Audit
Mapping of processing activities, data flows, legal bases, suppliers and existing security measures.
Dental clinics operating in Portugal process health data — a special category of data subject to enhanced protection. This practice area describes legal consultancy and audit on data protection under Portuguese law, with a written legal opinion. It does not include acting as Data Protection Officer (DPO).
Day to day, a dental clinic processes patient identification, clinical records, radiographs, treatment plans, billing and communications. Where those data reveal information about health, they fall within the special category under Article 9 of the GDPR, with stricter rules on lawfulness, security and accountability.
In Portugal, the framework combines the General Data Protection Regulation with Lei n.º 58/2019 (the Portuguese data protection act) and other applicable legislation. The principle of accountability requires the controller to be able to demonstrate compliance — it is not enough to say that the clinic “has a privacy policy”.
For clinics and oral healthcare providers, the practical questions are usually: what processing takes place, on what legal basis, which suppliers are involved, what risks arise, and what documentation supports the decisions taken.
Legal support is usually organised in stages. Each clinic starts from a different point; the concrete scope is fixed after an initial assessment.
Mapping of processing activities, data flows, legal bases, suppliers and existing security measures.
A written document with findings, material legal risks and a reasoned opinion on the state of compliance.
Prioritisation of corrective and preventive measures, in a practical order suited to the size of the clinic.
A session for the team on good practice in processing patient data and handling incidents.
Limited support on document reviews, data-subject requests or incidents, without acting as Data Protection Officer.
Depending on the agreed scope, the clinic may receive working documentation and legal guidance, for example:
Deliverables describe the legal work performed; they are not a “commercial package” and do not replace the controller’s own responsibility.
Not every clinic is required to appoint a Data Protection Officer. The obligation depends, in general terms, on the nature, scale and context of the processing. This page describes legal consultancy and audit with a written opinion; the firm does not act as Data Protection Officer (DPO).
Not always. Health data are a special category. In many clinical contexts, processing may rest on other legal bases under the GDPR and applicable national law, not only on consent. The appropriate basis must be assessed case by case.
A personal data breach is, in general terms, a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In certain cases there may be an obligation to notify the Portuguese data protection authority (CNPD) without undue delay and, where applicable, within 72 hours of becoming aware of the incident, under the GDPR.
No. The service consists of legal consultancy and audit, with a written opinion and, where requested, an action plan, training or limited legal follow-up. It does not include acting as Data Protection Officer.
As a rule, it is useful to gather an inventory of processing activities, privacy notices, contracts with processors, internal procedures and incident records, if any. The concrete documentation depends on the organisation and the systems in use.
No. The text is general and informative. Assessing a specific clinic requires knowledge of its processing activities, systems, contracts and organisational context.
To learn more about this practice area or to request a legal consultation on the clinic’s situation, use the firm’s contact details or the consultation request form available on this site.
Submitting an initial request does not, by itself, create a lawyer–client relationship or replace a legal consultation.
This page is informative. It does not replace legal consultation, does not remove the need to review the documents, and does not promise any outcome. The firm provides legal consultancy and audit on data protection, with a written opinion; it does not act as Data Protection Officer. Concrete action depends on the facts, the documentation, conflict-of-interest checks and acceptance of a mandate.