If you run a GP, dental, TCM, physio or aesthetic clinic, patients trust you with some of the most personal information there is. A privacy notice is how you show them β and the regulator β that you take that seriously. Let's keep it plain.
Why the PDPA asks for one
Two of the PDPA's core ideas are Notification and Openness. Notification means you must tell people the purposes you're collecting their data for, on or before collecting it. Openness means you make your data-handling practices available to anyone who asks, and you give them a way to reach the person responsible. A privacy notice is the single document that satisfies both β which is why it isn't optional, and why "we've never had one" is a gap worth closing. There's no size exemption: a solo practice needs one the same as a group.
What a clinic privacy notice must cover
You don't need legalese. You need to answer, honestly, the questions a patient would actually ask. Six things belong in every clinic notice:
- 1What data you collect β name, NRIC (only where truly needed), contact details, and medical information: symptoms, diagnoses, treatment and prescriptions.
- 2Why you collect it β the purposes: to treat the patient, keep medical records, bill and process claims, send appointment reminders, and meet MOH requirements.
- 3Who you share it with β labs for tests, specialists on referral, and insurers or MediSave and MOH systems for claims. Name the categories, not every vendor.
- 4How long you keep it β your retention approach, which reconciles MOH's record-keeping rules with the PDPA's don't-over-keep principle.
- 5Patients' rights β that they can ask to access a copy of their data and to correct anything wrong, and how to make that request.
- 6Your DPO's contact β a name or role plus an email, so a patient (or the PDPC) knows exactly who to reach.
A simple section-by-section outline
Here's a skeleton you can write straight into. Keep each part to a few plain sentences:
- βWho we are β your clinic's name and a one-line "this notice explains how we handle your personal data."
- βWhat we collect β the list of data types above.
- βWhy we collect it β the purposes, in patient-friendly language.
- βWho we share it with β labs, specialists, insurers/MediSave, and that you only share what's needed.
- βHow we protect and keep it β a line on security and your retention approach.
- βYour rights β how to access or correct records, and that you'll respond within a reasonable time.
- βContact us β your DPO's name/role and email, and the date the notice was last updated.
Where to display it
A notice only works if patients can see it before they hand over their data. So put it in two places:
At reception β a printed copy patients can read, or a clear line on your registration form (for example, "We handle your data per our privacy notice β ask for a copy or see [your website]"). This covers the walk-in moment when data is actually collected.
On your website β a Privacy Notice page linked in your footer. This is your always-available, openness version β the one patients and the PDPC can find any time. If your site has an appointment or contact form, or even analytics cookies, you need this page regardless.
Keep it plain, not legalese
The instinct is to copy a wall of legal text. Don't. A notice patients can actually read builds more trust β and the PDPA rewards being clear, not clever. Short sentences, no jargon, honest about what you do. If you wouldn't say it to a patient across the counter, don't write it.
How this connects to your DPO
The privacy notice isn't a one-off. Your Data Protection Officer is the person who writes it, keeps it current when your practices change, and answers the access and correction requests it invites. If you haven't appointed a DPO yet, start there β the notice is one of the first things they'll produce for you.
Common questions
Yes. The PDPA requires you to tell people why you collect, use and share their personal data before or at the point you collect it. A privacy notice is how a clinic meets that notification and openness obligation, and there is no size exemption for a small practice.
It should cover what patient data you collect, the purposes you use it for, who you share it with (such as labs, specialists and insurers or MediSave), how long you keep it, how patients can access or correct their records, and your DPO contact so patients know who to reach.
Put it where patients actually see it before they hand over their data: at reception (a printed copy or a clear sign on the registration form) and on your clinic website. Many clinics also add a short line on the intake form pointing to the full notice.
Yes, if your website collects any personal data at all β an appointment or contact form, or even just analytics cookies. A privacy notice page linked in your footer covers this, and it is also the easiest place to keep the always-available version patients and the PDPC can find.
Sources
- Personal Data Protection Commission (PDPC) β pdpc.gov.sg (Notification & Openness Obligations; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) β record-keeping requirements & the Healthcare Services Act (HCSA)
Want your clinic's privacy notice done for you?
We help Singapore clinics get PDPA-ready β a plain-English privacy notice, the policies behind it, and a named DPO. Done for you. Let's talk.