CORREIA CRESPO ADVOGADOS

The most common GDPR mistakes in a dental clinic

Many dental clinics operating in Portugal invest in software and in privacy notices, yet keep structural gaps in how they process health data. This article identifies frequent mistakes — without a checklist of miracle fixes — and points to what usually calls for legal attention.

The aim is informative: to help recognise points of risk. The concrete fix depends on each clinic's organisation, systems and documentation. For the framework of this practice area, see GDPR for dental clinics.

Relying only on consent at the reception desk

A recurring mistake is treating consent as a "universal key" for the clinical record. Health data are a special category. In many care-related contexts, processing may rest on other legal bases under the GDPR and applicable national law — and consent may be inappropriate or insufficient for certain purposes.

When consent is used unclearly, mixing clinical treatment, billing and marketing into the same document, the clinic loses transparency and weakens its legal basis. Separating purposes and giving each one a proper legal basis is, as a rule, sounder than a generic form signed in a hurry.

Suppliers without a processor agreement

Clinical management software, digital laboratories, email services, cloud storage, accounting and marketing providers can all process data on the clinic's behalf. Without an adequate processor agreement, the clinic is exposed — including as to instructions, security, sub-processing and data deletion.

Another misconception is assuming that "the supplier is well known in the market" removes the need for due diligence. The controller's responsibility includes choosing suppliers with adequate guarantees and documenting that relationship.

Shared access and lack of internal control

Shared credentials, screens visible at reception, open folders on shared drives, or sending radiographs through insecure channels are practical failures with legal impact. Health data require technical and organisational measures proportionate to the risk.

This is not about imposing disproportionate measures on a small clinic. It is about ensuring a coherent minimum: who can access what, with which profile, with what logging and with what training. Without that, the clinic will struggle to demonstrate compliance if questioned.

A website policy with no real inventory behind it

Publishing a privacy text copied from another site, without mapping the actual processing activities, creates a false sense of compliance. The accountability principle requires the clinic to be able to explain what it processes, for what purpose, on what legal basis and for how long — under the applicable legislation.

Without a Record of Processing Activities aligned with day-to-day practice, notices and procedures tend to drift away from reality. That drift is, in itself, a risk.

No plan for breaches and data-subject requests

When a laptop goes missing, an email is sent to the wrong recipient, or unauthorised access is detected, the clinic needs to know what to do in the first hours. The absence of an internal procedure delays the assessment of the incident and can jeopardise legal notification deadlines, where applicable.

The same applies to requests for access, rectification or objection. Without a defined channel and criteria, improvised responses create inconsistency. On responding to incidents, see also data breach in a clinic: what to do in the first 72 hours.

Confusing consultancy with the DPO role

Finally, clinics often look for "a DPO" when what is actually missing is an inventory, contracts, legal bases and an incident procedure. Appointing a Data Protection Officer, where mandatory, is a separate question from organising compliance. On that distinction, see does your dental clinic need a Data Protection Officer?.

Frequently asked questions

To learn more about the practice area of legal consultancy and GDPR audit for dental clinics, see the dedicated page or the firm's contact details.

Related reading