The most common GDPR mistakes in a dental clinic
Many dental clinics operating in Portugal invest in software and in privacy notices, yet keep structural gaps in how they process health data. This article identifies frequent mistakes — without a checklist of miracle fixes — and points to what usually calls for legal attention.
The aim is informative: to help recognise points of risk. The concrete fix depends on each clinic's organisation, systems and documentation. For the framework of this practice area, see GDPR for dental clinics.
Relying only on consent at the reception desk
A recurring mistake is treating consent as a "universal key" for the clinical record. Health data are a special category. In many care-related contexts, processing may rest on other legal bases under the GDPR and applicable national law — and consent may be inappropriate or insufficient for certain purposes.
When consent is used unclearly, mixing clinical treatment, billing and marketing into the same document, the clinic loses transparency and weakens its legal basis. Separating purposes and giving each one a proper legal basis is, as a rule, sounder than a generic form signed in a hurry.
Suppliers without a processor agreement
Clinical management software, digital laboratories, email services, cloud storage, accounting and marketing providers can all process data on the clinic's behalf. Without an adequate processor agreement, the clinic is exposed — including as to instructions, security, sub-processing and data deletion.
Another misconception is assuming that "the supplier is well known in the market" removes the need for due diligence. The controller's responsibility includes choosing suppliers with adequate guarantees and documenting that relationship.
Shared access and lack of internal control
Shared credentials, screens visible at reception, open folders on shared drives, or sending radiographs through insecure channels are practical failures with legal impact. Health data require technical and organisational measures proportionate to the risk.
This is not about imposing disproportionate measures on a small clinic. It is about ensuring a coherent minimum: who can access what, with which profile, with what logging and with what training. Without that, the clinic will struggle to demonstrate compliance if questioned.
A website policy with no real inventory behind it
Publishing a privacy text copied from another site, without mapping the actual processing activities, creates a false sense of compliance. The accountability principle requires the clinic to be able to explain what it processes, for what purpose, on what legal basis and for how long — under the applicable legislation.
Without a Record of Processing Activities aligned with day-to-day practice, notices and procedures tend to drift away from reality. That drift is, in itself, a risk.
No plan for breaches and data-subject requests
When a laptop goes missing, an email is sent to the wrong recipient, or unauthorised access is detected, the clinic needs to know what to do in the first hours. The absence of an internal procedure delays the assessment of the incident and can jeopardise legal notification deadlines, where applicable.
The same applies to requests for access, rectification or objection. Without a defined channel and criteria, improvised responses create inconsistency. On responding to incidents, see also data breach in a clinic: what to do in the first 72 hours.
Confusing consultancy with the DPO role
Finally, clinics often look for "a DPO" when what is actually missing is an inventory, contracts, legal bases and an incident procedure. Appointing a Data Protection Officer, where mandatory, is a separate question from organising compliance. On that distinction, see does your dental clinic need a Data Protection Officer?.
Frequently asked questions
No. Consent may be relevant for certain purposes, but health data require an assessment of the appropriate legal basis. In many clinical contexts, other legal bases under the GDPR and national law may apply.
When a supplier processes personal data on behalf of the clinic, a processor agreement with the clauses required by the GDPR is generally necessary, together with an assessment of the supplier's reliability.
No. Informing data subjects is necessary, but compliance also includes a Record of Processing Activities, legal bases, security, contracts, training and the ability to respond to requests and incidents.
There is no single mistake that is the most serious for every clinic. In practice, the combination of poorly controlled access, suppliers without adequate contracts and the absence of an incident procedure tends to create elevated risk.
To learn more about the practice area of legal consultancy and GDPR audit for dental clinics, see the dedicated page or the firm's contact details.
Information note
The information on this page is general and informative. It does not replace legal consultation, nor does it remove the need to review the clinic's processing activities, systems and organisation. The firm provides legal consultancy and audit on data protection, with a written opinion; it does not act as Data Protection Officer.