Les DPO de la Santé
All articles
Medical confidentiality

Medical confidentiality and the GDPR: two regimes to reconcile

Les DPO de la SantéPublished Updated 3 min
Medical confidentiality and the GDPR: two regimes to reconcile

Medical confidentiality and the GDPR pursue close but distinct objectives. How to reconcile them in day-to-day practice.

Medical confidentiality protects the care relationship; the GDPR governs the processing of personal data. The two regimes overlap and must be reconciled with rigour.

In practice

Information sharing between professionals, the retention of records and patients’ access to their data are all points where the two regimes meet.

Two logics that must never be confused

Professional secrecy in healthcare (Article L.1110-4 of the French Public Health Code, enforced by criminal penalties) protects trust in the care relationship: it covers everything that has come to the professional’s knowledge — confidences, observations, deductions. The GDPR, for its part, governs the processing of data: lawfulness, minimization, security, data subject rights. The practical consequence is essential: “GDPR” consent does not release anyone from medical confidentiality, which can only be lifted under the exceptions provided by law; and conversely, scrupulously respecting confidentiality does not make you GDPR-compliant — you also need the legal basis, the information, the retention periods, the security.

Information sharing: who, what, under which framework

Within the care team, the information strictly necessary for care is shared without express consent — the patient being informed and able to object. Outside the care team, sharing between professionals requires the patient’s consent. And around care revolve non-clinical actors — administrative staff, IT departments, contractors — who do not have “access to the secret” but may, through their duties, come across covered data: they are governed through access rights, confidentiality clauses and training.

This is where the two regimes converge: the access management policy required by the GDPR is also the best tool for protecting confidentiality.

Everyday friction points

Messaging: exchanges containing patient data belong on secure health messaging services, not in personal mailboxes or consumer messaging apps. Shared accounts and collective passwords: they destroy traceability — and therefore the ability to demonstrate that confidentiality is protected. “Curiosity” access to the record of a relative or a public figure: logging reveals it, and it exposes staff to disciplinary and criminal sanctions. Requests from third parties — employers, insurers, families: they are subject to strict rules, and the reflex must be refusal by default, then analysis.

What this means for your organization

Four concrete workstreams: a written access management policy, reviewed regularly and aligned with actual roles; logging of access to records that is actually reviewed — not merely stored; a charter and training that speak to clinicians through their own use cases, not in legal jargon; and clear procedures for sensitive situations (judicial requisitions, disclosure requests, reports). Medical confidentiality and the GDPR then stop being two competing constraints: they become the same system of trust, seen through two windows.

This article is provided for general information purposes and does not constitute personalized legal advice.

Turn your obligations into opportunities.

A free, no-obligation first conversation to review your compliance posture and identify your priorities — in English.

Response within 24 business hours · No obligation