A private medical practice can legally outsource telephone answering and appointment management to an external provider under GDPR, but only when a processor-level Data Processing Agreement meeting every requirement of Article 28(3) is in place before the first call is handled. Health data processed by an answering service falls under the most sensitive category of personal data, which means the compliance threshold is higher, not lower, than for general business outsourcing.
Three immediate actions for any practice considering outsourced telephone reception: First, request the provider’s full DPA draft, including all annexes. Second, ask for documented proof of ISO/IEC 27001, ISO/IEC 27701, NEN 7510, or Hébergement de Données de Santé (HDS) certification, or a Third Party Memorandum (TPM) when formal certification is absent. Third, request a current, named sub-processor list before signing anything.
Clicfone has operated as a specialist medical telephone answering service with long-term experience, and the compliance framework described throughout this guide reflects the documentation and contractual standards the practice should expect from any qualified provider.
Key Takeaways
A GDPR-compliant medical answering service requires a standalone DPA meeting all eight Article 28(3) requirements, documented security evidence, and a named sub-processor list before any patient data is processed.
| Point | Details | ||||
|---|---|---|---|---|---|
| DPA is mandatory | A general service contract does not satisfy Article 28; a standalone DPA with all eight Article 28(3) items is legally required. | ||||
Table of Contents
- What does GDPR Article 28 require when an answering service handles patient data?
- What documents should a practice request before signing a DPA?
- Concrete questions to send a provider when requesting compliance evidence
- When does a practice need a DPIA or a DPO?
- How to manage sub-processors and cross-border transfers in the DPA
- What technical and organizational measures should a practice expect?
- How to protect patient data when the contract ends
- How Clicfone meets GDPR Article 28 requirements for medical answering services
- What auditors actually look for in a medical answering service DPA
- Request Clicfone’s DPA and compliance documentation
- Sources
- FAQ
What does GDPR Article 28 require when an answering service handles patient data?
GDPR Article 28 is unambiguous: any outsourced service that processes personal data on behalf of a medical practice is a processor, and the practice remains the controller. That distinction carries real weight. The controller retains primary legal responsibility for every piece of patient data, regardless of who handles the call.
The CNIL guidance on controller and processor roles makes clear that compliance cannot be delegated by contract alone. The practice must actively verify that its answering service provides “sufficient guarantees,” document that verification, and repeat it when circumstances change.
A compliant DPA must explicitly address all eight mandatory Article 28(3) items:
- Processing on documented instructions only: the answering service may not use patient data for any purpose beyond what the practice specifies in writing.
- Confidentiality obligations: all staff with access to patient calls or records must be bound by confidentiality, either by contract or by professional duty.
- Security measures: the DPA must reference specific technical and organizational measures (TOMs) appropriate to the risk level of health data.
- Sub-processor restrictions: the provider may not engage additional sub-processors without prior written authorization from the practice.
- Assistance with data-subject rights: the provider must help the practice respond to patient access, rectification, and erasure requests within statutory deadlines.
- Breach cooperation: the provider must notify the practice in time to meet the 72-hour reporting window under Articles 33–34.
- Deletion or return of data: at contract end, all patient data must be returned or securely deleted, with documented proof.
- Audit and documentation rights: the practice must retain the contractual right to audit the provider’s compliance, directly or through an independent auditor.
The Weblex referential for medical practices provides a detailed DPA checklist aligned with these Article 28(3) requirements and is a practical starting point for comparing a provider’s draft against the statutory minimum.
Key compliance fact: A general commercial service contract does not satisfy Article 28. A standalone DPA with all eight Article 28(3) items is legally required whenever health data are processed, regardless of contract size or call volume.
What documents should a practice request before signing a DPA?
Collecting the right evidence before signing protects the practice during any supervisory authority audit. The following documents are the minimum a qualified provider should supply without hesitation.
Pro Tip: Request all documents simultaneously in a single written request and set a response deadline of ten business days. A provider that cannot supply its DPA draft and security documentation within that window is signaling an organizational gap worth noting before any contract is signed.
