AURA

Pet owner data at a veterinary clinic: how much is really needed

A new patient questionnaire at a veterinary clinic often contains unnecessary fields — PESEL number, education, occupation. Learn what GDPR says about data minimization and which fields are really needed for a visit.

Published
14 min read2707 words

AURA — a virtual business manager. Management on facts, not impressions. Who we are

Key takeaways

  • Pet owner data must be adequate, relevant, and limited to what is necessary — the minimization principle from Article 5 GDPR.
  • PESEL number, education, and occupation are not needed for a standard veterinary visit.
  • SMS consent must be clearly separated from other form elements.
  • The right to complain to the supervisory authority must be indicated, but the office address doesn't need to be provided.
  • At each visit, it's worth confirming the current contact details of the owner.

A veterinary clinic receives a new patient. The owner gets a form with a dozen fields to fill in: name and surname, home address, PESEL number, education, occupation, date of birth, phone number, email address, and sometimes even a bank account number. Some of this data is actually needed for the visit, but most of it is not. The clinic collects information it will never use, and the client provides it without a clear explanation of why it's needed. This is exactly the problem of the data minimization principle — one of the fundamental principles of GDPR.

This article shows which pet owner data is really necessary for a visit, what Article 5 of the GDPR says about this, how to inform clients about the right to complain without unnecessary fields in the form, and how to review a new patient questionnaire for unnecessary data.

Closed laptop on a table in a veterinary waiting room, next to a wooden bench and a plant in window light
A clinic can work without unnecessary form fields — you just need to understand what's really needed for a visit

Why new patient forms collect too much data

Veterinary clinic forms often look like they were designed for a bank or government office, not an animal medical facility. The owner comes in with a sick cat and has to provide a PESEL number, education, and occupation. This information has no connection to treating the animal, but it's in the form because "it's always been like that" or "that's how other clinics do it."

The problem stems from two sources. First, clinics copy questionnaires from competitors or use ready-made templates without analyzing whether each field is actually needed. Second, there's no one responsible for reviewing the form and removing fields that don't serve any specific purpose. The result is a data list that goes far beyond what is adequate for a veterinary visit.

Example with conditional numbers — use your own: if a form has 10 fields and 4 of them are not used, that's unnecessary data. With 100 clients per month, that's many records to check and clean.

The data minimization principle from Article 5 GDPR

Article 5 of the GDPR defines the fundamental principles for processing personal data. The first is the data minimization principle, which states that data must be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. The second principle is accuracy — data must be accurate and kept up to date where necessary. The third principle is storage limitation — data should be kept no longer than is necessary for the purpose.

Source: Urząd Ochrony Danych Osobowych — GDPR guide — Article 5 GDPR principles.

In practice, for a veterinary clinic this means a simple question: Is this field really needed to book an appointment, conduct an examination, or contact the owner? If the answer is "no" or "maybe someday," the field shouldn't be in the form. It's not about collecting as little data as possible, but about collecting exactly what's needed for a specific, defined purpose.

When consent is obtained — for example, for sending SMS reminders about vaccinations — the controller must be able to demonstrate that the individual gave consent. Importantly, the request for consent must be clearly distinguished from other matters in the same statement. You can't mix consent for marketing with consent for appointment reminders — each consent must be a separate, clearly identifiable element in the form.

What data must be accurate and up to date

The accuracy principle from Article 5 GDPR means data should be current. In the context of a veterinary clinic, this most often concerns the owner's phone number and email address. This data changes more often than you might think — the owner switches mobile carriers, moves to a new apartment, creates a new email address. If the clinic doesn't verify this data, it risks sending SMS reminders to numbers that no longer belong to the client.

Verification doesn't require adding new fields to the form. It's enough that at each visit — for example, during registration — the clinic staff asks if contact details have changed. This takes a few seconds and eliminates the problem of missed vaccination or follow-up visit reminders. Instead of collecting more fields "for the future," it's better to simply confirm from time to time that what we have is still current.

The right to complain — what the information clause must contain

When collecting data from a pet owner, the clinic must provide information required by Articles 13 and 14 GDPR. One of these is information about the right to lodge a complaint with a supervisory authority — that is, the Personal Data Protection Office. This is a mandatory element of the information clause.

However, regulations don't require providing the UODO address in the clause. It's enough to inform the owner that they have the right to lodge a complaint with a supervisory authority, without having to write the full office address. You can limit yourself to general information about the right to lodge a complaint without the mailing address. If the clinic already provided the address, there's no obligation to remove it, but adding it just to "have it" makes no sense.

