Health Data Protection and GDPR Compliance for Healthcare Professionals
Health data represents the most sensitive personal information under the GDPR. Discover all the obligations that apply to healthcare sector professionals in 2026.
Writer — Certyneo · About Certyneo

Health data occupies a unique position within the European regulatory landscape. Classified as data in a special category under the GDPR (Article 9), it is subject to enhanced protection requirements that apply to all professionals processing it: healthcare facilities, mutual societies, health software editors, laboratories, home care services, digital health and telemedicine providers. In 2026, the regulatory environment has become even more complex — with the phased implementation of the European Health Data Space (EHDS), updated CNIL recommendations, and record-breaking penalties issued across the EU, compliance is no longer optional. This article outlines, point by point, the applicable obligations and best practices for securing your data processing operations.
What is Health Data Under the GDPR?
The GDPR (Regulation No. 2016/679, Article 4 §15) defines health data as "personal data relating to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about the state of health of that person".
A broader scope than it might appear
This definition encompasses far more than traditional medical records. It covers:
- Medical history, diagnoses, prescriptions and test results;
- Data collected by connected devices (smartwatches, glucose monitors, menstrual tracking applications);
- Administrative data that may reveal health status (reimbursement rates, consultation frequency);
- Social security identification numbers (NIR) when cross-referenced with medical information.
In France, the CNIL has clarified, particularly in its key decision on health data repositories (EDS), that the definition should be interpreted broadly. For example, a photograph revealing a visible disability or biometric data (retinal scan) fall within its scope.
Why strengthened protection?
The particular sensitivity of health data stems from its potential for discrimination. Revealing a person's health status could affect their access to employment, insurance, credit or expose their privacy. The CNIL estimates that in 2024, violations involving health data represented over 36% of notifications it received — making it the leading category of compromised data.
The specific legal bases for processing health data
Article 9 §1 of the GDPR establishes a principle prohibiting the processing of sensitive data, subject to a limited number of exceptions. For healthcare professionals, the main applicable legal bases are:
Explicit consent (Art. 9 §2 a)
Consent must be freely given, specific, informed and unambiguous, expressed through a clear affirmative action. In the healthcare sector, this basis is often unsuitable for routine care (due to the power imbalance between doctor and patient), but remains essential for research, marketing or personal health applications.
Best practice in 2026: use electronic signatures in healthcare to collect patient consent in a traceable, timestamped manner, which simplifies proof during regulatory inspections.
Care and preventive medicine (Art. 9 §2 h)
This is the primary legal basis for healthcare professionals processing data within the scope of patient care. It applies provided the processing is carried out by — or under the responsibility of — a professional subject to medical confidentiality obligations.
Public interest and research (Art. 9 §2 i and j)
Processing for public health purposes (disease surveillance, pharmacovigilance) or scientific research may rely on these exceptions. In France, the Data Protection Act (Articles 65 to 68) and the decree governing the National Health Data System (SNDS) define the conditions for access.
Concrete obligations for data controllers
Whether a medical practice or a digital health solution editor, the obligations are structured around five pillars.
1. The processing register (Art. 30)
Every data controller and processor must maintain a register documenting each processing activity: purpose, legal basis, data categories, retention periods, recipients and security measures. The CNIL requires this register to be current and presentable without delay during an inspection.
2. Data protection impact assessment (DPIA / Art. 35)
Processing of health data on a large scale or for profiling purposes requires a mandatory DPIA. The CNIL has published a list of processing requiring DPIA, including health data repositories, health tracking mobile applications and connected medical devices.
Regarding the legal validity of electronic documents in this context, service providers must ensure that their collection mechanisms meet evidentiary requirements.
3. Designation of a Data Protection Officer (DPO)
Designation of a DPO is mandatory for:
- Healthcare professionals organised in groups (hospitals, care homes, healthcare structures with more than 50 staff);
- Mutual societies and health insurers;
- Health software editors processing data on a large scale.
Since 2024, the CNIL has stepped up inspections of the effectiveness of the DPO role, verifying in particular their actual independence and resources.
4. Information systems security (Art. 32)
Technical and organisational measures must be proportionate to the risk. The CNIL particularly recommends:
- End-to-end encryption of stored and transmitted data;
- Pseudonymisation whenever the purpose allows;
- Implementation of strict access controls (multi-factor authentication);
- Regular backups tested and disconnected from the main network;
- A business continuity plan (BCP) specific to health data.
Since the implementation of Directive NIS 2 (transposed into French law by the Act of 26 March 2025), the essential entities in the healthcare sector — including hospitals, medical device manufacturers and certain laboratories — are subject to even stricter cybersecurity requirements, with mandatory notification of major incidents to ANSSI within 24 hours.
5. Notification of data breaches (Art. 33 and 34)
Any breach of health data must be notified to the CNIL within 72 hours of discovery. If the breach is likely to pose a high risk to the rights and freedoms of individuals, affected patients must also be informed without undue delay.
In 2024, the CNIL imposed penalties for late notification, stressing that responsiveness is itself a compliance obligation.
