Informativo ⏱ 9 min read

GDPR for clinics in Spain: what you must have on your website

Clinics process special category health data under GDPR. What legal notice, privacy policy and forms you need to comply with regulations in 2026 and avoid AEPD sanctions.

Data protection document with stethoscope on medical consultation desk
Quick answer

Clinics process special category health data under GDPR, which requires a healthcare-specific legal notice, an adapted privacy policy, forms with double explicit consent, a compliant cookie banner and — if they regularly process data on more than 250 people — a Record of Processing Activities. Without these, the AEPD can impose fines of between 3,000 and 300,000 €.

Clinics have data protection obligations that are different from any other business. Not because there is more bureaucracy, but because health data is classified as a special category under the GDPR: it has its own legal framework, its own sanctions, and technical requirements that a generic website does not meet. And the AEPD knows it.

In this article I explain what your clinic's website must have to comply with regulations in 2026, what real sanctions are being imposed on clinics in Spain, and which specific mistakes mean a website «with a legal notice» is still non-compliant.

Why clinics have different obligations from other businesses

Article 9 of the GDPR classifies health data as a special category: information about a person's physical or mental health, including diagnoses, treatments and any data that reveals health information. When a patient fills in a form on your website indicating they have a knee injury or are seeking psychological treatment, you are already collecting special category data.

This is not a minor formality. Spain's LOPDGDD (Organic Law on Data Protection) adds further obligations for the healthcare sector on top of GDPR. Serious infringements in this area can reach 300,000 € for natural persons or up to 4% of annual global turnover for organisations.

How much has the AEPD fined clinics?

The AEPD has imposed fines on dental clinics, physiotherapy centres and private medical practices in recent years. Sanctions on small clinics typically range from 3,000 to 60,000 €. The most common reasons: web forms lacking explicit consent, data sharing without authorisation, and missing health-data-specific information clauses.

The 6 elements your website must have

1. Legal notice adapted to the healthcare sector

The standard legal notice generated by WordPress templates is not enough for a clinic. It must include the identity of the data controller for health data, the legal basis for processing (generally «performance of a healthcare services contract» or «explicit consent»), patient rights and how to exercise them, and the right to lodge a complaint with the AEPD.

2. Privacy policy for special category data

A generic privacy policy is not sufficient. A clinic's policy must explicitly state that health data is processed, the specific purpose (diagnosis, treatment, follow-up), the retention period for clinical records (minimum 5 years under Spain's Health Cohesion Act, though this varies by region), and any potential recipients of data if referrals or collaborations with other professionals exist.

3. Forms with double explicit consent

To collect health data, consent must be explicit and specific: a generic «I accept the privacy policy» tick box is not enough. First appointment or contact forms must include a separate tick box specifically for processing health data, distinct from any consent to commercial communications, with clear text explaining what data is collected and for what purpose.

4. Technically correct cookie banner

If your website uses Google Analytics, Meta pixels or any non-essential cookie, you need a consent banner that complies with AEPD guidelines: no pre-ticked accept button, with a reject option as prominent as the accept option, and no dark patterns that make rejection difficult. The AEPD's 2023 guidelines are explicit on this and have led to fines for non-compliant banners.

5. Record of Processing Activities

If your clinic processes data on more than 250 people, or regularly processes special category data — which applies to virtually any active clinic — you are required to maintain a Record of Processing Activities (RPA). This document is not public and does not go on your website, but the AEPD can request it at any inspection. Many clinics do not have one.

6. Appropriate technical security measures

GDPR requires «appropriate» security measures for the data processed. For health data this includes a valid HTTPS certificate, encrypted forms and databases, access control with strong passwords, and regular backups. A contact form that sends health data unencrypted is a direct infringement.

Does your clinic need a Data Protection Officer?

A DPO is mandatory for healthcare organisations that process data at large scale. In practice, small clinics with few professionals may not be required to appoint one, but specialist legal advice is recommended to determine this. Appointing a DPO voluntarily is not obligatory but is never harmful.

Common mistakes that leave your website non-compliant

Having «some legal notice» on your website does not mean GDPR compliance. These are the most common mistakes the AEPD finds on clinic websites:

  • Appointment booking forms that collect clinical information (symptoms, reason for visit) without explicit consent for health data processing.
  • Privacy policy copied from another website or AI-generated without adapting it to the actual health data processed.
  • Google Analytics active without a compliant cookie banner or without informing about analytical data processing.
  • Email or WhatsApp communications to patients without a documented legal basis for those communications.
  • Patient data stored in third-party cloud services (Google Drive, Dropbox) without a data processing agreement.

Frequently asked questions about GDPR for clinics

Can I use Google Forms to collect patient data?

Technically yes, but with conditions: Google Forms transfers data to Google servers (US), which requires an international data transfer with adequate safeguards. You must sign a data processing agreement with Google, explicitly inform the patient that their data is processed on Google servers, and obtain specific consent. In practice, most clinics do not meet these conditions when using third-party forms.

How often should I update my privacy policy?

Whenever you change the types of data you collect, the providers you share it with, the purposes of processing, or when there are relevant regulatory changes. At minimum, review it once a year. The date of the last update must be visible on the document.

Can I send promotional emails to my patients?

Only if you have their explicit and separate consent for commercial communications. Consent for health data processing does not automatically include consent to receive advertising. You need a specific opt-in for newsletters or promotional communications, separate from the healthcare consent.

What happens if a patient asks me to delete their data?

The right to erasure applies, but with an important exception in the healthcare sector: the clinical record must be retained for the minimum legal period (typically 5 years from the last clinical act), regardless of the patient's request. You can delete contact details and commercial communications, but not the clinical record itself.

Is there help to implement all this without being a lawyer?

Yes. There are consultancies specialising in GDPR for the healthcare sector that offer compliance packages for small clinics from 300-800 €. Additionally, many websites built by developers specialising in the sector already include adapted legal texts and forms with double consent correctly configured.

If you want to understand how GDPR affects the total budget of a clinic website, the article on clinic website prices in Granada explains what each price range includes and why legal compliance marks the difference between ranges.

🚀 Want to know what your business actually needs?

I'll give you a free, no-commitment consultation. No pressure, no selling you things you don't need. Write to me here →

Pablo Gómez Villén, Full Stack Developer

Written by

Pablo Gómez Villén

Full Stack Developer · Laravel, PHP, JavaScript

Full Stack Developer with over a year of production experience. Specialized in PHP (Laravel), JavaScript and MySQL. Shares learning and technical insights on this blog.

Contact

Book free meeting Request a quote

Before you go!

Let's work together

Tell me about your project or send me your offer, no commitment.
I respond in less than 24h.

Book a free call (20 min) Get a free quote
Call