one in every message after that

That’s it. A patient who came in for lip filler in 2024, gave you their email at booking, and was told they could unsubscribe at any time, can be emailed about your skin boosters. You do not need to go back and ask permission again.

Two things it does not cover: people who never enquired or booked (bought lists, scraped emails, competition entrants who ticked nothing), and marketing that isn’t yours (the local gym’s promo, an affiliate offer).

Note also that soft opt-in does not stretch to phone calls to numbers registered with the TPS, and live marketing calls have their own rules.

For anyone outside the soft opt-in — a newsletter signup, a lead magnet download, a walk-in who left an email — you need consent, and consent has a specific shape:

  • Unticked box. Pre-ticked is not consent and hasn’t been for years.
  • Separate from terms and conditions. Bundling “I agree to the T&Cs and to receive marketing” invalidates it.
  • Specific about channel. Email and SMS are different asks. List them separately.
  • Recorded. You need to be able to show when, how, and what they agreed to. Your booking system almost certainly stamps this — check it does.

The practical fix is a single line on your booking form and your website enquiry form: an unticked box saying “Email me occasional treatment offers and clinic news. Unsubscribe any time.” Ninety seconds of setup, and it takes every future patient out of the grey area entirely.

4. Treatment history is special category data

Here’s where aesthetics differs from a plumber’s mailing list. What treatment somebody had is health data, and health data carries an extra layer of protection.

Emailing your whole list about a Friday offer is fine. Emailing “everyone who had anti-wrinkle injections in the last six months” a reminder that they’re due a top-up is using their health data for marketing, and for that you want explicit consent — a clear, specific yes to that use.

It’s worth getting, because treatment-specific reminders convert several times better than a general newsletter. Ask for it at the point of treatment, in one line on the consent form: “Contact me with reminders and aftercare relevant to the treatments I’ve had.” Most patients say yes. They want the reminder.

And be careful with the subject line either way. “Time for your Botox top-up, Sarah” landing in a shared family inbox is a confidentiality problem before it’s a data one.

5. Before-and-after photos need their own permission

Treatment consent is not photo consent, and photo consent is not marketing consent. Three separate things, and clinics routinely collapse them into one signature.

Get a specific photo permission that names where the images may appear — website, Instagram, Google Business Profile, printed material — and make clear it can be withdrawn. Keep it with the patient record, not in a drawer.

Two practical points. Withdrawal means you have to be able to find and remove the images, so store them in a way that lets you trace which patient is which. And separately from data law, remember the ASA rules on advertising prescription-only medicines — a compliant photo can still be a non-compliant advert.

Ink flow diagram of boxes and arrows into a locked drawer, one arrow blocked

6. Reminders are not marketing — until you add an offer

Appointment confirmations, aftercare instructions, and “your appointment is tomorrow at 2pm” are service messages. They don’t need marketing consent and you can send them to anyone with a booking.

The moment you bolt an offer onto the end — “and 20% off skin boosters this month” — the whole message becomes marketing and needs to sit under soft opt-in or consent. Keep the two message types separate in your system. It’s tidier, and it stops one careless line reclassifying your entire reminder flow.

Review requests sit in a genuinely grey area. Some read them as service, some as marketing. I treat them as marketing and only send them to patients covered by soft opt-in. You lose almost nothing, because those are the patients who leave reviews anyway.

What to do this week

Four steps, in order:

  1. Add the unticked opt-in box to your booking form and your website enquiry form. This stops the problem growing while you fix the rest.
  2. Check what your booking system already records — most store a consent flag and a timestamp you didn’t know existed. You may be more covered than you think.
  3. Segment the list into three: patients who booked or enquired (soft opt-in, email them), patients who gave explicit consent for treatment-based messages (your best segment), and everyone else (leave alone or re-permission with a single honest email).
  4. Email the first group. Something useful, not an offer. The list has been quiet for a while, and the first message should earn the next one.

Doing this properly is not a compliance chore. It’s how you get to use the most valuable asset in the business without lying awake about it — Secure Every Enquiry (S in S.E.L.F.) applied to the enquiries you already won.


Surinder Ahitan grew the CoLaz aesthetic clinic group from one to nine UK locations in six years, mainly through search and well-built websites. If you want a structured look at how your clinic captures enquiries and what your website does with them, the free audit takes 15 seconds and lands in your inbox shortly after.

WhatsApp