TeledermatologyGDPR in Telemedicine: What Dermatology Clinics Must Get Right

GDPR in Telemedicine: What Dermatology Clinics Must Get Right in the Netherlands

Need an online dermatologist for gdpr in telemedicine in the Netherlands? iDerma's doctors review your photos and reply within 24 hours — from 49 €.

For a dermatology clinic, GDPR is not the paperwork you do after launching online consultations. It is a precondition for running them at all — because the most sensitive thing your patients send you, a clinical photograph, is special-category health data.

This guide covers what that means in practice, which obligations sit with the clinic rather than the software vendor, and the questions worth settling before a single case is submitted.

What counts as health data

Under Article 9 of the GDPR, data concerning health is a special category and carries stricter obligations than ordinary personal data. In a teledermatology service, the category covers more than you might expect:

  • Clinical photographs submitted by the patient
  • Structured intake questionnaires and history
  • Secure messages between patient and clinician
  • The clinical record of the consultation and its outcome
  • Associated metadata — timestamps, device information, IP addresses

Controller or processor: know which one you are

In almost every setup, the clinic is the controller — you decide why and how patient data is processed. The platform vendor is a processor acting on your instructions. That distinction matters, because the controller carries the accountability.

Article 28 requires a written data processing agreement (DPA) between the two. If a vendor cannot produce one, that is a hard stop, regardless of what the marketing page claims. A signed DPA is the evidence; "we are GDPR-compliant" is not. Note too that a vendor is usually an independent controller for its own product analytics and marketing — which is what the sub-processor question in the checklist below should surface.

Lawful basis

Processing health data needs a basis under both Article 6 and Article 9. For care delivered by a regulated professional, clinics typically rely on Article 9(2)(h) — processing necessary for the provision of health care — rather than consent alone. That basis is not self-executing: it must be grounded in Union or Member State law, and Article 9(3) requires the data to be handled by, or under the responsibility of, someone bound by an obligation of professional secrecy. National derogations under Article 9(4) vary, so confirm the position in each market you operate in. Consent remains relevant for adjacent purposes such as marketing or using images for teaching, and those must be separable: a patient must be able to decline them without losing access to care.

Where the data lives

Establish where patient data is hosted and where any support staff access it from. EU or EEA hosting keeps this simple. Transfers outside that area need a valid mechanism — such as an adequacy decision, standard contractual clauses or binding corporate rules — documented rather than assumed, and standard clauses also call for a transfer impact assessment. Ask the vendor directly and get the answer in writing.

Retention

Medical record retention is set by national law, not by the platform, and those periods are usually long. Your obligations are to define the retention period, document it, apply it consistently, and be able to delete data when the period ends. A platform that cannot enforce a retention rule leaves you unable to comply.

Patient rights you must be able to satisfy

  • Access: provide a copy of the record on request within one month, extendable by two further months for complex or numerous requests if you tell the patient inside the first month.
  • Rectification: correct inaccurate personal details.
  • Erasure: limited for clinical records held under a retention obligation — be able to explain why.
  • Portability: applies where processing rests on consent or a contract, so generally NOT to care delivered under Article 9(2)(h) — but the ability to export in a structured, commonly used and machine-readable format is worth having regardless.

Each of these is far easier when records are centralised in one system than when photographs are scattered across email and phones.

Security expectations

Article 32 requires measures appropriate to the risk. For teledermatology that realistically means encryption in transit and at rest, role-based access so staff see only what their job requires, multi-factor authentication, an audit trail of who opened which case and when, and tested backups. Consumer messaging apps meet none of these requirements reliably, which is why informal photo sharing is a common weak point even in an otherwise careful clinic.

Breach notification

A personal data breach must be reported to your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it — unless it is unlikely to result in a risk to patients — and to the affected individuals where the risk is high. Decide in advance who makes that call, and confirm the vendor is contractually obliged to notify you without undue delay.

