Guides

Data protection for nutritionists in Spain: a practical guide

What the GDPR and the LOPDGDD require from a nutrition practice in Spain: lawful basis, health data, minimum safeguards, processors, and what to do after a breach.

11 min read

The data you handle in practice — conditions, medication, body measurements — is a special category under the GDPR. That changes the lawful basis you need and the level of safeguards expected of you. This guide turns that into concrete decisions.

Two rules apply in Spain: the General Data Protection Regulation (Regulation EU 2016/679) and Organic Law 3/2018 (LOPDGDD), which implements it. The supervisory authority is the Spanish Data Protection Agency (AEPD).

Why your practice is a special case

Article 9 of the GDPR generally prohibits processing health data, then opens exceptions. Everything you record in a nutrition clinical record — diagnoses, medication, allergies, body composition tied to a health status — falls in that category. The practical consequence is twofold: you need an Article 9 exception to cover the processing, and the safeguards expected of you are higher than for a business handling only names and emails.

Which lawful basis to use

For care itself, the usual route is Article 9(2)(h): processing necessary for preventive medicine, medical diagnosis, or the provision of health care. That basis does not depend on consent and is more stable. Consent is still needed, separately, for everything that is not care:

  • Sending marketing communications or newsletters.
  • Publishing before-and-after photographs, even without a name.
  • Using the case for teaching or public content.
  • Sharing data with third parties not involved in care.

The documentation you must hold

DocumentWhat it is forApplies to a solo practice?
Record of processing activitiesDescribes what data you process, why, and how long you keep itYes — the size exemption does not cover health data
Privacy information noticeMeets Articles 13 and 14: who you are, why you process, what rights applyYes
Separate consentsCovers non-care usesYes, if you do marketing or public content
Processor agreementGoverns vendors that access data on your behalfYes, with every vendor
Risk analysisJustifies the safeguards you choseYes
Data protection impact assessmentRequired for high-risk large-scale processingUsually not for a solo practice
The Article 30(5) exemption for organisations under 250 employees does not apply when special categories of data are processed — which is your case.

Your vendors count too

Any service processing your clients’ data on your behalf is a processor and needs an Article 28 contract: the practice management software, the payment gateway, email, cloud storage, the video-call tool. A vendor being large and well known is not enough; you need the contract and you need to know where the data lives.

  • Ask each vendor for their data processing agreement before signing up.
  • Check whether there are international transfers and what safeguards cover them.
  • Keep the vendor list current: it is part of your record of processing activities.
  • When you stop using a vendor, verify data is returned or deleted.

Reasonable minimum safeguards

  • Individual credentials for every person who touches the data — never a shared login.
  • Second-factor authentication on anything holding clinical records.
  • Disk encryption on laptops and on any mobile device used to view data.
  • Backups with restoration actually tested, not merely scheduled.
  • Automatic session lock in the consultation room.
  • Access revoked the same day someone stops working with you.
  • Documents sent over channels that do not leave the file reachable by public link.

If there is a breach

For a security breach posing a risk to clients’ rights, you have 72 hours to notify the AEPD from becoming aware of it. Where the risk is high, affected people must be told as well. Losing an unencrypted laptop holding clinical records is a notifiable breach; the same laptop encrypted generally is not.

Client rights

Access, rectification, erasure, restriction, portability, and objection. You have one month to respond, extendable to three for complex cases. The point that causes most confusion: the right to erasure does not cancel the duty to retain the clinical record. Faced with a deletion request, delete what is not subject to a legal obligation, block the rest, and explain that to the client in writing.

Frequently asked questions

Do I need a data protection officer?

A solo practice normally does not reach the large-scale processing threshold that triggers the requirement. A centre with several professionals and high volume should assess it case by case.

Can I use WhatsApp with clients?

It is widely used and not prohibited, but keep it to logistics (reminders, confirmations) rather than clinical content, tell clients you use that channel, and do not leave sensitive documents stored there.

What if I work from home?

The obligations are identical. What changes is the risk analysis: you must account for third-party access to the home, the domestic network, and shared devices.

Is my website privacy policy enough?

It covers the website, not the practice. Processing clinical records needs its own privacy information and its own record of processing activities.

This guide is informational and is not legal advice. Check the regulations in force in your country and consult a professional if in doubt.

Next step

Take clinical nutrition to the next level with Almendra

Design plans, manage clients, and automate follow-ups in a single platform.

Get started for free
We use cookies
These cookies help us keep the page secure, give you a better experience, and show you more relevant advertising. We won't turn them on unless you agree.

Read more on our Privacy policy