If you run a medical-aesthetic clinic — injectables, lasers, skin, body — you're sitting on some of the most personal data there is: people's faces, their bodies, and how they feel about both. And unlike a GP, you actively show that data off to win new patients. That's exactly where the PDPA gets sharp. Let's keep it plain.
Yes, the PDPA applies — and you need a DPO
The PDPA says every organisation must appoint at least one Data Protection Officer and make that person's business contact available. An aesthetic clinic is no exception — there's no size exemption, and no "we're a beauty business, not a hospital" loophole. If anything you're held to a higher standard, because you handle health data where a breach can cause real harm, and you sit alongside MOH rules for licensed clinics. If you haven't sorted this yet, start with our pillar guide: does my clinic need a DPO?
The data you're actually holding
Most aesthetic clinics underestimate this. You're typically holding:
- ✓Health & treatment data — conditions, allergies, what was injected or lasered, dosages, consult notes.
- ✓Before-and-after photos — often of the face or body, sometimes intimate. The most sensitive thing you keep.
- ✓Identity & contact data — name, NRIC (only when truly needed), phone, email, address.
- ✓Financing / instalment data — if you offer buy-now-pay-later or instalment plans, that's financial data too.
- ✓Marketing data — enquiry forms, ad leads, WhatsApp chats, loyalty and campaign lists.
Every one of those needs a lawful basis to collect, a reason to keep it, and a way to protect it. But one deserves its own section.
The standout issue: before-and-after photos
This is where I see aesthetic clinics get caught out more than anywhere else. A patient letting you take a clinical photo for their record is not the same as them agreeing you can post it on Instagram. Under the PDPA, using someone's photo for marketing is a separate purpose that needs its own clear, separate consent. Think of it as three distinct permissions:
- 1Consent to take the photo — as part of documenting their treatment.
- 2Consent to store it — kept securely, as sensitive as any medical record.
- 3Consent to use it — the big one: to publish it in ads, on your website, or on social media. This must be specific and informed — where it'll appear, and for how long.
Get this in writing, and make it real: if a patient only agreed to storage, that photo does not go on your feed, full stop. Store the images securely — not on a staff member's personal phone camera roll, not in an open shared folder — and control who can see them. And remember a patient can withdraw consent at any time; if they ask you to take a photo down, you take it down and stop using it going forward. Building your consent form so these three are ticked separately is the single best habit an aesthetic clinic can adopt.
Patient testimonials & reviews
Same principle, one step further. A glowing review that names a patient or shows their face is their personal data — so you need their consent to publish it, and you should stop if they later ask you to. Two extra rules worth stating plainly: don't fabricate or edit testimonials to mislead, and be careful with medical claims — aesthetic advertising in Singapore also sits under MOH and advertising guidelines, so "guaranteed results" language is a separate risk on top of the PDPA. Consent first, honesty always.
Heavy marketing = the three consents + DNC
Aesthetic clinics market hard — ads, promos, birthday offers, "book your next session" nudges. The PDPA governs all of it. The core idea is the three separate consents: agreeing to treatment is not agreeing to marketing, and agreeing to marketing by email is not agreeing to calls or texts. On top of that, the PDPA's Do Not Call (DNC) rules apply to marketing calls, SMS and faxes to Singapore numbers:
- ✓Get clear opt-in consent before adding someone to a promo list — don't assume a patient is a marketing contact.
- ✓Check the DNC registry before marketing calls, texts or faxes, unless you have the right clear-and-unambiguous consent on file.
- ✓Give an easy opt-out in every message — and actually honour it, quickly.
WhatsApp & how long you keep things
Two practical bits that come up constantly in aesthetic clinics:
WhatsApp. It's how most clinics talk to patients now — appointment reminders, aftercare, photos. That's fine, but the same rules apply: marketing blasts on WhatsApp need consent and an opt-out, and patient photos or details in a chat are personal data living on someone's phone. Use a proper clinic number and account, not a therapist's personal WhatsApp, and don't let sensitive photos pile up in personal chats.
Retention. For licensed clinics, MOH generally expects medical records to be kept for a minimum period — commonly cited as at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA pulls the other way: don't keep personal data (including marketing lists and old photos) longer than you actually need. You reconcile the two with a written retention schedule — how long each type of data is kept and when it's securely deleted.
So — what should you do?
Two moves. First, protect the data: appoint a DPO, map what you hold, secure the photos, and write your privacy notice and retention schedule. Second, fix your consent form so treatment, storage, marketing-use of photos, and marketing contact (email vs call/SMS) are all ticked separately — that one form solves most of your risk. If nobody on your team has the time or the specialist knowledge to own this, it's the kind of thing worth having done for you.
Common questions
Yes. A patient consenting to have a photo taken for their treatment record is not consenting to it being posted on your website or social media. Using before-and-after photos for marketing needs clear, separate, informed consent — ideally in writing — that names where and how the images will be used. A patient can also withdraw that consent later, and you must then stop using the photos.
Yes. Under the PDPA every organisation must appoint at least one Data Protection Officer, and an aesthetic clinic is no exception. Because you hold health data plus before-and-after photos and market heavily, the bar is higher, so a real DPO matters more.
Only with consent, and honestly. A testimonial that names a patient or shows their photo uses their personal data, so you need their permission to publish it. You must not fabricate or edit reviews to mislead, and if the patient asks you to take it down you should.
Only with the right consent and after checking the Do Not Call registry for calls, texts and faxes to Singapore numbers. Promotional messages need clear opt-in consent, every message needs an easy way to opt out, and you must honour opt-outs. WhatsApp marketing to patients is covered by the same rules.
Sources
- Personal Data Protection Commission (PDPC) — pdpc.gov.sg (appointing a DPO; consent; Do Not Call registry; Healthcare Sector Advisory Guidelines)
- Ministry of Health (MOH) — record-keeping requirements, the Healthcare Services Act (HCSA) & advertising guidelines for licensed clinics
Want this handled for your aesthetic clinic?
We help Singapore aesthetic clinics get PDPA-ready and stand in as your outsourced DPO — photo consent, secure storage, marketing rules, staff trained, done for you. Let's talk.