Sector guide

GDPR for medical practices: complete guide and free audit 2026

A practical GDPR guide for medical practices. Understand the main risks, obligations and concrete steps for your website.

5 GDPR obligations specific to medical practices

These points are systematically checked during a DPA audit in your sector.

1

Map personal data

Document what data you collect, why you need it and how long you keep it.

2

Use a valid legal basis

Link each processing activity to consent, a contract, a legal obligation or legitimate interest.

3

Inform visitors clearly

Provide a plain-language privacy policy that matches how your website actually works.

4

Secure data and vendors

Limit access, assess processors and put appropriate data-processing agreements in place.

5

Respect privacy rights

Make access, correction, deletion and objection easy, and answer requests on time.

Real DPA fines in this sector

Documented cases. Official sources available on cnil.fr.

2022
1,5 M€
DEDALUS BIOLOGIE

Documented breach of data-protection requirements.

CNIL délibération SAN-2022-009
2023
1,5 M€
Hospices Civils de Lyon

Documented breach of data-protection requirements.

CNIL délibération SAN-2023-016
2023
Mise en demeure publique
Cabinet médical (mise en demeure)

Documented breach of data-protection requirements.

CNIL MED-2023-014

How to check your GDPR compliance as medical practices

RGPDScan automatically audits your website against 30+ DPA checkpoints. Detailed report in 60 seconds, with sector-specific recommendations.

  • Cookies and trackers detection
  • AI dark pattern analysis
  • Non-EU data transfers detected
  • Quantified fine risk

Frequently asked questions

Does GDPR apply to medical practices?
Yes. GDPR applies whenever an organization processes personal data relating to people in the European Economic Area.
What does RGPDScan check?
RGPDScan checks cookies, trackers, consent, forms and the content of legal pages, among other website risks.
Is an automated scan a complete legal opinion?
No. It identifies website-related risks and helps prioritize action. Complex situations may still require legal advice.

Audit your site in 60 seconds

Free GDPR scan. No credit card.