Available only in Switzerland

Schweizerform is currently available exclusively for users in Switzerland. Account creation from your region is restricted.
Back to Blog

Collecting Health Data in Forms: What «Sensitive Data» Actually Requires

You do not have to be a clinic to be processing health data. A dietary field, an accessibility question, a sick-note upload, a «tell us anything we should know» box — each can move an ordinary form into the sensitive-data category, with explicit consent, an impact assessment and a much shorter list of people who may read it. What actually counts, what it triggers, and the fields to drop instead.

Collecting Health Data in Forms: What «Sensitive Data» Actually Requires

Most organisations that hold health data did not set out to. A conference registration form asks about dietary requirements and receives «coeliac disease, and I am on immunosuppressants». A school trip form asks about medication. A sports club asks members to confirm they are fit to compete. An HR onboarding form asks for emergency contacts and any «conditions we should be aware of». None of these is a medical practice, and every one of them is now processing data about health — with all the consequences that follow.

The short version

Under Art. 5 lit. c of the nFADP, data on health is sensitive personal data, in the same class as religious and political views, genetic and biometric data, intimate life, and criminal proceedings. The label is not about who collects it — a sports club and a hospital hold the same category. What it triggers: a higher bar for consent where consent is your basis (it must be explicit, Art. 6 para. 7 lit. a), a much stronger case for a data protection impact assessment under Art. 22, stricter access control, and disclosure to third parties that now needs its own justification. The cheapest compliance strategy by a very large margin is not to collect it.

This article is for the non-clinical case: employers, schools, event organisers, associations, insurers, studios and everyone else who ends up with medical information because a field seemed harmless. If you are a medical practice, the healthcare use case and the professional-secrecy angle matter more than this piece; if you are running a study, start with data protection in clinical research.

What Actually Counts as Health Data

Broader than people expect. Health data is not only a diagnosis: it is any information from which the physical or mental health of a person can be inferred — past, present or future. That inference test is what catches the ordinary form, because most of these fields never mention a condition at all.

The innocuous fieldWhy it is health dataWhat to do instead
Dietary requirements (free text)«Coeliac», «diabetic», «low-sodium» are diagnoses; halal or kosher reveals religion, also sensitiveOffer named menu options — vegetarian, vegan, gluten-free, lactose-free — with no reason field
Accessibility needsReveals disability, mobility limitation or sensory impairmentAsk what accommodation is needed, not what condition causes it: «step-free access», «induction loop»
Fitness-to-participate confirmationA negative answer is a health disclosure; a positive one implies a medical assessmentA self-declaration checkbox with no explanation field, and a route to talk to a named person
Emergency contact plus «anything we should know»The second half is an open invitation to disclose conditions, allergies and medicationKeep the contact, narrow or drop the box, and say who reads it and when it is deleted
Sick-note or certificate uploadA medical document, often containing far more than the absence dates you neededAsk for the dates and the fact of incapacity; accept the certificate only where a rule requires it
Absence reason in a leave formDistinguishing «sick» from «holiday» is health data about a named employeeRecord the category only, and keep it out of general team-visible calendars
Insurance or membership numberOften reveals scheme, entitlement and sometimes condition-specific coverageCollect at the point it is actually used, not at first contact

Free text is where health data arrives uninvited

The single most common route into this category is a box you did not intend as a medical question. «Is there anything else we should know?» reliably produces diagnoses, medication lists and mental-health disclosures — from people who assumed you asked because you would act on it. If you keep the box, say in one line what you will and will not do with the answer, and treat the whole field as sensitive from the start rather than sorting it afterwards.

What the Sensitive Label Actually Triggers

«Sensitive» does not mean forbidden, and it does not mean you need a lawyer for every allergy field. It means five specific things change.