Documentation that regulators actually ask for

Two records do most of the work: a record of processing activities under Article 30, and a data protection impact assessment under Article 35. Large-scale processing of health data is exactly the scenario a DPIA is designed for, so most services operating at any meaningful volume will need one — check your supervisory authority's Article 35(4) list, since a single practitioner's processing is not automatically "large scale". Writing the assessment also forces useful decisions about retention, access and minimisation. Article 37 may additionally oblige you to appoint a data protection officer.

A short vendor checklist

  1. Will you sign a DPA, and what does it say about sub-processors?
  2. Where is data hosted, and under what transfer mechanism if outside the EEA?
  3. Can we configure retention, and export everything if we leave?
  4. What does the audit trail record, and for how long?
  5. What is your breach notification commitment to us?

If you are still mapping out how online consultations would work in your practice, start with what teledermatology is, then use the compliance questions above alongside the wider evaluation criteria in our guide to choosing teledermatology software.

iDerma is built for clinics operating under these obligations — ask us for the data processing agreement, hosting details and audit-trail specification as part of your own due diligence, exactly as you would of any vendor.

This article is general information, not legal advice. National implementations and supervisory-authority guidance differ — confirm your position with your data protection officer or regulator.

Frequently asked questions

Are patient photographs really special-category data?
Yes. A clinical photograph submitted for dermatology care is data concerning health under Article 9 of the GDPR, which means stricter conditions than ordinary personal data — an appropriate lawful basis, tighter security, and defined retention.
Is the clinic or the software vendor responsible for compliance?
Both, but not equally. The clinic is normally the controller and carries accountability for how data is used; the vendor is a processor acting on the clinic's instructions. A written data processing agreement under Article 28 is required between them.
Do we need patient consent for every online consultation?
Not usually as the lawful basis. Clinics providing care through regulated professionals generally rely on Article 9(2)(h) rather than consent. Consent is still needed for separate purposes such as marketing or teaching use of images, and patients must be able to refuse those without losing access to care.
Can we host patient data outside the EU?
Only with a valid transfer mechanism, such as an adequacy decision or standard contractual clauses, and it must be documented. EU or EEA hosting avoids most of the question, which is why many clinics require it — but remember that remote access from outside the EEA, including vendor support staff, is itself a transfer.
Do we need a DPIA for teledermatology?
Often yes. Large-scale processing of health data is precisely the situation Article 35 targets, though a single practitioner's processing is not automatically large scale — check your supervisory authority's Article 35(4) list. Beyond compliance, the assessment is a practical way to settle retention periods, access rules and data minimisation before launch.
Still unsure?

A dermatologist writes a plan made for your skin.

Not another off-the-shelf cream — a certified specialist’s diagnosis and personal treatment plan, within 24 hours.

Start your consultation
Personal treatment plan
24h
Diagnosis
Treatment plan
Prescriptions
iDerma
Board-certified dermatologist

Article by

Anna Tunkeviča

Medical content reviewed by

Eglė Zinkevičienė(Dermatologist)

Our other articles

Side of the neck showing several skin tags and pigmented moles along the skin.

Skin tag removal: is it necessary and is it safe?

Skin tags are common benign skin growths that can appear on various parts of the body. Is removal necessary? When is treatment recommended and when is monitoring enough? This article explains the causes, risk factors, removal options, and safety considerations based on dermatological guidelines and current medical evidence.
Raised papilloma and two pigmented moles on the skin, common skin growths assessed during a dermatology consultation.

Mole removal: when is it really necessary?

Mole removal may be performed for cosmetic or medical reasons. This article explains when removal is truly necessary, which symptoms may indicate risk, and what modern dermatological treatment options are available.
A child's hand with dry, rough and reddened skin showing signs of atopic dermatitis on the hand.

Atopic dermatitis in children: causes, symptoms, and effective care

Atopic dermatitis in children causes dry, itchy skin and frequent flare-ups. Learn how to manage eczema, reduce irritation, and keep your child’s skin healthy.
Red, scaly and inflamed skin of atopic dermatitis on the forearm and wrist

Atopic dermatitis: how to recognize, treat, and care for your skin

Atopic dermatitis is a chronic skin condition causing dryness and itching. Learn about symptoms, triggers, and effective treatments for lasting relief.