Customer Impact

Website & Development

GDPR Compliant Forms for Appointments and Contact on a Healthcare Website

Copy for AI

A healthcare website is allowed to offer appointment and contact forms, but you have to be careful about what you ask for. Health data falls under the special categories of the GDPR (the European data protection law) and is subject to a processing ban in principle. The practical solution is almost always the same: ask for as little sensitive information as possible on the form itself, base your processing on a valid legal ground and be transparent about what happens to the data. This article shows you how to build GDPR compliant forms without watching your submissions dry up.

What makes a healthcare website different from a regular B2B site?

The difference lies in the type of data. Ordinary contact details such as a name, email address and phone number are regular personal data. As soon as a visitor reveals something about a complaint, a condition, a treatment or medication, you are dealing with health data, and the GDPR treats that as sensitive.

For those special categories, Article 9 of the GDPR sets out a general ban on processing. So you cannot simply collect them, not even through an innocent-looking free text field on an appointment form. That ban has exceptions, for example the explicit consent of the data subject, or processing that is necessary for the provision of care or medical treatment. Which exception applies to you depends on who you are (a hospital or practice is in a different position than a supplier serving healthcare organisations) and on what you use the data for.

The supervisory authority in Belgium is the Data Protection Authority (DPA), which has overseen the correct application of the GDPR since 2018. If you are unsure about your legal ground, have it reviewed by a lawyer or your data protection officer. This article covers the web side: how to build your forms so that you keep the risk small.

Which data should you ask for, and which should you avoid?

The core rule is data minimisation: only ask for what you genuinely need for the purpose of the form. On most healthcare websites that purpose is not “building a medical record”, but simply “calling someone back” or “scheduling an appointment”. You do not need a diagnosis for that.

So on the form itself, stick to this:

  • Do ask for: name, phone number or email address, and optionally a preferred time slot or the department or service the person is calling about. That is enough to get in touch.
  • Better not to ask for: specific complaints, symptoms, diagnoses, medication or other medical details. Even an open field saying “describe your question” invites exactly that kind of information.

If you do want to offer a free text field, add a short line asking the visitor not to share medical details and to save them for a personal conversation. That way you steer behaviour and reduce the chance of receiving health data you never wanted. The real substantive conversation then happens through a secure channel, by phone or at the practice, not through an open web form.

This approach is not only cleaner legally, it is also better for your conversion. Every extra field costs you completions. The principles behind form conversion optimisation and those behind privacy point the same way: shorter is almost always better.

Good consent is specific, freely given and unambiguous, which in practice means: no pre-ticked boxes. The visitor ticks a box themselves or takes a deliberate action, and you explain in one sentence what you use the data for, with a link to your privacy statement.

A few practical points:

  • Separate your purposes. Consent to be contacted about a request is not the same as consent for a newsletter. Do not lump the two together in a single checkbox.
  • Keep the text readable. One line next to the submit button, with a link to the full explanation. A wall of legal text under every form damages both trust and conversion.
  • Distinguish types of consent. The cookie consent for analytics or marketing on your site is separate from the ground on which you process the form data. Do not confuse the two in your copy.

Note: if you base your processing on a legal ground other than consent, for example because the data is necessary for providing care, a consent checkbox is not always the correct or required basis. Have that decided case by case. What always applies: be transparent about who you are, what you do with the data and how long you keep it.

How do you keep the form technically secure?

Transparency and data minimisation are half the work, the technical side is the other half. A few things should be in order by default on a healthcare website:

  • Encrypted connection. The entire site, and certainly the form pages, run over HTTPS so that submitted data is encrypted in transit.
  • Secure handling of submissions. Do not send form submissions in plain text to an unsecured mailbox that half your team can read. Limit who has access and store the data somewhere with appropriate security.
  • A deliberate data policy. Agree on a retention period and delete submissions once you no longer need them. Less stored data means less risk.
  • Watch your processors. A form tool, CRM or email platform that processes the data on your behalf is a processor. That calls for a data processing agreement, and you should check where the data is stored. Choose tools that support this properly.

Whether you build in Webflow, WordPress or a headless setup, these requirements apply regardless of the platform. We are platform independent and look case by case at which combination of form tool, hosting and processors best fits your security and growth needs. You can read more about that approach on our page about web design and in the website development guide.

How do you stop privacy from costing you conversions?

Good privacy and good conversion do not contradict each other, they reinforce each other. A form that is short, makes clear what will happen and why it is safe, feels more trustworthy. On a healthcare website in particular, where the threshold for sharing data is higher, that trust is decisive.

A few things that help both privacy and conversion:

  • Say what happens after submitting. “We will call you back within one working day” creates clarity and takes the tension away.
  • Show trust signals around the form. A real phone number, an address and a face do more than a long disclaimer. See also building trust on a B2B website.
  • Offer an alternative. Not everyone wants to fill in a form. A visible phone number or email address gives people the choice.
  • Make it accessible. Clear labels, sufficient contrast and keyboard operation help everyone, and prevent common web accessibility mistakes.

Also be honest about what a website can and cannot do. A form captures the request in a safe, conversion-friendly way. The medical substance and the real trust emerge in the contact that follows.

The short summary

A healthcare website can absolutely offer appointment and contact forms, as long as you treat health data as a special category. Ask only for contact details on the form, deliberately keep medical details out of view, base your processing on a valid legal ground and be transparent about the purpose and the retention period. On the technical side, make sure you have HTTPS, restricted access and proper processor agreements. Do that well and you gain both trust and completed requests. Do you want to set up your healthcare website so that it is both GDPR compliant and conversion focused?

Schedule your free intake

Free website scan

Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.

Where should we send your report?

We only use your details for your scan. No spam, unsubscribe anytime.