Certix

Socio-health sector

Data protection for
care homes for the elderly

Clinical records, dependency data and the personal information of people in a situation of particular vulnerability require the highest level of protection under art. 9 GDPR. Depending on the nature and classification of the centre, the obligation to appoint a Data Protection Officer may apply. Each case requires individual analysis.

Art. 9

GDPR — health and dependency data

Art. 34

LOPDGDD — analyse by centre type

72 h

to report a breach

24 h

personalised proposal

Regulatory context

General obligations for care homes and socio-health centres

Care homes concentrate health data, social data and data relating to people in a situation of particular vulnerability in a single space, with multiple parties accessing that information on a daily basis.

Health and dependency data (art. 9 GDPR)

Data on health status, dependency level, medication and diagnoses are special-category data under art. 9 GDPR. Their processing requires a specific legal basis, reinforced security measures and strictly controlled access.

Authorised family members and legal representation

The care home may only provide information to family members whom the resident has expressly authorised or who hold accredited legal representation. Managing and correctly documenting these authorisations is an obligation.

CCTV in the premises

CCTV in communal areas requires visible information signage, restricted access and a maximum retention period of 30 days. In bedrooms, it is only permissible in exceptional circumstances with consent and a rigorous proportionality analysis.

Coordination with external healthcare services

External doctors, specialists, emergency services and insurers who receive residents' data act as collaborators in the provision of care. Each communication must be documented and backed by its corresponding legal basis.

Medication and monitoring data

Data on prescribed medicines, dosages and administration are particularly sensitive health data. Access must be limited to healthcare and care staff with direct care functions, with individual credentials.

Residents with legal capacity support measures

Where the resident has a recognised legal capacity support measure, GDPR rights are exercised by their legal representative. The care home must document this situation and act accordingly, always respecting the resident's wishes as far as possible.

Data Protection Officer

The DPO in care homes: when it may be required

The art. 34.1.g of the LOPDGDD provides for the obligation to appoint a Data Protection Officer (DPO) at healthcare centres legally required to maintain clinical records. The application of this provision to a specific care home depends on its nature and legal classification.

Care homes with a healthcare classification and a clinical record obligation will generally be subject to this requirement. Those of an exclusively social nature require individual analysis. The volume of data and the exact nature of the processing activities are determining factors.

The DPO oversees regulatory compliance, acts as the point of contact with the AEPD and advises the management and care team. Certix assumes this function as an independent service, quoted to measure according to the characteristics of the centre.

Centres where DPO appointment may be applicable

Care homes for the elderly
Day centres with healthcare services
Dependency care centres
Day stay units with nursing staff
Care homes with a palliative care unit
Residential centres with ongoing medical supervision

Indicative list. The specific obligation for each entity requires individual analysis.

The service

What the data protection service for your care home includes

Certix's standard contract, adapted to the specific circumstances of a care home or socio-health centre.

RoPA and technical-organisational structure

Adapted Record of Processing Activities: clinical and social records, CCTV, coordination with external services and residential management software.

Adapted information clauses

Texts adapted to admission contracts, admission forms, healthcare consents and communications with family members and legal representatives.

Adapted web documentation

Documentation adapted for the centre's website: contact form, information request and cookie management.

Data Processing Agreements (DPA)

Processing agreements for residential management software, CCTV systems and outsourced healthcare or care services.

Data breach protocol

Internal procedure to detect, classify and report incidents to the AEPD within the 72-hour deadline required by the GDPR.

Data subject rights management

Documented procedure for handling requests from residents and their legal representatives within the established time limits.

Document management platform

Access to a private platform with all documents, templates and electronic signatures updated in real time.

Ongoing support

Ongoing support in the face of regulatory changes, new AEPD guidelines or changes in the centre's activities.

External DPO (independent service)

The formal appointment of a Data Protection Officer (DPO) is a separate contract, quoted to measure according to the characteristics of the centre.

Need a proposal for your care home?

