Blog
Dental clinics and health data: EIPD, DPO and consents
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
Direct answer: a dental clinic processes health data in every clinical record, which triggers the strictest level of the RGPD, the EU's data protection regulation (art. 9). In practice, this means three things: you need a data protection officer (DPO) unless you practise entirely on your own (art. 34.1.l LOPDGDD, Spain's data protection act), it is advisable to carry out an impact assessment (EIPD) when the clinical record is combined with another risk factor, such as patients who are minors (art. 35 RGPD), and consents for photos or marketing always go separately from clinical care. This guide, reviewed on 16 July 2026, explains each point with its legal basis.
Contents
- Why does a dental clinic have stricter obligations?
- What health data does a dental clinic process, and on what legal basis?
- Does my clinic need a data protection officer (DPO)?
- When is an EIPD needed in a dental clinic?
- What consents do you have to ask patients for?
- What happens if you do not comply? A real case
- Checklist in 15 minutes
- Frequently asked questions
Why does a dental clinic have stricter obligations?
The RGPD distinguishes between ordinary personal data and special category data: health, ethnic origin, religion, sexual orientation, fingerprint or face, among others (art. 9 RGPD). This data has more protection because misuse can do more harm to the person.
A dental patient's clinical record fits squarely there: medical history, allergies, medication, diagnosis, treatment and, frequently, X-rays or intraoral photographs. By law (Ley 41/2002, de autonomía del paciente, Spain's patient autonomy act, arts. 14 and 17), you are also obliged to keep it and retain it for a minimum period — it is not a business decision, it is a healthcare obligation that drags data protection obligations along with it.
That combination —sensitive data + a legal obligation to retain it— is the reason a dental clinic has a longer compliance journey than, say, a hairdresser's or a car repair shop. It is not paperwork for its own sake: it is proportionate to the real risk to your patients.
What health data does a dental clinic process, and on what legal basis?
In practice, a dental clinic handles several different processing operations, each with its own legal basis:
- The patient's clinical record (name, medical history, allergies, diagnosis, treatment, X-rays). Legal basis: performance of the care contract (art. 6.1.b RGPD) plus the legal obligation to retain it (Ley 41/2002). For the health data itself, the special basis is art. 9.2.h RGPD (healthcare) — here you do not need to ask the patient for consent: signing the information sheet is not signing a consent, they are different things.
- Data of patients who are minors, when you do paediatric dentistry: the person with parental responsibility or guardianship signs (art. 7 LOPDGDD, under 14).
- Clinical photographs of the before and after: if they are for the record, they go with the clinical record. If they are for your website or your social media, that is a different processing operation and needs its own consent (art. 9.2.a RGPD).
- Appointments and reminders: these are not health data in themselves, but it is advisable that the message does not say what the treatment is, only the day and the time.
An important nuance for day-to-day work: the dental prosthetics laboratory also receives patient data (mould, measurements, sometimes the name) when you order a piece from it. That makes it a processor and it needs a contract under art. 28 RGPD. The most prudent practice is to send it a patient code instead of the patient's full name.
Does my clinic need a data protection officer (DPO)?
This is where there is most doubt, and the answer has a very specific legal basis. Art. 34.1.l of the LOPDGDD requires a data protection officer to be appointed by «healthcare centres legally obliged to maintain patients' clinical records».
A dental clinic fits: it is a healthcare centre (subject to authorisation by the comunidad autónoma, the regional government) and it is legally obliged to keep and retain its patients' clinical records (Ley 41/2002). Therefore, the DPO obligation applies by default.
There is an exception, written into the letter of the law itself, it is not an interpretation: health professionals who practise on an individual basis are excluded, with no company and no staff. If you are a dentist working entirely on your own, you probably do not need a DPO — but it is advisable for your gestoría (the firm that handles your administrative paperwork) to confirm it case by case, because the line between «practising alone» and «with a structure» is not always obvious (a clinic with a single dentist but with a receptionist or a hygienist on the payroll already has a structure).
A detail that is often overlooked: if you appoint a DPO —even voluntarily, without being obliged to— you have to notify the AEPD (Spain's data protection authority) within ten days (art. 34.3 LOPDGDD, art. 37.7 RGPD). The DPO can be someone on your team with sufficient knowledge, or an external service, such as the one usually offered by a gestoría or a data protection consultancy.
When is an EIPD needed in a dental clinic?
The EIPD (data protection impact assessment) is an analysis that the law requires before processing data when the processing may entail a high risk to individuals (art. 35 RGPD). It is not a fine disguised as a formality: it is, in essence, stopping to think about what can go wrong and what you do to prevent it, in writing.
Here it is worth being precise, because not every processing of health data automatically triggers the EIPD simply by virtue of being health data. Art. 35.3.b RGPD requires it when the processing of special data is carried out «on a large scale» — a neighbourhood clinic with five or six people can reasonably argue that it does not reach that scale.
