A screen showing a privacy lock
Home / Guides / Data and privacy abroad
Safety and trust guide · Last reviewed 2 October 2025
Written and maintained by the Clinics for Kings editorial desk·Edited by Morten Andersen & Fredrik Filipsson
Fact-checked against the cited medical and cost sources by the Clinics for Kings editorial desk·General information, not a clinician’s review — always consult a licensed doctor.

Data and privacy abroad.

Booking treatment abroad means sending photos, scans, and a medical history to people you have never met, often through agencies and apps. Here is how your health data is protected and how to keep control of it.

General health information, not medical advice, and not a substitute for a qualified doctor. Always consult a licensed professional before making any decision.
Special category
health data gets the strongest protection under GDPR Article 9
Transfers controlled
moving data outside the EU needs a lawful mechanism
You have rights
access, correction, and erasure, within limits
The one honest thing
Once your scans and photos sit on a server in another country, getting them deleted is much harder than choosing not to send them.
Quick answer

Is my health data protected?

It depends on where it ends up. In the EU and UK, health data is a special category under Article 9 of the GDPR and receives the strongest protection, with processing restricted and your explicit consent often required. Once data moves to a country outside that area, it is only protected to the standard of that country unless a lawful transfer mechanism keeps the protection with it.

In medical travel your data often passes through agents, booking platforms, and clinics in different countries. Each hop is a point where protection can weaken. You cannot control every system, but you can control what you share, with whom, and on what terms, which is where most of your real protection lives.

What the law says

Why health data is treated specially.

Health data can reveal the most private facts about you, so the law guards it more tightly than ordinary personal data.

Under the GDPR, which applies across the EU and, in its retained form, the UK, health data is a special category of personal data under Article 9. Processing it is prohibited by default and allowed only under specific conditions, such as your explicit consent or the provision of healthcare. That higher bar reflects how sensitive it is, since a leak can affect employment, insurance, relationships, and reputation.

The same framework gives you rights over your data: to be told how it is used, to access a copy, to have errors corrected, and, in defined circumstances, to have it erased or its processing restricted. Organisations must also keep it secure and use it only for the purposes you were told about.

These protections are strongest while your data stays within the EU and UK. The question for medical travel is what happens when it leaves.

Crossing borders

What changes when data leaves.

A different country can mean a different standard of protection, unless a recognised mechanism carries the protection across.

Sending your data to a clinic outside the EU and UK is, in data protection terms, an international transfer. The law allows this only with a valid basis and an approved safeguard. The main routes are an adequacy decision, where the destination country is judged to offer equivalent protection, standard contractual clauses or binding corporate rules agreed between the organisations, or, for occasional transfers, your explicit and informed consent.

In practice, when you upload photos and scans to a clinic or an agency in another country, you are often relying on consent you gave when you ticked a box. That is lawful, but it means you should know who receives your data, in which country, and what they will do with it, because once it is there your home country's rules no longer control it.

Agencies and booking platforms add more parties. The more hands your data passes through, the more places it can be stored, copied, or exposed.

Staying in control

What to ask, and what to limit.

You will not audit a clinic's servers, and you do not need to. Control what you share and on what terms. These questions, and a little restraint, do most of the work.

1
Who exactly will receive my data, and in which countries?
Ask for the clinic and any agency or platform involved, and where each is based, so you know where your data goes.
2
What is the lawful basis and safeguard for sending it abroad?
Look for explicit consent, an adequacy decision, or standard contractual clauses. A clear answer signals a serious operator.
3
What will be used for marketing, and can I opt out?
Your medical photos and history should not become advertising. Confirm this and withhold consent for marketing use.
4
How long is my data kept, and can I have it deleted?
Ask about retention and your right to erasure, and get the deletion process in writing.
5
How is the data stored and secured?
Encryption, access controls, and secure channels matter. Avoid sending sensitive files over open email or chat where you can.
6
Will my before and after images ever be published?
Never assume consent to publish. If you do not want your images used, say so in writing and keep the reply.
Practical protection

Share less, and share it carefully.

The simplest privacy control is the one fully in your hands: what you choose to send, and how.

Share only what is clinically necessary, and prefer secure channels over open email or social messaging for photos and scans. Be wary of sending identifiable images you would not want made public, and never agree to your before and after photos being used in marketing unless you genuinely accept that. Read the privacy notice and consent boxes before you tick them, and keep a copy of what you agreed to.

If you later want your data removed, ask in writing and reference your right to erasure where it applies, though be realistic that enforcement across a border can be slow. The most reliable protection remains not sending sensitive data to parties you have not vetted in the first place.

This is general information, not legal advice. Data protection rules and how they are enforced vary by country, so confirm the specifics with a qualified professional if a particular concern matters to you.

Get Matched with a vetted clinic

Now you know what to ask, compare safely.

Send one brief and we route it to vetted clinics that meet the standards in this guide. They return tailored plans and all in prices. You choose, with no pressure.

Free and no obligation. Accredited clinics only. We never sell your details and we never name a clinic to you here.

We reply within two working days. Your details are never sold.

How we make money: the guides are free and no clinic can pay to be named, ranked or recommended. We never name clinics. Get Matched is an optional service that helps keep the guides free and independent of any one clinic; using it is always your choice and you are never charged. How this works.

Common questions

The things people ask.

Is my health data protected when I book treatment abroad?

Within the EU and UK it is strongly protected, because health data is a special category under Article 9 of the GDPR with processing restricted and explicit consent often required. Once your data moves to a country outside that area, it is only protected to that country's standard unless a lawful transfer mechanism carries the protection with it.

What does special category data mean?

It is a class of especially sensitive personal data, including health information, that the GDPR protects more tightly than ordinary data. Processing it is prohibited by default and permitted only under specific conditions, such as your explicit consent or the provision of healthcare, because a leak can cause serious harm.

What are the rules when my data leaves the EU?

Sending health data outside the EU and UK is an international transfer that needs a valid basis and an approved safeguard. The main routes are an adequacy decision, standard contractual clauses or binding corporate rules, or, for occasional transfers, your explicit informed consent. In medical travel, consent you gave when uploading files is often what the transfer relies on.

Can a clinic use my before and after photos in advertising?

Not without a proper basis, and you should never assume you have agreed to it. If you do not want your images published or used in marketing, say so in writing and keep the reply. Withhold consent for marketing use even if you consent to clinical processing.

How can I keep control of my health data?

Share only what is clinically necessary, use secure channels rather than open email or chat, read privacy notices and consent boxes before agreeing, and ask who receives your data and where. Keep copies of what you agreed to, and request deletion in writing if you later want your data removed.

Keep reading

Where to go next.

You can also Get Matched with vetted clinics or read how this guide works.

The newsletter

Subscribe to The Second Opinion.

One short, honest dispatch a week. A cost reality, a safety question, and one thing to ask before you book anything.

Email

No spam. Unsubscribe anytime.