The GDPR in your practice: the essentials, without the overkill
A health professional practicing individually is, as a rule, not required to appoint a DPO — the very example cited by the European guidelines themselves. But every other obligation applies: record of processing activities, patient information, security, retention periods, breach notification. And the CNIL has already sanctioned independent physicians — €3,000 and €6,000 in 2020, for medical images accessible online and an unnotified breach.

What is at stake for your organization
- Secure the workstation, the internet router and the software — the exact failure that earned the two physicians their sanctions.
- Keep a record of processing activities proportionate to the practice’s activity.
- Inform patients: a waiting-room notice, statements on documents.
- Frame the secretariat, remote secretarial services and online scheduling (roles and contracts).
- Know how to react to a breach: qualify, notify within 72 hours where required, document.
What triggers the need
- Installing or changing practice software or an online scheduling tool
- Joining forces with other practitioners or hiring a secretariat
- A patient requesting access to their record
- An incident: lost equipment, a misdirected message, a compromised workstation
Sound familiar? Now is the right time to get the subject under control — before it takes control on its own.
The most common mistake
Thinking “I’m too small to be concerned”. The two physicians sanctioned by the CNIL in 2020 practiced individually: size only exempts you, as a rule, from the obligation to appoint a DPO — not from the record of processing, not from security, not from breach notification.
What we put in place
- An express diagnostic tailored to independent practice
- A proportionate documentation kit: simplified record, notices, procedures
- Review of the practice’s tools and providers
- Awareness for the practitioner and the secretariat
- One-off support in the event of an incident or a patient request
Your questions
Must an independent physician appoint a DPO?
In principle no, for individual practice: the European guidelines expressly cite this case as not amounting to large scale. Things change in group practice — MSP, health center, a large group practice — where the analysis is made case by case. A voluntary appointment remains possible and sometimes relevant.
What does a practice really risk?
Real but proportionate sanctions: in 2020, two independent physicians were fined €3,000 and €6,000 for a security failure (images accessible online) and for failing to notify the breach. Beyond the fine, what is at stake is patients’ trust — and that cannot be bought back.
Where to start without spending weeks on it?
Three proportionate work streams: check basic security (passwords, updates, backups, router configuration), keep a simplified record of the practice’s processing activities, and display clear information for patients. Our express diagnostic covers these points and delivers a roadmap within ten days.
Let’s secure the compliance of your organization
A free first conversation to review your situation and identify your priorities.
Response within 24 business hours · No obligation