That is why the soundest basis is not that article in isolation, but the art. 35.4 RGPD together with the list of types of processing that require an EIPD published by the AEPD, which works by accumulating risk criteria (profiling, special category data, vulnerable subjects, among others). In a dental clinic, that threshold is usually reached through the combination of health data (the clinical record) plus patients who are minors (paediatric dentistry), which is a particularly vulnerable category of subjects.
The prudent criterion —and the one we recommend— is to carry out the EIPD when that combination arises, even if the clinic is small: the document is short, it stays on file as evidence of proactive accountability (art. 24 RGPD), and it avoids having to argue afterwards, in the event of an inspection, about whether or not your volume amounted to «a large scale».
What consents do you have to ask patients for?
One fixed rule in data protection, and one that in a dental clinic is especially easy to break through carelessness: one consent per purpose, never one that bundles several different things together. Three specific cases:
- Treating the patient: this does not need consent as such (see above, art. 9.2.h RGPD). It does need you to inform them clearly about what you do with their data.
- Photos for social media or the website: separate consent, specific, informed and one that the patient can withdraw whenever they want. Never the same box as the clinical photo in the record.
- Advertising and news: an empty box by default, never pre-ticked. Watch out for a common mistake in the sector: segmenting offers according to the patient's treatment («implants only to those who need implants») uses health data for commercial purposes and requires a separate explicit consent (art. 9.2.a RGPD) — the generic marketing consent is not enough.
And with patients who are minors, the person who signs the consent and receives the information is the father, the mother or the guardian, not the minor (art. 7 LOPDGDD for children under 14).
What happens if you do not comply? A real case
The AEPD monitors the health sector as one of its areas of focus (you can consult its published complaints in health matters). A case reported by the specialist legal press illustrates the most common type of failure well, and it is not exclusive to clinics: according to ForLOPD and El Economista Jurídico, the AEPD imposed a penalty of 16,000 euros on a pharmacy that kept, in an Excel file, without encryption or appropriate protective measures, health identifiers, the medication requested and the prescribing doctor of its patients — without having informed them of that processing.
You do not need a sophisticated cyberattack to have a problem: the most frequent cause is a spreadsheet with health data, saved on a shared computer, without telling anyone and with no access control. In a dental clinic, the equivalent would be a list of patients with their diagnosis saved outside the practice management software, on the desktop of a computer that the whole front desk can see.
That is why this article does not close with a fine figure as its argument: it closes with the concrete solution. The clinical record goes in your practice management software, with a username and password specific to each person; no loose health data in spreadsheets, shared folders or anyone's personal phone.
Checklist in 15 minutes
To find out where your clinic stands right now, go through these six points:
- Is your clinical record in a program with a username and password specific to each person, not on loose paper or in Excel?
- Do you know whether you are required to have a DPO (do you practise alone or with a team/company?) and, if you are, has it been notified to the AEPD?
- Have you carried out the EIPD if you treat minors or combine the clinical record with another risky processing operation?
- Do the photos for your website or Instagram have a consent separate from the clinical record, signed and with the option to withdraw it?
- Has your dental prosthetics laboratory signed a processor contract (art. 28 RGPD)?
- Does the appointment reminder message avoid saying what the treatment is?
If any answer is «I do not know», that is exactly the starting point of the Tranquilia wizard for the dental clinic profile: it asks these questions for you and generates the documents that are missing.
Frequently asked questions
Does a dental clinic need a data protection officer? Yes, almost always, unless you practise entirely on your own, with no company and no staff. Art. 34.1.l LOPDGDD requires it for healthcare centres obliged to keep clinical records.
Does every dental clinic have to carry out an EIPD? When the processing of the clinical record is combined with another risk factor, such as patients who are minors, the prudent thing is to do it. It rests on art. 35.4 RGPD and on the AEPD's list of processing operations, not only on the «large scale» criterion in art. 35.3.b, which a small clinic can dispute.
Does a photo of a dental treatment need consent? The clinical photo for the record does not need a separate consent: it is part of the clinical record (art. 9.2.h RGPD). The photo for your website or your social media does need a separate, specific consent that can be withdrawn (art. 9.2.a RGPD).
Is the patient's consent needed to process their clinical record? No. The legal basis is performance of the care contract and the legal obligation to retain it (art. 6.1.b and 6.1.c RGPD, Ley 41/2002), together with art. 9.2.h RGPD for the health data. Informing the patient is obligatory; asking them to sign a consent in order to be treated is not.
Report produced with Tranquilia — it does not constitute an official certification or a legal opinion. For your specific case, talk to your gestoría.
Do you want to see exactly which documents Tranquilia generates for a dental clinic? See the full use case with the step-by-step walkthrough: Dental clinic in Tranquilia.
Review: Article written with AI support from primary sources (AEPD, BOE) and moderated before publication. See the «Editorial policy» page for the full process. It is not a legal opinion: for your specific case, talk to your gestoría. Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.