Skip to content
WebAsk
CRM & Automation

CRM for UK Clinics: What to Check Before You Buy

A clinic CRM can hold health data. What to check before you choose one: the processor contract, where data goes, access and logs, patient rights and records.

WebAsk founder Ansar Cheema
Ansar Cheema

Founder · · 20 min read

A manager at an aesthetic clinic, dental practice or beauty and wellness business has two CRM trials open side by side. Both show tidy pipelines and reminder texts.

So what should you check in a CRM for UK clinics? Start with the data. If it reveals a patient's health, UK GDPR asks more of you.

Checked against the regulations, the ICO's guidance and the vendors' own pages on 5 October 2026. WebAsk is a web and CRM agency, not a law firm. This is not legal advice.

TL;DR

A clinic CRM can hold health data, which needs an Article 9 condition as well as a lawful basis. Check the contract, where the data is stored, who can see it, and how you export and delete a patient's record. GoHighLevel's and HubSpot's own pages both put conditions on health data. A table of questions to ask any vendor, with what both vendors' pages say, is near the end.

Why a clinic CRM can hold health data

A CRM can hold intake answers, bookings and invoices. The Information Commission (the ICO) says health data can include "appointment details, reminders and invoices which tell you something about the health of the individual" (special category guidance, under review). They "must reveal something about a person’s health status". The ICO adds that you "could reasonably infer health data" from a list of appointments at an osteopath clinic.

Where those records reveal health, the ICO's rules page (under review) says "you must identify both a lawful basis under Article 6 and a condition for processing special category data under Article 9." Forms are covered in our clinic website compliance checklist.

Article 9 conditions for health care and consent

Article 9(2) lists the conditions. One is health or social care (9(2)(h)). It is met "if the processing is necessary for health or social care purposes", including "the provision of health care or treatment" (Data Protection Act 2018, Schedule 1). It needs an obligation of secrecy (Article 9(3)). Another is explicit consent (9(2)(a)), which "must be confirmed in a clear statement", the ICO says (under review).

No source we read decides whether a cosmetic treatment is "health care or treatment". The choice is the clinic's to make and record.

Can GoHighLevel or HubSpot hold health data?

Both set conditions. HighLevel, the company behind GoHighLevel, says in its data processing addendum (July 2026): "The Parties do not anticipate the transfer of special categories of data, unless Customer first notifies HighLevel". Its security overview (16 June 2026), which says it is not binding, adds that the products "should not be used" for "health information except as otherwise permitted".

HubSpot's product catalogue says "Customers with an Enterprise edition subscription may enable Sensitive Data", and lists "Health data" as a permitted type. Once on, "it’s not possible to remove the selected categories" (help page, 21 September 2026). GoHighLevel's plans and prices are in our buyer's guide.

Is GoHighLevel GDPR compliant?

HighLevel's overview says: "While HighLevel seeks to enable your GDPR compliance efforts, use of the HighLevel product alone does not make you GDPR compliant." Article 28(1) says to use "only processors providing sufficient guarantees". The ICO's security guide (under review) says the controller is responsible, and "this includes what the processor does with the data". No ICO page we read calls a product "GDPR compliant"; it puts compliance on the controller.

The processor contract under Article 28

In the ICO's example, a cloud service an organisation uses to store its data is "its processor". The ICO says "there must be a written contract" (ICO, under review). Article 28(3) says the contract "shall stipulate", among other things, that the processor acts "only on documented instructions" and keeps the data secure. It must also say the processor helps you answer patients' requests "insofar as this is possible", and "deletes or returns" the data at the end. Under a general written authorisation, Article 28(2) gives you "the opportunity to object" to a new sub-processor.

Where clinic data is stored and sent

HighLevel's overview says: "Our product infrastructure resides in the United States." HubSpot's hosting FAQ (24 July 2026) lists data centres in the United States, Canada, Australia and "European Union (Germany)", and none in the UK.

Since 5 February 2026, Article 44A allows a transfer abroad only if regulations approve it, it has "appropriate safeguards", or "a derogation for specific situations" applies.

The UK Extension and the DPF list

For the US, the approval is the UK–US data bridge (SI 2023/1028). It covers transfers to businesses on the Data Privacy Framework (DPF) List "participating in the UK Extension". The ICO's UK Extension page (30 July 2026) says the business must have "an active status on the DPF list", and "You should undertake periodic checks".

On 5 October 2026, the DPF List showed HighLevel Inc and HubSpot, Inc. as active for the UK Extension, for non-HR data. HubSpot's next certification is due on 6 November 2026, and HighLevel's on 15 September 2027.

The government's data bridge factsheet (21 September 2023) says "medical or health conditions" are sensitive under the DPF, and that this "must correctly be identified by UK organisations" when shared. Without the UK Extension, it points to safeguards such as the International Data Transfer Agreement. The ICO's transfers guide (15 January 2026) adds: "If you rely on a safeguard, you must also ensure that you have completed a transfer risk assessment (TRA)."

