Guides
GDPR for nutritionists: a 10-step compliance self-audit
A practical checklist for reviewing GDPR compliance in a nutrition practice in Spain: what document to produce at each step, in what order, and how to know it is right.
This guide does not explain the GDPR: it audits it. Ten steps in the order worth doing them, each with a concrete deliverable. Complete all ten and you have the compliance folder an inspection would ask for.
If you are looking for why the GDPR requires all this, that is in the data protection guide for nutritionists in Spain. Here we go straight to execution: what you do, in what order, and what document you are left with.
The ten steps
| # | Step | Deliverable |
|---|---|---|
| 1 | Data inventory | A list of what data you hold, about whom, and where |
| 2 | Processing map | Each purpose, separated, with its lawful basis |
| 3 | Record of activities | The Article 30 document, signed and dated |
| 4 | Privacy notice | The text you give the client at the first visit |
| 5 | Separate consents | Distinct forms per non-care purpose |
| 6 | Vendor contracts | A processor agreement for each service |
| 7 | Risk analysis | Risks identified and measures adopted |
| 8 | Rights procedure | How you handle access, rectification, erasure |
| 9 | Breach procedure | Who detects, who decides, who is notified |
| 10 | Annual review | The next review date, in the calendar |
Step 1 · Data inventory
Before documenting anything you need to know what you hold. Walk mentally through a client’s full cycle and note everywhere their information ends up: the practice software, email, your phone, the cloud folder, the notebook on the desk, the old spreadsheet nobody deleted, the WhatsApp group. Two or three places that were not on the initial list almost always turn up.
Step 2 · Processing map
Separate the purposes. Seeing a client is not the same as sending them a newsletter, and each needs its own lawful basis. A minimum map for a practice:
- Nutritional care — GDPR Article 9(2)(h).
- Invoicing and tax obligations — legal obligation.
- Appointment management and reminders — performance of a contract.
- Marketing communications — consent.
- Publishing cases or photographs — specific consent.
Step 3 · Record of activities
This is the Article 30 document and it is mandatory in your case: the exemption for organisations under 250 employees does not apply when special categories of data are processed. A table with one row per processing activity is enough, with these columns: purpose, categories of data subjects, categories of data, recipients, retention period, and safeguards.
Step 4 · Privacy notice
This is what the client reads or receives before you start processing their data. It must cover the controller’s identity, purposes and bases, recipients, retention, rights and how to exercise them, and the option to complain to the AEPD. Two levels work well: a short version on the first-visit form and the full text on your site.
Step 5 · Separate consents
One form per non-care purpose, each with an unticked box and a statement that it can be withdrawn at any time. Record which version each client signed and when: if you change the text, old consents still refer to the old text.
Step 6 · Vendor contracts
List every service that touches client data and obtain each one’s processor agreement. The ones almost always missing:
- The practice management software.
- The email provider.
- The cloud storage where plan PDFs live.
- The payment gateway.
- The video-call tool.
- Your accountant, if they access client data.
- The e-signature service, if you use it for consents.
Step 7 · Risk analysis
A small practice does not need a formal methodology. Listing the realistic scenarios — lost laptop, improper access by a collaborator, sending to the wrong recipient, ransomware, vendor shutting down — and noting next to each what measure you have and what is missing is enough. What will be expected of you is having thought about the risk and acted, not a beautiful document.
Step 8 · Rights procedure
Write down which channel receives requests, how you verify the requester’s identity, who responds, and within what deadline. One month, extendable to three where justified. And decide the hard case in advance: what you answer to an erasure request when you are required to retain the clinical record.
Step 9 · Breach procedure
Seventy-two hours is not enough time to improvise. Put on one page: how a breach is detected, who assesses the risk, on what criteria you decide to notify, who notifies the AEPD, and who informs affected people where the risk is high. Document every breach, including those you decide not to notify, with the reason.
Step 10 · Annual review
Put a date in the calendar. At the review: check whether you have added new vendors, started new processing, left access active for people who no longer work with you, and whether retention periods are actually being applied. Most non-compliance comes not from never having done the work but from never having updated it.
Frequently asked questions
How long do the ten steps take?
For a solo practice, one to two days of work spread out, with step 6 depending most on others because you have to request documentation from each vendor.
Do I need to hire a consultancy?
A solo practice can complete this self-audit alone. External support makes more sense if you have several professionals, unusual processing, or doubts about the lawful basis for a specific use.
Does this work if I also see clients outside Spain?
The structure does, but each country adds its own requirements. If you practise in Latin America, review the corresponding country guide as well.
What if the audit turns up a compliance gap?
Fix it and record when you found it and what you did. Accountability values exactly that: identifying and remedying, not pretending there was never a problem.
This guide is informational and is not legal advice. Check the regulations in force in your country and consult a professional if in doubt.
Next step
Take clinical nutrition to the next level with Almendra
Design plans, manage clients, and automate follow-ups in a single platform.