Health data hosting: a France-specific requirement
In France, the Act of 26 January 2016 (Article L. 1111-8 of the Public Health Code) requires that personal health data be hosted by a certified HDS provider (Health Data Hosting Provider). This certification, issued by COFRAC-accredited bodies on the basis of ISO 27001 standard and the HDS reference framework from the National Digital Health Agency (ANS), covers six distinct activities.
Who is subject to HDS certification?
All actors that host, administer or operate information systems containing health data on behalf of third parties are affected: cloud providers, shared medical record (DMP) editors, telemedicine platforms, and — since 2023 — personal health app editors insofar as they retain identifiable data.
Using a certified HDS provider does not relieve the data controller of their own obligations: they must imperatively formalise a processor contract compliant with Article 28 of the GDPR, detailing instructions given to the provider, security guarantees and audit arrangements.
The European Health Data Space (EHDS): what impact in 2026?
The EHDS Regulation (adopted in late 2025 with initial provisions coming into force progressively until 2027) establishes a framework for cross-border access to health data for research, innovation and public health. For French professionals, two immediate impacts:
- The obligation to respect enhanced portability rights (structured format, machine-readable) for patient records;
- The prohibition of processing primary health data for advertising targeting purposes, even with consent — a stricter restriction than the GDPR alone.
These developments make it essential to update privacy policies and processor contracts before the end of 2026. For professionals using electronic signatures compliant with eIDAS, the traceability of consents and authorisations represents a significant advantage in demonstrating compliance during an audit.
Patient rights and exercise of GDPR rights
Patients have all GDPR rights (access, rectification, erasure, restriction, portability, objection), subject to a few sectoral adjustments.
The right to access health data
A patient can request access to their entire medical record (Article L. 1111-7 CSP). The professional has 8 days (48 hours for recent data, recent hospitalisations) and 2 months for older data. Both the CNIL and the Ombudsman have sanctioned institutions refusing or delaying such requests.
The right to erasure and its limitations
The "right to be forgotten" is limited by statutory retention periods: 20 years for adult medical records, 28 years if the procedure was performed before the age of majority. These statutory periods take precedence over any early erasure request — the data controller must explain this clearly to the patient.
Managing requests through electronic channels
For institutions that have digitised their processes, rights requests can be submitted and processed via secure forms. The qualified electronic timestamping of requests and responses is a best practice allowing proof of compliance with regulatory timescales during a CNIL inspection.
Legal framework applicable to health data protection
The compliance of healthcare professionals and their technology partners rests on articulation of European and national legislation that must be mastered.
GDPR — Regulation (EU) No. 2016/679 of 27 April 2016: the cornerstone of the framework, it classifies health data as special category data (Art. 4 §15), prohibits its processing except for limited exceptions (Art. 9 §2), requires DPIA (Art. 35), DPO designation (Art. 37), breach notification (Art. 33-34) and proportionate security measures (Art. 32). Penalties reach 20 million euros or 4% of annual global turnover — whichever is higher.
Data Protection Act (Act No. 78-17 of 6 January 1978 as amended): transposing the GDPR into French law, it empowers the CNIL to adopt sectoral health-specific reference frameworks and defines conditions for SNDS access.
Public Health Code — Art. L. 1111-7 and L. 1111-8: guarantee the patient's right to access their medical record and the obligation to host data with a certified HDS provider.
HDS Reference Framework (Health Data Hosting Provider): published by the National Digital Health Agency (ANS), it defines six certification activities covering physical infrastructure, platform and application software.
Directive NIS 2 — Directive (EU) 2022/2555, transposed into French law by the Act of 26 March 2025: subjects essential entities in the healthcare sector (hospitals treating over 30,000 patients/year, medical device manufacturers class IIb and III, reference laboratories) to strengthened cybersecurity obligations, particularly notification to ANSSI within 24 hours in case of a significant incident, and implementation of annually tested incident response plans.
eIDAS Regulation No. 910/2014 and eIDAS 2.0 (Regulation (EU) 2024/1183): govern the legal validity of electronic signatures used for consents, digitised medical acts and contracts with service providers. Advanced or qualified electronic signatures are recommended for any act where evidential value could be disputed.
EHDS Regulation (European Health Data Space Regulation, 2025): strengthens patient rights over their primary data and regulates use of secondary data for research, with the creation of health data access bodies in each Member State.
Concrete legal risks: beyond CNIL administrative penalties, data controllers face civil liability actions (Art. 82 GDPR), criminal prosecution (Article 226-17 of the Criminal Code, maximum sentence of 5 years imprisonment and 300,000 € fine for legal entities), and reputational damage whose economic impact often exceeds the penalty amount itself.
Use scenarios: GDPR compliance and health data in practice
Scenario 1 — A group of private clinics managing approximately 1,200 beds
A group of intermediate-sized private clinics (approximately 1,200 beds across three sites) was managing patient consents on paper forms, stored in poorly secured filing cabinets. During an internal audit preparing for a CNIL inspection, several gaps were identified: inability to quickly retrieve a consent dated over two years earlier, lack of traceability for consents relating to medical video surveillance and transmissions to third parties (insurers, referring physicians).
