By Clara Team
GDPR for Psychologists in Spain: A Practical Checklist
Records held by a psychology practice can contain health data, information about sexual life or orientation, beliefs, and other highly sensitive details. The GDPR, Spain's LOPDGDD, and applicable healthcare and regional rules all need to be considered.
This checklist is written for practices in Spain. It is educational information, not a determination of which legal or healthcare rules apply to a particular service.
A quick checklist for a psychology practice
- Map each processing activity: clinical record, scheduling, billing, forms, video calls, recording, transcription, and note generation.
- Identify the purpose, an Article 6 basis, and an Article 9 condition where special-category data is involved.
- Give the person clear information before collecting or using their data.
- Collect only what is necessary for the defined clinical or administrative purpose.
- Record which providers access data and put an Article 28 agreement in place where they act as processors.
- Check locations, subprocessors, and the relevant mechanism for any international transfer.
- Set retention rules by information category rather than applying one period to everything.
- Protect access, devices, backups, exports, and deletion.
- Define how rights requests and personal-data breaches will be handled.
- Assess whether the processing is likely to create high risk and requires a data protection impact assessment.
What needs special protection
Health data is special-category data. A note, transcript, or recording can also reveal other protected information even when the clinician did not explicitly request it.
Classification depends on content and context, not the filename. An appointment diary may reveal that someone receives psychological care. A follow-up email may contain symptoms. A receipt may connect identity with a health service.
Controller, processor, and provider
In private practice, the professional or practice usually determines why and how practice data is processed and therefore commonly acts as controller. A provider processing data on those instructions may act as processor.
Article 28 requires that relationship to be documented. Before adopting a service, check:
- What data it receives and for which purposes.
- Whether it uses data for purposes of its own.
- Which subprocessors are involved.
- Where data is processed and stored.
- How it supports rights, incidents, export, and deletion.
- What happens when the service ends.
Spain's data protection authority explains the minimum content of processor agreements.
Legal basis depends on the specific processing
Processing special-category data requires an Article 6 basis and an applicable Article 9 exception or condition. Article 9(2)(h) may be relevant to healthcare delivered by professionals bound by professional secrecy, but it is not an automatic answer for every psychologist, service, or purpose.
Explicit consent may be appropriate for some activities. Other activities may rely on healthcare provision, legal obligations, or another basis recognized by law. Recording a session, transcribing it, and maintaining the clinical record are not necessarily the same processing operation and do not automatically share one basis.
The decision should be documented against the professional context, purpose, and applicable law. The AEPD guide for healthcare professionals explores controller and processor responsibilities in this setting.
What to explain to the person
A privacy notice should make it possible to understand:
- who the controller is;
- what information is collected and why;
- the applicable legal basis;
- who may receive the information;
- whether international transfers take place;
- how long information is kept or how the period is decided;
- which rights can be exercised and how;
- whether AI is used to prepare transcripts or drafts;
- whether recording occurs, what happens to the audio, and when it is deleted.
Therapeutic consent, privacy information, and any specific permission required for recording serve different purposes. They should not be hidden inside one generic checkbox.
Using AI for transcripts or note drafts
An AI service introduces practical questions:
- Is audio necessary, or could another input be used?
- Are the transcript and note draft retained separately?
- Is clinical information used to train models?
- Can the clinician correct the output before it enters the record?
- What information from previous sessions is used?
- How are audio, transcript, note, and recovery copies deleted?
- Can the record be exported in a usable format?
Accuracy is also a data-protection principle. An automatically generated note should remain a draft until it has been reviewed. If the overall processing may create high risk, assess whether a data protection impact assessment is required.
Location and international transfers
It is too broad to say that personal data can never leave the EEA. GDPR permits certain international transfers through adequacy decisions or recognized safeguards such as standard contractual clauses, subject to the applicable conditions.
The practical question is not only where the primary server is located. It also includes which providers and subprocessors can access data, from where, and under which mechanism. The European Commission explains the available transfer mechanisms.
Retention and deletion
There is no single retention period for every item in a practice. Where Spain's Law 41/2002 applies, Article 17 establishes a minimum of five years from discharge for clinical documentation, without excluding other purposes or regional rules that may require different periods.
Scheduling, billing, consent records, temporary audio, transcripts, and clinical notes may answer to different obligations. Define a period for each category and what follows: secure deletion, valid anonymisation, restriction where required, or justified retention.
The right to erasure does not automatically require deletion of every part of a clinical record. Retention obligations and other GDPR grounds may limit it. A response should explain what can be erased, what must remain, and why.
Security and personal-data breaches
Controls should match the actual risk. Basic questions include encryption in transit and at rest, authentication, access control, device protection, backups, activity records, and recovery procedures.
When a breach occurs, contain it, document it, and assess the risk. Where notification to the authority is required, GDPR says it should be made without undue delay and, where feasible, within 72 hours after the controller becomes aware. Communication to affected people depends in part on the level of risk. The AEPD provides breach assessment guidance.
Test a tool before using real client information
Start with a fictional case and complete the entire workflow:
- Create a record and note which fields are mandatory.
- Generate a transcript and a note draft.
- Correct an attribution or interpretation.
- Export the information.
- Delete the session and confirm what remains.
- Review the processor agreement, subprocessors, and retention policy.
Our clinical notes software comparison and AI notes security guide turn these questions into a practical evaluation.
How Clara approaches these questions
Clara encrypts data in transit and at rest. Its primary infrastructure is hosted in the EU, and contracted providers process the information needed to deliver the service. Clinical data is not used to train models. Session audio may remain securely on the server for up to 14 days after processing and is then deleted. A local recovery copy from an interrupted browser recording may remain on the device for up to 7 days, or be removed sooner after recovery or manual deletion.
Clara prepares an editable draft. The clinician decides what to correct and when the record represents their clinical work. See AI clinical notes with Clara or try Clara free.