Health Data Protection and GDPR Compliance for Professionals
Health data is the most sensitive personal data under the GDPR. Discover all the obligations that apply to professionals in the sector in 2026.
Writer — Certyneo · About Certyneo

Health data occupies a special place in the European regulatory landscape. Qualified as data of a special category by the GDPR (Article 9), it is subject to a reinforced protection regime that applies to all professionals who process it: healthcare facilities, mutual societies, health software editors, laboratories, home care services, e-health and telemedicine actors. In 2026, the regulatory landscape has become even more complex — with the progressive entry into force of the European Health Data Space (EHDS), updated recommendations from the CNIL, and record-breaking sanctions handed down across the EU, compliance is no longer optional. This article describes, point by point, the applicable obligations and best practices to adopt in order to secure your processing activities.
What is health data under the GDPR?
The GDPR (Regulation No. 2016/679, Article 4 §15) defines health data as "personal data relating to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about the health status of that person".
A scope broader than it may appear
This definition encompasses much more than conventional medical records. It includes:
- Medical history, diagnoses, prescriptions and test results;
- Data collected by connected objects (smartwatches, glucose monitors, menstrual tracking applications);
- Administrative data that allows one to infer a person's health status (reimbursement rates, frequency of consultations);
- Social security numbers (NIR) when cross-referenced with medical information.
In France, the CNIL has clarified, notably in its reference decision on health data repositories (EDS), that the concept should be interpreted broadly. Thus, a simple photo revealing a visible disability or biometric data (iris scan) falls within the scope.
Why heightened protection?
The particular sensitivity of health data stems from its potential for discrimination. Disclosing someone's health status can affect their access to employment, insurance, credit or expose their privacy. The CNIL estimates that violations involving health data represented, in 2024, more than 36% of the notifications it received — the leading category of data breached.
Legal bases specific to health data processing
Article 9 §1 of the GDPR establishes a principle prohibiting the processing of special category data, with limited, enumerated exceptions. For healthcare professionals, the applicable legal bases are mainly:
Explicit consent (Art. 9 §2 a)
Consent must be free, specific, informed and unambiguous, expressed through a clear affirmative action. In the healthcare sector, this basis is often unsuitable for routine care (power imbalance between doctor and patient), but remains essential for treatments for research, marketing or use of consumer health applications.
Best practice 2026: use electronic signatures in healthcare to obtain patient consent in a traceable and timestamped manner, which facilitates proof in the event of an inspection.
Care and preventive medicine (Art. 9 §2 h)
This is the primary legal basis for healthcare professionals processing data in the context of a care relationship. It applies provided that the processing is carried out by — or under the responsibility of — a professional subject to medical confidentiality.
Public interest and research (Art. 9 §2 i and j)
Processing for purposes of public health (epidemic surveillance, pharmacovigilance) or scientific research may rely on these exceptions. In France, the Data Protection Act (Articles 65 to 68) and the decree governing the National Health Data System (SNDS) define the conditions for access.
Concrete obligations of data controllers
Whether it is a medical practice or a digital health solution editor, obligations are structured around five pillars.
1. The processing records (Art. 30)
Every data controller or processor must maintain a record documenting each processing: purpose, legal basis, data categories, retention periods, recipients, security measures. The CNIL requires that this record be kept up to date and readily presentable in the event of an inspection.
2. Data Protection Impact Assessment (DPIA / Art. 35)
Processing of health data on a large scale or for profiling purposes mandatorily requires a DPIA. The CNIL has published a list of processing activities subject to mandatory DPIA, including health data repositories, health status monitoring mobile applications and connected medical devices.
On the legal value of electronic documents in this context, service providers must ensure that their collection mechanisms meet evidentiary requirements.
3. The appointment of a Data Protection Officer (DPO)
The appointment of a DPO is mandatory for:
- Healthcare professionals organized in groups (hospitals, nursing homes, care facilities with more than 50 people);
- Mutual societies and health insurers;
- Health software editors processing data on a large scale.
