Healthcare sector
Data protection for
pharmacies
The pharmacological history and electronic prescriptions are health data under art. 9 GDPR and require the highest level of protection. This is compounded by the management of employees, software providers and any CCTV systems.
Art. 9
GDPR — health data
72 h
to report a breach
24 h
personalised proposal
Regulatory context
General obligations for pharmacies
Pharmacies process health data on a daily basis and are subject to the GDPR and the LOPDGDD on the same terms as any other controller that handles special categories of data.
Health data and duty of confidentiality
The pharmacological history and dispensation data are special-category data under art. 9 GDPR. Their processing requires an appropriate legal basis, reinforced security measures and strict confidentiality.
Duty to inform the patient
Customers must be clearly and accessibly informed about what data is collected, for what purpose and who the controller is. This includes paper forms, digital systems and the website.
Staff access control
The pharmacist-owner, qualified technicians, assistants and trainees do not have the same level of access. Profiles must be defined, documented and adjusted to the data minimisation principle.
Pharmacy software and providers
Management software providers, electronic prescription systems or cloud services that access customer data must be correctly identified and documented.
Security CCTV
If the pharmacy has cameras, it must comply with the information signage requirements, restrict access to recordings and observe the maximum 30-day retention period established by law.
Data breach protocol
In the event of any incident affecting personal data, the pharmacy must be in a position to report it to the AEPD within 72 hours and, where applicable, to the affected individual.
Data Protection Officer
Is a DPO mandatory at a pharmacy?
Pharmacies are healthcare establishments that routinely process health data, but they do not necessarily fall within the healthcare centres subject to the medical record obligation under art. 34.1.g LOPDGDD. The provision refers to healthcare centres in the strict sense, not to healthcare establishments in general.
The need to appoint a DPO depends on the type, volume and scale of each pharmacy's specific processing activities. A pharmacy that processes health data at large scale or in a systematic manner should assess whether the conditions of art. 37 GDPR are met. Each case requires individual analysis.
If the analysis determines that a DPO is advisable, Certix's external DPO assumes this function under a contract independent of the standard consultancy service.
When to evaluate DPO appointment
Pharmacies with personalised pharmaceutical care and follow-up
Ongoing and systematic processing of health data may require assessment of the obligation.
Pharmacies with large-volume compounding
The volume and depth of health data processing are relevant factors.
Pharmacies integrated in networks or chains
Large-scale processing of patient data may trigger the conditions of art. 37 GDPR.
Pharmacies with complementary health services
Expanding care activities may increase the risk and volume of processing.
The service
What the data protection service for your pharmacy includes
Certix's standard contract, adapted to the operational needs of a community pharmacy.
RoPA and technical-organisational structure
Record of Processing Activities (RoPA) adapted to the pharmacy's activities: dispensation, pharmacological history, employees and management software.
Adapted information clauses
Texts adapted for the counter, patient care forms and customer communications.
Adapted web documentation
Documentation adapted for the pharmacy's website: contact form, online shop if applicable and cookie management.
Data Processing Agreements (DPA)
Processing agreements for the pharmacy management software provider and cloud storage services.
Data breach protocol
Internal procedure to detect, classify and report incidents to the AEPD within the 72-hour deadline required by the GDPR.
Data subject rights management
Documented procedure for handling customers' access, rectification, erasure and objection requests.
Document management platform
Access to a private platform with all documents and templates updated in real time.
Ongoing support
Ongoing support in the face of regulatory changes or changes in the pharmacy's activities.
External DPO (independent service)
The appointment of a Data Protection Officer (DPO) is a separate contract, quoted to measure if individual analysis determines it is advisable.
Need a proposal for your pharmacy?
Tell us about your activities. Personalised proposal within 24 hours.
Good practice
Key aspects in the day-to-day running of a pharmacy
Regulatory compliance at a pharmacy goes beyond documentation. There are everyday situations that require clear judgement:
- Collection of medicines by third parties. When a family member collects medicines on behalf of the account holder, the pharmacy must verify authorisation to avoid an unlawful disclosure of health data.
- Loyalty programmes. Those that record medication or health product history are subject to severe restrictions. They require explicit consent and a legal basis separate from dispensation.
- Compounding. This involves processing the patient's health data with the same reinforced safeguards as any other health data.
- Care of minors. Dispensing to minors entails additional considerations regarding consent and legal representation that should be reviewed and documented.
Most common legal bases in pharmacies
Art. 9.2.h GDPR
Provision of healthcare — principal basis for processing health data in dispensation.
Art. 6.1.b GDPR
Performance of the pharmaceutical services contract.
Art. 6.1.c GDPR
Compliance with legal obligations: retention of dispensation documentation.
Art. 6.1.a + 9.2.a GDPR
Explicit consent — for loyalty programmes linked to health data and commercial communications.
Art. 6.1.f GDPR
Legitimate interests — for security CCTV at the establishment, subject to prior proportionality analysis.
FAQ
Frequently asked questions about data protection in pharmacies
Is a DPO mandatory at a pharmacy?
Pharmacies are healthcare establishments that routinely process health data, but they do not necessarily fall within the healthcare centres subject to the medical record obligation under art. 34.1.g LOPDGDD. The obligation to appoint a DPO depends on the type, scale and specific volume of each establishment's processing activities. Each case requires individual analysis.
Is the pharmacological history health data?
Yes. A record of dispensed medicines linked to a specific patient is health data under art. 9 GDPR. Its processing requires a specific legal basis, reinforced security measures and access restricted to staff with care functions.
Can a pharmacy assistant access the customer's pharmacological history?
Only to the extent necessary for their duties. The pharmacy must define differentiated access profiles by role, limiting access to health data to the minimum necessary in accordance with the data minimisation principle.
Can pharmacy loyalty cards use health data?
Loyalty programmes that record medication history are subject to severe restrictions as they involve health data. They require explicit consent and a legal basis separate from dispensation. Each case requires prior legal analysis.
How long must the pharmacological history be retained?
As a general rule, the 5-year minimum period under Law 41/2002 applies, without prejudice to any specific periods established by regional pharmacy legislation. During the legally required retention period, the data cannot be deleted even if the customer requests it.
Is the pharmacy's cloud-based management software a data processor?
As a general rule, yes. SaaS pharmacy software providers that process patient data on behalf of the pharmacy may act as data processors. The specific legal relationship depends on each provider's conditions; it is advisable to review them and, where the provider acts as a processor, to formalise the corresponding Data Processing Agreement.
How long can recordings from a pharmacy's CCTV cameras be retained?
As a general rule, CCTV recordings may not be retained for more than 30 days except in the event of a police or judicial request. The pharmacy must display visible information signage and restrict access to the footage.
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Healthcare sector
GDPR compliance
for your pharmacy.
A data protection expert analyses your activities and proposes the most suitable solution. No intermediaries, no bureaucracy.
Proposal within 24 h · info@certix.es
Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.