Data about people's health is among the most sensitive a company handles. Here, point by point, is what a clinic, practice or healthcare company must have in place to be in order with the GDPR.
A dental practice, a private clinic, a medical lab, a pharmacy, a telemedicine app — they all have one thing in common: they work with data about people's health. And the GDPR handles this data with care, because a leak here doesn't just mean an exposed email — it means diagnoses, test results, medical history.
The good news is that "being compliant" is no mystery. The GDPR tells you fairly clearly what to do. Let's take it one item at a time, like a list you can tick off.
The GDPR puts responsibility on the controller — the company that decides why and how data is used (the clinic, the practice, the company). Article 5(2) and Article 24 say it plainly: it's not enough to follow the rules, you must be able to prove you follow them. That's why almost everything below means, in practice, "have it on paper and actually do it".
The list below follows the thread of the controller's obligations from Chapter II (principles), Chapter III (people's rights) and Chapter IV (controller and processor).
Any use of data needs a reason permitted by law. With health data there are two layers: the general basis (Art. 6) and an exception from Art. 9, because health data is, in principle, prohibited from processing. For the medical act, the usual basis is Art. 9(2)(h) — medical care. For newsletters, marketing reminders or testimonials, you need separate consent (Art. 6(1)(a) + Art. 9(2)(a)). Tick: you know, for each type of data, the basis on which you use it.
A document showing what data you collect, why, how long you keep it, who you share it with and how you protect it. It's the first sheet the authority asks for in an audit. For a clinic, the record covers patients, employees, suppliers, job applicants and so on.
The patient has the right to know, before or at the moment of collection, who uses their data, why, for how long and what rights they have. The notice must be understandable, not a dense legal text. You keep it at reception, on the website and in consent forms.
A person can ask for: access to their data, correction of a mistake, erasure (with the limits in point 13), restriction of use, objection, or portability. You need a clear way to receive and handle such requests, usually within 30 days. Tick: who answers, in what time, and how you prove you answered.
When you rely on consent (marketing, follow-up reminders, photos, studies), it must be free, clear, specific and as easy to withdraw as to give. Note: for the medical act itself you do NOT ask for GDPR consent — there the basis is Art. 9(2)(h). Mixing the two is a common mistake.
If you process health data on a large scale — and most medical units do — you need a DPO (Art. 37). They guide, check and keep in touch with the authority. They can be in-house or outsourced. More in our articles on what a DPO is and its responsibilities and on the outsourced DPO.
Sensitive data means matching protection: access control (who sees what), encryption, pseudonymisation where possible, backups, access logging, strong passwords and up-to-date software. Practical detail in our article on securing medical data.
For large-scale processing of health data, the GDPR requires a Data Protection Impact Assessment (DPIA) before you start. In practice: you analyse what could go wrong and what measures you take. It's mandatory, for example, for a telemedicine app or a new electronic records system.
Anything that touches your data from the outside needs a contract: the medical software vendor, the hosting/cloud, the external lab, the archiving company, outsourced IT, the booking platform. The contract (DPA) establishes that they use the data only on your instructions and with the same care.
If data is exposed, you usually have 72 hours to notify the authority and, when the risk is high, to inform the patients. You must have the procedure written before anything happens. See how it's done in our article on breach notification and a real example in the incident with medical data in an Excel file.
If you use a service that keeps data outside the European Union (cloud, a US tool, etc.), you need additional safeguards. Check where your data actually sits.
Most incidents come from people, not hackers: a record left in view, an email sent to the wrong address. Train your team regularly and put confidentiality clauses in contracts. It's a measure required as part of security too (Art. 32).
Data is kept only as long as needed. In healthcare, however, the law imposes retention periods for medical records — so here "erasure on request" has limits. The key is to have a retention policy: what you keep, for how long, and what you delete when it no longer has a basis.
When you choose new software or launch a service, data protection must be built in from the start, not bolted on at the end: you collect only what you need, the safe settings are the defaults, access is limited. This is the "privacy by design & by default" principle.
Healthcare is treated as a critical sector by other new rules too. The NIS2 Directive brings cybersecurity obligations for many medical units, and at European level the European Health Data Space (EHDS) is being built. The good news: if your GDPR foundations are in place, you're already a step ahead for these too.
The list looks long, but you don't have to tackle it all at once. Start with an X-ray: what you already have and what's missing. On askGDPR.ro there's a free GDPR self-assessment module that shows you, in a few minutes, how close you are to compliance. And if you have questions along the way, the same page has a GDPR assistant that answers on the spot — especially useful before investing in consultancy.
For an overview across all areas, see also the complete GDPR checklist for 2026.
Yes. Health data is a special category of data under Article 9 of the GDPR. Processing it is prohibited in principle, except in situations clearly set out in law — for a healthcare provider, the usual basis is Article 9(2)(h): medical care and the management of health services.
Usually yes. Under Article 37 of the GDPR, a Data Protection Officer (DPO) is mandatory when you process special-category data on a large scale — and health data is exactly that. Most clinics, hospitals and labs fall into this case.
Not always in full. The right to erasure (Article 17) does not apply when keeping the data is a legal obligation — and medical records have retention periods set by law. You can delete what no longer has a basis (for example marketing data), but not the medical documentation you are required to archive.
The simplest way is a self-assessment. askGDPR.ro has a free GDPR self-assessment module and an assistant that answers questions, so you can quickly see what you already have and what's missing before investing in consultancy.
Start with the free GDPR self-assessment on askGDPR.ro and use the GDPR assistant for questions. Then, if you want to put everything in order without the hassle, we'll help — from the record and privacy notices to the DPO and security.