Since 2024, the CNIL has strengthened its controls over the effective role of the DPO, notably verifying their actual independence and resources.
4. Information system security (Art. 32)
Technical and organizational measures must be proportionate to the risk. The CNIL notably recommends:
- End-to-end encryption of stored and in-transit data;
- Pseudonymization whenever the purpose allows;
- The implementation of strict access controls (multi-factor authentication);
- Regular backups tested and disconnected from the main network;
- A business continuity plan (BCP) specific to health data.
Since the entry into application of the NIS 2 Directive (transposed into French law by the Act of March 26, 2025), essential entities in the healthcare sector — including hospitals, medical device manufacturers and certain laboratories — are subject to even stricter cybersecurity requirements, with mandatory notification of major incidents to ANSSI within 24 hours.
5. Data breach notification (Art. 33 and 34)
Any health data breach must be notified to the CNIL within 72 hours of discovery. If the breach is likely to pose a high risk to the rights and freedoms of individuals, the affected patients must also be informed without undue delay.
In 2024, the CNIL imposed fines for late notification, reminding that responsiveness is itself a compliance obligation.
Health data hosting: a France-specific obligation
In France, the Act of January 26, 2016 (Art. L. 1111-8 of the Public Health Code) requires that personal health data be hosted by a certified HDS provider (Health Data Hosting provider). This certification, awarded by COFRAC-accredited bodies on the basis of ISO 27001 standard and the HDS reference framework of the National Digital Agency (ANS), covers six distinct activities.
Who is subject to HDS certification?
All actors who host, administer or operate information systems containing health data on behalf of third parties are subject to this requirement: cloud service providers, DMP editors (shared medical record), telemedicine platforms, and — since 2023 — consumer health app editors insofar as they retain identifying data.
The use of a certified HDS provider does not exempt the data controller from their own obligations: they must necessarily formalize a subprocessing contract compliant with Article 28 of the GDPR, detailing instructions given to the host, security guarantees and audit procedures.
The European Health Data Space (EHDS): what impact in 2026?
The EHDS regulation (adopted end of 2025 with initial provisions entering into application progressively through 2027) establishes a framework for cross-border access to health data for research, innovation and public health. For French professionals, two immediate impacts:
- The obligation to respect enhanced data portability rights (structured, machine-readable format) for patient files;
- The prohibition on processing primary health data for advertising targeting purposes, even with consent — a stricter restriction than GDPR alone.
These developments make it essential to update privacy policies and processor contracts before the end of 2026. For professionals using eIDAS-compliant electronic signature tools, the traceability of consents and authorizations constitutes a considerable advantage in demonstrating compliance during an audit.
Patient rights and exercise of GDPR rights
Patients have all GDPR rights (access, rectification, erasure, restriction, portability, opposition), with a few sectoral adjustments.
The right of access to health data
A patient may request access to their entire medical file (Art. L. 1111-7 CSP). The professional has a deadline of 8 days (48 hours for recent data, recent hospitalizations) and 2 months for older data. The CNIL and the Rights Defender have both sanctioned facilities that refused or delayed such requests.
The right to erasure and its limits
The "right to be forgotten" is governed by legal retention periods: 20 years for adult medical files, 28 years if the procedure was performed before reaching adulthood. These legal periods take precedence over any request for early erasure — the data controller must clearly explain this to the patient.
Managing rights requests through electronic channels
For facilities that have digitized their processes, rights exercise requests can be transmitted and handled via secure forms. The qualified electronic timestamping of requests and responses constitutes a best practice enabling proof of compliance with regulatory deadlines during a CNIL inspection.
Legal framework applicable to health data protection
Compliance by healthcare professionals and their technology partners rests on an articulation of European and national texts that must be mastered.