- Full DPA draft with all annexes (Annex II: TOMs; Annex IV: sub-processor list; Annex III: transfer mechanisms where applicable)
- Current information security policy and, where available, a summary of recent penetration test results
- ISO/IEC 27001 and/or ISO/IEC 27701 certificates, or NEN 7510 for Dutch-market providers, or HDS certification where patient-record hosting is involved
- A recent independent audit report or, where certification is absent, a Third Party Memorandum from an accredited auditor
- Named sub-processor list with country of processing for each sub-processor
- Evidence of Standard Contractual Clauses (SCCs) or an adequacy decision for any processing outside the EEA
- Incident notification SLA confirming the provider will alert the practice within a timeframe that allows the 72-hour regulatory window to be met
- Business-continuity and disaster-recovery plan summary
- Integration documentation for appointment platforms (Doctolib, LibreRDV, Maiia, CalenDoc) confirming data flows and access controls
CNIL’s guidance on managing subcontracting security recommends requiring certifications or a TPM as practical evidence of sufficient guarantees, and advises controllers to keep copies of all received documentation in their compliance file.
Concrete questions to send a provider when requesting compliance evidence
A structured written request produces more useful responses than a general inquiry. The following questions can be adapted into a short RFP or pre-contract questionnaire.
- “Please provide your current DPA template, including Annex II (TOMs), Annex IV (sub-processor list), and any transfer mechanism schedules.”
- “Which certifications does your organization currently hold? Please attach current ISO/IEC 27001, ISO/IEC 27701, NEN 7510, or HDS certificates, or a TPM from an accredited auditor dated within the last 24 months.”
- “Describe the encryption standards applied to patient call data in transit and at rest, and confirm whether multi-factor authentication (MFA) is enforced for all staff with access to patient records.”
- “What is your contractual SLA for notifying a controller of a personal data breach? Please confirm the notification timeline in hours.”
- “List all current sub-processors by name and country. How will you notify us of any change to this list, and what is our right to object?”
- “For any processing outside the EEA, which transfer mechanism applies? Please provide the relevant Standard Contractual Clauses or adequacy decision reference.”
- “Describe your staff confidentiality training program and how you document completion.”
- “What is your process for returning or securely deleting all patient data at contract termination, and do you provide a certificate of deletion?”
- “Can you provide a sample integration guide for Doctolib, LibreRDV, Maiia, or CalenDoc, confirming how appointment data is accessed and protected?”
- “What audit rights does the DPA grant the controller, and what is the process for requesting an onsite or third-party audit?”
Suggested reply deadline: 10 business days for documentation; 5 business days for a DPA draft.
When does a practice need a DPIA or a DPO?
A Data Protection Impact Assessment (DPIA, also called an AIPD in French-language jurisdictions) is mandatory when processing is likely to result in a high risk to individuals. For medical practices outsourcing telephone reception, three specific triggers apply:
- Large-scale processing of health data: a practice handling a high volume of patient calls through an outsourced service, particularly with AI-assisted triage or 24/7 coverage, should assess whether the scale crosses the threshold for mandatory DPIA.
- Systematic monitoring: automated call logging, sentiment analysis, or AI-driven call routing constitutes systematic monitoring and typically triggers a DPIA obligation.
- New technology: deploying an AI agent for round-the-clock call handling is a new technological approach that raises questions about automated decision-making and data minimization, both DPIA triggers.
A Data Protection Officer (DPO) is mandatory for healthcare providers that process health data on a large scale as a core activity. Smaller practices that do not meet that threshold may still benefit from a mutualized or external DPO arrangement, which several specialist providers offer for the healthcare sector.
The DPIA documentation should include an assessment of the processing and its risks, mitigation measures, and evidence that the processor’s guarantees were verified before processing began.
How to manage sub-processors and cross-border transfers in the DPA
Sub-processor transparency is one of the most frequently audited elements of a DPA. The EDPB opinion on reliance on processors and sub-processors confirms that controllers must know the identity of every sub-processor in the chain and should be able to demonstrate due diligence across that chain, not just at the first tier.
