ComplianceGDPR

GDPR checklist for care homes in 2026

Thirty essential points for a care home to comply with GDPR and ENS Medium category without surprises.

OmiCare

Roles

  • Controller: care home management.
  • Processor: the software vendor.
  • Data Protection Officer (DPO): may be mandatory under GDPR Article 37 and applicable national law when legal criteria apply (e.g. large-scale processing of special categories of data). There is no automatic threshold by bed count; see your supervisory authority guidance.

Technical checklist

  1. AES-256-GCM encryption at rest and in transit.
  2. Immutable audit of every clinical access.
  3. Mandatory multi-factor authentication for privileged roles.
  4. Encrypted backups with verified quarterly restoration.
  5. Centralised logs with retention >= 12 months.
  6. No providers outside the EU in the production data path.

Organisational checklist

  1. Up-to-date record of processing activities (RoPA).
  2. Data Protection Impact Assessments (DPIA) for each new critical flow.
  3. Incident management policy with 72-hour deadline.
  4. Processor agreements signed with every vendor.
  5. Internal policies for rights management (access, rectification, erasure, restriction, portability, objection) with 30-day deadline.

Contractual checklist

  1. Standard EU clauses for sub-processors.
  2. Exit guarantee with data in standard format.
  3. Penalisable SLA for incidents without response.

Want to download it in Excel? Request it and we will adapt it to your centre.

Session of approximately 45 minutes. We review your facility's needs and answer functional, technical and security questions.

  • Walkthrough of your priority processes
  • Demonstration with relevant use cases
  • Identification of efficiency and improvement opportunities
  • Indicative scope for implementation, migration and integrations
  • Q&A session with a product specialist