Back to all lessons
Awareness Lessons
3 months ago

Dental Clinic Violates GDPR by Failing to Define Data Roles with Invisalign Provider

OÜ Dr Mõttus Hambaravi failed to establish and document whether it and Align Technology (Invisalign) acted as joint controllers or processor/controller in handling patient data, a fundamental GDPR requirement. Patients were not given adequate transparency or consent information about how their data was shared with a third-party technology vendor. This case highlights how healthcare providers frequently overlook the data governance implications of integrating commercial technology platforms into clinical workflows. The failure to define third-party data relationships is not merely a legal formality — it directly undermines patient rights to access, rectification, and erasure of their personal data.

Tactical Insight

Immediate actions

  • Conduct a data mapping exercise to identify all third-party vendors receiving patient data and classify each relationship as controller, processor, or joint controller.
  • Update patient consent forms and privacy notices to explicitly disclose data sharing with technology partners such as Invisalign/Align Technology.

Contractual & vendor management

  • Establish Data Processing Agreements (DPAs) or Joint Controller Agreements with every third-party vendor before sharing personal data.
  • Perform a GDPR Article 28 compliance review for all existing vendor contracts to ensure processor obligations are formally documented.

Long-term improvements

  • Implement a Third-Party Risk Management (TPRM) process that requires privacy impact assessments before onboarding any new clinical technology platform.
  • Schedule annual GDPR compliance audits covering data flows, consent mechanisms, and vendor role classifications.
  • Train clinical and administrative staff on recognising when new tools trigger data protection obligations.