What GDPR obligations do I have in a dental practice?
A dental practice processes health data — precisely the category GDPR protects most strictly. The obligations are not settled with a form signed at the front desk: they require a list of processing activities, access control and evidence that you follow the rules.
Short answer
- Patients' medical data is a special category (art. 9 GDPR), so it requires stricter measures than ordinary data.
- You inform the patient, in writing and in plain language, what data you collect, why and for how long you keep it.
- You keep a register of processing activities and a legal basis for each one.
- You limit access by role and keep a log of accesses to patient records.
- You sign processing agreements with the suppliers that touch the data (software, dental lab, hosting).
- A security breach posing a risk to patients is notified to the authority within 72 hours.
The framework applicable in Romania
The base is Regulation (EU) 2016/679 (GDPR), supplemented in Romania by Law no. 190/2018. Health data falls under art. 9, which prohibits processing as a rule and allows it through exceptions — for a practice, typically the healthcare purpose. Law no. 46/2003 on patients' rights adds a confidentiality duty and the patient's right of access to their own data. The supervisory authority is ANSPDCP. Retention periods for medical records come from health-sector regulations, not from GDPR — check them for your specialty; GDPR only says you cannot keep data forever "just in case".
What you put in practice, step by step
- Inventory the data: what you collect at the front desk, in the surgery, in billing, in marketing.
- Write the privacy notice, display it and hand it over at the first visit.
- Establish the basis for each processing activity — healthcare, legal obligation, consent for marketing.
- Configure roles and individual passwords; no shared "front desk" account.
- Sign processing agreements with the software provider, the dental lab and the hosting provider.
- Document the breach procedure: who detects it, who notifies, within what time.
Practical example
Example: the practice wants to send 6-month check-up reminders. A reminder tied to ongoing treatment rests on the healthcare purpose; a newsletter with teeth-whitening offers is marketing and needs separate, patient-ticked, revocable consent. In practice the two lists are kept distinct in the software, and unsubscribing from the newsletter does not stop the clinical reminder.
Common mistakes
- A single user account used by the whole team — you cannot evidence who opened a record.
- Asking consent for treatment where the basis is healthcare, and forgetting it where it is needed (marketing).
- Sending results or treatment plans over insecure channels.
- Having no processing agreement with the software provider or the dental lab.
- Keeping data "just in case", with no established retention period.
How 4dental helps
- Individual accounts and role-based access, separating the front desk from clinical data.
- Hosting, in-transit encryption and automatic backups included, with no server in the practice.
- Separate lists for clinical reminders and for marketing communications.
- Documents and consents kept in the patient record, not in parallel folders.