Les DPO de la Santé
Insights

Making sense of digital-health compliance

Our articles and regulatory analyses — GDPR, HDS hosting, AI Act, NIS2, medical confidentiality — written by practising DPOs and checked against the official sources. Every article is available in English and in French.

Midnight-blue desk with newspapers, glasses and a keyboard
September 5, 20269 min read
Cybersecurity

A €500,000 fine: at Hôpital privé de la Loire, one account was all it took

An attacker used a doctor's credentials and exfiltrated 524,867 patient records. The alert came not from any system detecting the extraction, but from a practitioner who could no longer log in. The CNIL's decision shows what must protect the data once the first barrier gives way.

August 7, 20266 min read
GDPR

GDPR sanctions and health data: seven decisions that draw the red line

From a doctor fined €3,000 to a group ordered to pay €5 million: a sourced review of the landmark decisions and their operational lessons for the sector.

August 2, 20264 min read
Artificial Intelligence

AI Act: August 2, 2026 was supposed to change everything — here is what actually applies

The AI Regulation was due to reach full application on August 2, 2026. But the Omnibus package voted by the European Parliament on June 16 reshuffled the deck for high-risk systems. An analysis for healthcare players.

July 20, 20264 min read
Regulation

Digital Omnibus: what the GDPR “simplification” changes (and does not change) for healthcare

A redefined notion of personal data, legitimate interest for AI training, cookies brought into the GDPR, a postponed AI Act: the Omnibus package is shaking up European digital law. Where things stand in summer 2026 for healthcare players.

July 5, 20264 min read
EHDS

EHDS: the European Health Data Space has entered into force — why to start preparing in 2026

The EHDS Regulation will apply in stages by the end of the decade: interoperable health records, patient access, regulated data reuse. Organizations that prepare now will gain a head start.

June 15, 20263 min read
HDS hosting

HDS v2: the May 16, 2026 deadline has passed — are your hosting providers still certified?

Since May 16, 2026, HDS certificates issued under the former v1.1 standard are no longer enough: every hosting provider had to migrate to the v2 standard. What every healthcare organization and software vendor must check, now.

May 28, 20264 min read
HDS hosting

Health data hosting (HDS): what you need to know in 2026

Who is subject to HDS certification, what obligations apply to software vendors and healthcare organizations, and how to frame a compliant hosting project.

May 12, 20264 min read
Artificial Intelligence

The AI Act and healthcare: what obligations for your AI systems?

Most AI systems in healthcare fall into the “high-risk” category. An overview of the obligations and of the right reflexes to adopt from the design stage.

April 21, 20264 min read
GDPR

CNIL inspections: how to prepare with confidence

An inspection cannot be improvised. The documents to keep up to date and the reflexes that make the difference on the day.

March 30, 20263 min read
Cybersecurity

The NIS2 Directive: what impact on the healthcare sector?

Healthcare is one of NIS2’s “highly critical” sectors. New cybersecurity and governance obligations to anticipate.

March 8, 20263 min read
Medical confidentiality

Medical confidentiality and the GDPR: two regimes to reconcile

Medical confidentiality and the GDPR pursue close but distinct objectives. How to reconcile them in day-to-day practice.

February 18, 20264 min read
GDPR

The record of processing activities: where to start?

The cornerstone of compliance, the record of processing activities is too often neglected. A method to build it and keep it alive.

Prefer to discuss it in English?

Book a call with our team: we work with international vendors, sponsors and healthcare organizations, and can walk you through any of these topics in English.

Response within 24 business hours · No obligation