Psychology records can reveal diagnoses, symptoms, family circumstances, disability, medication, sexuality, and other highly sensitive facts. The practice needs both an Article 6 basis and an Article 9 condition, plus the professional and health-law rules that apply in Spain.
This guide is a review framework, not a conclusion for a particular practitioner. Registration, service type, public or private setting, region, patient group, and scale can change the answer.
1. Establish the professional and service context
Record:
- the professional qualification and registration status;
- whether the activity is healthcare, social, educational, employment, forensic, research, or another service;
- who is the controller for each record;
- whether another clinic, insurer, employer, school, or court is involved; and
- which Spanish and autonomous-community rules apply.
The AEPD’s guide for healthcare professionals explains the controller’s responsibilities in the Spanish health context.
2. Do not treat explicit consent as the universal health-data basis
The GDPR separates the Article 6 lawful basis from the Article 9 special-category condition.
For healthcare delivered by or under the responsibility of a professional subject to secrecy, Article 9(2)(h) together with Article 9(3) and applicable Union or Member State law may be the relevant condition. A practitioner who does not meet that professional and legal context cannot assume it applies.
Explicit consent under Article 9(2)(a) is another possible condition. It must be explicit, informed, specific, freely given, demonstrable, and withdrawable. Withdrawal can make future consent-based processing unavailable but does not undo earlier lawful processing. It may be unsuitable where there is a power imbalance or the service cannot genuinely be refused.
Clinical consent to assessment or treatment, a professional confidentiality duty, and GDPR consent to data processing are related but distinct questions. Do not combine them into one unexplained signature.
3. Give layered information
At intake, explain controller, purposes, bases, health-data condition, recipients, retention, rights, complaint route, and any mandatory data. Use a short first layer and a complete second layer.
Explain material disclosures, including referrals, insurers, public bodies, emergency contacts, cloud clinical systems, video consultation, and transcription or AI tools. Do not promise absolute confidentiality when law or immediate risk can create a defined disclosure duty.
4. Control the clinical record
Spanish Law 41/2002 governs patient autonomy and clinical information in its scope. Article 17 contains minimum retention rules and purposes for preserving clinical documentation. Autonomous-community law and professional rules can impose additional periods.
Build a schedule by record type and legal purpose. Avoid inventing one universal number for every note, appointment email, invoice, or assessment. Restrict access to what each role needs, log clinical-record access, protect exports, and define secure destruction.
Keep personal working notes separate where the law and professional context recognise them, and confirm their access and retention treatment with a qualified reviewer.
5. Make rights and safety work together
Prepare a procedure for access, rectification, restriction, objection, portability where applicable, and deletion. A deletion request does not always require erasing a clinical record that must be preserved, but the refusal needs a specific legal reason and an explanation.
Verify identity proportionately. Avoid sending records through ordinary email without an appropriate security assessment. Record any restriction on access needed to protect third-party rights or confidential information.
6. Review processors, security, and incidents
Clinical software, cloud hosting, appointment systems, email, video, storage, accounting, and AI may receive data. Confirm roles, Article 28 terms, locations, subprocessors, transfers, retention, access, and exit.
Use strong authentication, least privilege, device encryption, backups, patching, access review, and a breach plan. The event log should support assessment under Articles 33 and 34 without exposing more clinical detail than necessary.
7. Apply the DPO and DPIA tests
Article 37 can require a DPO where core activities include large-scale processing of special categories. “Large scale” is contextual; a solo practice is not automatically exempt from the analysis, and a group clinic is not automatically caught without looking at scale and activity.
Article 35 requires a DPIA for processing likely to result in high risk. New systematic monitoring, high-volume health data, vulnerable people, novel AI, automated scoring, or linked datasets should trigger a documented screening. The AEPD provides DPIA guidance and tools.
Release gate
Before using this guide or a GDPR.Direct draft in a live Spanish practice, obtain review from:
- a qualified Spanish data-protection professional;
- a clinician familiar with the service and record obligations; and
- a native-language reviewer for patient-facing text.
GDPR.Direct can draft public and internal documents from supplied facts. It cannot determine professional status, clinical necessity, regional retention, safeguarding duties, or whether Article 9(2)(h), consent, a DPO, or a DPIA applies.
This guide is educational information, not legal or clinical advice.