Verbal consent can satisfy GDPR in France, but for health data it rarely stands on its own. Routine care almost always relies on Article 9(2)(h) rather than consent, which removes the need to collect any permission at all. When consent is genuinely the right basis, an unrecorded verbal exchange is close to worthless in an audit, because the controller carries the burden of proving it happened.
TL;DR:
- Verbal consent can be valid under GDPR only if it is explicitly documented through recordings or immediate follow-up confirmation, especially for health data under Article 9(2)(a).
- Routine clinical activities automatically fall under Article 9(2)(h), allowing processing without consent as long as professionals act within medical secrecy bounds and for care purposes.
- Most compliance issues stem from practices assuming consent is always necessary, instead of relying on care necessity exemptions, which diminishes audit risk.
- Maintaining detailed, timestamped, and verifiable consent records, including specific scripts and revocation procedures, is essential to pass inspections and avoid penalties.
- Outsourcing call handling to providers with contractual, logging, and technical safeguards aligned with CNIL rules can help practices gather defensible consent evidence while remaining the legal controller.
Table of Contents
- Verbal Consent Under GDPR Healthcare Rules: The Legal Framework
- Verbal Consent in Practice: What Passes and What Fails
- Documenting Verbal Consent So It Survives an Audit
- Why Article 9(2)(h) Beats Consent for Routine Care
- A Practical Checklist and Script for Capturing Verbal Consent
- What Triggers CNIL Scrutiny in Health Data Cases
- How an Outsourced Answering Service Supports Documentation
- What French Healthcare Teams Should Actually Do Next
- Clicfone: Traceable Call Handling Built for French Medical Practices
- Primary Sources for Verifying These GDPR Healthcare Rules
- Sources
- FAQ
Verbal Consent Under GDPR Healthcare Rules: The Legal Framework
Health data sits in a protected category under the GDPR, and Article 9(1) starts from a flat prohibition: processing data concerning health is banned unless one of the exceptions in Article 9(2) applies. This is the piece of the regulation that trips up most French practices, because they assume consent is the default gateway to using patient data. It is not. It is one of ten narrow exceptions, and for day-to-day clinical work, it is usually the wrong one.
Article 9(2)(h) permits processing health data without consent when it is “necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment.” The CNIL confirms that liberal healthcare professionals in France do not need patient consent to process health data strictly necessary for diagnosis, care, or medical record management, as long as the professional is bound by medical secrecy. A general practitioner updating a patient file, a specialist coordinating with a lab, a physiotherapist logging a treatment plan: none of that requires asking “do you consent?” It requires acting within the scope of care and respecting confidentiality.
Article 7 governs what happens when consent is the chosen basis, and it sets a demanding bar. Article 7(1) states plainly that the controller must be able to demonstrate that the patient consented to the processing. That single clause is the reason verbal-only consent creates so much operational anxiety: a spoken “yes” leaves no trace unless someone captures it. The CNIL’s guidance on legal bases treats this proof requirement as non-negotiable, regardless of whether the consent was written, clicked, or spoken.

French law layers additional structure onto the European regulation. The Loi Informatique et Libertés, updated to align with the GDPR, and the Code de la santé publique both shape how health data moves between professionals, especially around medical secrecy and data sharing outside a care team. The CNIL has also published a specific referential for medical and paramedical practices that translates these obligations into operational requirements: contract clauses with subcontractors, access logging, and technical safeguards for anyone handling patient records in a French cabinet médical.
Putting the pieces together, a French healthcare controller works within three layers at once:
- Article 9 decides whether health data can be processed at all, and under which exception.
- Article 6 supplies the general legal basis (consent, contract, legitimate interest, legal obligation) that must also be satisfied alongside Article 9.
- Article 7 governs the mechanics of consent specifically, including the burden of proof, whenever consent is the chosen route.
- French sectoral rules (Code de la santé publique, CNIL referential) add practice-level detail on secrecy, subcontracting, and technical controls.
Most compliance failures in French practices trace back to skipping straight to “we need consent” without checking whether Article 9(2)(h) already covers the activity.
