Patient Intake Forms for Clinics — GDPR Compliance
Compare GDPR-aware intake forms software for clinics: lawful basis, special category data, consent records, EU hosting, and data subject rights.

Compare GDPR-aware intake forms software for clinics: lawful basis, special category data, consent records, EU hosting, and data subject rights. It covers what makes clinical intake forms different from standard forms, GDPR requirements for the intake form itself, what to look for in intake forms software, and platform comparison.
Patient Intake Forms Software for Clinics — GDPR Guide (2026)
Patient intake forms software for clinics is the digital system that collects, stores, and routes new patient information before or at the first appointment. For EU-based clinics, the selection criteria go beyond usability and feature set — the system must handle special category health data under GDPR, which imposes requirements that standard form software (Google Forms, Typeform, generic CRMs) is not designed to meet.
This guide covers what intake forms software must do to be GDPR-ready in a clinical setting, the specific data fields and consent mechanisms that create compliance obligations, and how to evaluate platforms for EU practices.
What Makes Clinical Intake Forms Different from Standard Forms
A standard web form collects contact information or preferences. A clinical intake form collects health data — medical history, current medications, presenting symptoms, allergies, prior diagnoses. Under GDPR, health data is "special category" personal data under Article 9, subject to higher protection requirements than ordinary personal data.
The practical implications:
Stricter lawful basis: Processing special category data requires not only a lawful basis under Article 6 but also an additional condition under Article 9(2). For clinical treatment, Article 9(2)(h) — processing necessary for the purposes of preventive or occupational medicine, medical diagnosis, or the provision of health or social care — is typically the basis. This must be documented.
Data minimisation: The intake form should collect only the information genuinely necessary for the clinical purpose. A physiotherapy clinic does not need full psychiatric history. A veterinary clinic does not need the owner's employment details. Over-collection of special category data creates compliance risk with no clinical benefit.
Security requirements: Special category data requires "appropriate technical and organisational measures" — encrypted transmission, encrypted storage, access controls (only clinical staff who need the data can access it), and audit logging of who accessed what and when.
Data subject rights: Patients have rights under GDPR including access, rectification, restriction of processing, and erasure. The system must be able to export a complete individual record and delete or anonymise it on request.
GDPR Requirements for the Intake Form Itself
Consent vs contractual basis
Many clinics default to a consent checkbox on the intake form: "I consent to my data being processed for clinical care." This is often the wrong legal basis.
When to use consent (Art. 6(1)(a)): For optional processing — marketing emails, newsletter subscriptions, research participation. Consent must be freely given, specific, informed, and withdrawable. If a patient refuses, they must still be able to receive care.
When to use contractual basis (Art. 6(1)(b)): For processing necessary to provide the clinical service the patient is booking. The appointment cannot happen without basic demographic and contact data. The intake form should state: "We collect this information to provide clinical care. Processing is necessary under our contract with you (Art. 6(1)(b))."
For health data — Art. 9(2)(h): Health information on the intake form is processed under the clinical care exemption. This does not require explicit consent — it requires that the processing is performed by a healthcare professional under a duty of confidentiality.
The privacy notice linked from the intake form must state the lawful basis for each category of data collected.
Mandatory disclosures
Every clinical intake form must include or link to:
- Identity and contact details of the clinic (data controller)
- Purpose and legal basis for each category of data collected
- How long data will be retained
- The patient's rights (access, rectification, restriction, erasure, complaint to supervisory authority)
- Contact details for the data protection officer if one has been appointed
This information typically sits in a privacy notice linked from the form — but the link must be prominent and accessible before submission.
Consent records for marketing
If the intake form includes an optional marketing consent checkbox, that consent must be recorded: the text shown, the date and time, the IP address, and whether consent remains active or has been withdrawn. This is the audit trail required to demonstrate valid consent.
What to Look for in Intake Forms Software
Field configuration and data minimisation
The system should support configuring exactly which fields appear on each form template — new patient intake, returning patient update, consent-only form, minor patient form. Each template should include only the fields relevant to that clinical context.
Red flag: Systems where the intake form is a fixed template with fields you cannot remove. This may result in collecting more data than is necessary for the clinical purpose.
Conditional logic
Clinical intake forms benefit from conditional logic: if the patient answers "yes" to a medical history question, additional relevant questions appear. This reduces form length for patients without the condition while collecting necessary detail from those who do have it.
Digital signature for consent forms
For forms requiring explicit consent — clinical treatment consent, research participation, data sharing authorisation — the system should support a legally valid digital signature. At minimum, a simple electronic signature (SES under eIDAS) with the patient's name, date, and IP address recorded. For higher-risk clinical contexts, consider whether advanced electronic signatures (AES) are required.
Secure submission and storage
Transmission must be over HTTPS. Storage must be encrypted at rest. The system must provide evidence of these controls — not just a policy statement.
