Certix

Healthcare sector

Data protection for
dental clinics

The dental record, X-rays and diagnostic images are special-category data under art. 9 GDPR. The regulations require a reinforced level of compliance and, in the majority of clinics, the mandatory appointment of a Data Protection Officer.

Art. 9

GDPR — health data

Art. 34

LOPDGDD — mandatory DPO

72 h

to report a breach

24 h

personalised proposal

Regulatory context

General obligations for dental clinics

The dental record is not ordinary data. The GDPR classifies it as a special category and requires a significantly more demanding compliance regime than other commercial sectors.

Health data (art. 9 GDPR)

The dental record, diagnoses, accepted treatment plans and diagnostic images are special-category data. Their processing requires a specific legal basis and reinforced security measures.

Differentiated access profiles

The dentist, hygienist, dental nurse and receptionist do not have the same level of access. Defining, documenting and reviewing these profiles is an obligation, not an option.

Relationships with third parties

Dental laboratories, external specialists and management platforms may be involved in the processing of patient data. Each relationship must be analysed and documented appropriately.

Staff training and awareness

All staff who access patient data must know their obligations and act accordingly. The human factor is the primary risk vector in any healthcare centre.

Appropriate security measures

Per-user access controls, device encryption, back-ups and protection of the digital radiological archive are basic measures in any dental clinic.

Retention periods

Law 41/2002 and regional legislation establish how long the dental record must be retained. During that period, it cannot be deleted even if the patient requests it.

Legal obligation

DPO appointment is mandatory at dental clinics

The art. 34 of the LOPDGDD requires the appointment of a Data Protection Officer (DPO) at private healthcare centres, a category that includes dental clinics. The legislation expressly provides an exception: healthcare professionals practising on an individual basis fall outside its direct scope of application.

The specific application to each clinic requires individual analysis. The DPO oversees regulatory compliance, acts as the point of contact with the AEPD and advises the team on the processing of health data. Certix assumes this function as an independent service from day one.

Centres generally subject to art. 34 LOPDGDD

Dental clinics and odontology practices
Orthodontics and dentofacial orthopaedics clinics
Implantology and oral surgery centres
Aesthetic dentistry and tooth whitening clinics
Endodontics and periodontics centres
Paediatric dentistry centres
Clinics with digital radiology or CBCT

Indicative list. The specific obligation for each entity requires individual analysis.

The service

What the data protection service for your dental clinic includes

Certix's standard contract, adapted to the specific circumstances of a dental clinic.

RoPA and technical-organisational structure

Record of Processing Activities (RoPA) adapted to your dental activity, together with the structure of technical and organisational measures applicable to your centre.

Adapted information clauses

Texts adapted to patient admission forms, informed consents and communications with laboratories and specialists.

Adapted web documentation

Documentation adapted for the clinic's website: online appointment form, contact and cookie management.

Data Processing Agreements (DPA)

Processing agreements for dental laboratories, clinical record software and appointment management platforms.

Data breach protocol

Internal procedure to detect, classify and report incidents to the AEPD within the 72-hour deadline required by the GDPR.

Data subject rights management

Documented procedure for handling patients' and employees' rights requests within the established time limits.

Document management platform

Access to a private platform with all documents, templates and electronic signatures updated in real time.

Ongoing support

Ongoing support in the face of regulatory changes, new AEPD guidelines or changes in the clinic's activities.

External DPO (independent service)

The formal appointment of a Data Protection Officer (DPO) is a separate contract, quoted to measure according to the characteristics of the centre.

Need a proposal for your dental clinic?

Tell us about your activities and the size of your centre. Personalised proposal within 24 hours.

Request a proposal

Good practice

Key aspects in the day-to-day running of a dental clinic

Regulatory compliance does not end with documentation. In the dental sector, the way the team manages information on a day-to-day basis is decisive:

  • Before/after photographs in marketing. Intraoral or smile photographs obtained during treatment are health data. Their use in advertising or on social media requires specific consent, separate from clinical informed consent.
  • Referrals to specialists. When a patient is referred to a specialist with their records or images, a legal basis for that communication must exist and the patient must have been informed of this possibility.
  • Cloud-based clinical software. Providers of dental clinical record software may act as data processors. This relationship must be backed by an appropriate Data Processing Agreement.
  • Staff confidentiality. All team members who access patient data are subject to a duty of confidentiality. This must be documented and known to every person at the centre.

Most common legal bases in a dental clinic

Art. 9.2.h GDPR

Provision of healthcare — principal basis for processing the dental record and care data.

Art. 6.1.b GDPR

Performance of the dental services contract: appointments, treatment plans, billing.

Art. 6.1.c GDPR

Compliance with legal obligations: retention of medical records and billing.

Art. 6.1.a + 9.2.a GDPR

Explicit consent — for non-care uses: commercial communications or images used in marketing.

Art. 6.1.f GDPR

Legitimate interests — for appointment reminders and follow-up within the care relationship.

FAQ

Frequently asked questions about data protection in dental clinics

Is it mandatory to appoint a DPO at a dental clinic?

Art. 34 of the LOPDGDD requires the appointment of a Data Protection Officer (DPO) at private healthcare centres, a category that includes dental clinics, with the exception of healthcare professionals practising on an individual basis. The specific application to each centre requires individual analysis.

Are dental X-rays and CBCT scans health data?

Yes. Dental X-rays, intraoral scans and CBCT images are health data under art. 9 GDPR and receive reinforced protection. Their storage, access and possible transfer to laboratories or specialists require an appropriate legal basis and, where applicable, a Data Processing Agreement.

How long must the dental record be retained?

Law 41/2002 establishes a minimum of 5 years from the last care episode. Some autonomous communities extend this period. During the legally required retention period, the data cannot be deleted even if the patient requests it.

Is the dental laboratory that manufactures prostheses a data processor?

As a general rule, a dental laboratory that receives patient data to manufacture prostheses or orthodontic appliances acts as a data processor. It is advisable to verify the specific contractual relationship and, if that position is confirmed, to formalise a Data Processing Agreement governing the laboratory's obligations regarding security and confidentiality.

Can administrative staff access the patient's medical record?

Administrative staff may only access the data necessary for their functions: appointments, billing, contact details. The full clinical record must be restricted to staff with a direct care function. The clinic must define and document differentiated access profiles by professional category.

Can before/after photographs be used in marketing or on social media?

Intraoral or smile photographs obtained during treatment are health data. Their use in advertising, on a website or on social media requires specific and separate consent, independent of clinical informed consent. Its absence may constitute a serious infringement.

Does a small dental clinic need to comply with the GDPR in the same way as a large one?

Yes. The GDPR does not establish thresholds based on size. Any dental clinic that processes patient health data is subject to its obligations, regardless of whether it has one or twenty employees. What may vary is the scale and complexity of the documentation required.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Healthcare sector

GDPR compliance
for your dental clinic.

A data protection expert analyses your activities and proposes the most suitable solution. No intermediaries, no bureaucracy.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.