Verbal Consent in Practice: What Passes and What Fails
Not every conversation involving a patient touches Article 9. The dividing line is whether the processing sits inside a care relationship or outside it, and healthcare providers frequently blur that line when they add administrative or commercial layers on top of clinical work.
Processing that happens within care, such as a nurse logging vitals or a receptionist confirming an appointment tied to treatment, falls under Article 9(2)(h) and needs no consent hunt at all. Processing that happens outside care, such as enrolling a patient in a research study, sharing data with a third-party wellness app, or sending marketing about a new service, needs its own legal basis, and that basis is frequently consent.
Where consent applies, the standard it must meet depends on which article governs it. Article 6 accepts an “unambiguous indication,” which can be inferred from a clear affirmative action. Article 9(2)(a), covering special categories like health data, demands “explicit consent,” a stricter threshold that requires an unmistakable statement or act, not an inference. The EDPB’s guidelines on consent draw this distinction directly and confirm that recorded oral consent can satisfy the explicit standard, provided the recording captures the necessary elements and is stored reliably.
Here is how that plays out across common scenarios French practices encounter:
- Telemedicine enrollment. Registering a patient for a teleconsultation platform outside the immediate care act typically needs explicit consent for the data sharing involved, since the platform is often a separate processor with its own data flows. A recorded verbal confirmation, paired with a written summary sent afterward, can meet the bar.
- Research participation. Enrolling a patient in a clinical study almost always requires explicit, documented consent distinct from any care-related processing. Verbal agreement alone, without a signed or recorded record, exposes the sponsor and the site to real audit risk.
- Appointment reminders. Confirming or rescheduling an appointment tied to ongoing care generally falls under Article 9(2)(h) and contractual necessity, not consent. No explicit permission is needed simply to call a patient about their own upcoming visit.
- Marketing opt-in. Inviting a patient to a paid wellness program, a newsletter, or a partner service requires clear, separate consent under Article 6, and health-adjacent marketing often triggers Article 9 as well if it references the patient’s condition.
- Sharing data with an external app. Passing patient information to a third-party scheduling or engagement tool that is not acting purely as a processor under contract usually demands explicit consent, since the data leaves the direct care relationship.
The pattern holds across all five: the closer the activity sits to the actual delivery of care, the less likely consent is even the right basis. The farther it drifts toward research, marketing, or third-party tools, the more explicit and documented that consent needs to be.
Documenting Verbal Consent So It Survives an Audit
A verbal “yes” during a phone call is not inherently invalid evidence. It is inherently fragile evidence, and fragility is what CNIL inspectors and opposing counsel exploit. The fix is not switching to paper forms for everything; it is making the verbal exchange traceable the moment it happens.
Three approaches tend to hold up, in ascending order of strength:
- Audio recording against a fixed script. The call is recorded, the staff member reads a defined consent statement, and the patient’s affirmative response is captured on the recording itself.
- Signed post-call confirmation. The verbal exchange happens first, followed immediately by an SMS or email restating exactly what was agreed, with a link or reply mechanism the patient can use to confirm or revoke.
- Timestamped EMR entry with exact wording. The staff member logs the precise consent language used, the date and time, and the patient identifier directly into the medical record system at the moment of the call.
Legal commentary on building GDPR traceability recommends going further than a bare “consent obtained” note. The record should specify who collected the consent, how the patient’s identity was verified, the exact timestamp, which version of the information notice was read to the patient, and where the underlying evidence is stored. A detailed methodology for proving consent suggests linking the EMR entry to a hashed pointer for any audio file rather than storing raw recordings in multiple systems, which keeps the evidence auditable while limiting exposure if a breach occurs.
Pro Tip: Combine the channels instead of picking one. Record the call for immediacy, then send a short SMS with the consent text and a revocation link right after hanging up. That hybrid gives you both a real-time capture and a persistent written trail a patient can act on later.
