Dominican Republic — ANX-CAC §DO: Central America and Caribbean Annex, Dominican Republic Section
Document ID: ANX-CAC §DO · Version: 1.0 · Effective date: [[TO CONFIRM: publication date]]
Language: Spanish controls (es/annex-do.md). This English text is a convenience translation.
Applies to: Clinics established in the Dominican Republic. Part of the Master Data Processing Agreement (the "MDPA"). Terms defined in the MDPA have the same meaning here.
1. Legal framework and roles
This Section governs the processing of Clinic Data by:
- VstreamX, as encargado del tratamiento (processor); and
- the Clinic, as responsable del archivo, registro, base o banco de datos (controller).
It is made under Law 172-13 on the Comprehensive Protection of Personal Data (the "Law"). It also respects the right of habeas data under the Constitution of the Dominican Republic.
2. Processing on the Clinic's behalf; no assignment
2.1 Instructions and purpose. VstreamX processes the Clinic Data only:
- on the Clinic's instructions (MDPA clause 3); and
- for the purposes in MDPA Schedule 1 (MDPA clause 4).
2.2 No assignment. VstreamX does not assign (ceder) the Clinic Data to any third party, and does not communicate it except to the authorised Sub-processors (MDPA Schedule 3) or where the law requires (Law, Art. 28).
3. Secrecy
3.1 Who is bound. VstreamX, its personnel and its Sub-processors are bound by professional secrecy over the Clinic Data (Law, Arts. 5.6 and 78), including the health data of the Clinic's patients.
3.2 How long it lasts. That duty survives the end of the relationship with the Clinic (MDPA clause 5).
4. Security
VstreamX adopts the technical and organisational measures in MDPA Schedule 2. They guarantee the security and confidentiality of the data, and prevent its alteration, loss or unauthorised processing or access (Law, Art. 5.5).
5. International transfer
5.1 Hosting abroad is a transfer. Under Article 6.20 of the Law, the communication of the Clinic Data to VstreamX in Canada, and to the Sub-processors in the United States and other countries, is an international transfer. This is so even though the recipients are encargados.
5.2 The basis for the transfer.
- Primary basis: consent. The transfer is made on the basis of the consent of each data subject (Law, Art. 80.1), which the Clinic obtains under clause 7.
- Subsidiary grounds. Where they apply, the exceptions in Article 80 of the Law support it in the alternative, including:
- the transfer is necessary for the provision of health care to the data subject (Art. 80.2); and
- the transfer is necessary for the performance of a contract between the data subject and the Clinic, or in the data subject's interest (Art. 80.6).
[[TO CONFIRM: the exact numbering of the Article 80 exceptions relied on]]
5.3 VstreamX's undertakings as recipient. VstreamX:
- applies to the Clinic Data the protections of this Section; and
- ensures that each Sub-processor applies equivalent protections.
6. Habeas data
VstreamX assists the Clinic within 5 business days (MDPA clause 8) to respond to data subjects exercising their rights of access, rectification, cancellation and blocking, and the right of habeas data. DentalX lets the Clinic access, rectify, cancel and block a patient's data itself.
7. Patients' consent and the Clinic's obligations
7.1 Consent before health data is entered. The Clinic obtains from each patient, before any of that patient's health data is entered into DentalX, an express, written consent to the processing of their health data (Law, Art. 76). That consent includes a separate line authorising the storage and processing of their data in the United States and in the other countries named in MDPA Schedule 3 (Law, Art. 80.1). DentalX enforces this with the consent gate in clause 7.2(b), so that the transfer never takes place without its basis. [[TO CONFIRM: Dominican counsel's opinion on relying instead on the health-care exception in Article 80 for the transfer; if counsel confirms it, a new version may relax the gate]]
7.2 DentalX's tools. DentalX provides:
- (a) a Spanish consent template with that separate line;
- (b) a consent gate: DentalX does not save health data for a patient until a signed consent with that separate line is on file. Before then, the Clinic can record only the patient's name, contact details and appointments, so that it can send the consent [[TO CONFIRM: counsel's view that this minimal record is covered by Article 80 or by the patient's own request for an appointment]];
- (c) storage and export of the signed consent; and
- (d) a template of the internal manual of policies and procedures that the Clinic must adopt (Law, Art. 13.5).
8. Security breaches
8.1 Notice to the Clinic. VstreamX notifies the Clinic within 24 hours of establishing a breach affecting the Clinic Data (MDPA clause 9).
8.2 Assistance. The Law sets no period for notification by the Clinic. VstreamX assists the Clinic with any notice the Clinic decides or is required to give.
9. Retention
DentalX does not delete clinical records automatically. The Clinic decides how long to keep them, in accordance with the health regulations. At the end of the service, the export allows the Clinic to keep them (MDPA clause 14).
10. Applicable law
The Law applies to the processing of the Clinic Data whatever law governs the commercial relationship under MDPA clause 23.
Items to confirm before publication (Dominican Republic)
- Publication date.
- The exact numbering of the Article 80 exceptions relied on (§5.2).
- Dominican counsel's opinion on the Article 80 health-care exception and the minimal pre-consent record (§7).