GDPR — Regulation (EU) No. 2016/679 of April 27, 2016: the cornerstone of the system, it qualifies health data as special category data (Art. 4 §15), prohibits its processing except for limited exceptions (Art. 9 §2), requires DPIA (Art. 35), DPO designation (Art. 37), breach notification (Art. 33-34) and proportionate security measures (Art. 32). The sanctions provided reach 20 million euros or 4% of annual worldwide turnover — the higher amount being retained.
Data Protection Act (Law No. 78-17 of January 6, 1978 as amended): transposing the GDPR into French law, it empowers the CNIL to adopt sector-specific referentials specific to health and defines the procedures for access to the SNDS.
Public Health Code — Art. L. 1111-7 and L. 1111-8: enshrine the patient's right of access to their medical file and the obligation to host data with a certified HDS provider.
HDS Reference Framework (Health Data Hosting Provider): published by the National Digital Health Agency (ANS), it defines six certification activities covering physical infrastructure, platforms and application software.
NIS 2 Directive — Directive (EU) 2022/2555, transposed into French law by the Act of March 26, 2025: subjects essential entities in the healthcare sector (hospitals treating more than 30,000 patients/year, medical device manufacturers class IIb and III, reference laboratories) to reinforced cybersecurity obligations, particularly notification to ANSSI within 24 hours in case of a significant incident, and implementation of incident response plans tested annually.
eIDAS Regulation No. 910/2014 and eIDAS 2.0 (Regulation (EU) 2024/1183): govern the legal value of electronic signatures used for consents, digitized medical acts and contracts with service providers. Advanced or qualified electronic signature is recommended for any act whose evidentiary value may be disputed.
EHDS Regulation (European Health Data Space Regulation, 2025): strengthens patient rights over their primary data and frames the use of secondary data for research, with the creation of health data access bodies in each Member State.
Concrete legal risks: beyond CNIL administrative fines, data controllers face liability actions (Art. 82 GDPR), criminal prosecution (Art. 226-17 of the Penal Code, maximum penalty of 5 years imprisonment and €300,000 fine for legal entities), and reputational damages whose economic impact often exceeds the fine amount itself.
Use cases: GDPR compliance and health data in practice
Scenario 1 — A group of private clinics managing approximately 1,200 beds
A group of intermediate-sized private clinics (approximately 1,200 beds spread across three sites) was handling patient consents on paper forms, stored in poorly secured physical filing cabinets. During an internal audit in preparation for a CNIL inspection, several gaps were identified: inability to quickly retrieve consent dating back more than two years, lack of traceability for consents related to medical video surveillance and transmission to third parties (insurers, referring physicians).
The management deployed a qualified electronic signature solution integrated with the hospital information system. Results measured at six months: the processing time for access requests to medical files fell from 14 to 4 business days (71% reduction), the time to retrieve consent dropped to under 2 minutes compared to an average of 45 minutes previously, and the group obtained HDS certification for the application layer.
Scenario 2 — An editor of telemedicine solutions for independent specialists
A company editing a remote consultation platform for independent specialists (approximately 4,000 active physician users) was exposed to a major risk: its servers were hosted with an American cloud provider without a contractual clause compliant with Article 28 of the GDPR, and without HDS certification. The platform was nonetheless collecting consultation reports, prescriptions and clinical photos.
After an impact assessment (DPIA) conducted with an external DPO, the company migrated to an HDS-certified host based in France, reviewed all processor contracts and integrated a timestamped informed consent mechanism before each consultation. It also implemented an internal incident notification procedure within 12 hours, enabling compliance with the regulatory 72-hour deadline to the CNIL. The cost of compliance was estimated at €180,000 — compared to the €400,000 fine imposed by the CNIL against a comparable actor in the sector the same year.
Scenario 3 — A network of independent pharmacies
A group of approximately forty independent pharmacies was using centralized management software processing prescription histories and loyalty data (linked to implicit health profiles). Without a designated DPO and without an up-to-date processing record, the group was unable to respond to a patient's rights exercise request within 30 days.