Retention and access controls matter as much as the initial capture. Consent records should be encrypted at rest, restricted to staff who need them for compliance or care purposes, and minimized to only the metadata actually required rather than full call transcripts by default. Every consent log also needs a live link to a revocation workflow: if a patient withdraws consent next month, the system has to update every downstream processor and stop future processing on that basis, not just flag the original entry as outdated.
Why Article 9(2)(h) Beats Consent for Routine Care
Consent feels like the safe, patient-friendly choice, which is exactly why so many French practices default to it. In practice, it is the basis that creates the most administrative exposure for the least legal benefit when the processing is already covered by care necessity.
Article 9(2)(h) works because it does not depend on a patient’s mood, memory, or willingness to sign something during a rushed appointment. It applies automatically to diagnosis, treatment, and care coordination performed by professionals bound by medical secrecy, with no consent form to lose and no withdrawal to track.
Consent, by contrast, brings three recurring headaches:
- Withdrawal rights. A patient can revoke consent at any time, and the controller must be able to act on that revocation across every system where the data lives.
- Recordkeeping burden. Article 7(1) demands durable proof, which means every verbal consent needs a corresponding log, recording, or written confirmation, indefinitely.
- Audit exposure. If the CNIL requests evidence and the practice only has a note saying “patient agreed on the phone,” that gap becomes the finding in an inspection report.
Consent still earns its place for research, commercial use of patient data, and integrations with external apps that sit outside the direct care relationship. For everything inside that relationship, treating care necessity as the default and consent as the exception saves both risk and paperwork.
A Practical Checklist and Script for Capturing Verbal Consent
When consent genuinely is the right basis, staff need something they can follow on the call without improvising legal language.
- Confirm the basis first. Verify the activity actually requires consent rather than falling under care necessity; do not ask for permission you do not need.
- Read a fixed script. Use consistent wording every time so the recording or log always contains the same explicit statement.
- Capture identity and timestamp. Log how the patient’s identity was confirmed, along with the exact date and time of the exchange.
- Record or log immediately. Either record the call or enter the consent text into the EMR in real time, not from memory afterward.
- Send written confirmation. Follow up with an SMS or email restating the consent and a clear way to withdraw it.
- Propagate revocations everywhere. Make sure any withdrawal updates every connected platform and processor, not just the originating system.
A short script staff can adapt: “Before we continue, I need your clear agreement to [specific purpose]. This means [plain description of the data use]. Do you agree to this, yes or no?” That phrasing satisfies the EDPB’s requirement for a clear affirmative act rather than a vague nod along the way.
Pro Tip: Test your revocation workflow before you need it. Have a staff member simulate a patient withdrawing consent and time how long it takes to stop processing across every connected calendar and messaging tool.
What Triggers CNIL Scrutiny in Health Data Cases
The CNIL’s enforcement pattern in health data cases centers on two failures: weak traceability and mismanaged retention. The Doctissimo case is the clearest recent illustration, where the CNIL issued a €380,000 sanction over consent and retention failures tied to health questionnaires. The lesson for a private practice is the same lesson at smaller scale: collecting data is not the risk, keeping it without a clear consent trail or retention limit is.
The most frequent pitfalls the CNIL flags in inspections include:
- Poor traceability, where a practice cannot produce the exact consent wording, date, or collector identity on request.
- Conflating medical consent with data-processing consent, treating a patient’s agreement to treatment as if it also covers marketing or research use.
- Weak subcontractor contracts, missing the Article 28 clauses the CNIL referential requires for any processor handling patient data on the practice’s behalf.
Inspectors typically request the consent log itself, the information notice version in force at the time, and the subcontractor agreements covering any outsourced processing.
How an Outsourced Answering Service Supports Documentation
A telephone-answering provider cannot take on a practice’s legal accountability, but it can build the traceability layer that makes verbal consent defensible when consent is genuinely the right basis. That distinction, controller accountability versus processor evidence, is exactly where a service like Clicfone fits.
Relevant operational features include:
- Timestamped call records tied to each patient interaction, not just a call log summary.
- Recorded consent scripts stored against a fixed, auditable wording.