Source: Urząd Ochrony Danych Osobowych, 25.04.2025 — regulations don't require providing UODO address in the information clause.

What is really needed for a visit

Very little data is actually needed to conduct a veterinary visit and contact the pet owner. The basic information is the owner's name and phone number — to call if something changes in the visit plan or to send a reminder about a vaccination. An email address is needed if the clinic sends email confirmations or visit reports, but it's not essential if the clinic uses only SMS.

Pet data — name, species, breed, age — is of course information necessary for the examination. But that's data about the pet, not the owner, so GDPR doesn't apply in the same way. Visit history at the clinic allows the doctor to see previous illnesses, procedures performed, and recommendations, but this data concerns the pet, not the owner.

A PESEL number, education, occupation, date of birth, or bank account number are not needed for a veterinary visit. They might be needed in other situations — for example, for settlements with an insurance company if the clinic cooperates with insurance firms — but then you should clearly define the purpose and legal basis for processing them, not collect them "just in case."

The difference between owner data and pet health data

The owner's data — name, phone number, email — is personal data within the meaning of GDPR because it identifies a specific natural person. Data about the pet's health — symptoms, test results, diagnoses, prescribed medications — is data that concerns the pet, not the person. GDPR protects personal data of natural persons, not animals. Therefore, medical information about the pet has a different legal status than the owner's data.

This important distinction helps understand that the clinic must protect the owner's data, but information about the pet's health is regulated by different rules. This doesn't mean it can be treated carelessly — it just means different regulations govern its processing.

If the clinic wants to send owners SMS reminders about upcoming vaccination appointments, follow-up visits, or new services, it needs consent for this. This consent must meet the requirements of Article 7 GDPR — it must be voluntary, specific, informed, and unambiguous. Importantly, the controller must be able to demonstrate that consent was given.

In practice, this means the request for SMS consent should be clearly separated from other elements of the form. You can't mix it with general terms and conditions of using the clinic's services. It's best to have it as a separate checkbox with clear text: "I consent to receiving SMS reminders about appointments and vaccinations to the phone number provided." Only checking this box means consent.

Consent can be withdrawn at any time. The clinic must therefore provide an easy way to unsubscribe — for example, a link in every SMS reminder or clear instructions on how to stop receiving messages.

Consent must be voluntary, specific, informed, and unambiguous. Voluntary means the owner must have a genuine choice — you cannot make the ability to use the clinic's services dependent on giving consent. Specific — it must relate to a specific purpose, such as sending SMS about vaccinations, not generally all marketing activities. Informed — the owner must know what they are consenting to and what will happen with their data. Unambiguous — it must be an active action, such as checking a box, not a pre-checked default.

Do it yourself: review the new patient form

Review the new patient form at your clinic and ask yourself about each field: "Why do I need this information? When will I actually use this in the clinic's work?" If you can't point to a specific moment when this data will be needed — field to remove.

Example field list for verification:

  1. Owner's name and surname — needed for contact, stays.
  2. Phone number — needed for sending reminders and contact in emergencies, stays.
  3. Email address — optional, depends on whether the clinic sends emails.
  4. Home address — rarely needed for a visit, unless the clinic offers home visits, then stays.
  5. PESEL number — usually unnecessary for a standard visit, remove unless there's a specific reason.
  6. Education, occupation, date of birth — unnecessary, remove.
  7. Bank account number — unnecessary for a visit, remove unless the clinic offers installment payments with a finance company.
  8. Consent for SMS — separate field, stays as a separate checkbox.

After removing unnecessary fields, the form becomes shorter, the owner fills it out faster, and the clinic is certain it's processing only the data it actually needs.

A vet gently examining a relaxed cat on a towel-covered table while the owner watches
Examining the animal doesn't require collecting additional owner data

Benefits of organized data

When a clinic processes only necessary data, it gains several benefits. First, less risk of GDPR violations — the less data, the fewer potential problems. Second, easier management — less data means less time for checking and updating. Third, better communication with clients — contact details are current, so SMS and emails reach the owners. Fourth, savings in system space and staff time, who don't need to enter and check unnecessary information.

A clinic management system can help implement the data minimization principle. The registration form includes only fields actually needed for the visit: owner's name and surname, phone, optionally email, pet data. SMS consent is a separate checkbox, clearly distinguished from other information — in accordance with Article 7 GDPR requirements.

When the owner gives consent for SMS, the system automatically sends reminders about upcoming vaccination appointments, follow-up visits, or the next appointment. Everything happens without manual data entry by clinic staff — the system stores consent itself, knows when to send a reminder, and records the fact of sending.

