CRM for private clinics and health-data protection (Spain)
What a CRM or diary must meet in a private clinic: health data, provider contract, security, retention and fines, with the articles cited.
Héctor RedondoCEO and founder of BAI Business

Contents
- Health data is a special category
- Five things to check before you choose
- 1. Which health data goes into the tool
- 2. Contract with the provider
- 3. Security
- 4. Where the data is processed
- 5. Retention
- What non-compliance costs
- Where BAI fits and where it doesn't
- Frequently asked questions
- Is a patient's data a special category?
- Do I need a contract with my diary or CRM provider?
- How long must the clinical record be kept?
- How much can an infringement cost?
- You may also be interested in
- Sources
Health data is a special category: the GDPR prohibits processing it unless an exception applies, such as providing healthcare. A clinic choosing a diary or CRM must check five things: the legal basis, the contract with the provider, security, retention and which health data goes into the tool.
Reviewed on 2026-10-10. BAI Business offers a CRM and a diary and publishes this article. This guide does not replace the advice of a lawyer or of your data protection officer.
Health data is a special category
Article 9(1) of Regulation (EU) 2016/679 (GDPR) prohibits the processing of data concerning health, among others. Article 9(2) lists the circumstances in which the prohibition does not apply. Two are relevant for a clinic: that the data subject has given explicit consent (point a) and that the processing is necessary for the purposes of medical diagnosis or the provision of health care or treatment, on the basis of Union or Member State law or under a contract with a health professional (point h) (source: EUR-Lex, accessed on 2026-10-10).
Healthcare for the patient has its exception. What does not automatically have one is everything else done with their data: sending them advertising, for example, needs another legal basis.
Five things to check before you choose
1. Which health data goes into the tool
Decide what goes into the CRM or the diary and what stays in the clinical record. A diary can work with the name, the contact details and the time of the appointment without the clinical reason appearing. The less health data passes through the tool, the fewer reinforced obligations it carries.
2. Contract with the provider
If the provider of the diary or CRM processes your patients' data on your behalf, it is a processor. Article 28(3) of the GDPR requires processing by a processor to be governed by a contract or other legal act. Ask for it before you start and keep it.
3. Security
Article 32(1) of the GDPR obliges the controller and the processor to implement technical and organisational measures appropriate to the risk, which include, among others, the pseudonymisation and encryption of personal data (accessed on 2026-10-10). Ask the provider which measures it applies and how it controls who accesses what.
4. Where the data is processed
Article 44 of the GDPR only allows transfers of personal data to a third country if the controller and the processor comply with the conditions of the relevant chapter (accessed on 2026-10-10). Ask the provider where the data is hosted and who else processes it.
5. Retention
Article 17 of Law 41/2002 obliges healthcare centres to keep clinical documentation for at least five years from the date of discharge of each care process (source: BOE, accessed on 2026-10-10). The clinical record has its own system; the CRM or the diary do not replace it.
What non-compliance costs
Article 83(5) of the GDPR provides for fines of up to 20 million euros or, in the case of an undertaking, 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher, for infringements of the basic principles for processing, including the conditions of Article 9 (accessed on 2026-10-10). That is the maximum; the real amount depends on each case.
Where BAI fits and where it doesn't
BAI Business is a management platform for the self-employed and small businesses with CRM, diary and bookings, invoicing and receptionist. According to the sheet for its diary solution, your booking page counts your places and the customer receives a reminder of their appointment. You can see it on the online booking and diary page.
For a clinic, the question is which health data goes into the tool. BAI fits as a diary, contact record and communication; we do not describe here a clinical record or its retention, which belongs to a specific clinical program. Before taking on any provider, ours included, ask for the data processing contract and the security measures in writing.
Frequently asked questions
Is a patient's data a special category?
Yes. Article 9(1) of the GDPR prohibits the processing of data concerning health unless one of the exceptions in Article 9(2) applies, among them providing healthcare or treatment (point h) or explicit consent (point a).
Do I need a contract with my diary or CRM provider?
Yes. If the provider processes your patients' data on your behalf it is a processor, and Article 28(3) of the GDPR requires the processing to be governed by a contract or other legal act. Ask for it before you start.
How long must the clinical record be kept?
Article 17 of Law 41/2002 obliges healthcare centres to keep clinical documentation for at least five years from the discharge of each care process (accessed on 2026-10-10). A diary and communication CRM does not replace the clinical record.
How much can an infringement cost?
Infringements of the basic principles for processing, including those of Article 9, can be fined up to 20 million euros or 4% of worldwide annual turnover, according to Article 83(5) of the GDPR (accessed on 2026-10-10).
You may also be interested in
- GDPR for your small business: what customer data you can keep and for how long: the retention periods for customer data.
- Best diary and booking apps with CRM: comparison of booking apps.
Sources
- Regulation (EU) 2016/679 (GDPR), consolidated text, accessed on 10 October 2026.
- Law 41/2002, basic law on patient autonomy, BOE, accessed on 10 October 2026.
- Organic Law 3/2018 (LOPDGDD), BOE, accessed on 10 October 2026.
Keep reading
Customers and sales
CRM or ERP: differences and which one your SME needs
Differences between a CRM and an ERP, where they overlap, what Spain's INE says about their use and how to decide which to start with without overspending.
Customers and sales
What a CRM is and when your business needs one
What a CRM is, explained without jargon, how many companies use one according to Spain's INE, what it needs in an SME and when you do not need one.
Customers and sales
What an ERP is and when an SME needs one
What an ERP is, what it contains, how many companies use one according to Spain's INE and how to tell whether your SME needs one or something lighter.
