Health and wellbeing
Data protection
for opticians
Opticians process medical prescriptions and visual health data belonging to their customers. Art. 34 of the LOPDGDD may require the appointment of a DPO depending on the type and scale of the processing. Managing prescription histories, contact lens records and ocular pathologies requires the highest GDPR safeguards.
art. 34
LOPDGDD — possible DPO
Art. 9
GDPR — visual health data
5 years
min. clinical record retention
24 h
personalised proposal
Sector challenges
General obligations for opticians
Prescriptions and visual health data
Prescriptions, contact lens prescriptions and data on ocular pathologies are health data (art. 9 GDPR) requiring reinforced protection and a specific legal basis for each processing activity.
Customer optical record
The record of the customer's check-ups and prescriptions must be retained in accordance with regional healthcare legislation and tax retention periods, with access restricted to authorised staff.
Possible DPO under art. 34
Opticians that carry out sight examinations and dispense prescription products must assess whether the conditions of art. 34 LOPDGDD are met for a possible DPO appointment.
Prescription medical devices
Dispensing medical devices (glasses, contact lenses) under a medical prescription involves processing the customer's health data with all GDPR safeguards.
Optician management software
Platforms managing customer records, prescriptions, lens stock and invoicing may act as data processors; it is advisable to review each provider's conditions and, where they act as such, to formalise the specific DPA for health data.
Marketing and customer communications
Sending check-up reminders, offers and commercial communications requires a legal basis separate from the provision of the optical service, particularly where health data is involved.
Legal obligation
A DPO may be required for opticians
The art. 34 of the LOPDGDD provides for the possible obligation to appoint a Data Protection Officer (DPO) at healthcare establishments and centres. Opticians that carry out sight examinations and dispense medical devices under prescription may fall within those provisions depending on their classification as an establishment or healthcare centre under applicable healthcare legislation, although the specific application depends on the type and scale of the processing.
The DPO must be external or internal, with specialist knowledge in data protection and healthcare law, and must be independent from the controller. If the individual analysis determines that the optician must appoint a DPO and fails to do so, this may be viewed negatively in the event of an inspection or incident before the AEPD. As a general rule for the sector, opticians are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis.
Enquire about an external DPO for my opticianThe service
What the service for your optician includes
RoPA
Record of Processing Activities adapted to your business: customers/patients, employees, prescriptions and optician management software.
Information clauses
Texts for the customer file, consents for health data and commercial communications.
Privacy policy and legal notice
Documentation for the optician's website.
Data Processing Agreements
DPA for management software, contact lens platforms and marketing tools.
Data breach protocol
Response procedure with notification within 72 hours.
Data subject rights management
Procedure for customer requests: access, rectification and erasure of records.
Document management platform
Access to a private platform with documents and electronic signatures.
Ongoing support
Unlimited queries. Updated following regulatory changes.
External DPO
Independent contract. Recommended if individual analysis advises appointment under art. 34 LOPDGDD.
Need a proposal for your optician?
Tell us the number of locations and patient volume. Proposal within 24 hours.
FAQ
Frequently asked questions about data protection in opticians
Are opticians required to appoint a Data Protection Officer?
Opticians that carry out sight examinations and dispense products under prescription process health data (a special category under art. 9 GDPR). Art. 34 of the LOPDGDD provides for the possible obligation to appoint a DPO at this type of establishment, although the specific application depends on the type and scale of the processing. The case should be analysed on an individual basis.
Is the customer's optical prescription health data?
Yes. Visual acuity, contact lens prescriptions and any data relating to a customer's visual sharpness or ocular pathologies are health data under art. 4.15 GDPR. Their processing requires a reinforced legal basis (explicit consent or necessity for the provision of care) and additional security measures.
How long must an optician retain customer records?
Healthcare legislation establishes retention periods for clinical documentation (a minimum of 5 years from the last appointment in some autonomous communities). Invoicing data must be retained for 4 years to comply with tax obligations. The optician must establish differentiated retention periods for clinical and commercial data.
Can an optician use customers' health data to send advertising?
Not directly. Health data (prescription, type of lens) cannot be used to send commercial communications without the customer's explicit consent for that specific purpose. The existing customer exception (art. 21.2 LSSI) allows advertising for similar products to those already purchased, but only if it does not involve processing health data for that purpose.
Can employed optometrists access the full records of all customers?
Only the data necessary for attending the customer they are currently serving. The GDPR's data minimisation principle requires access to health records to be restricted to staff who need that information to provide the service. Indiscriminate access by employees to other customers' records is a security infringement.
Does the optician's management software require a Data Processing Agreement?
As a general rule, yes. Optician management platforms that store customer records, prescriptions and invoicing data may act as data processors. The exact legal relationship depends on each provider's conditions; it is advisable to review them and, where the provider acts as such, to formalise a DPA with specific security measures for health data and verify GDPR compliance for special-category data.
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Health and wellbeing
GDPR compliance
for your optician.
An expert analyses your activities and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.