Why a booking form is not an ordinary contact form
The moment a form asks what treatment someone is enquiring about, whether they are in pain, or anything about their dental history, it is processing data concerning health.
Article 9 prohibits processing special category data by default, subject to specific conditions. Ordinary consent-and-carry-on handling of a contact form does not automatically satisfy it.
Even a form that only asks for a name and phone number can fall in scope by context — a form headed 'Book an emergency appointment' tells you something about the person's health by the fact of its submission.
What this changes in practice
Ask for less. The strongest privacy position and the strongest conversion position agree here: a short form collects less special category data and completes more often.
Know where the submission goes. A form that emails a plain-text submission to a personal address, or posts into a third-party tool outside the EU, is a different risk profile from one writing to a controlled system.
Have a processing agreement with anyone handling it on your behalf — form provider, CRM, practice management system.
Say what happens to the data at the point of collection, in language a patient understands, and retain it only as long as you need it.
The common failure
The most common problem we see is not a missing privacy policy — it is a form built by a general web agency with no thought given to what the data is, wired into whatever tool was convenient, with submissions sitting indefinitely in an inbox.
That is a compliance issue and an operational one: enquiries in a personal inbox get missed, which is the same reason it costs the practice money.
Questions
Does an appointment request really count as health data?
It generally does where the form or its context reveals something about the person's health — treatment sought, symptoms, urgency. Treat dental enquiry forms as in scope unless you have advice saying otherwise.
Is consent enough?
Explicit consent is one of the Article 9 conditions, but it must be freely given, specific, informed and unambiguous, and withdrawable. Whether it is the right condition for your practice is a question for your own advisor.
Who is responsible — the practice or the web agency?
The practice is normally the data controller and carries the obligation. An agency handling data on your behalf is typically a processor and should be covered by a written agreement.