If you run a physiotherapy clinic, you're sitting on some of the most personal information there is — how someone's body works, what's wrong with it, and how they're recovering. That's exactly the kind of data the PDPA cares most about. So this is worth ten minutes. Let's keep it plain.
Yes, the PDPA applies — and you must appoint a DPO
The PDPA covers every organisation in Singapore, and a physio clinic is no exception — solo practice or multi-therapist group, it's the same rule. Two parts matter most. First, you must appoint at least one Data Protection Officer (DPO) and make their business contact available (a name or role plus an email, on your website or at reception). Second, because you handle health data, the PDPC expects a higher standard of protection — a data breach at a physio clinic can cause real harm to a patient, so "we're small" is not a shield. If you're unsure whether the DPO rule really applies to a clinic your size, I've written a fuller piece on that: does my clinic need a DPO?
The data a physio clinic actually holds
It's more than most owners realise once you list it out. A typical physio clinic holds:
- 1Injury and medical history — the intake form, referrals, past conditions, medications, red flags.
- 2Assessment and treatment notes — your findings, the plan, session-by-session progress.
- 3Movement photos and videos — gait, range-of-motion or exercise clips you record to track progress.
- 4Insurance, corporate and MC claim details — policy numbers, employer letters, claim forms, medical certificates.
- 5The plumbing — names, NRIC, phone, email, appointment history, payment records — often spread across your clinic system, paper files, WhatsApp and email.
Every one of those is personal data, and most of it is health data — which is exactly why the care you take with it matters.
The everyday gaps that trip physio clinics up
These aren't hypotheticals — they're the ordinary moments where a clinic quietly does the wrong thing without meaning to:
- ✓Sharing reports with insurers, corporate clients and referrers — sending a progress report to a patient's insurer, employer or referring doctor needs a proper basis, usually the patient's specific consent to share that report with that party. A general treatment consent doesn't cover it, and you should share only what's needed.
- ✓Movement photos and videos — recording a patient is collecting their personal data. You need consent to record, a secure place to store it (your clinic system, not a personal camera roll), and separate consent again if you ever want to use a clip for marketing.
- ✓WhatsApp on personal phones — therapists messaging patients or saving photos of notes on their own phones is a common, real exposure. If the phone is lost or the staff member leaves, the data walks out with it.
- ✓Reception privacy — the next patient in the queue overhearing a name and condition, or seeing a screen or file left open at the front desk.
- ✓Marketing without consent — adding every patient to a promotional broadcast, or posting a "recovery story", without their say-so. Being a patient is not consent to be marketed to.
The three consents — keep them separate
This is the single idea that clears up most confusion. A patient can say yes to one thing and not the others, and you have to track that:
- 1Consent to treatment — they agree to be assessed and treated. This is clinical, and it's not the same as agreeing to how their data travels.
- 2Consent to use their data — collecting, storing, and sharing it (for example, sending a report to their insurer or employer). This should be specific about who receives what.
- 3Consent to marketing — newsletters, promotions, using their photo or recovery story. This is a separate opt-in, and they can withdraw it any time.
Mixing these three up is the most common physio-clinic mistake. There's more on getting this right in our guide to consent and marketing.
How long to keep records
Two rules pull in different directions, and you need a schedule that satisfies both. MOH generally wants medical records kept for at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA says the opposite pressure — don't keep personal data longer than you need it. So you can't keep everything forever, and you can't bin it early either. A clear retention schedule (what you keep, for how long, and how you securely dispose of it after) is what reconciles the two — and it's one of the first things a proper DPO sets up.
So — what should you do?
Appoint a DPO (you legally must), then work through the practical list: know what data you hold and where it lives, tidy up how you take the three consents, fix the report-sharing and photo/video habits, get WhatsApp and personal phones under control, and put a retention schedule in place. Most of this is common sense once someone maps it out — the hard part is finding the time and knowing the details.
If nobody on your team has the hours or the specialist knowledge, this is worth having done for you — mapped, documented, staff trained, with someone on call if a patient complains or something goes wrong. In a physio clinic, patients' trust is your whole business; better to have this quietly in place than to explain, after an incident, why it wasn't.
Common questions
Yes. Under the PDPA every organisation — including a physiotherapy clinic — must appoint at least one Data Protection Officer and make their business contact available. There's no exemption for small clinics, and because a physio clinic holds patient health data the bar for protecting it is higher.
Only with a proper basis — usually the patient's clear, specific consent to share that report with that party. A general treatment consent is not enough. Get written consent naming the insurer or employer, share only what's needed, and send it through a secure channel.
Yes, if it's for the patient's care and you have their consent. Photos and videos of a person are personal data, so you need separate consent to record, to store them, and again if you ever want to use them for marketing. Keep them in your secure clinic system, not on a personal phone.
MOH generally requires records kept at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA also says don't keep data longer than needed — so a physio clinic needs a retention schedule that reconciles both.
Sources
- Personal Data Protection Commission (PDPC) — pdpc.gov.sg (appointing a DPO; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) — record-keeping requirements & the Healthcare Services Act (HCSA)
Want this handled for your physio clinic?
We help Singapore physio clinics get PDPA-ready and stand in as your outsourced DPO — mapped, documented, staff trained, done for you. Let's talk.