Minimum contractual requirements for sub-processor management:
- Annex IV must list every sub-processor by name, registered country, and the specific processing activity they perform.
- The DPA must require the provider to notify the practice of any intended change to the sub-processor list, with sufficient advance notice for the practice to object.
- The practice’s right to object must be explicit and enforceable, not merely advisory.
- Each sub-processor must be bound by data protection obligations equivalent to those in the main DPA.
For cross-border transfers, the applicable safeguard depends on the destination country. Transfers to countries covered by an EU adequacy decision require no additional mechanism. For all other destinations, Standard Contractual Clauses issued by the European Commission remain the standard instrument, and the DPA should reference the specific SCC module applicable to the processor-to-sub-processor relationship.
What technical and organizational measures should a practice expect?
Health data processed through telephone channels requires a higher standard of technical protection than general business data. The CNIL subcontracting security guidance identifies the following as baseline expectations for processors handling sensitive data:
- Encryption: all patient data must be encrypted in transit (TLS 1.2 minimum) and at rest using current standards.
- Multi-factor authentication: MFA must be enforced for every staff member with access to patient call records or appointment systems.
- Role-based access control: access to patient data must be limited to staff whose role requires it, with access logs retained for audit purposes.
- Detailed logging: all access events, data exports, and administrative actions must be logged with timestamps and retained for a defined period.
- Secure backups and business continuity: regular encrypted backups, tested restoration procedures, and a documented recovery plan are required.
- Secure telephony: call routing and recording infrastructure must meet the same encryption and access-control standards as stored data.
Certification standard: ISO/IEC 27001 covers information security management; ISO/IEC 27701 extends that to privacy information management. NEN 7510 is the Dutch healthcare-specific standard. HDS certification is required in France for providers that host patient health records. A practice should verify which certifications apply to its jurisdiction and confirm the provider’s certificate scope covers the specific services being contracted.
Call recording requires particular attention. Recording patient calls is permissible only when a valid legal basis exists, patients have been informed, recordings are stored with the same security controls as other health data, and access is restricted to authorized personnel. Redaction procedures for sensitive data mentioned incidentally during calls should be documented in the TOMs.
How to protect patient data when the contract ends
Contract termination is the point at which data protection obligations are most often overlooked. A well-drafted DPA addresses exit procedures with the same specificity as operational security.
Exit checklist for practices ending an answering service contract:
- Confirm the data export format and timeline before giving notice, so appointment data can be migrated to a successor provider or internal system without gaps in patient care.
- Require written confirmation of the deletion date and method for all patient data held by the provider and its sub-processors.
- Request a certificate of deletion (or certificate of destruction) as a formal document for the practice’s compliance file.
- Verify that pending appointments and urgent patient contacts are handed over in a structured format, with a defined continuity window.
- Confirm that sub-processors have also deleted the data and that the provider can evidence this.
The DiliTrust guide on GDPR subcontracting obligations notes that the DPA must give the controller the information necessary to demonstrate compliance at every stage, including at termination. A suggested SLA for final data handover is 30 calendar days from the contract end date, with the deletion certificate delivered within the same period.
How Clicfone meets GDPR Article 28 requirements for medical answering services
Clicfone’s compliance framework is built around the specific obligations that apply to medical telephone answering under GDPR. Practices contracting with Clicfone receive:
- A complete DPA draft with all Article 28(3) annexes, including a named sub-processor list (Annex IV) and TOMs documentation (Annex II), ready for review before service begins.
- Security documentation covering encryption standards, access controls, and incident notification procedures, aligned with CNIL and EDPB expectations.
- Integration guides for Doctolib, LibreRDV, Maiia, and CalenDoc, confirming how appointment data flows are protected and how access is controlled.
- A breach notification SLA designed to give the practice sufficient time to meet the 72-hour regulatory window.
- Staff confidentiality commitments and training documentation available on request.
Onboarding typically follows a structured workflow: DPA review and negotiation (5–10 business days), technical integration setup with the practice’s appointment platform (3–5 business days), and a compliance walkthrough before the first live call. The full process from initial contact to operational service generally takes two to four weeks, depending on the complexity of the practice’s setup.
