If you run an aesthetic, dermatology, dental or GP clinic, before-and-after photos are gold for marketing — and one of the most common places clinics quietly break the PDPA. The good news: getting it right is simple once you see the three separate consents. Let's walk through it.
First: a patient photo is personal data
A photo that identifies a patient is their personal data under Singapore's PDPA — and because it's tied to a treatment, it's the kind of data where a leak or misuse causes real harm. The PDPA doesn't have a separate EU-style "sensitive data" bucket, but the PDPC treats health and medical information as data you must protect to a higher standard. Clinics also sit under MOH rules and the Healthcare Services Act (HCSA). So a casual "we always take photos" habit isn't enough — you need consent, and you need it for the right purpose.
The three consents (this is the whole article)
Here's the part most clinics miss. There isn't one consent — there are three, and each is a different purpose:
- 1To take the photo. You need the patient's okay to photograph them at all — before, during or after treatment.
- 2To store it in the record. Keeping the image in the clinical file, so who can see it and how long you hold it are covered.
- 3To use it in marketing. Posting on Instagram or TikTok, putting it on your website, using it in an ad or a printed brochure. This is the critical one — and it is not covered by the first two.
A patient consenting to treatment, or to you photographing the result for their record, has not agreed to appear in your marketing. Treat marketing as its own, explicit yes. Mixing these up is the single most common clinic mistake in this area.
What good consent looks like
You don't need a lawyer's contract. You need it specific and provable:
- ✓Written and specific — a short consent form (or a clear tick-box in your intake) that names each use: record, and separately, marketing/social media/website. Not one blanket "I agree to everything".
- ✓Freely given — treatment must not depend on the patient agreeing to be in your marketing. Keep the marketing consent optional.
- ✓Withdrawable — tell the patient they can change their mind later, and record when they do.
- ✓Dated and kept — so if anyone ever asks, you can show exactly what the patient agreed to, and when.
Patients can withdraw — and then you must stop
Under the PDPA a patient can withdraw consent at any time. If someone who's happy to be your marketing model today asks you to take the post down next year, you have to stop using the photo and remove the public posts within a reasonable time. Have a simple way to honour that — an email to reception, a note in the file. You may still keep the image in the clinical record where MOH record-keeping rules require it; withdrawing marketing consent doesn't wipe the medical file.
Store the photos properly
Because these images are sensitive, how you hold them matters as much as consent:
- ✓Secure storage with access controls — in your clinic system, not scattered across staff personal phones or a shared WhatsApp group.
- ✓Limit who can see them — the front desk doesn't need the full before-and-after library.
- ✓Keep the marketing set separate — the photos a patient approved for posting should live apart from the general clinical record, so nothing gets published by accident.
- ✓Consider anonymising — crop out the face, tattoos or other identifiers where the result still reads. Less identifiable means lower risk (though a distinctive feature can still identify someone, so don't treat cropping as a free pass on consent).
Don't reuse old photos for new campaigns
A photo a patient approved for one Instagram post three years ago is not a blank cheque for every future ad, a new website, or a printed flyer. If the use has meaningfully changed — a new campaign, a new channel, a paid ad — get fresh consent. This is easy to forget when you're refreshing your marketing and reaching for the old library. When in doubt, ask again.
So — what should you do?
Put a simple before-and-after consent form in place that separates record from marketing, make the marketing part optional, keep the signed consents, store the images securely, and honour withdrawals quickly. It's a small bit of admin that removes one of the biggest quiet risks an aesthetic or dental clinic carries. And if you'd rather not build the forms and process yourself, it's exactly the kind of thing a clinic DPO sets up for you.
Common questions
Yes. A patient photo is personal data, so you need the patient's consent to take it in the first place. That consent should be specific — taking the photo for the clinical record is a different purpose from using it for marketing, so ask for each purpose separately.
Only if the patient has given clear, specific consent to that use. Consent to treatment, or to storing the photo in their record, does not cover posting it on Instagram, your website or an ad. Marketing use needs its own explicit consent, ideally in writing.
Yes. Under the PDPA a patient can withdraw consent at any time. Once they do, you must stop using the photo for marketing and take down public posts within a reasonable time. You may still keep it in the clinical record if MOH record-keeping rules require it.
Store them securely with access controls — in your clinic system, not on staff personal phones or a shared WhatsApp. Limit who can see them, keep the marketing-approved set separate from the clinical record, and delete or anonymise photos you no longer need.
Sources
- Personal Data Protection Commission (PDPC) — pdpc.gov.sg (consent obligation; withdrawal of consent; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) — record-keeping requirements & the Healthcare Services Act (HCSA)
Want your clinic's photo consent sorted?
We help Singapore clinics get PDPA-ready — consent forms, secure storage, staff trained, done for you. Let's talk.