AI and GDPR: can you use AI with patient data?
It's the question every clinic asks us: "can I have an AI that touches patient data?". The short answer is yes, but with conditions. Here are the ones that matter, no small print.
Minimise and justify
GDPR requires processing only the data strictly necessary for the purpose. An AI receptionist doesn't need the full medical record to book an appointment: just the minimum to identify the patient and find a slot.
Where the data lives
Processing and storing data in the European Union is key. At Noema, sensitive processing is self-hosted in Europe, and health data never goes to third-party services outside the EU.
| Question | What you need to be able to show |
|---|---|
| What is your legal basis? | Health data needs an Article 9 condition; the usual generic consent is not enough |
| Where is the data processed? | Each provider's country, and the safeguards if it leaves the EU |
| Who have you signed a processing agreement with? | A DPA with every provider involved: hosting, AI model, messaging, calendar |
| How long is it kept? | A written retention period and a purge that runs by itself, not by promise |
| How do you handle an erasure request? | A procedure and a deadline; GDPR gives you one month |
| Is it in your record of processing? | An updated ROPA covering the new processing, and an impact assessment where the risk calls for one |
Processing agreement and rights
Any provider that handles data for you must sign a data processing agreement (DPA) and respect patient rights as set by the data protection authority: access, rectification and erasure. If a provider won't sign one, that's a red flag.
Frequently asked questions
Can I use ChatGPT with patient data?
Not on your usual personal account: you have no processing agreement, no control over where the data goes, and you may be feeding a model's training. With a business contract and the right terms it is a different conversation, but it is a decision to document before, not after.
Do I need a data protection impact assessment (DPIA)?
Often yes. Systematic processing of health data is one of the triggers, and supervisory authorities publish lists of cases where it is mandatory. It costs less than you would think, and it is the first document anyone will ask for if an inspection ever comes.
Do patients have to know they are talking to an AI?
Yes, and since 2 August 2026 it is an express obligation under Article 50 of Regulation (EU) 2024/1689. In practice the agent must say so in its first message, without waiting to be asked.
If the provider is American, is it all lost?
No, but you need to know it and have it covered: a transfer mechanism, a contract and transparency towards the patient. The problem is never that a provider is foreign; it is being unable to explain where the data goes when someone asks.
Got questions about your specific case?
We'll explain how we handle data and share our compliance documentation.
Free demo