Yes: GDPR and the French Public Health Code apply to any telephone call carrying health information, and recording it is lawful only in narrow, documented cases. Your practice stays the data controller even when a secretariat answers the phone. Three actions come first: sign an Article 28 data processing agreement with any outsourced provider, strip call scripts down to the minimum data needed, and confirm that anyone storing recordings holds a valid health-data hosting certification.
TL;DR:
- Recording calls is only lawful when absolutely necessary, such as proving agreement in disputes or confirming urgent clinical instructions, not for staff training or quality assurance.
- A practice must have a signed data processing agreement with any third-party call handler, detailing purpose, data categories, security measures, and compliance obligations.
- Storing call recordings or logs requires HDS certification for health data hosting and implementation of encryption, access controls, and detailed logs to ensure security.
- In case of a data breach, clinics must notify CNIL within 72 hours and only directly notify patients if the breach poses a high risk to their rights or health.
- Retention periods for call data must be justified, documented, and include automated deletion once the purpose is fulfilled to minimize compliance risks.
Table of Contents
- GDPR Medical Calls: The Legal Framework Behind Every Ring
- When Recording a Medical Call Is Actually Legal
- Outsourcing Your Phone Lines Without Outsourcing Your Liability
- Encryption, Access Control, and the Hosting Question Nobody Skips
- What Happens After a Breach, and How Long Data Should Live
- A Short, Realistic Compliance Checklist for Medical Offices
- How a Compliant Answering Provider Puts These Rules Into Practice
- What Actually Reduces Risk (And What’s Just Theater)
- How Clicfone Handles Compliance So You Don’t Have To
- Sources
- FAQ
GDPR Medical Calls: The Legal Framework Behind Every Ring
A phone call mentioning a diagnosis, a prescription, or an appointment reason is not casual chatter under French law. It is special-category data, and GDPR Article 9 puts an extra layer of restriction on how it can be collected, stored, and shared. This matters for medical secretariats specifically, because the phone is where most patient data enters a clinic’s systems before it ever touches an electronic health record.
France doesn’t rely on GDPR alone. The Public Health Code adds its own rules, chiefly Article L.1111-8, which governs where and how health data can be hosted. A clinic that records calls or keeps detailed call logs containing clinical details is handling data that falls under both frameworks simultaneously. Ignoring one because you’ve satisfied the other is a common and costly mistake.
Two documentation obligations follow directly from this. First, every practice must maintain a register of processing activities, listing what data is collected by phone, why, for how long, and who can access it. The CNIL’s guidance on good practices for controllers and processors treats this register as the backbone of accountability, not a paperwork formality.
Second, a Data Protection Impact Assessment (DPIA) becomes mandatory when call handling crosses certain risk thresholds. Under GDPR Article 35, that threshold is usually met when:
- Calls are systematically recorded rather than recorded on an exceptional basis.
- An automated triage or AI-assisted system sorts patients by urgency or symptom before a human reviews the case.
- Call data feeds into a broader health information system with other clinical records.
- A new telehealth or remote-consultation workflow processes health data at scale.
If none of those apply, a full DPIA usually isn’t required. But the analysis itself, even a short one, needs to be documented. CNIL inspectors ask for the reasoning, not just the conclusion.
Telemedicine adds another layer. Teleconsultation platforms fall under a specific interoperability and security framework published by the Agence du Numérique en Santé, which expects integration with Pro Santé Connect and MSSanté, along with periodic intrusion testing. A clinic offering remote consultations, even occasionally, should treat that referential as a checklist, not background reading.
None of this means every clinic needs a legal department. It means the phone system, the appointment platform, and the secretariat handling calls all sit inside the same regulatory perimeter as the exam room.
When Recording a Medical Call Is Actually Legal
Recording a patient call is the exception, not the default. The CNIL’s own guidance on phone conversation recording for contractual proof sets a high bar: recording is permitted only when it’s genuinely necessary, and only when no other reasonable method could establish the same proof.
In practice, that leaves a short list of legitimate cases:
- Establishing that an appointment or agreement was made, when no other durable record exists and a dispute is plausible.
- Rare clinical necessity, such as confirming instructions given during a time-sensitive call, where written confirmation isn’t feasible in the moment.
- Quality or safety review tied to a specific, documented incident, never as a blanket policy for all incoming calls.
Recording every call “just in case,” or to train staff, or to monitor performance generally, does not meet the necessity test. If a written confirmation, an SMS, or a booking platform log could do the same job, that alternative should be used instead of a recording.
When recording is justified, transparency isn’t optional. Patients must be told, typically through a recorded announcement or a verbal notice at the start of the call, that the conversation may be recorded, why, how long it’s kept, and how they can request access or object. Recordings must also be scoped tightly. If only the final thirty seconds of a call establish the appointment agreement, that’s the only portion worth keeping. The rest should never be captured or should be discarded immediately after the call ends.

Pro Tip: Set recording to trigger manually, not automatically, at the exact point where consent or agreement is confirmed. This alone eliminates most of the retention and minimization headaches clinics run into later.
