← Insights Say hi 👋
Data protection · Physio clinics

PDPA for physiotherapy clinics in Singapore

The short answer

Yes — the PDPA applies to your physio clinic in full. You hold patient health data — injury and medical history, assessment and treatment notes, sometimes movement photos and videos, and often insurance or corporate claim details. Because that's health data, you're held to a higher standard, and you must appoint a Data Protection Officer. The good news: the everyday fixes are practical, not scary. This guide walks through the data you hold, the gaps that trip clinics up, and what to do.

If you run a physiotherapy clinic, you're sitting on some of the most personal information there is — how someone's body works, what's wrong with it, and how they're recovering. That's exactly the kind of data the PDPA cares most about. So this is worth ten minutes. Let's keep it plain.

Yes, the PDPA applies — and you must appoint a DPO

The PDPA covers every organisation in Singapore, and a physio clinic is no exception — solo practice or multi-therapist group, it's the same rule. Two parts matter most. First, you must appoint at least one Data Protection Officer (DPO) and make their business contact available (a name or role plus an email, on your website or at reception). Second, because you handle health data, the PDPC expects a higher standard of protection — a data breach at a physio clinic can cause real harm to a patient, so "we're small" is not a shield. If you're unsure whether the DPO rule really applies to a clinic your size, I've written a fuller piece on that: does my clinic need a DPO?

The data a physio clinic actually holds

It's more than most owners realise once you list it out. A typical physio clinic holds:

Every one of those is personal data, and most of it is health data — which is exactly why the care you take with it matters.

The everyday gaps that trip physio clinics up

These aren't hypotheticals — they're the ordinary moments where a clinic quietly does the wrong thing without meaning to:

The three consents — keep them separate

This is the single idea that clears up most confusion. A patient can say yes to one thing and not the others, and you have to track that:

Mixing these three up is the most common physio-clinic mistake. There's more on getting this right in our guide to consent and marketing.

How long to keep records

Two rules pull in different directions, and you need a schedule that satisfies both. MOH generally wants medical records kept for at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA says the opposite pressure — don't keep personal data longer than you need it. So you can't keep everything forever, and you can't bin it early either. A clear retention schedule (what you keep, for how long, and how you securely dispose of it after) is what reconciles the two — and it's one of the first things a proper DPO sets up.

So — what should you do?

Appoint a DPO (you legally must), then work through the practical list: know what data you hold and where it lives, tidy up how you take the three consents, fix the report-sharing and photo/video habits, get WhatsApp and personal phones under control, and put a retention schedule in place. Most of this is common sense once someone maps it out — the hard part is finding the time and knowing the details.

If nobody on your team has the hours or the specialist knowledge, this is worth having done for you — mapped, documented, staff trained, with someone on call if a patient complains or something goes wrong. In a physio clinic, patients' trust is your whole business; better to have this quietly in place than to explain, after an incident, why it wasn't.

On cost: getting a physio clinic PDPA-ready is more affordable than most owners expect — and right now we're running a founding-clinic offer (a substantial first-year discount) to make it easy to start. Ask us about it.
This is general information to help physio clinic owners understand the PDPA — it isn't legal advice. For your clinic's specific situation, check the PDPC's official guidance, the MOH healthcare guidelines, or a qualified professional.

Common questions

Yes. Under the PDPA every organisation — including a physiotherapy clinic — must appoint at least one Data Protection Officer and make their business contact available. There's no exemption for small clinics, and because a physio clinic holds patient health data the bar for protecting it is higher.

Only with a proper basis — usually the patient's clear, specific consent to share that report with that party. A general treatment consent is not enough. Get written consent naming the insurer or employer, share only what's needed, and send it through a secure channel.

Yes, if it's for the patient's care and you have their consent. Photos and videos of a person are personal data, so you need separate consent to record, to store them, and again if you ever want to use them for marketing. Keep them in your secure clinic system, not on a personal phone.

MOH generally requires records kept at least 6 years for adults, and for children until they turn 21 plus 6 years. The PDPA also says don't keep data longer than needed — so a physio clinic needs a retention schedule that reconciles both.

Sources

  • Personal Data Protection Commission (PDPC) — pdpc.gov.sg (appointing a DPO; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
  • Ministry of Health (MOH) — record-keeping requirements & the Healthcare Services Act (HCSA)
Eugene
Eugene

I build websites and help Singapore businesses run them well. HeyAda is my Singapore web studio — design, SEO, and the practical side of running a business online, including the patient data your physio clinic collects. I write these guides in plain English, and I can be your clinic's outsourced DPO. Getting your clinic PDPA-ready? Say hi.

Want this handled for your physio clinic?

We help Singapore physio clinics get PDPA-ready and stand in as your outsourced DPO — mapped, documented, staff trained, done for you. Let's talk.