A compliance project spread over eight months made it possible to designate a shared DPO (a common and lawful solution for groups of SMEs), to document 23 distinct processing activities in the record, to review the retention period policy (loyalty data was retained for 10 years without justification), and to train all pharmacy staff on the right reflexes in case of a patient request or an inspector visit. The estimated ex-ante fine risk exceeded €150,000.
Frequently asked questions
Are health data collected by a mobile application subject to the GDPR?
Yes, as soon as the application collects data allowing one to infer a person's health status (heart rate, menstrual tracking, blood glucose, diet), this data constitutes health data within the meaning of Article 4 §15 of the GDPR. The editor is a data controller and must obtain explicit consent, host the data with an HDS-certified service provider and conduct a DPIA if the processing is on a large scale.
Must a self-employed physician designate a DPO?
No, the designation of a DPO is not mandatory for a self-employed physician practicing alone or in a small practice, except if processing involves health data on a large scale. However, this physician remains a data controller and must maintain a processing record, apply the data minimization principle and be able to respond to patient rights exercise requests within regulatory deadlines.
What sanctions can the CNIL impose in the event of a health data breach?
The CNIL has the power to impose administrative sanctions reaching 20 million euros or 4% of annual worldwide turnover, the higher amount being retained. Beyond the fine, it can issue a compliance order with penalty interest, or make the decision public. On the criminal side, Article 226-17 of the Penal Code provides for up to 5 years imprisonment and €300,000 fine for legal entities.
Is a processor (software, cloud) liable in the event of a health data leak?
Yes. The GDPR (Art. 28 and 82) establishes joint responsibility of the data controller and processor toward affected individuals. The processor is directly liable if it acted outside the instructions of the data controller or if it failed to comply with its own GDPR obligations. It is therefore essential to formalize a precise processor contract and to ensure that the host is HDS certified for health data.
Is HDS certification mandatory for all digital health actors?
HDS certification is mandatory for any service provider that hosts, administers or operates information systems containing personal health data on behalf of a third party. It therefore applies to cloud service providers, medical SaaS editors and telemedicine platforms. Conversely, a healthcare professional hosting their own data (without entrusting it to a third party) is not directly subject to this obligation, but remains bound by the security measures in Article 32 of the GDPR.
Conclusion
The protection of health data constitutes, in 2026, one of the most complex and closely monitored regulatory issues in the digital sector. Between the GDPR, the Data Protection Act, the HDS hosting obligation, the NIS 2 Directive and the emergence of the European Health Data Space, professionals must maintain ongoing monitoring and structure their compliance around five pillars: processing records, DPIA, DPO, technical security and management of patient rights.
Certyneo supports healthcare actors in the secure digitization of their processes: collection of timestamped consents, qualified electronic signature of contracts with service providers, evidentiary traceability of each act. Discover how our solution can strengthen your GDPR compliance by visiting our dedicated healthcare professionals space or by starting free on Certyneo.
Try Certyneo for free
Send your first signature envelope in under 5 minutes. 5 free envelopes per month, no credit card required.
Go deeper on the topic
Reference articles on this topic.
Go deeper on the topic
Our comprehensive guides to master electronic signatures.
Recommended articles
Deepen your knowledge with these related articles.

VAT 2026: calculation, declaration and new obligations for businesses
The VAT 2026 reform is changing the calculation and declaration rules for millions of French businesses. Master the new obligations before they apply to you.

EIRL vs SARL: Complete Comparison of Legal Status in 2026
Choosing between EIRL and SARL is a strategic decision that affects your assets, tax situation, and professional future. Discover the complete comparison for 2026.

SignRequest Alternative Electronic Signature | Certyneo
SignRequest alternatives are in demand after the Box acquisition. Discover how to choose a compliant e-signature platform that satisfies eIDAS, GDPR, and the ESIGN Act across 7 global markets.