Management deployed a qualified electronic signature solution integrated into the hospital information system. Results measured six months later: the average time to process medical record access requests dropped from 14 to 4 working days (a 71% reduction), the time to locate a consent fell to less than 2 minutes versus an average of 45 minutes previously, and the group obtained HDS certification for the application layer.
Scenario 2 — A telemedicine solution editor for independent specialists
A company developing a remote consultation platform for independent specialists (approximately 4,000 active physician users) faced a major risk: its servers were hosted by an American cloud provider without a processor contract compliant with Article 28 of the GDPR, and without HDS certification. The platform was nonetheless collecting consultation reports, prescriptions and clinical photographs.
Following an impact assessment (DPIA) conducted with an external DPO, the company migrated to a HDS-certified provider based in France, reviewed all its processor contracts and integrated a timestamped informed consent mechanism before each consultation. It also implemented an internal incident notification procedure within 12 hours, allowing compliance with the regulatory 72-hour deadline to the CNIL. The cost of achieving compliance was estimated at 180,000 € — compared to the 400,000 € penalty imposed by the CNIL against a comparable sector player the same year.
Scenario 3 — A network of independent pharmacies
A group of approximately forty independent pharmacies was using centralised management software processing prescription histories and loyalty data (linked to implicit health profiles). Without a designated DPO and without an updated processing register, the group was unable to respond to a patient's rights request within 30 days.
An eight-month compliance project made it possible to designate a shared DPO (a common and lawful solution for SME groups), document 23 distinct processing activities in the register, review retention duration policy (loyalty data was being kept for 10 years without justification), and train all pharmacy staff in proper procedures when faced with a patient request or regulatory inspection. The estimated ex-ante penalty risk exceeded 150,000 €.
Frequently asked questions
Is health data collected by a mobile application subject to the GDPR?
Yes, where the application collects data allowing inference of a person's health status (heart rate, menstrual tracking, blood glucose, diet), such data constitutes health data under Article 4 §15 of the GDPR. The editor is a data controller and must obtain explicit consent, host data with a HDS-certified provider and conduct a DPIA if processing is large-scale.
Must a self-employed physician designate a DPO?
No, DPO designation is not mandatory for a self-employed physician working alone or in a small practice, unless processing involves large-scale health data. However, such a physician remains a data controller and must maintain a processing register, apply the data minimisation principle and be able to respond to patient rights requests within regulatory timescales.
What sanctions can the CNIL impose in case of a health data breach?
The CNIL has administrative sanctioning power reaching 20 million euros or 4% of annual global turnover, whichever is higher. Beyond the fine, it may issue a compliance order with penalty interest or make the decision public. At the criminal level, Article 226-17 of the Criminal Code provides for up to 5 years imprisonment and 300,000 € fine for legal entities.
Is a processor (software, cloud) liable in case of health data leakage?
Yes. The GDPR (Art. 28 and 82) establishes joint liability of the data controller and processor towards data subjects. The processor is directly liable if it acted outside the controller's instructions or failed to meet its own GDPR obligations. It is therefore essential to formalise a precise processor contract and ensure the hosting provider is HDS-certified for health data.
Is HDS certification mandatory for all digital health actors?
HDS certification is mandatory for any provider that hosts, administers or operates information systems containing personal health data on behalf of a third party. It therefore applies to cloud providers, medical SaaS editors and telemedicine platforms. Conversely, a healthcare professional hosting their own data (without entrusting it to a third party) is not directly subject to this obligation, but remains bound by Article 32 GDPR security measures.
Conclusion
Health data protection constitutes, in 2026, one of the most complex and closely monitored regulatory challenges in the digital sector. Between the GDPR, the Data Protection Act, the HDS hosting obligation, Directive NIS 2 and the emergence of the European Health Data Space, professionals must maintain constant vigilance and structure their compliance around five pillars: processing register, DPIA, DPO, technical security and management of patient rights.
Certyneo supports healthcare actors in the secure digitisation of their processes: timestamped consent collection, qualified electronic signatures for contracts with service providers, evidentiary traceability of each action. Discover how our solution can strengthen your GDPR compliance by visiting our dedicated healthcare professionals section or by starting free on Certyneo.
Try Certyneo for free
Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.
Go deeper into this topic
Reference articles on this topic.
Go deeper into this topic
Our comprehensive guides to master electronic signatures.
Recommended articles
Deepen your knowledge with these related articles.

VAT 2026: calculation, declaration and new obligations for businesses
The VAT reform of 2026 overhauls the rules for calculation and declaration affecting millions of French businesses. Master the new obligations before they apply to you.

EIRL vs SARL: Complete Comparison of Legal Structures in 2026
Choosing between EIRL and SARL is a strategic decision that affects your assets, taxation and professional future. Discover the complete comparison for 2026.

Property Management Mandate and Electronic Signature: The 2026 Guide for Agents and Landlords
Electronic signature is revolutionising property management mandates by eliminating postal delays and unnecessary travel. Discover how agents and landlords can sign in full eIDAS compliance from 2026 onwards.