Skip to content
noema.
Compliance

AI and GDPR: can you use AI with patient data?

It's the question every clinic asks us: "can I have an AI that touches patient data?". The short answer is yes, but with conditions. Here are the ones that matter, no small print.

Minimise and justify

GDPR requires processing only the data strictly necessary for the purpose. An AI receptionist doesn't need the full medical record to book an appointment: just the minimum to identify the patient and find a slot.

Where the data lives

Processing and storing data in the European Union is key. At Noema, sensitive processing is self-hosted in Europe, and health data never goes to third-party services outside the EU.

The GDPR questions you must be able to answer before connecting AI to patient data.
QuestionWhat you need to be able to show
What is your legal basis?Health data needs an Article 9 condition; the usual generic consent is not enough
Where is the data processed?Each provider's country, and the safeguards if it leaves the EU
Who have you signed a processing agreement with?A DPA with every provider involved: hosting, AI model, messaging, calendar
How long is it kept?A written retention period and a purge that runs by itself, not by promise
How do you handle an erasure request?A procedure and a deadline; GDPR gives you one month
Is it in your record of processing?An updated ROPA covering the new processing, and an impact assessment where the risk calls for one

Processing agreement and rights

Any provider that handles data for you must sign a data processing agreement (DPA) and respect patient rights as set by the data protection authority: access, rectification and erasure. If a provider won't sign one, that's a red flag.

Frequently asked questions

Can I use ChatGPT with patient data?

Not on your usual personal account: you have no processing agreement, no control over where the data goes, and you may be feeding a model's training. With a business contract and the right terms it is a different conversation, but it is a decision to document before, not after.

Do I need a data protection impact assessment (DPIA)?

Often yes. Systematic processing of health data is one of the triggers, and supervisory authorities publish lists of cases where it is mandatory. It costs less than you would think, and it is the first document anyone will ask for if an inspection ever comes.

Do patients have to know they are talking to an AI?

Yes, and since 2 August 2026 it is an express obligation under Article 50 of Regulation (EU) 2024/1689. In practice the agent must say so in its first message, without waiting to be asked.

If the provider is American, is it all lost?

No, but you need to know it and have it covered: a transfer mechanism, a contract and transparency towards the patient. The problem is never that a provider is foreign; it is being unable to explain where the data goes when someone asks.

Got questions about your specific case?

We'll explain how we handle data and share our compliance documentation.

Free demo