The GDPR Code of Conduct for Healthcare — What It Really Offers a Medical Facility
Medical facilities process some of the most sensitive data there is — information about patients’ health. At the same time, ever since the GDPR came into force, the healthcare sector has raised the most interpretive doubts: how to reconcile medical records with the right to erasure, how to approach monitoring, when a procedure may be recorded. In response to these problems, a tool emerged that many facilities still do not know about: the code of conduct for the healthcare sector approved by the Polish supervisory authority (UODO).
This is not another informal “good practice guide”. A code of conduct is an instrument provided for directly in the GDPR (Articles 40–41), and applying it has real legal weight — it helps demonstrate compliance and is taken into account when the supervisory authority considers imposing a fine.
This article explains what a code of conduct is under the GDPR, who the healthcare code is addressed to, what specific doubts it resolves, what real benefits it offers a facility, and what to bear in mind when considering joining it.
What a Code of Conduct Is under the GDPR
A code of conduct is a mechanism provided for in Article 40 GDPR. Organisations representing controllers or processors in a given sector may draw up a document that clarifies and facilitates the proper application of the GDPR, taking into account the specifics of that sector.
The key point is that a code is not one company’s internal document — to have effect, it must be approved by the supervisory authority (the President of UODO). In addition, under Article 41 GDPR, compliance with an approved code is monitored by an independent body accredited by the supervisory authority, which verifies whether members actually apply its provisions. It is precisely this oversight that distinguishes a code from a mere set of recommendations.
The Healthcare Sector Code — The Facts
The President of UODO approved the Code of Conduct for the healthcare sector on 11 December 2023 — as the second approved sectoral code in Poland. The key facts:
Author. The applicant was the Polish Hospital Federation (Polska Federacja Szpitali), working with a steering committee bringing together, among others, the Telemedicine Working Group Foundation, Private Medicine Employers, the Lewiatan Confederation, the Polish Chamber of Information Technology and Telecommunications, and the “Porozumienie Zielonogórskie” federation.
Who it is for. Contrary to a common belief, the code is not reserved for large hospitals. It is addressed to all entities performing medical activity — regardless of legal form, ownership structure, participation in public funding, or the scope and type of activity. It therefore covers hospitals as well as individual medical, nursing and physiotherapy practices. Importantly, it provides express relief for the smallest entities (more on this below). The code also applies to processors acting on behalf of medical entities (chiefly for the security requirements in Chapter 5). It is at the same time the first code that allows public hospitals to confirm the compliance of their processing with the GDPR. The code does not, however, cover entities outside medical activity — such as the fitness, lifestyle or dietetics industries — even if they process health data.
Monitoring body. This role is performed by KPMG Advisory sp. z o.o. sp.k., accredited by UODO, which admits new members, runs a contact point and verifies application of the code among private-sector members.
Content. The document runs to 112 pages, a large part of which are 10 practical annexes — including a model consent form, a sample risk-analysis procedure, a list of IT system safeguards, a list of information-security standards, and template applications for the status of an entity adhering to the code.
Nature. Applying the code is voluntary.
What the Code Resolves in Practice — Examples
The greatest value of the code lies in its concrete resolution of the dilemmas facilities face every day. A few examples straight from its text:
CCTV monitoring. The code clarifies the legal bases for monitoring in a facility (Article 6(1)(e) or (f) and — for patient data — Article 9(2)(i) GDPR, in conjunction with Article 23a of the Act on Medical Activity), sets the maximum retention period for recordings — 3 months — and provides that monitoring of patient bed rooms means, as a rule, live viewing without recording (recording only where medical knowledge dictates it should form part of the documentation). This is exactly the area UODO plans to inspect in 2026.
Recording of medical services. Recording the course of procedures for health purposes (for example endoscopic procedures, operating-field monitoring, sleep studies) becomes part of the medical records. Recording for purposes other than health — scientific research, commercial or training purposes — requires the patient’s explicit consent (Article 9(2)(a) GDPR).
“Large scale” and the DPO obligation. The code establishes that individual practices (medical, nursing, physiotherapy) do not, as a rule, process data “on a large scale” — and therefore need not appoint a data protection officer on that basis (Article 37(1)(c) GDPR), although the obligation may arise on other grounds. This is genuine relief for the smallest entities.