If the owner unsubscribes from SMS — for example, by clicking a link in the received message — the system immediately stops sending further reminders. Consent is stored separately from other owner data, making it easy to withdraw without having to edit the entire client profile.

Lead forms allow building interactive multi-step questionnaires with conditional logic — where the next question depends on the previous answer. This way, the owner sees only fields that apply to them, not a list of questions that don't.

Automatic messages handle sending confirmations, reminders, and thank-you messages by SMS, email, or WhatsApp — always with client consent and an opt-out option. This is a ready-to-use solution that can be implemented in a clinic without programming.

CRM and automations collect all consents in one place and allow centralized management. SMS consent is visible in the client card, easy to withdraw or re-collect.

Customer Data is one customer card instead of five lists in five systems. Reservations, calls and orders go into a common profile, after which you can actually calculate something.

Integrations connect the systems the clinic already uses and make sure the connection doesn't quietly break.

Read more about automation and GDPR — where customer data physically ends up, and about automation costs to understand what it might cost. Learn more about reporting automation and where to start automation.

Reviewing the questionnaire for unnecessary fields is a task the clinic owner can do themselves using the data minimization principle. However, in some cases it's worth consulting a lawyer or Data Protection Officer. This applies when the clinic processes sensitive data — for example, information about the pet's health that could indirectly reveal information about the owner, or when cooperating with insurance companies and external partners that require specific data.

Also, if the clinic recently changed forms and isn't sure whether new fields have a legal basis — consulting a DPO will help avoid problems with UODO. In most standard cases, however, self-reviewing the questionnaire using the principle "is this field really needed?" is enough to organize pet owner data.

Frequently asked questions

Do I need to collect the owner's PESEL number?

No, a PESEL number is not needed for a standard veterinary visit. It's only needed when the clinic cooperates with an insurer that requires owner identification, or when there's another specific legal basis. In most cases, name, surname, and phone number are sufficient.

No, sending SMS reminders about appointments or vaccinations requires the owner's consent. Consent must be voluntary, specific, and clearly separated from other form elements. Without consent, you can contact by phone, but not send automated text messages.

What must the information clause contain in a veterinary practice?

The information clause should contain the controller's data, purpose and legal basis for processing, data retention period, the individual's rights (access, rectification, erasure, restriction of processing, objection), the right to lodge a complaint with UODO, and — if applicable — information about transfers to third countries. You don't need to provide the UODO address; general information about the right to complain is sufficient.

Does pet health data fall under GDPR?

Data about the pet's health — diagnoses, test results, prescribed medications — concerns the pet, not the owner. GDPR protects personal data of natural persons, so medical information about the pet has a different legal status. However, the owner's data (phone, email, address) still falls under GDPR and must be protected according to Article 5 principles.

How often should I verify the owner's data accuracy?

Verifying data at each visit is the simplest solution — the clinic staff simply asks if contact details have changed. There's no formal frequency requirement, but the accuracy principle from Article 5 GDPR suggests that data should be current. It's worth confirming whether the phone number and email are still current at every client contact.

Can I remove all fields from the form and leave only the phone number?

Not quite. At minimum, the owner's name and surname and phone number are needed for visit registration. Without this data, the clinic can't contact the owner or confirm the appointment time. It's worth keeping the minimum set: name and surname, phone, optionally email, and pet data (name, species, breed, age). The rest depends on the clinic's specific needs.

Written consent is not required in all cases. If the legal basis is a contract — for example, a contract for veterinary services — consent isn't needed; the contract execution is sufficient. Consent is needed for additional activities, such as sending marketing SMS or sharing data with partners. In every case, the controller must be able to demonstrate the legal basis for processing.

Who writes this

See your business as a system.

Aura is a virtual business manager: management on facts, not impressions. For a company that wants a system running its processes instead of the owner’s memory.

The website, CRM, admin panel and automations are modules of the same system. We are not a website agency.

Look at my business

You will land on the home page. Give a company name — Aura looks at it in public data and shows what a client sees before calling you. No promises of a result.

See what we do

Related services

Read next Scroll for more

Let us look at your numbers

Tell us how enquiries are handled today — how many there are, who picks them up, where they get lost. Aura walks the process with you and shows what can be taken off a person, and what is better left alone.

Talk to Aura

The home page with Aura opens. Give a company name — she looks at it in public data and shows what a client sees. No promises of a result.

Prefer to write? marketing@auraglobal-merchants.com

Next step

Let us check whether Aura fits your place

We do not take everyone: first we look at your processes, sales and current systems and tell you honestly whether it makes sense for us to come in. A few questions, about five minutes.

Take the assessment →