EU data residency
Health data collected from EU patients must be hosted within the EU, or Standard Contractual Clauses (SCCs) must be in place for any third-country transfers. Confirm where the system's servers are physically located. "EU-compliant" is not the same as "EU-hosted."
processor terms
The intake forms software vendor processes health data on behalf of your clinic — this makes them a data processor under GDPR, and processor terms must be in place. This is a contractual obligation, not an option. If the vendor does not offer a standard processor terms, or charges extra for it, that is a compliance gap.
Integration with patient records
Intake form data should flow directly into the patient record in the practice management system — not require manual re-entry by front desk staff. Re-entry introduces transcription errors and defeats the efficiency purpose of digital intake.
Platform Comparison
| Feature | Tregovia Client Forms | Generic form tools | Clinical platforms |
|---|---|---|---|
| Privacy terms | Review current terms | Varies | Usually yes |
| GDPR-aware workflow support | Yes | Varies | Varies |
| Art. 9(2)(h) basis support | Yes | No | Yes |
| Conditional logic | Yes | Yes | Yes |
| Digital signature (SES) | Yes | Varies | Yes |
| Direct EHR/record integration | Yes | No | Yes |
| Consent record audit trail | Yes | No | Yes |
| DSAR export per patient | Yes | No | Varies |
| Flat-rate pricing | Yes | Varies | Per user |
Verify current features at each vendor's website before purchasing.
Setting Up in Tregovia
Tregovia's Client Forms module (EUR 15/month) supports GDPR-aware patient intake workflows for EU clinical practices:
Form configuration:
- Configurable field sets per form template (new patient, follow-up, consent-only)
- Conditional logic: show/hide fields based on patient answers
- Required field enforcement before submission
Privacy workflow:
- Add privacy notice text or links inside form instructions
- Use separate fields for care-related information and marketing consent
- Store submitted data against the client and, where relevant, the appointment
- Use signature fields for acknowledgement where a full e-signature envelope is not required
Data flow:
- Submitted intake data automatically routes to the patient record
- No manual re-entry required
- Form completion tracked per patient record
Rights management:
- DSAR export: complete patient data record exportable per patient
- Erasure request: patient record anonymisation tool
Compliance note: Confirm processor terms, hosting, sub-processor, and retention terms before collecting special-category health data. Tregovia can support the workflow, but the clinic remains responsible for lawful basis and process design.
Pricing: Base plan EUR 47/month (up to 2 staff, up to 100 clients (extra users EUR 10/month per 5 seats)). Forms & Intake module EUR 15/month — flat rate. 14-day free trial.
FAQ
Can a clinic use Google Forms for patient intake under GDPR?
Not for collecting health information. Google processes data on US-based infrastructure, and while Google does offer SCCs, Google Forms is not designed for health data processing — it lacks a health-context processor terms, does not have clinical access controls, and does not produce the audit trail required for special category data. The data protection authority in most EU member states would not consider Google Forms an appropriate tool for patient health data collection.
What is the retention period for intake form data?
It depends on the data category and the member state's healthcare regulations. Clinical records are typically subject to a minimum retention period under national healthcare law — commonly ten years from the last clinical contact, or until age 18 plus ten years for minors (whichever is longer). Marketing consent records should be retained for as long as the consent is relied upon plus a reasonable dispute resolution period. The intake forms system should support configurable retention periods and automated flagging for records approaching their retention limit.
Does every new patient need to complete an intake form?
Yes, as the basis for establishing the clinical record. The intake form creates the minimum dataset necessary to provide safe clinical care: identity verification, contact details, emergency contact, relevant medical history, and current medications and allergies. Even returning patients who previously completed a paper form should complete a digital intake form when the practice transitions to a digital system, to establish a baseline record and update any changed information.
What happens to intake form data if the patient does not convert to an ongoing patient?
If a prospective patient submits an intake form but never attends an appointment, the data was collected for a clinical purpose that was not completed. Under GDPR, it should be retained for a defined period (typically aligned with the standard clinical record retention period) and then deleted or anonymised. The intake forms system should support automated deletion or anonymisation of non-converted records after the retention period expires.
Should the intake form be completed before or at the first appointment?
Before, where possible. Sending the intake form link in the appointment confirmation email allows the patient to complete it at home without time pressure and without requiring a paper form or digital kiosk at the clinic. Pre-appointment completion also allows clinical staff to review the intake information before the appointment and flag anything requiring additional preparation — a complex medical history, an allergy that requires different materials, or a request for adjustments. Same-day digital completion is a fallback, not the primary workflow.
Related articles
Commercial
Best Massage Therapist Software for Booking and Intake
What massage therapists should look for in software: online booking, deposits, intake forms, notes, packages, reminders, and mobile-friendly admin.
Commercial
Best Nail Salon Software: Booking, Deposits, Reminders (2026)
Choose nail salon software that cuts no-shows with deposits and reminders, sells packages and gift cards, and keeps client preferences in one place.
Commercial
Booksy Total Cost for Barbers
A practical Booksy total cost model for barbers: subscription, staff, Boost, payments, VAT/tax, reminders, migration time, and CRM comparison.
GDPR-ready practice management software
Platform gives teams GDPR-aware controls for consent records, access, exports, and right-to-erasure workflows. Review your DPA and local obligations before going live.