Tell us about your activities and the number of places. Personalised proposal within 24 hours.

Request a proposal

Good practice

Key aspects in the compliance of a care home for the elderly

Regulatory compliance does not end with documentation. In the day-to-day running of a care home, there are everyday situations that require specialist judgement:

  • Family member access. The care home must have a clear protocol regarding what information can be provided to family members and under what conditions. The resident's consent or proof of legal representation are indispensable prerequisites.
  • CCTV. Camera systems in communal areas must be documented, with visible information signage, restricted access to recordings and a maximum retention period of 30 days. Installation in bedrooms requires individual analysis and justification of proportionality.
  • Data of deceased residents. Following a resident's death, the data must be retained for the legally required periods. Family members may request access to the deceased's record by evidencing their relationship, provided the resident had not expressly prohibited access during their lifetime.
  • Residential management software. Cloud-based management systems may act as data processors depending on each provider's conditions. It is advisable to verify the location of the data, the security measures and, where applicable, to formalise the corresponding Data Processing Agreement.

Most common legal bases in care homes for the elderly

Art. 9.2.h GDPR

Provision of healthcare and social care — principal basis for processing health and dependency data.

Art. 6.1.b GDPR

Performance of the residential services contract.

Art. 6.1.c GDPR

Compliance with legal obligations: documentation required by social services and healthcare legislation.

Art. 6.1.f GDPR

Legitimate interests — for CCTV in communal areas for security purposes, subject to prior proportionality analysis.

Art. 9.2.c GDPR

Vital interests — for urgent treatments where the resident cannot give consent and no representative is available.

FAQ

Frequently asked questions about data protection in care homes for the elderly

Is a DPO mandatory at a care home for the elderly?

It depends on the type of centre. Art. 34.1.g of the LOPDGDD provides for the obligation to appoint a DPO at healthcare centres legally required to maintain clinical records. Care homes with healthcare classification and a clinical record obligation will generally be subject to this requirement; those of an exclusively social nature require individual analysis. The volume of data and the legal nature of each centre are the determining factors.

Can family members access the resident's data?

Only where the resident has expressly authorised them to do so or where they hold accredited legal representation (guardianship, curatorship or a legal capacity support measure). The care home cannot provide clinical or personal information to family members without that basis. Where the resident lacks the capacity to exercise their rights, legal representatives act on their behalf.

Is CCTV surveillance permitted in the rooms of a care home?

CCTV in bedrooms is subject to very strict restrictions. In communal areas it may be justified on security grounds, with visible information signage and restricted access to recordings. In bedrooms, it is only permissible in exceptional circumstances with the consent of the resident or their legal representative and a rigorous proportionality analysis. Images may not be retained for more than 30 days except pursuant to a court order.

Can the care home share medical data with the resident's GP?

Yes, where the communication falls within the provision of healthcare and the resident or their representative has been informed. The legal basis is art. 9.2.h GDPR. The communication must be documented and a clear procedure must exist to govern these transfers.

What happens to a resident's data after they pass away?

The GDPR does not apply to deceased persons, but the care home must retain the record for the legally required periods (Law 41/2002 and regional legislation). Family members may request access to the deceased's record by evidencing their relationship, unless the resident had expressly prohibited access during their lifetime.

How is consent managed for residents with recognised legal incapacity?

Where the resident has a legal capacity support measure in place, the legal representative exercises data protection rights on their behalf. The care home must document the representation and act accordingly, respecting the resident's own wishes and preferences as far as possible.

How long must the resident's record be retained?

Law 41/2002 establishes a minimum of 5 years from the last care episode. Regional legislation may extend this period. Additionally, the social care record may have its own retention periods under the social services legislation applicable in each autonomous community. During the legally required retention period, the data cannot be deleted even if the resident or their representatives request it.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Socio-health sector

GDPR compliance
for your care home.

A data protection expert analyses your activities and proposes the most suitable solution. No intermediaries, no bureaucracy.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.