UK GDPR notes for independent Ayurveda practitioners
Independent practitioners in the UK are data controllers the moment they keep a client record. That comes with real obligations, and most of them are simpler to meet than they sound — as long as client data and marketing data are never stored in the same place.
Keep client records and marketing files separate
Client health information (assessments, therapy plans, follow-up notes) should live in a system with strict access control and no public exposure. Marketing material — practitioner bios, headshots, blog posts — is a completely different category and should never share a storage bucket, database table, or backup with client records.
Consent is per purpose
A client consenting to treatment is not consenting to their case being used as a testimonial. A practitioner consenting to a marketing profile is not consenting to that data being merged with client-facing systems. Track consent per purpose, with a clear record of when it was given and how it can be withdrawn.
Practical checklist
- Separate storage for client data vs. marketing/public content.
- Explicit, timestamped consent for anything used publicly.
- A documented process for consent withdrawal (Kosha Connect uses a 14 business day window internally).
- Access limited to the practitioner and the client, not the whole team, by default.
None of this requires expensive tooling — it requires deciding early which data is which, and never letting the two mix.