The right to erasure vs medical records. The code sets out the limits of the right to be forgotten where it meets the statutory obligation to retain medical documentation — one of the most common sources of confusion in the sector.
This shows that the code is not a set of generalities, but answers facilities’ real questions — from legal bases, through patients’ rights (Articles 13–21 GDPR), to security and risk analysis.
What It Really Offers a Facility — The Benefits
The key question is: why should a facility join the code? The benefits are concrete.
Evidence of compliance. The code expressly states that applying it is a circumstance confirming the fulfilment of GDPR obligations and serves the accountability principle. This concerns in particular the obligation to apply appropriate data protection measures (Articles 24 and 32 GDPR). Instead of building its case from scratch, the facility relies on a standard accepted by the supervisory authority.
Consideration when setting a fine. This is one of the strongest arguments. Under Article 83(2)(j) GDPR, when considering whether to impose a fine and its amount, the supervisory authority must in each case take into account whether the entity applies an approved code of conduct. Proper application of the code therefore works in the facility’s favour.
A ready-made standard and templates. The annexes (model consent, risk-analysis procedure, list of safeguards) save time and reduce the risk of error compared with drafting documentation alone.
Oversight and credibility. Monitoring by an accredited body gives patients, partners and payers confirmation that the facility genuinely cares about compliance — which matters for reputation and contracts.
Interpretive certainty. The code answers the doubts the sector has faced since the GDPR came into force, reducing the risk of misinterpreting the rules.
What to Bear in Mind
The code is not a “magic” solution and is worth approaching deliberately.
First, joining is voluntary, but it entails submitting to monitoring by the accredited body (KPMG) — which means specific obligations and rules of cooperation. Second, the code does not replace GDPR implementation — the facility must actually implement and apply its provisions; joining “on paper” alone offers no protection. Third, applying the code does not remove liability or exclude UODO’s powers — the supervisory authority retains full inspection competences. Finally, the monitoring body is KPMG, not UODO — this is independent sectoral oversight, not a “certificate from the authority”.
How to Prepare a Facility to Apply the Code
A sensible path to using the code runs through several steps:
- Assess the fit — whether the code matches the facility’s scale and profile (from an individual practice to a hospital).
- Review the current state — audit the documentation and processes against the code’s requirements: legal bases, notices, record of processing activities, risk analysis, safeguards.
- Close the gaps — align procedures and templates with the code’s standard.
- Join and be monitored — apply to the monitoring body and submit to verification.
- Maintain compliance — apply the provisions on an ongoing basis and update them as things change.
Why This Matters Especially in 2026
The topic is particularly timely. UODO’s 2026 sectoral inspection plan includes healthcare entities — specifically the security of data when using CCTV monitoring, with particular attention to children’s data. The code contains a dedicated section on monitoring (legal bases, retention, bed rooms), so applying it — or at least carrying out a readiness audit — is genuine preparation for an authority visit.
Checklist — Before You Join the Code
- Established whether the code matches the facility’s scale and profile.
- Carried out a compliance audit of current documentation and processes.
- Verified the legal bases for processing patient and employee data.
- Implemented a risk analysis and security measures (Articles 24 and 32 GDPR).
- Tidied up privacy notices and the handling of patients’ rights.
- Verified CCTV monitoring (basis, 3-month retention, bed rooms) and the rules on recording services.
- Checked the obligation to appoint a DPO in light of the scale of processing.
- Planned the application to the monitoring body and ongoing compliance.
Need to Prepare Your Medical Facility to Apply the GDPR Code?
The code of conduct for the healthcare sector is a real opportunity for medical facilities — from individual practices to hospitals — but to make use of it, you first need to bring data protection up to the required standard. At the Law Office of Dr Joanna Maniszewska-Ejsmont, we help medical entities assess their readiness, carry out a GDPR audit and align their documentation and processes — so that the facility can safely apply the code and be prepared for a UODO inspection.

Check the details of our GDPR audit and implementation for healthcare and get in touch — we will help you prepare your facility.
