Skip to main content
advanced

Data protection for psychology practices in Spain

A source-led review of health-data bases, clinical records, information duties, retention, rights, processors, DPOs, and DPIAs in Spain.

advanced
12 min read
February 3, 2025
gdpr psychology health data spain clinical records

Psychology records can reveal diagnoses, symptoms, family circumstances, disability, medication, sexuality, and other highly sensitive facts. The practice needs both an Article 6 basis and an Article 9 condition, plus the professional and health-law rules that apply in Spain.

This guide is a review framework, not a conclusion for a particular practitioner. Registration, service type, public or private setting, region, patient group, and scale can change the answer.

1. Establish the professional and service context

Record:

  • the professional qualification and registration status;
  • whether the activity is healthcare, social, educational, employment, forensic, research, or another service;
  • who is the controller for each record;
  • whether another clinic, insurer, employer, school, or court is involved; and
  • which Spanish and autonomous-community rules apply.

The AEPD’s guide for healthcare professionals explains the controller’s responsibilities in the Spanish health context.

The GDPR separates the Article 6 lawful basis from the Article 9 special-category condition.

For healthcare delivered by or under the responsibility of a professional subject to secrecy, Article 9(2)(h) together with Article 9(3) and applicable Union or Member State law may be the relevant condition. A practitioner who does not meet that professional and legal context cannot assume it applies.

Explicit consent under Article 9(2)(a) is another possible condition. It must be explicit, informed, specific, freely given, demonstrable, and withdrawable. Withdrawal can make future consent-based processing unavailable but does not undo earlier lawful processing. It may be unsuitable where there is a power imbalance or the service cannot genuinely be refused.

Clinical consent to assessment or treatment, a professional confidentiality duty, and GDPR consent to data processing are related but distinct questions. Do not combine them into one unexplained signature.

3. Give layered information

At intake, explain controller, purposes, bases, health-data condition, recipients, retention, rights, complaint route, and any mandatory data. Use a short first layer and a complete second layer.

Explain material disclosures, including referrals, insurers, public bodies, emergency contacts, cloud clinical systems, video consultation, and transcription or AI tools. Do not promise absolute confidentiality when law or immediate risk can create a defined disclosure duty.

4. Control the clinical record

Spanish Law 41/2002 governs patient autonomy and clinical information in its scope. Article 17 contains minimum retention rules and purposes for preserving clinical documentation. Autonomous-community law and professional rules can impose additional periods.

Build a schedule by record type and legal purpose. Avoid inventing one universal number for every note, appointment email, invoice, or assessment. Restrict access to what each role needs, log clinical-record access, protect exports, and define secure destruction.

Keep personal working notes separate where the law and professional context recognise them, and confirm their access and retention treatment with a qualified reviewer.

5. Make rights and safety work together

Prepare a procedure for access, rectification, restriction, objection, portability where applicable, and deletion. A deletion request does not always require erasing a clinical record that must be preserved, but the refusal needs a specific legal reason and an explanation.

Verify identity proportionately. Avoid sending records through ordinary email without an appropriate security assessment. Record any restriction on access needed to protect third-party rights or confidential information.

6. Review processors, security, and incidents

Clinical software, cloud hosting, appointment systems, email, video, storage, accounting, and AI may receive data. Confirm roles, Article 28 terms, locations, subprocessors, transfers, retention, access, and exit.

Use strong authentication, least privilege, device encryption, backups, patching, access review, and a breach plan. The event log should support assessment under Articles 33 and 34 without exposing more clinical detail than necessary.

7. Apply the DPO and DPIA tests

Article 37 can require a DPO where core activities include large-scale processing of special categories. “Large scale” is contextual; a solo practice is not automatically exempt from the analysis, and a group clinic is not automatically caught without looking at scale and activity.

Article 35 requires a DPIA for processing likely to result in high risk. New systematic monitoring, high-volume health data, vulnerable people, novel AI, automated scoring, or linked datasets should trigger a documented screening. The AEPD provides DPIA guidance and tools.

Release gate

Before using this guide or a GDPR.Direct draft in a live Spanish practice, obtain review from:

  1. a qualified Spanish data-protection professional;
  2. a clinician familiar with the service and record obligations; and
  3. a native-language reviewer for patient-facing text.

GDPR.Direct can draft public and internal documents from supplied facts. It cannot determine professional status, clinical necessity, regional retention, safeguarding duties, or whether Article 9(2)(h), consent, a DPO, or a DPIA applies.

This guide is educational information, not legal or clinical advice.

Ready to Create Your First Draft?

Use the free plan to create editable drafts, verify the facts, and publish only what an accountable owner approves.

Get Started Free