  1. Consent, where you rely on it, must be explicit. Art. 6 para. 7 lit. a nFADP requires express consent for the processing of sensitive personal data where consent is the justification. A pre-ticked box, a bundled agreement or a «by submitting this form you agree» footer does not clear that bar. Note also that consent is not always the right basis: for an employer, contract performance and legal obligation usually do more work, and employee consent is weak anyway.
  2. A data protection impact assessment becomes likely. Art. 22 nFADP requires one where processing is likely to result in a high risk, and large-scale processing of sensitive data is the textbook trigger. A club with 40 members is not there; a 2,000-employee wellbeing survey is.
  3. Disclosure to third parties needs its own justification, including to colleagues who do not need it. «The whole committee is in the shared mailbox» is a disclosure decision, whether or not anyone made it deliberately.
  4. Security has to be proportionate to the risk under Art. 8, and the risk is now higher by definition. Access control, encryption and a short reader list are no longer optional extras.
  5. The record of processing matters more. Small businesses can be exempt from keeping one under the ordinance — but the exemption falls away for large-scale processing of sensitive data or high-risk profiling, which we cover in the nFADP compliance checklist.

Under the GDPR the equivalent is Art. 9, which starts from a prohibition and then lists exceptions — explicit consent, employment and social-security law, vital interests, and others. If you have EU respondents, run both analyses; the practical outcome is usually similar but the drafting is not.

The Rules That Sit on Top, Depending on Who You Are

Employers

Art. 328b of the Code of Obligations permits an employer to process data about an employee only to the extent that it concerns their suitability for the job or is necessary to perform the employment contract. The Federal Data Protection and Information Commissioner is explicit that this cannot be departed from to the employee's detriment even with consent — which disposes of the most common shortcut. In practice: you may generally record that someone is absent and unfit for work; you generally may not require the diagnosis. Health questionnaires at hiring must stay within what the specific role actually requires.

Schools and organisations working with minors

Two things stack: the data is sensitive, and the person is a child. Under Swiss civil law, rights closely tied to the person are exercised by a minor who is capable of judgement, which means older pupils have a say in their own data — while parents typically decide for younger ones. Cantonal school data protection rules add a further layer, and they differ. Allergy and medication lists for a school camp are legitimate and necessary; the same list circulating in a parents' chat group is not. Our educational institution use case goes into the workflow.

Regulated professions and their auxiliaries

Where Art. 321 StGB professional secrecy applies — physicians, dentists, pharmacists, psychologists, and their auxiliary persons — the duty is criminal law sitting on top of data protection law, and it reaches everyone who can access the data in the course of the professional's work. That includes a software vendor whose staff can read submissions. It is the strongest single reason for a practice to choose a tool where the provider cannot read anything at all.

Event organisers, clubs and studios

No special statute applies — which is exactly why this group processes the most health data with the least structure. A marathon with a fitness declaration, a summer camp with medication lists, a tattoo studio with a blood-borne-infection screening: all ordinary nFADP processing of sensitive data, usually on a spreadsheet, usually retained forever. See the event registration use case for the version of this that works.

Designing the Form So It Asks Less

1

Write the decision the field feeds

«We need to order the right meals.» «We need to book a step-free room.» «We must know whether to call an ambulance.» If you cannot write the decision, delete the field. Most medical questions on non-medical forms fail this test on the first attempt.

2

Ask for the accommodation, not the condition

The operational answer is what you act on. «Requires a ground-floor room» is enough to book the room; the diagnosis behind it is data you now have to protect for no additional benefit.

3

Prefer closed options over free text

Named choices keep the data structured, comparable and deletable. A free-text medical box is the field you cannot anonymise later and cannot safely export.

4

Separate the sensitive part from the rest

A registration form and a medical form can be two forms with two audiences and two retention periods. The person handling the invoices does not need the allergy list.

5

Name the readers before you publish

Who opens these answers, in which role, and what happens when they leave the role. For health data, the correct list is usually two or three people — and it should be written down.

6

Set the deletion date at the same moment

Health data collected for an event has no purpose after the event. Two weeks afterwards is a defensible rule; «we still have the 2023 camp list» is the outcome of never deciding. See form data retention.

