What GDPR obligations do I have in a dental practice?

Q&A • GDPR

What GDPR obligations do I have in a dental practice?

A dental practice processes health data — precisely the category GDPR protects most strictly. The obligations are not settled with a form signed at the front desk: they require a list of processing activities, access control and evidence that you follow the rules.

Short answer

  1. Patients' medical data is a special category (art. 9 GDPR), so it requires stricter measures than ordinary data.
  2. You inform the patient, in writing and in plain language, what data you collect, why and for how long you keep it.
  3. You keep a register of processing activities and a legal basis for each one.
  4. You limit access by role and keep a log of accesses to patient records.
  5. You sign processing agreements with the suppliers that touch the data (software, dental lab, hosting).
  6. A security breach posing a risk to patients is notified to the authority within 72 hours.

The framework applicable in Romania

The base is Regulation (EU) 2016/679 (GDPR), supplemented in Romania by Law no. 190/2018. Health data falls under art. 9, which prohibits processing as a rule and allows it through exceptions — for a practice, typically the healthcare purpose. Law no. 46/2003 on patients' rights adds a confidentiality duty and the patient's right of access to their own data. The supervisory authority is ANSPDCP. Retention periods for medical records come from health-sector regulations, not from GDPR — check them for your specialty; GDPR only says you cannot keep data forever "just in case".

What you put in practice, step by step

  1. Inventory the data: what you collect at the front desk, in the surgery, in billing, in marketing.
  2. Write the privacy notice, display it and hand it over at the first visit.
  3. Establish the basis for each processing activity — healthcare, legal obligation, consent for marketing.
  4. Configure roles and individual passwords; no shared "front desk" account.
  5. Sign processing agreements with the software provider, the dental lab and the hosting provider.
  6. Document the breach procedure: who detects it, who notifies, within what time.

Practical example

Example: the practice wants to send 6-month check-up reminders. A reminder tied to ongoing treatment rests on the healthcare purpose; a newsletter with teeth-whitening offers is marketing and needs separate, patient-ticked, revocable consent. In practice the two lists are kept distinct in the software, and unsubscribing from the newsletter does not stop the clinical reminder.

Common mistakes

  • A single user account used by the whole team — you cannot evidence who opened a record.
  • Asking consent for treatment where the basis is healthcare, and forgetting it where it is needed (marketing).
  • Sending results or treatment plans over insecure channels.
  • Having no processing agreement with the software provider or the dental lab.
  • Keeping data "just in case", with no established retention period.

How 4dental helps

  • Individual accounts and role-based access, separating the front desk from clinical data.
  • Hosting, in-transit encryption and automatic backups included, with no server in the practice.
  • Separate lists for clinical reminders and for marketing communications.
  • Documents and consents kept in the patient record, not in parallel folders.
4b2b.net
Business Ecosystem
4conta.ro
Accounting
4invoices.net
Invoicing App
4expenses.net
Expense Management
4notify.net
Notifications
4hosting.net
Hosting
4database.net
Databases
4buildsite.net
Website Builder
4myapp.net
App Builder
4avatars.net
AI Avatars
4chaty.net
AI Chatbot
4webagency.net
Web Agency Software
4softedu.net
Education Websites
4softcrm.net
CRM Platform
4softerp.net
ERP System
4softhr.net
HR Management
4mystaff.net
Staff Portal
4myprojects.net
Project Manager
4mycontracts.net
Contracts
4docs.net
Document Management
4appointments.net
Appointments
4marketingonline.net
Marketing
4insurance.net
Insurance
4property.net
Real Estate
4lawyers.net
Legal Software
4mygarage.net
Auto Service
4driving.net
Driving Schools
4fleet.net
Fleet Management
4myevents.net
Events
4therapy.net
Therapy
4clinics.net
Clinics
4dental.net
Dental Practices
4restaurants.net
Restaurants
4beautify.net
Beauty Salon
4gym.net
Fitness Gyms
4guards.net
Security Companies
4construct.net
Construction Companies
4marketplace.net
Marketplace
4shopy.net
Online Store
4pricing.net
Price Comparison
4salefood.net
Food Delivery
4rentify.net
Rentals
4transports.net
Transport
4agencytravel.net
Travel Agency
4hotel.net
Hotel Management
4ong.net
NGO Management
What GDPR obligations do I have in a dental practice? | 4dental