Skip to content
WebCheap

Pharmacy website compliance checklist

By Umair ShahPublished

If you run a community pharmacy or an online prescribing service, a pharmacy website compliance checklist is not a nice-to-have before your next GPhC inspection, it is one of the first things an inspector or a patient complaint will pull up on screen. The GPhC, the MHRA and the ICO each have specific expectations for what a pharmacy site displays, collects and stores, and most of them are not difficult to meet once you know what they are. This is the practical version, written for the person who owns the website, not the person who wrote the SOP.

💊 What GPhC actually wants to see on the site

The GPhC's focus for registered pharmacies providing services online comes down to three things: can a patient tell who they are dealing with, can they verify that the pharmacy and the prescriber are legitimately registered, and is there a clear route to raise a concern. In practice that means your website needs:

  • The pharmacy's GPhC registration number, displayed clearly, not buried in a footer link three clicks deep.
  • The superintendent pharmacist's name and registration status, if you are operating as a distance-selling or online pharmacy.
  • A visible link or instruction for checking the pharmacy on the GPhC register, so patients can verify you independently rather than taking your word for it.
  • Clear identification of any third-party prescribers used for online consultations, including which regulator they sit under (GMC, NMC or GPhC), since the pharmacy owner carries responsibility for due diligence on anyone prescribing through the site.

None of this is complicated to build. It is a page or a block of content, written once and kept current. Where pharmacies fall down is letting it go stale after a change of superintendent or a new prescribing partner.

🔒 Data protection the ICO will actually check

Every pharmacy website that collects patient information, whether that is a repeat prescription request, a consultation form or a simple contact form asking about a condition, is processing special category health data under UK GDPR. That raises the bar above a standard business privacy policy. At minimum your site needs:

  • A privacy notice that specifically names health data as a category you collect, not a generic template written for a retail shop.
  • A lawful basis stated for processing that data, and how long you retain it.
  • Secure handling of any uploaded documents (ID, prescriptions, photos), meaning the form submission should not land in an unencrypted inbox that sits on a shared email account.
  • A cookie banner that genuinely blocks non-essential tracking until consent is given, not one that fires analytics scripts regardless of the answer.

If your current contact form just emails submissions to "info@", that is the first thing to fix. It is a one-afternoon job to move patient-facing forms to a properly encrypted submission flow, and it closes a gap that would otherwise sit there indefinitely.

📋 Distance selling and online prescribing specifics

If you sell medicines online or run any form of remote consultation, there are a handful of details the GPhC and MHRA both expect to be visible, not hidden in terms and conditions:

  • The pharmacy's physical premises address, even if you operate entirely online. An online-only pharmacy still needs a registered physical location stated.
  • Clear information on how prescription-only medicines are supplied, including what questions a patient will be asked and what safety checks happen before dispensing.
  • A statement on what happens if a request is refused on clinical grounds, so patients understand the safety net rather than assuming the site is a vending machine for medicines.
  • Distance selling logo and verification details where applicable, linked correctly rather than as a static image with no working link behind it.

These are the details inspectors increasingly check by actually using the site as a patient would, rather than just reading a document about it. A site that looks compliant on paper but breaks when someone tries to use the consultation form is a worse outcome than having no online consultation route at all.

🛠️ Turning the pharmacy website compliance checklist into a working site

Most of what sits in a pharmacy website compliance checklist is content and structure, not clever engineering: a clearly written registration section, an honest privacy notice, a prescribing disclosure page, and forms that handle health data properly rather than as an afterthought. Where pharmacies lose points is usually not the policy itself, it is the gap between the policy and what the live site actually does.

If you are building or rewriting a pharmacy site, budget for these pages as standard content rather than extras bolted on later: a registration and verification page, a privacy notice written for health data specifically, and a secure form setup for anything that touches patient details. At WebCheap this typically sits within a standard build from £395, with ongoing pages at £25 each and ongoing content changes handled through the £95/month care plan, so the compliance pages stay current as your registration details or prescribing partners change.

The honest takeaway: treat your website as part of your regulatory evidence, not a marketing extra. If an inspector or a worried patient can verify who you are, understand what happens to their data, and see exactly how a prescription request is handled, in under a minute, the website has done its job.

Websites for these industries

Start here

Tell us what you need built. Get a fixed price back.

The form takes five minutes. We send a fixed quote and a start date within two working days.

Two or three sentences is plenty. The quote comes back fixed either way.

Fixed quote back within two working days.