Operationally, this means giving staff a clear, simple rule: record only the specific segment that matters, delete anything captured outside that scope, and never let a recording sit on a device or system that hasn’t been checked for security controls.
Outsourcing Your Phone Lines Without Outsourcing Your Liability
Handing call answering to an outside secretariat does not transfer legal responsibility. Under French data protection rules, the medical practice remains the data controller for every call, every appointment note, and every patient detail collected on its behalf. The CNIL’s 2022 deliberation on processor contracts makes this explicit: outsourcing changes who perform the task, not who answers for it.
That accountability has to be written down. Article 28 of the GDPR requires a formal contract, often called a Data Processing Agreement (DPA), between the clinic and any processor handling patient data. A CNIL and CNOM practical guide for health professionals lists the clauses that separate an adequate contract from a risky one:
- The exact purpose, duration, and nature of the processing.
- The specific categories of health data being handled.
- Security measures the processor commits to, in concrete terms, not vague assurances.
- The processor’s obligation to assist with patient rights requests (access, rectification, objection).
- Audit rights, allowing the clinic to verify compliance rather than take it on faith.
- Rules for any subprocessors, including notification before a new one is added.
A contract missing any of these isn’t just incomplete. It’s a documented gap that a CNIL inspection would flag immediately.
Verification matters as much as the paperwork. Before signing with any outsourced provider, ask for their information security policy, sample access logs showing who can see patient data and when, proof that staff complete confidentiality training, and confirmation that the audit clause is real rather than decorative.
Pro Tip: Ask a prospective provider to walk through what happens, step by step, if a staff member leaves the company. If they can’t describe how access gets revoked within hours, that’s a preview of how they’ll handle a real incident.
Encryption, Access Control, and the Hosting Question Nobody Skips
Storing call recordings or detailed call logs containing health data triggers a hosting obligation that catches many clinics off guard. Any provider storing that data may need Hébergeur de Données de Santé (HDS) certification under Article L.1111-8 of the Public Health Code. Using a host without that certification, even a reputable general-purpose cloud provider, can constitute a compliance failure on its own, independent of whether a breach ever occurs.
HDS certification isn’t uniform. A provider’s certificate can cover only certain services or infrastructure layers, so checking the scope and expiry date matters as much as confirming the certificate exists at all. A security-focused review of HDS requirements notes that clinics often assume a vendor’s certification covers everything it does, when in fact it may apply only to a subset of stored data.
Beyond hosting, a short list of technical controls separates a defensible setup from a vulnerable one:
- Encryption in transit and at rest for any call recording, transcript, or log containing patient information.
- Multi-factor authentication for anyone accessing systems that touch call data.
- Role-based access control, so a receptionist and a physician don’t have identical visibility into stored records.
- Detailed access logging, so every view, export, or deletion of a recording is traceable.
- Secure deletion procedures, not just moving a file to a trash folder that lingers on a server.
Organizational habits matter just as much as software settings. Staff vetting, confidentiality training refreshed regularly rather than delivered once at onboarding, vetting of any subcontractor a provider brings in, periodic penetration testing, and a documented incident response plan all belong on the same checklist as encryption. Guidance on health-data hosting in France frames privacy by design as the practical standard: collect only what the triage or booking process actually requires, and build systems that make over-collection the harder option, not the default.
CNIL’s own cybersecurity guidance for controllers points to a pattern worth internalizing: most compliance failures trace back not to sophisticated attacks but to weak contract language and unverified hosting claims. The fix is rarely more technology. It’s a more careful reading of what a vendor’s paperwork actually promises.
What Happens After a Breach, and How Long Data Should Live
A data breach involving patient call information starts a clock the moment it’s discovered. Under the 72-hour notification rule, the clinic must report the incident to the CNIL within that window whenever the breach poses a risk to patients’ rights or freedoms. Missing that deadline compounds the original problem with a procedural violation.
The reporting process has three parts worth building into a template in advance:
- Internal breach log first. Document the nature of the breach, when it was discovered, and what data was exposed, even before the CNIL notification is filed.
- CNIL notification within 72 hours, including the estimated number of affected patients, the likely consequences, and the mitigation steps already taken or planned.
- Patient notification without undue delay, but only when the breach carries a high risk to those individuals. A minor, contained incident with no exposure of sensitive details may not require notifying patients directly. A leaked recording containing diagnosis or treatment details almost certainly does.
Retention policy prevents many of these problems before they start. Call recordings and logs should be kept only as long as the original purpose requires, whether that’s a short window to resolve a scheduling dispute or a longer period tied to a specific clinical or legal need. Every retention period should be written down in the register of processing activities, with an automated deletion process behind it rather than a manual cleanup that gets postponed indefinitely.
A Short, Realistic Compliance Checklist for Medical Offices
Compliance doesn’t require a legal team. It requires finishing a short list of concrete tasks and being able to prove you did.
- Update the register of processing activities to reflect exactly what happens on incoming and outgoing calls.
