Back to the blog

GDPR and health advertising: what UK clinics can and cannot do

What UK clinics can and cannot do in health advertising under UK GDPR: special category data, safe targeting options and consent basics, in plain English.

Brand Developer · 14 April 2026 · 6 min read

The short answer: UK clinics can advertise online effectively and legally, but they cannot use people's health information to target them. Health data is "special category data" under UK GDPR, which means you must not build audiences based on medical conditions, treatments received or interest in specific procedures inferred from personal data. What you can do is advertise to people based on what they are searching for, the content they are viewing and your own properly consented lists.

That distinction, targeting the intent rather than the person's health status, is the line that keeps a clinic on the right side of the rules. This article walks through what it means in practice for Google and Meta advertising. One caveat before we start: this is practical guidance from a marketing perspective, not legal advice, and your data protection officer or adviser should review your specific setup.

What counts as special category data?

Under UK GDPR, data concerning health gets extra protection. For a clinic's marketing, that includes obvious things like patient records, but also less obvious ones: the fact that someone enquired about dental implants, attended a consultation or filled in a form about a specific treatment. Even an email list labelled "Invisalign enquiries" is, arguably, health-related data, because membership of the list reveals something about the person's health interests.

The consequences of getting this wrong are not theoretical. The Information Commissioner's Office (ICO) can issue fines of up to 17.5 million pounds or 4% of annual worldwide turnover, whichever is higher, and health data breaches are treated among the most serious. For a clinic, the reputational damage of a data misuse story usually costs more than the fine itself.

What can clinics NOT do in their advertising?

Four practices to avoid, all of them common enough to mention:

  1. Uploading patient lists to ad platforms without a proper lawful basis and explicit consent. Sending your patient database to Meta or Google to build a "custom audience" processes health data. Doing it without explicit consent is the classic mistake.
  2. Building remarketing audiences from treatment-specific pages without consent. If your cookie banner is decorative and tracking fires before anyone consents, every visitor to your "dental implants" page ends up in a health-related audience unlawfully.
  3. Targeting by health conditions or inferred health interests. The major platforms have removed most health-based targeting options themselves, but recreating them through lookalikes built on patient data lands in the same place.
  4. Putting health details in ad tracking. Sending treatment names, form answers or anything identifying into analytics or ad pixels alongside personal identifiers is a data leak you built yourself.

What CAN clinics do?

Plenty, and the effective channels are mostly the compliant ones anyway:

  • Search advertising on intent. Someone typing "emergency dentist near me" is expressing intent in that moment. Showing them an ad is advertising to a search, not processing their health data. This is why Google Ads remains the backbone of clinic marketing.
  • Contextual and broad awareness campaigns. Advertising your clinic to a geographic area, without health-based targeting, is fine and often works better than clinics expect.
  • First-party audiences built with real consent. A newsletter list where people explicitly agreed to marketing, with clear wording about what they signed up for, is a legitimate asset. The keyword is explicit: pre-ticked boxes and buried clauses do not count.
  • Remarketing behind a genuine consent banner. If tracking only fires after a real choice, and your privacy notice explains it, remarketing from general site pages is workable. Expect a real cost: a meaningful share of visitors will decline, and campaigns must live with that.

How should a clinic set this up in practice?

Three practical steps cover most of the risk. First, implement a proper consent management platform and Google consent mode, so tags respect the visitor's choice instead of ignoring it. Second, audit what your pixels actually send: form contents, page URLs with treatment names attached to identifiers, anything that could link a person to a condition. Third, document your lawful basis for each marketing activity, because "we did not think about it" is the one answer the ICO never accepts.

It is also worth reframing the effort: consent-based marketing produces smaller but cleaner audiences, and clinics that adapt early tend to build an advantage while competitors keep relying on tracking that quietly stopped being lawful years ago.

What about advertising content rules?

Data protection is only half the picture. What your ads actually say is governed separately by the Advertising Standards Authority (ASA) and the CAP Code, and for regulated professionals by the General Dental Council or equivalent body. The recurring pitfalls: before-and-after claims that overpromise, time-limited discount pressure on medical treatments, and testimonials implying guaranteed outcomes. None of that is a GDPR issue, but it triggers complaints just as effectively, and a pulled campaign costs you the same either way. A practical habit that prevents most problems: have one person in the clinic review every new ad against a short internal checklist (claims substantiated, no outcome guarantees, pricing conditions clear) before it goes live.

The bottom line

You do not need grey-area targeting to fill a clinic's diary. Intent-based search, honest local awareness and properly consented first-party lists do the job, and they keep working when regulations tighten further. If you would like a plain-English review of how your current campaigns and tracking handle these rules, you can request a free audit at brand-developer.com; we will map what your setup collects, where the risks sit and what we would fix first.

Found it useful? Let's see what it means for you.

Fill in the form and we'll talk about your business. We'll tell you honestly what we'd do in your position, including when the answer is that we can't help.

An honest analysis of your situation, not a sales pitch
Concrete numbers and observations, not impressions
Free, with no obligation
GDPR and health advertising: what UK clinics can and cannot do | Brand Developer