Pro Tip: Keep a dedicated compliance folder for each processor contract. Store the signed DPA, all annexes, certification evidence, the sub-processor list, and any TPM or audit report received. Auditors expect to see this documentation organized and current, not assembled under pressure after a request.
What auditors actually look for in a medical answering service DPA
Most practices that face a supervisory authority inquiry about their answering service are not caught by a technical failure. They are caught by a documentation gap: a general service contract where a DPA should be, a sub-processor list that was never requested, or a deletion certificate that was never issued.
The practical priority order for any practice is straightforward. Confirm first that a standalone DPA exists and covers all eight Article 28(3) items. Then verify that the sub-processor list is current, named, and contractually locked. Third, check that security evidence, whether a certification or a TPM, is on file and dated within the last two years.
Negotiating Annex IV update rights is worth the effort. A provider that resists giving the practice a right to object to new sub-processors is signaling a compliance posture that will create problems later. Where certification is absent, a TPM from an accredited auditor is the recognized fallback under the BoZ model DPA framework and is accepted by most supervisory authorities as evidence of sufficient guarantees. Store every piece of vendor evidence in the practice’s compliance file alongside the signed DPA.

Request Clicfone’s DPA and compliance documentation
Clicfone’s outsourced medical secretarial service gives private practices and paramedical professionals a direct path to GDPR-compliant telephone answering without the administrative burden of building compliance from scratch. With more than 15 years of specialist experience and over half of its clients having worked with the service for more than a decade, Clicfone provides a compliance pack that includes a ready-to-review DPA, TOMs documentation, a named sub-processor list, and integration guidance for Doctolib, LibreRDV, Maiia, and CalenDoc.

Practices can request the full compliance documentation package, including the DPA draft and security evidence, within five business days of initial contact. A compliance walkthrough and technical integration demo are available before any contract is signed. To receive the compliance pack or schedule a demo, contact Clicfone directly through the secure appointment management guide or visit the main service page to begin the onboarding conversation.
Sources
Storing copies of the following documents in the practice’s compliance file supports audit readiness and demonstrates due diligence to supervisory authorities.
- Gdpr
- Référentiel cabinet (DPA checklist) | Weblex (referential for medical practices)
- Responsable du traitement, sous-traitants : comment bien identifier son rôle ? | CNIL
- EDPB opinion on reliance on processors and sub-processors | EDPB (French text)
- Commission decision on standard contractual clauses (SCCs) and processor clauses | EUR-Lex
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

FAQ
What is a DPA for a medical answering service?
A Data Processing Agreement (DPA) is a mandatory contract under GDPR Article 28 between a medical practice (the controller) and its answering service (the processor). It must cover processing instructions, confidentiality, security measures, sub-processor rules, breach notification, and data deletion or return.
Is a standard service contract enough for GDPR compliance?
No. A general commercial contract does not satisfy Article 28. A standalone DPA addressing all eight Article 28(3) requirements is legally required whenever an answering service handles patient health data, regardless of call volume or contract duration.
When is a DPIA required for outsourced telephone answering?
A DPIA is required when the processing is likely to result in high risk, including large-scale processing of health data, systematic call monitoring or AI-assisted triage, or deployment of new technology such as 24/7 AI agents for patient call handling.
What certifications should a medical answering service hold?
Practices should request ISO/IEC 27001 (information security), ISO/IEC 27701 (privacy management), NEN 7510 (Dutch healthcare standard where applicable), or HDS certification for providers hosting patient records. Where formal certification is absent, a Third Party Memorandum from an accredited auditor is the accepted alternative.
How does Clicfone support GDPR compliance for medical practices?
Clicfone provides a complete compliance documentation pack, including a ready-to-review DPA with all Article 28(3) annexes, a named sub-processor list, TOMs documentation, and integration guides for Doctolib, LibreRDV, Maiia, and CalenDoc, typically delivered within five business days of initial contact.