7

Say it plainly on the form

Four lines: what you ask, why, who reads it, when it is deleted. With health data this is not just an Art. 19 duty — it measurably improves the quality of what people tell you, because they can see the boundary.

The notification e-mail undoes all of it

If new responses are e-mailed to the organisers with the answers included, every allergy, medication and diagnosis is now sitting unencrypted in several mailboxes, forwarded, on phones, and backed up wherever that mail provider backs up. It is the most common way health data escapes an otherwise careful setup. Switch notifications to an alert without content, and read the responses in the tool.

Where It Is Stored, and Who Can Read It

Once you accept that the form holds sensitive data, the vendor question changes shape. The relevant question is no longer «is it encrypted» — nearly everything is encrypted in transit and at rest — but «who can read it». On a mainstream form tool the honest answer includes the provider's staff with production access and its sub-processors, because the provider holds the keys. For a lunch poll that is irrelevant. For a list of children's medications it is the whole question.

Two properties are worth insisting on for this category: end-to-end encryption, so the provider is outside the set of people who could read a submission at all, and a hosting and sub-processor chain you can describe in one sentence. The reasoning behind the first is in encryption at rest vs end-to-end; the second is worked through in which form tools are hosted in Switzerland. File uploads deserve their own attention, because a certificate or a photograph carries far more than the fact you asked for — see secure file uploads.

The Three Questions People Actually Ask

«Can I ask for health information in a survey?»

Yes, with two conditions that are easy to state and often missed. It has to be necessary for a purpose you can name, and if the survey is meant to be anonymous, health answers plus any demographic breakdown will re-identify people faster than you expect in a small population. Questions about stress, exhaustion, burnout and sleep are health data — which is why a workplace wellbeing survey is a sensitive-data processing operation, not a pulse check. The threshold arithmetic is in anonymous employee surveys.

«How should I handle sensitive health information once I have it?»

Shorten the list of readers, shorten the retention period, and stop making copies. In descending order of real-world impact: turn off answer-bearing notifications, keep it out of shared drives and general mailboxes, restrict access by role rather than by trust, delete on a stated schedule, and make sure exports are governed by the same rule as the original. Encryption matters, but it is the fifth-most-important thing on this list for most organisations.

«Is it safe to collect appointment requests through a web form?»

Yes, and it is usually safer than the alternatives people default to — an unencrypted e-mail, a voicemail transcript, a note at reception. The conditions are that the form asks for the minimum needed to make the appointment, that the content is not mirrored into an inbox, and that the provider cannot read it if you are bound by professional secrecy. A request that says «Tuesday morning, existing patient, call-back number» is a scheduling message; a request that says «Tuesday morning, chest pain since Friday» is a medical record, and the difference is set by how you word the field.


Bottom Line

Health data does not arrive with a label. It arrives through a dietary field, an accessibility box, a certificate upload and a well-meant open question — and once it is in your system, the rules do not care that you are a club, a school or a conference organiser rather than a clinic. Explicit consent where consent is the basis, an impact assessment where the scale is real, proportionate security, a short reader list and a deletion date.

The good news is that the strongest control is also the cheapest and needs no technology at all: ask for the accommodation instead of the condition. Data you never collected cannot be leaked, subpoenaed, mis-shared, or forgotten in a spreadsheet three years from now.

When you genuinely do need the medical detail — camps, events, treatments, intake — Schweizerform encrypts responses in the respondent's browser, so the readers are you and whoever you share the Vault key with, and nobody at the provider. Hosting is in Switzerland on every plan. Related reading: healthcare forms, event registration with medical or accessibility needs, and how to create a secure online form.

Disclaimer: This article is general information and marketing content, not legal advice. References to the nFADP (Art. 5 lit. c, 6, 8, 19, 22), the Data Protection Ordinance, Art. 328b and Art. 321 StGB, Swiss civil law on minors and Art. 9 GDPR are simplified summaries reflecting the position in July 2026. Cantonal rules for schools and public bodies, and sector-specific duties, may impose more — have forms that process health data reviewed by qualified data protection counsel.