A remote consultation almost always asks for photographs — often of intimate areas — along with scans, test results, and a medical history. Sharing them is frequently necessary for an honest assessment before you travel. But once an image leaves your phone you lose physical control of it, and in UK law this is not ordinary personal data: it is health data, one of the most strongly protected categories. This guide is about sharing deliberately — the minimum needed, to a named recipient, on the clearest terms you can get — rather than refusing to share at all.
Why your photos count as sensitive data
Under UK GDPR, health data is special category data — one of nine categories the Information Commissioner's Office identifies as needing extra protection. The [ICO's guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-is-special-category-data/) defines it as personal data about a person's physical or mental health that reveals information about their health status, and an organisation generally needs a specific condition under Article 9 of the UK GDPR to process it lawfully. A clinical photograph that reveals a condition, and the records you attach to it, fall squarely inside this category. That is the legal weight of the attachment you are about to send.
Know who you are actually sending them to
Before you upload anything, establish who receives it. In medical tourism the first contact is often a facilitator or booking agency rather than the treating clinic, and the two are not the same legal entity. Ask, in writing: Are you the clinic that would treat me, or an intermediary? What is the legal name of the organisation that will hold my data? Getting the entity name also feeds the checks in [how to check whether a clinic is licensed](/guides/check-if-clinic-licensed). If you cannot find out who controls the data, that is a reason to pause.
Prefer a secure channel, and send less
Open messaging apps and ordinary email are convenient and not designed for sensitive records. Ask whether the clinic offers a secure upload or patient portal, and prefer it. Reduce what the image reveals: photograph only the area that is clinically relevant, keep your face out of frame where it is not needed, and strip location metadata (EXIF) from phone photos before sending, so the file does not quietly carry the time and place it was taken. Sharing less is the protection most within your control.
Ask the data questions before you upload
Put these to the recipient in writing and keep the answers:
- What will you use my photos and records for — assessment only, or also marketing? - Who else will see them (surgeons, third parties, before-and-after galleries, social media)? - Where will they be stored, in which country, and for how long? - Will any image ever be published or used in advertising, and can I refuse that separately?
Consent to treatment and consent to marketing use are different things, and you are entitled to say yes to one and no to the other. For reference, the registry itself does not publish before-and-after images or clinic marketing photographs of patients — see the [surgeon listings policy](/methodology/surgeon-listings).
Warning signs when you ask about data
How a clinic answers these questions is itself information. Treat the following as reasons to slow down:
- a consent form that bundles treatment consent together with blanket permission to use your images in advertising, with no way to decline the marketing part; - a vague or evasive answer about who holds your data and in which country; - a request to send intimate photographs through an ordinary social-media chat as the only option; - pressure to send images quickly to "secure a price" before you have had your questions answered.
None of these is proof of bad faith, but each is a point at which you are entitled to pause, ask again, and get the answer in writing before you share anything further.
Your rights, and their limits
UK data law gives individuals rights over their data, including the right to get it deleted. The [ICO explains](https://ico.org.uk/for-the-public/your-right-to-get-your-data-deleted/) that you can ask an organisation to erase your personal data in certain circumstances — for example where you withdraw consent you previously gave, or the data is no longer needed — and that the organisation normally has one calendar month to respond. More broadly, the [ICO's guidance for the public](https://ico.org.uk/for-the-public/) sets out your data protection rights and how to exercise them.
There is an important limit. These rights bind organisations that are subject to UK (or EU) data law. A clinic established purely in another country may not be, which can make a deletion request hard to enforce in practice. This is exactly why what you choose to send — and to whom — matters more than any remedy after the fact.
A minimum-sharing checklist
Before you press send:
- confirm the legal name of the organisation receiving the data; - share only what is clinically necessary, with metadata stripped and your face excluded where possible; - get the purpose, storage location, retention period, and any marketing use in writing; - confirm you can refuse marketing or gallery use separately from treatment; - keep your own copies and a record of what you sent, to whom, and when.
The registry's [consent review tool](/tools/consent-review) and [records-to-obtain tool](/tools/records-to-obtain) can help you work through consent terms and keep an organised file. Share the minimum, to a named entity, on terms you have in writing — and keep the evidence.