- Sign or review Article 28 DPAs with every outsourced secretariat, answering service, or telehealth vendor.
- Confirm HDS certification scope and expiry for any provider storing recordings or detailed call logs.
- Set retention periods for call data and automate deletion once those periods expire.
- Run a DPIA if call handling includes systematic recording or automated triage.
- Schedule recurring staff training on confidentiality and call-handling procedures, not a single onboarding session.
- Keep proof of every decision, audit, and supplier guarantee in a format ready to hand a CNIL inspector.
Pro Tip: Treat the register of processing activities as a living document, not an annual chore. Update it the same week a new tool, script change, or vendor gets added, while the details are still fresh.
How a Compliant Answering Provider Puts These Rules Into Practice
The gap between theory and daily operations usually shows up in the paperwork a provider is willing to hand over. A provider worth trusting with medical calls should offer a DPA with explicit clauses on data subject assistance, not a generic template borrowed from another industry. Integration with platforms like Doctolib, LibreRDV, Maiia, or CalenDoc changes how data flows between the phone and the calendar, so it’s worth asking exactly what gets transmitted and stored at each step.
Look for these signals before signing anything:
- Published, specific compliance documentation rather than a one-line assurance on a sales page.
- Clear retention policies stated in writing, not “as needed.”
- Evidence of staff training tied to healthcare confidentiality specifically.
- A willingness to support access, rectification, and objection requests from patients on request.
What Actually Reduces Risk (And What’s Just Theater)
Most clinics overinvest in recording policy and underinvest in contracts. A weak Article 28 clause creates more real exposure than a missing recording announcement ever will, because the contract is what CNIL inspectors examine first when something goes wrong downstream.
Recording should be a last resort, used narrowly and sparingly, not a default safety net. Hosting verification and staff training, done consistently, protect a clinic far more than any single technical fix. Documented decisions, reviewed on a schedule, are what actually hold up under scrutiny.
— Rudolph
How Clicfone Handles Compliance So You Don’t Have To
Most clinics don’t have a compliance officer on staff, which means every hour spent verifying a vendor’s DPA or checking HDS scope is an hour not spent with patients. Some providers specializing in medical and paramedical call handling incorporate contractual and security groundwork such as Article 28 clauses, calendar integrations with platforms like Doctolib, LibreRDV, Maiia, and CalenDoc, and documented data-handling practices into their service operations.

Rather than building an internal call-recording and hosting review process from scratch, clinics can request DPA language and compliance documentation directly from providers before committing to anything. The secrétariat téléphonique à distance service handles day-to-day call answering and appointment booking, while the medical phone triage offering covers urgent call sorting for practices that need faster clinical routing without adding headcount. For clinics also looking at how outsourced reception affects appointment volume and patient flow, a healthcare-focused marketing partner can help align demand with the capacity a compliant call setup actually supports. Interested parties can reach out to providers to request DPA text, hosting proof, and a short pilot period before making any changes to their call-handling setup.
Sources
For details beyond this guide, go directly to the primary sources. The full GDPR text covers Articles 9, 28, 32, and 35 in full. The CNIL’s call recording guidance and Public Health Code hosting rules are updated periodically, so checking the CNIL’s site directly before major decisions is worth the ten minutes it takes.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
FAQ
Does GDPR Apply to Medical Calls in France?
Yes. GDPR applies to any phone call where health information is collected, discussed, or stored, and France adds its own layer through the Public Health Code and CNIL guidance. A clinic remains the data controller even when an outsourced secretariat answers the phone.
What Are the Main GDPR Requirements for Medical Call Handling?
The core requirements are a lawful basis for processing, a signed Article 28 contract with any processor, data minimization, documented retention limits, breach notification within 72 hours, and support for patient rights like access and objection. GDPR Articles 9, 28, 32, and 35 cover most of these obligations directly.
Can a Medical Office Legally Record Patient Phone Calls?
Only in narrow, necessary cases, such as proving an appointment agreement was made when no other record exists. The CNIL’s guidance on call recording requires that patients be informed and that recordings be limited to the relevant portion of the call.
What Should Be in a DPA With an Outsourced Answering Service?
A compliant DPA specifies the purpose and duration of processing, the categories of data involved, concrete security measures, audit rights, subprocessor rules, and the provider’s obligation to assist with patient rights requests. Clicfone’s medical secretariat services are built around this kind of documented contract.
How Long Can a Clinic Keep Call Recordings or Logs?
Retention should match the specific purpose the data serves, whether that’s resolving a short-term scheduling dispute or meeting a documented clinical need, and the period must be written into the register of processing activities. Automated deletion once that period ends is the safest practice, rather than relying on manual cleanup.
What Happens if a Clinic Has a Data Breach Involving Call Data?
The clinic must notify the CNIL within 72 hours when the breach risks patients’ rights, including details on what happened, how many people were affected, and what mitigation steps were taken. Patients themselves must be notified without undue delay only when the risk to them is high.