Certix

Healthcare sector

Data protection for
physiotherapists and rehabilitation

The treatment history and clinical information of the patient are special-category data under art. 9 GDPR. The regulations require a reinforced level of compliance and, in physiotherapy centres, the mandatory appointment of a Data Protection Officer.

Art. 9

GDPR — health data

Art. 34

LOPDGDD — mandatory DPO

72 h

to report a breach

24 h

personalised proposal

Regulatory context

General obligations for physiotherapists and rehabilitation centres

Physiotherapy clinics handle health data including treatment history, functional assessment data and information on referred patients, with specific regulatory obligations.

Health data (art. 9 GDPR)

The physiotherapy record, including assessments, techniques applied and patient progress, is health data with the highest level of protection. It requires a specific legal basis and restricted access.

Relationships with third parties

Referring doctors, accident mutual insurance companies, insurers and management platforms may be involved in data processing. Each relationship must be analysed and documented appropriately.

Staff training and awareness

All staff who access patient data must know their data protection obligations and act accordingly.

Appropriate security measures

Individual credential access, device encryption and regular back-ups are basic measures in any physiotherapy clinic.

Retention periods

Law 41/2002 and regional legislation establish how long the patient record must be retained. During that period, it cannot be deleted even if the patient requests it.

Legal obligation

DPO appointment is mandatory at physiotherapy and rehabilitation clinics

The art. 34 of the LOPDGDD requires the appointment of a Data Protection Officer (DPO) at private healthcare centres, a category that includes physiotherapy and rehabilitation clinics. The legislation expressly provides an exception: healthcare professionals practising on an individual basis fall outside its direct scope of application.

The specific application to each centre requires individual analysis. The DPO oversees regulatory compliance, acts as the point of contact with the AEPD and advises the team on the processing of health data. Certix assumes this function as an independent service from day one.

Centres generally subject to art. 34 LOPDGDD

Physiotherapy and rehabilitation clinics
Sports physiotherapy centres
Neurological and trauma rehabilitation centres
Osteopathy clinics with healthcare classification
Workplace physiotherapy centres
Paediatric rehabilitation centres

Indicative list. The specific obligation for each entity requires individual analysis.

The service

What the data protection service for your clinic includes

Certix's standard contract, adapted to the specific circumstances of a physiotherapy or rehabilitation clinic.

RoPA and technical-organisational structure

Record of Processing Activities (RoPA) adapted to your activities: treatment history, data of minors, relationships with third parties and management software.

Adapted information clauses

Texts adapted to admission forms and communications with referring doctors, insurers and mutual insurance companies.

Adapted web documentation

Documentation adapted for the clinic's website: online appointment form, contact and cookie management.

Data Processing Agreements (DPA)

Processing agreements for clinical record software, online appointment platforms and therapeutic exercise apps.

Data breach protocol

Internal procedure to detect, classify and report incidents to the AEPD within the 72-hour deadline required by the GDPR.

Data subject rights management

Documented procedure for handling patients' and employees' rights requests within the established time limits.

Document management platform

Access to a private platform with all documents, templates and electronic signatures updated in real time.

Ongoing support

Ongoing support in the face of regulatory changes, new AEPD guidelines or changes in the clinic's activities.

External DPO (independent service)

The formal appointment of a Data Protection Officer (DPO) is a separate contract, quoted to measure according to the characteristics of the centre.

Need a proposal for your clinic?

Tell us about your activities and the size of the centre. Personalised proposal within 24 hours.

Request a proposal

Good practice

Key aspects in the day-to-day running of a physiotherapy clinic

Regulatory compliance does not end with documentation. In physiotherapy practice, there are everyday situations that require specialist judgement:

  • Data from workplace accident mutual insurance companies. Patients referred by accident mutual insurance companies or other insurers may generate data communications with third parties that require an appropriate legal basis.
  • Cloud-based clinical software. Providers of clinical record software may act as data processors. This relationship must be backed by an appropriate Data Processing Agreement.

Most common legal bases in physiotherapy

Art. 9.2.h GDPR

Provision of healthcare — principal basis for treatment history and progress recordings.

Art. 6.1.b GDPR

Performance of the physiotherapy services contract.

Art. 6.1.c GDPR

Compliance with legal obligations: retention of the clinical record.

Art. 6.1.a + 9.2.a GDPR

Explicit consent — for use of images outside the clinical record or non-strictly care-related treatments.

Art. 6.1.f GDPR

Legitimate interests — for appointment reminders and treatment follow-up.

FAQ

Frequently asked questions about data protection in physiotherapy

Is a DPO mandatory at a physiotherapy clinic?

Art. 34 of the LOPDGDD requires the appointment of a Data Protection Officer (DPO) at private healthcare centres, a category that includes physiotherapy and rehabilitation clinics, with the exception of healthcare professionals practising on an individual basis. The specific application to each centre requires individual analysis.

How long must the physiotherapy record be retained?

Law 41/2002 establishes a minimum of 5 years from the last care episode. Some autonomous communities extend this period. During the legally required retention period, the data cannot be deleted even if the patient requests it.

Can the physiotherapist share the patient's record with the referring doctor?

Yes, when the communication falls within the provision of care and the patient has been informed of this possibility in the information clause. The legal basis is art. 9.2.h GDPR. The communication must be documented.

Are therapeutic exercise apps data processors?

It depends on the model. If the clinic has access to the patient's functional data stored in the app, the provider may act as a data processor and the corresponding Data Processing Agreement must be formalised. Each case requires verification of the provider's conditions.

Does a self-employed physiotherapist working alone need to comply with the GDPR?

Yes. The GDPR applies to any professional who processes patient health data. A physiotherapist practising on an individual basis is exempt from the obligation to appoint a DPO under art. 34 LOPDGDD, but must comply with all other obligations: RoPA, information clauses, security measures and a data breach protocol.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Healthcare sector

GDPR compliance
for your physiotherapy clinic.

A data protection expert analyses your activities and proposes the most suitable solution. No intermediaries, no bureaucracy.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.