- Integration with the scheduling platforms French practices already use, including Doctolib, LibreRDV, Maiia, and CalenDoc.
- Confidentiality commitments and an Article 28 processor contract specifying exactly how consent metadata is logged and made available for audits.
The CNIL referential is explicit that any subcontractor handling this data needs contractual obligations covering logging and audit access, which is a requirement Clicfone’s processor agreements are built to satisfy. The practice remains the data controller and the accountable party throughout; the answering service supplies the evidence trail that makes the practice’s own compliance provable.
What French Healthcare Teams Should Actually Do Next
The safest posture is to stop reaching for consent by default. Most clinical work already qualifies under Article 9(2)(h), and forcing a consent conversation onto activities that don’t need one just creates paperwork nobody can produce later. When consent genuinely applies, document it as if an inspector will ask for it tomorrow, because eventually one might.
Three priorities are worth acting on this quarter: audit existing consent records for gaps, rewrite call scripts to capture explicit wording, and run a live test of the revocation workflow. Get sign-off from the practice’s DPO before rolling any of it out. None of this is complicated, but it does require someone to actually own it.
— Rudolph
Clicfone: Traceable Call Handling Built for French Medical Practices
A telephone-answering provider can offer outsourced call answering services with audit trails to support verbal consent documentation. Where an in-house receptionist might jot “patient agreed” on a sticky note, Such systems can produce timestamped records tied directly to calls, and can integrate with common scheduling platforms used by medical practices.

The practice stays the data controller and keeps full legal accountability, exactly as GDPR requires. The answering service can act as a processor under an Article 28 contract, supplying logging and confidentiality guarantees consistent with CNIL requirements for subcontractors handling patient data. That split matters in an inspection: the practice can point to a documented processor relationship instead of an informal call log nobody can reconstruct.
Practices weighing whether to keep call handling in-house or hand it to a specialized team can start by comparing options against alternatives to a traditional call center, or look directly at how specialty medical appointment management works in practice before requesting a quote.
Primary Sources for Verifying These GDPR Healthcare Rules
Anyone implementing these rules should read the underlying texts directly rather than relying on secondhand summaries, including this one.
- The CNIL’s guidance for liberal healthcare professionals explains Article 9(2)(h) and when consent is not required for care.
- The CNIL’s page on legal bases and consent covers the Article 7(1) burden of proof in detail.
- The EDPB’s guidelines on consent lay out the distinction between unambiguous and explicit consent under the full regulation.
- The CNIL referential for medical and paramedical practices sets out contractual, technical, and logging obligations for French cabinets and their subcontractors.
- Enforcement context from the Doctissimo sanction summary illustrates what happens when consent and retention practices fail an inspection.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- RGPD et professionnels de santé libéraux : ce que vous devez savoir — CNIL
- Consentement — Les bases légales — CNIL
- Guidelines on consent under Regulation 2016/679 (EDPB)
- Référentiel relatif aux traitements de données à caractère personnel destinées à la gestion des cabinets médicaux et paramédicaux — CNIL
- RGPD et santé : protection des données médicales — Legiscope
FAQ
Is verbal consent valid under GDPR for healthcare in France?
Yes, but only when it meets the explicit consent standard for health data and the controller can prove it happened, typically through a recording or an immediate written confirmation, per CNIL guidance.
Does GDPR apply to healthcare providers in France?
Yes, GDPR applies directly across France as an EU member state, layered with French rules like the Code de la santé publique and CNIL referentials that add sector-specific detail for medical practices.
What are the requirements for valid consent under GDPR?
Valid consent must be freely given, specific, informed, and unambiguous, and for health data specifically, Article 9(2)(a) raises that to an explicit, clearly documented statement or act.
When can a French practice process health data without asking for consent?
Whenever the processing is necessary for diagnosis, treatment, or care coordination by a professional bound by medical secrecy, Article 9(2)(h) applies and no consent is needed.
What happens if a practice cannot prove consent was given?
The CNIL treats missing or vague consent records as a compliance failure, and enforcement history, including the Doctissimo sanction, shows this can result in significant financial penalties.