Certix

Health and wellbeing

Data protection
for opticians

Opticians process medical prescriptions and visual health data belonging to their customers. Art. 34 of the LOPDGDD may require the appointment of a DPO depending on the type and scale of the processing. Managing prescription histories, contact lens records and ocular pathologies requires the highest GDPR safeguards.

art. 34

LOPDGDD — possible DPO

Art. 9

GDPR — visual health data

5 years

min. clinical record retention

24 h

personalised proposal

Sector challenges

General obligations for opticians

Prescriptions and visual health data

Prescriptions, contact lens prescriptions and data on ocular pathologies are health data (art. 9 GDPR) requiring reinforced protection and a specific legal basis for each processing activity.

Customer optical record

The record of the customer's check-ups and prescriptions must be retained in accordance with regional healthcare legislation and tax retention periods, with access restricted to authorised staff.

Possible DPO under art. 34

Opticians that carry out sight examinations and dispense prescription products must assess whether the conditions of art. 34 LOPDGDD are met for a possible DPO appointment.

Prescription medical devices

Dispensing medical devices (glasses, contact lenses) under a medical prescription involves processing the customer's health data with all GDPR safeguards.

Optician management software

Platforms managing customer records, prescriptions, lens stock and invoicing may act as data processors; it is advisable to review each provider's conditions and, where they act as such, to formalise the specific DPA for health data.

Marketing and customer communications

Sending check-up reminders, offers and commercial communications requires a legal basis separate from the provision of the optical service, particularly where health data is involved.

Legal obligation

A DPO may be required for opticians

The art. 34 of the LOPDGDD provides for the possible obligation to appoint a Data Protection Officer (DPO) at healthcare establishments and centres. Opticians that carry out sight examinations and dispense medical devices under prescription may fall within those provisions depending on their classification as an establishment or healthcare centre under applicable healthcare legislation, although the specific application depends on the type and scale of the processing.

The DPO must be external or internal, with specialist knowledge in data protection and healthcare law, and must be independent from the controller. If the individual analysis determines that the optician must appoint a DPO and fails to do so, this may be viewed negatively in the event of an inspection or incident before the AEPD. As a general rule for the sector, opticians are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis.

Enquire about an external DPO for my optician

The service

What the service for your optician includes

RoPA

Record of Processing Activities adapted to your business: customers/patients, employees, prescriptions and optician management software.

Information clauses

Texts for the customer file, consents for health data and commercial communications.

Privacy policy and legal notice

Documentation for the optician's website.

Data Processing Agreements

DPA for management software, contact lens platforms and marketing tools.

Data breach protocol

Response procedure with notification within 72 hours.

Data subject rights management

Procedure for customer requests: access, rectification and erasure of records.

Document management platform

Access to a private platform with documents and electronic signatures.

Ongoing support

Unlimited queries. Updated following regulatory changes.

External DPO

Independent contract. Recommended if individual analysis advises appointment under art. 34 LOPDGDD.

Need a proposal for your optician?

Tell us the number of locations and patient volume. Proposal within 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in opticians

Are opticians required to appoint a Data Protection Officer?

Opticians that carry out sight examinations and dispense products under prescription process health data (a special category under art. 9 GDPR). Art. 34 of the LOPDGDD provides for the possible obligation to appoint a DPO at this type of establishment, although the specific application depends on the type and scale of the processing. The case should be analysed on an individual basis.

Is the customer's optical prescription health data?

Yes. Visual acuity, contact lens prescriptions and any data relating to a customer's visual sharpness or ocular pathologies are health data under art. 4.15 GDPR. Their processing requires a reinforced legal basis (explicit consent or necessity for the provision of care) and additional security measures.

How long must an optician retain customer records?

Healthcare legislation establishes retention periods for clinical documentation (a minimum of 5 years from the last appointment in some autonomous communities). Invoicing data must be retained for 4 years to comply with tax obligations. The optician must establish differentiated retention periods for clinical and commercial data.

Can an optician use customers' health data to send advertising?

Not directly. Health data (prescription, type of lens) cannot be used to send commercial communications without the customer's explicit consent for that specific purpose. The existing customer exception (art. 21.2 LSSI) allows advertising for similar products to those already purchased, but only if it does not involve processing health data for that purpose.

Can employed optometrists access the full records of all customers?

Only the data necessary for attending the customer they are currently serving. The GDPR's data minimisation principle requires access to health records to be restricted to staff who need that information to provide the service. Indiscriminate access by employees to other customers' records is a security infringement.

Does the optician's management software require a Data Processing Agreement?

As a general rule, yes. Optician management platforms that store customer records, prescriptions and invoicing data may act as data processors. The exact legal relationship depends on each provider's conditions; it is advisable to review them and, where the provider acts as such, to formalise a DPA with specific security measures for health data and verify GDPR compliance for special-category data.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Health and wellbeing

GDPR compliance
for your optician.

An expert analyses your activities and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.