For a dermatology clinic, GDPR is not the paperwork you do after launching online consultations. It is a precondition for running them at all — because the most sensitive thing your patients send you, a clinical photograph, is special-category health data.
This guide covers what that means in practice, which obligations sit with the clinic rather than the software vendor, and the questions worth settling before a single case is submitted.
What counts as health data
Under Article 9 of the GDPR, data concerning health is a special category and carries stricter obligations than ordinary personal data. In a teledermatology service, the category covers more than you might expect:
- Clinical photographs submitted by the patient
- Structured intake questionnaires and history
- Secure messages between patient and clinician
- The clinical record of the consultation and its outcome
- Associated metadata — timestamps, device information, IP addresses
Controller or processor: know which one you are
In almost every setup, the clinic is the controller — you decide why and how patient data is processed. The platform vendor is a processor acting on your instructions. That distinction matters, because the controller carries the accountability.
Article 28 requires a written data processing agreement (DPA) between the two. If a vendor cannot produce one, that is a hard stop, regardless of what the marketing page claims. A signed DPA is the evidence; "we are GDPR-compliant" is not. Note too that a vendor is usually an independent controller for its own product analytics and marketing — which is what the sub-processor question in the checklist below should surface.
Lawful basis
Processing health data needs a basis under both Article 6 and Article 9. For care delivered by a regulated professional, clinics typically rely on Article 9(2)(h) — processing necessary for the provision of health care — rather than consent alone. That basis is not self-executing: it must be grounded in Union or Member State law, and Article 9(3) requires the data to be handled by, or under the responsibility of, someone bound by an obligation of professional secrecy. National derogations under Article 9(4) vary, so confirm the position in each market you operate in. Consent remains relevant for adjacent purposes such as marketing or using images for teaching, and those must be separable: a patient must be able to decline them without losing access to care.
Where the data lives
Establish where patient data is hosted and where any support staff access it from. EU or EEA hosting keeps this simple. Transfers outside that area need a valid mechanism — such as an adequacy decision, standard contractual clauses or binding corporate rules — documented rather than assumed, and standard clauses also call for a transfer impact assessment. Ask the vendor directly and get the answer in writing.
Retention
Medical record retention is set by national law, not by the platform, and those periods are usually long. Your obligations are to define the retention period, document it, apply it consistently, and be able to delete data when the period ends. A platform that cannot enforce a retention rule leaves you unable to comply.
Patient rights you must be able to satisfy
- Access: provide a copy of the record on request within one month, extendable by two further months for complex or numerous requests if you tell the patient inside the first month.
- Rectification: correct inaccurate personal details.
- Erasure: limited for clinical records held under a retention obligation — be able to explain why.
- Portability: applies where processing rests on consent or a contract, so generally NOT to care delivered under Article 9(2)(h) — but the ability to export in a structured, commonly used and machine-readable format is worth having regardless.
Each of these is far easier when records are centralised in one system than when photographs are scattered across email and phones.
Security expectations
Article 32 requires measures appropriate to the risk. For teledermatology that realistically means encryption in transit and at rest, role-based access so staff see only what their job requires, multi-factor authentication, an audit trail of who opened which case and when, and tested backups. Consumer messaging apps meet none of these requirements reliably, which is why informal photo sharing is a common weak point even in an otherwise careful clinic.
Breach notification
A personal data breach must be reported to your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it — unless it is unlikely to result in a risk to patients — and to the affected individuals where the risk is high. Decide in advance who makes that call, and confirm the vendor is contractually obliged to notify you without undue delay.
Documentation that regulators actually ask for
Two records do most of the work: a record of processing activities under Article 30, and a data protection impact assessment under Article 35. Large-scale processing of health data is exactly the scenario a DPIA is designed for, so most services operating at any meaningful volume will need one — check your supervisory authority's Article 35(4) list, since a single practitioner's processing is not automatically "large scale". Writing the assessment also forces useful decisions about retention, access and minimisation. Article 37 may additionally oblige you to appoint a data protection officer.
A short vendor checklist
- Will you sign a DPA, and what does it say about sub-processors?
- Where is data hosted, and under what transfer mechanism if outside the EEA?
- Can we configure retention, and export everything if we leave?
- What does the audit trail record, and for how long?
- What is your breach notification commitment to us?
If you are still mapping out how online consultations would work in your practice, start with what teledermatology is, then use the compliance questions above alongside the wider evaluation criteria in our guide to choosing teledermatology software.
iDerma is built for clinics operating under these obligations — ask us for the data processing agreement, hosting details and audit-trail specification as part of your own due diligence, exactly as you would of any vendor.
This article is general information, not legal advice. National implementations and supervisory-authority guidance differ — confirm your position with your data protection officer or regulator.






