Guides

GDPR for nutritionists: a 10-step compliance self-audit

A practical checklist for reviewing GDPR compliance in a nutrition practice in Spain: what document to produce at each step, in what order, and how to know it is right.

9 min read

This guide does not explain the GDPR: it audits it. Ten steps in the order worth doing them, each with a concrete deliverable. Complete all ten and you have the compliance folder an inspection would ask for.

If you are looking for why the GDPR requires all this, that is in the data protection guide for nutritionists in Spain. Here we go straight to execution: what you do, in what order, and what document you are left with.

The ten steps

#StepDeliverable
1Data inventoryA list of what data you hold, about whom, and where
2Processing mapEach purpose, separated, with its lawful basis
3Record of activitiesThe Article 30 document, signed and dated
4Privacy noticeThe text you give the client at the first visit
5Separate consentsDistinct forms per non-care purpose
6Vendor contractsA processor agreement for each service
7Risk analysisRisks identified and measures adopted
8Rights procedureHow you handle access, rectification, erasure
9Breach procedureWho detects, who decides, who is notified
10Annual reviewThe next review date, in the calendar

Step 1 · Data inventory

Before documenting anything you need to know what you hold. Walk mentally through a client’s full cycle and note everywhere their information ends up: the practice software, email, your phone, the cloud folder, the notebook on the desk, the old spreadsheet nobody deleted, the WhatsApp group. Two or three places that were not on the initial list almost always turn up.

Step 2 · Processing map

Separate the purposes. Seeing a client is not the same as sending them a newsletter, and each needs its own lawful basis. A minimum map for a practice:

  • Nutritional care — GDPR Article 9(2)(h).
  • Invoicing and tax obligations — legal obligation.
  • Appointment management and reminders — performance of a contract.
  • Marketing communications — consent.
  • Publishing cases or photographs — specific consent.

Step 3 · Record of activities

This is the Article 30 document and it is mandatory in your case: the exemption for organisations under 250 employees does not apply when special categories of data are processed. A table with one row per processing activity is enough, with these columns: purpose, categories of data subjects, categories of data, recipients, retention period, and safeguards.

Step 4 · Privacy notice

This is what the client reads or receives before you start processing their data. It must cover the controller’s identity, purposes and bases, recipients, retention, rights and how to exercise them, and the option to complain to the AEPD. Two levels work well: a short version on the first-visit form and the full text on your site.

Step 5 · Separate consents

One form per non-care purpose, each with an unticked box and a statement that it can be withdrawn at any time. Record which version each client signed and when: if you change the text, old consents still refer to the old text.

Step 6 · Vendor contracts

List every service that touches client data and obtain each one’s processor agreement. The ones almost always missing:

  • The practice management software.
  • The email provider.
  • The cloud storage where plan PDFs live.
  • The payment gateway.
  • The video-call tool.
  • Your accountant, if they access client data.
  • The e-signature service, if you use it for consents.

Step 7 · Risk analysis

A small practice does not need a formal methodology. Listing the realistic scenarios — lost laptop, improper access by a collaborator, sending to the wrong recipient, ransomware, vendor shutting down — and noting next to each what measure you have and what is missing is enough. What will be expected of you is having thought about the risk and acted, not a beautiful document.

Step 8 · Rights procedure

Write down which channel receives requests, how you verify the requester’s identity, who responds, and within what deadline. One month, extendable to three where justified. And decide the hard case in advance: what you answer to an erasure request when you are required to retain the clinical record.

Step 9 · Breach procedure

Seventy-two hours is not enough time to improvise. Put on one page: how a breach is detected, who assesses the risk, on what criteria you decide to notify, who notifies the AEPD, and who informs affected people where the risk is high. Document every breach, including those you decide not to notify, with the reason.

Step 10 · Annual review

Put a date in the calendar. At the review: check whether you have added new vendors, started new processing, left access active for people who no longer work with you, and whether retention periods are actually being applied. Most non-compliance comes not from never having done the work but from never having updated it.

Frequently asked questions

How long do the ten steps take?

For a solo practice, one to two days of work spread out, with step 6 depending most on others because you have to request documentation from each vendor.

Do I need to hire a consultancy?

A solo practice can complete this self-audit alone. External support makes more sense if you have several professionals, unusual processing, or doubts about the lawful basis for a specific use.

Does this work if I also see clients outside Spain?

The structure does, but each country adds its own requirements. If you practise in Latin America, review the corresponding country guide as well.

What if the audit turns up a compliance gap?

Fix it and record when you found it and what you did. Accountability values exactly that: identifying and remedying, not pretending there was never a problem.

This guide is informational and is not legal advice. Check the regulations in force in your country and consult a professional if in doubt.

Next step

Take clinical nutrition to the next level with Almendra

Design plans, manage clients, and automate follow-ups in a single platform.

Get started for free
We use cookies
These cookies help us keep the page secure, give you a better experience, and show you more relevant advertising. We won't turn them on unless you agree.

Read more on our Privacy policy