Do you need a DPIA for a clinic CRM?

The ICO's rules page says you "must do a data protection impact assessment (DPIA) for any type of processing which is likely to be high risk". You are "more likely to need to do a DPIA for special category data", it adds. And you "must carry out a DPIA" if you plan to process special category data "on a large scale", matching Article 35(3)(b).

The ICO's DPIA guidance (under review) weighs factors such as "the number of individuals concerned". Its large-scale examples include "a hospital (but not an individual doctor) processing patient data". And: "Individual professionals processing patient or client data are not processing on a large scale." A clinic with several practitioners sits between those examples, and no source we read places it.

The same guidance lists "Sensitive data or data of a highly personal nature" and "Data concerning vulnerable data subjects" among nine criteria that "may act as indicators of likely high risk processing". It says vulnerability "could also arise" from "the specific context of the processing (e.g. patients receiving medical care)". And: "In most cases, a combination of two of these factors indicates the need for a DPIA. However, this is not a strict rule." The ICO's rules page adds: "If in doubt, we recommend you carry out a DPIA."

Access, two-step login and audit logs

Article 32 requires security "appropriate to the risk". The ICO's security outcomes (under review) say access must be "limited to those users who reasonably need such access". You should "consider two-factor or hardware authentication measures" for users with privileged access, it says, and ensure "an appropriate audit trail".

HighLevel's audit log entries are "retained for 60 days and then purged" (see the table), so export what you need.

Patient rights the CRM has to support

Subject access within the time limit

Test this before you sign: can staff find and export everything about one patient?

The ICO says "You must respond without undue delay, and within one month of receipt of the request" (subject access guide, 16 July 2026). The same guide says the month can instead run from receiving "information confirming the identity of the person the information is about", "information that shows a third party is authorised to act on behalf of the person" or "a fee". It also says "In most circumstances, you cannot charge a fee to deal with a request", and "you should only request formal identification if necessary". Article 12(3) points to Article 12A: "one month beginning with the relevant time". By notice, you can extend it "by two further months" where complex or numerous requests make that necessary.

Erasure, correction and objections

Patients can have inaccurate data corrected "without undue delay" (Article 16). Erasure "is not absolute", says the ICO (right to erasure, under review). Under the health-care condition, "the individual does not have a right to erasure" (conditions page, under review). Where erasure applies, backups count too: the ICO says to put them "beyond use".

A patient can object to direct marketing "at any time" (Article 21). The ICO calls this "an absolute right" (right to object, under review). Keeping a suppression list is covered in our database reactivation guide.

Ask whether the CRM can record, for each patient, the lawful basis, the Article 9 condition, marketing consent by channel and any objection. Neither vendor names an Article 9 field on the pages we read. HighLevel's chat widget can "Pre-check the box by default" (consent article, 1 September 2026). The ICO says "Don’t use pre-ticked boxes" for consent (consent guidance, under review).

Our reminders guide covers whether a reminder is marketing, and our missed-call guide covers texts after a missed call.

How long clinic records are kept

"The UK GDPR does not set specific time limits for different types of data. This is up to you, and will depend on how long you need the data for your specified purposes", says the ICO (storage limitation, under review). Personal data shall be kept "for no longer than is necessary" (Article 5(1)(e)).

Dental practices

The GDC's Standards (4.1.3) say you "must follow appropriate national advice on retaining, storing and disposing of patient records". For NHS dental practices, the NHS Business Services Authority's FAQ gives "clinical care records - 11 years". It points to the Records Management Code of Practice on the NHS England website, which we could not open on 5 October 2026. No page we read sets a period for private dental records. In England, Regulation 17(2)(c) requires systems that let a CQC-registered provider "maintain securely an accurate, complete and contemporaneous record" for each service user. It sets no period. See also our page for dental practices.

Aesthetic clinics and beauty businesses

No source we read sets a period for private aesthetic or beauty records. Regulation 17 applies only to a clinic registered with the CQC, and whether one must register depends on what it does. See also our pages for aesthetic clinics and beauty and wellness clinics.

Questions to ask any CRM vendor

What each vendor's own pages said on 5 October 2026. Not a ranking. Pages change, so check again before you sign.

