Medical data privacy by country
Medical data privacy in France.
France regulates where your records are stored as well as who reads them: the servers themselves must be certified. Ask the clinic which certified host it uses.
General information, checked against the law on 23 September 2026. For your own case, ask a lawyer in France.
What the law says
How France treats your health data.
- The regulator
- Commission nationale de l'informatique et des libertés (CNIL)[S108]
- Health data
- Health data is a special category under Article 9 of the GDPR. It may be processed only on a listed ground, such as your explicit consent or care by health professionals bound by secrecy.[S76]
- Sending it abroad
- Data moves freely within the European Economic Area. Leaving it needs an adequacy decision for the destination or other safeguards (GDPR Chapter V).[S76]
- Medical records
- Anyone hosting health data for patients, doctors or clinics must hold health data hosting (HDS) certification, under Article L1111-8 of the Public Health Code.[S108][S109]
- EU adequacy
- Not needed: as an EU member, the GDPR applies directly.[S76]
- If there is a breach
- Within 72 hours to the national authority where feasible, and to the people affected without undue delay when the risk to them is high (Articles 33 and 34).[S76]
- Fines
- Up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher (Article 83).[S76]
Questions
France: common questions.
Is it safe to email medical records to a clinic in France?
Email is protected between mail servers only when both providers support TLS, and it stays readable on each server afterwards. Once your records reach a clinic in France, local law applies: health data is a special category under Article 9 of the GDPR. It may be processed only on a listed ground, such as your explicit consent or care by health professionals bound by secrecy. For a full history, use a channel where you hold the key, such as a link that expires by itself.
How does France protect health data?
Health data is a special category under Article 9 of the GDPR. It may be processed only on a listed ground, such as your explicit consent or care by health professionals bound by secrecy. Breaches must be reported within 72 hours to the national authority where feasible, and to the people affected without undue delay when the risk to them is high (Articles 33 and 34). The regulator is the Commission nationale de l'informatique et des libertés (CNIL).
Can a clinic in France send my medical records abroad?
Data moves freely within the European Economic Area. Leaving it needs an adequacy decision for the destination or other safeguards (GDPR Chapter V). Anyone hosting health data for patients, doctors or clinics must hold health data hosting (HDS) certification, under Article L1111-8 of the Public Health Code.
Keep reading
More on France, and elsewhere.
- Is it safe to send your medical records to a clinic abroad?
- Medical data privacy in South Korea
- Medical data privacy in Turkey
- Medical data privacy in Thailand
- Medical data privacy in China
- Medical data privacy in Vietnam
- Medical data privacy in Indonesia
- Medical data privacy in United Kingdom
- Medical data privacy in Switzerland
- Medical data privacy in Germany
- Medical data privacy in Spain
- Medical data privacy in Hungary
Sources are numbered in the text and listed in full in the reference list.