Guides
Data protection for nutritionists in Spain: a practical guide
What the GDPR and the LOPDGDD require from a nutrition practice in Spain: lawful basis, health data, minimum safeguards, processors, and what to do after a breach.
The data you handle in practice — conditions, medication, body measurements — is a special category under the GDPR. That changes the lawful basis you need and the level of safeguards expected of you. This guide turns that into concrete decisions.
Two rules apply in Spain: the General Data Protection Regulation (Regulation EU 2016/679) and Organic Law 3/2018 (LOPDGDD), which implements it. The supervisory authority is the Spanish Data Protection Agency (AEPD).
Why your practice is a special case
Article 9 of the GDPR generally prohibits processing health data, then opens exceptions. Everything you record in a nutrition clinical record — diagnoses, medication, allergies, body composition tied to a health status — falls in that category. The practical consequence is twofold: you need an Article 9 exception to cover the processing, and the safeguards expected of you are higher than for a business handling only names and emails.
Which lawful basis to use
For care itself, the usual route is Article 9(2)(h): processing necessary for preventive medicine, medical diagnosis, or the provision of health care. That basis does not depend on consent and is more stable. Consent is still needed, separately, for everything that is not care:
- Sending marketing communications or newsletters.
- Publishing before-and-after photographs, even without a name.
- Using the case for teaching or public content.
- Sharing data with third parties not involved in care.
The documentation you must hold
| Document | What it is for | Applies to a solo practice? |
|---|---|---|
| Record of processing activities | Describes what data you process, why, and how long you keep it | Yes — the size exemption does not cover health data |
| Privacy information notice | Meets Articles 13 and 14: who you are, why you process, what rights apply | Yes |
| Separate consents | Covers non-care uses | Yes, if you do marketing or public content |
| Processor agreement | Governs vendors that access data on your behalf | Yes, with every vendor |
| Risk analysis | Justifies the safeguards you chose | Yes |
| Data protection impact assessment | Required for high-risk large-scale processing | Usually not for a solo practice |
Your vendors count too
Any service processing your clients’ data on your behalf is a processor and needs an Article 28 contract: the practice management software, the payment gateway, email, cloud storage, the video-call tool. A vendor being large and well known is not enough; you need the contract and you need to know where the data lives.
- Ask each vendor for their data processing agreement before signing up.
- Check whether there are international transfers and what safeguards cover them.
- Keep the vendor list current: it is part of your record of processing activities.
- When you stop using a vendor, verify data is returned or deleted.
Reasonable minimum safeguards
- Individual credentials for every person who touches the data — never a shared login.
- Second-factor authentication on anything holding clinical records.
- Disk encryption on laptops and on any mobile device used to view data.
- Backups with restoration actually tested, not merely scheduled.
- Automatic session lock in the consultation room.
- Access revoked the same day someone stops working with you.
- Documents sent over channels that do not leave the file reachable by public link.
If there is a breach
For a security breach posing a risk to clients’ rights, you have 72 hours to notify the AEPD from becoming aware of it. Where the risk is high, affected people must be told as well. Losing an unencrypted laptop holding clinical records is a notifiable breach; the same laptop encrypted generally is not.
Client rights
Access, rectification, erasure, restriction, portability, and objection. You have one month to respond, extendable to three for complex cases. The point that causes most confusion: the right to erasure does not cancel the duty to retain the clinical record. Faced with a deletion request, delete what is not subject to a legal obligation, block the rest, and explain that to the client in writing.
Frequently asked questions
Do I need a data protection officer?
A solo practice normally does not reach the large-scale processing threshold that triggers the requirement. A centre with several professionals and high volume should assess it case by case.
Can I use WhatsApp with clients?
It is widely used and not prohibited, but keep it to logistics (reminders, confirmations) rather than clinical content, tell clients you use that channel, and do not leave sensitive documents stored there.
What if I work from home?
The obligations are identical. What changes is the risk analysis: you must account for third-party access to the home, the domestic network, and shared devices.
Is my website privacy policy enough?
It covers the website, not the practice. Processing clinical records needs its own privacy information and its own record of processing activities.
This guide is informational and is not legal advice. Check the regulations in force in your country and consult a professional if in doubt.
Next step
Take clinical nutrition to the next level with Almendra
Design plans, manage clients, and automate follow-ups in a single platform.