Question to askThe law or ICO guidance behind it (read 5 October 2026)GoHighLevel's own pagesHubSpot's own pages
Will you sign a processor contract?Article 28(3) and (9): a contract "in writing, including in electronic form"Addendum (July 2026): "HighLevel will act as a Processor"Agreement (16 September 2026): "we are the Processor under the Agreement"
May I store health data, and on what terms?Article 9(1); ICO: health data "can include" appointment detailsAddendum: not anticipated "unless Customer first notifies HighLevel". Overview (not binding): "should not be used" for health information "except as otherwise permitted"Catalogue: Sensitive Data on Enterprise, under the Sensitive Data Terms; categories cannot be removed once on
Where is the data stored?Article 44A; an EEA state counts as approved (Data Protection Act 2018, Schedule 21)Overview (16 June 2026): "Our product infrastructure resides in the United States." No UK or EU option statedHosting FAQ (24 July 2026): United States, Canada, Australia or Germany; none in the UK. Assigned by "the geolocation of your IP address at sign-up"; with a paid subscription, "you can change your data center". "In a very limited number of cases", processing can happen elsewhere
Is your US company active on the DPF List for the UK Extension?SI 2023/1028; ICO: "You should undertake periodic checks"HighLevel Inc: active, non-HR data, next certification due 15 September 2027HubSpot, Inc.: active, non-HR data, next certification due 6 November 2026
How will I hear about new sub-processors?Article 28(2): "the opportunity to object"List last modified September 2025, in the United States and India; addendum: "written notice", you "may subscribe to receive such notifications", and 30 days to objectList (16 September 2026); agreement: notice "at least 30 days" ahead, only "If you opt in to receive such email"
Can I limit access and require two-step login?Article 32; ICO: "consider two-factor or hardware authentication measures"Roles (1 October 2026): "Admin or User", plus "Only Assigned Data". Overview: built-in login users "are protected by two-factor authentication"; administrators "may require" it for all usersLimit access (30 September 2026): manage access "so only the right teams and users can view and edit them". 2FA (28 September 2026): "required for all users" logging in with a password on Starter, Professional and Enterprise
How long are audit logs kept?ICO: "an appropriate audit trail"Audit logs (12 May 2026): "retained for 60 days and then purged"; export to CSVAudit log (23 September 2026): the All Logs view shows "all log categories within the last 30 days"; a security activity export covers "the last year"; changes from form submissions are not shown
Can I find and export one patient's record?Articles 12A and 15; the ICO's subject access guide (16 July 2026): requests can come "verbally or in writing, including via social media"Addendum, under data portability: "Customers can download their personal data from within the Service."Agreement: controls "to retrieve, correct, delete, or restrict" personal data
What does deletion remove, and when?Article 17; ICO: backups "beyond use"Delete contacts (13 June 2025): admins only; restorable for 60 days; linked conversations and notes "permanently lost"Permanent delete (28 September 2026): one record at a time; purge "up to 30 days"
Can I record the lawful basis, Article 9 condition and consent?Articles 6 and 9; ICO: "Don’t use pre-ticked boxes"Consent article (1 September 2026): a legal-basis custom field with "Consent, Contractual Obligation, Legitimate Interest"; no Article 9 field namedLawful basis (28 September 2026): "Legal basis for processing contact's data", six default options; no Article 9 field named
Can I set how long records are kept?Article 5(1)(e)Unsettled. Addendum: "Data retention can be configured with respect to specific individuals by the customer administrator." Overview: does not currently offer "custom data retention policies"Not stated on the pages read
Will you help with a DPIA?Article 35Addendum: will "assist Customer" with "data protection assessments" "when required pursuant to Applicable Data Protection Laws", "taking into account the nature of Processing and information available"Agreement: "To the extent that the required information is reasonably available to us, and you do not otherwise have access to the required information", "reasonable assistance to you with any data protection impact assessments"
How soon will you tell me about a breach?Article 33(2): the processor tells you "without undue delay"Addendum: "within seventy-two (72) hours of becoming aware"Agreement: "no later than seventy-two (72) hours, after we become aware"
Do the AI features change any of this?Article 28(2): another processor needs your "prior specific or general written authorisation"Terms (June 2026): do not provide "sensitive personal information, Protected Health Information (PHI)" to the AI featuresCatalogue: agents may access Sensitive Data "only where the applicable feature is designated as supporting it under the Sensitive Data Terms"; some features are "Unavailable for Sensitive Data accounts due to additional legal, compliance, and AI-processing requirements"

A checklist before you sign

  1. Decide whether the CRM will hold health data. If so, record your lawful basis and Article 9 condition.
  2. Read the processor contract against Article 28(3), and opt in to sub-processor notices.
  3. Before adding health data, notify HighLevel, or turn on Sensitive Data in HubSpot Enterprise.
  4. Check the vendor's US company on the DPF List, and diarise a re-check.
  5. If you rely on a safeguard instead, complete a transfer risk assessment.
  6. Limit access by role, consider two-step login for admin users, and export audit logs you need.
  7. Test a subject access export and a deletion on a test record.
  8. Add fields for lawful basis, Article 9 condition, marketing consent and objections.
  9. Set how long each kind of record is kept, and write it down.
  10. Screen for a DPIA, and do one if in doubt.

Where to start

  1. Check what you run now against the checklist. Moving from HubSpot to GoHighLevel? Our migration guide covers the move.
  2. If you want it built, our CRM and automation service is "built on GoHighLevel first and HubSpot where it fits", with "legal form and consent recorded at entry", in "an account you own".
  3. Get in touch.

Ready to put this into practice?

Book a 30-minute discovery call — we'll map the highest-leverage moves for your business and send a written scope within three working days.

Book a discovery call