International Edition
Latest News
Technology

Doctolib Faces Backlash Over Use of 50 Million Users’ Health Data for AI Research

French health data platform Doctolib has initiated a controversial program to use the health data of approximately 50 million users for artificial intelligence research, drawing sharp criticism from data protection advocates over transparency and consent mechanisms. Research Partnership…

Doctolib Faces Backlash Over Use of 50 Million Users’ Health Data for AI Research

French health data platform Doctolib has initiated a controversial program to use the health data of approximately 50 million users for artificial intelligence research, drawing sharp criticism from data protection advocates over transparency and consent mechanisms.

Research Partnership and Data Scope

The AI research initiative operates in partnership with several prominent French entities, including the public research institute Inria, the medical research agency Inserm, and the Université Paris Cité. According to the project parameters, the program aims to identify health risks earlier and streamline clinical treatment workflows. The platform compiles demographic details alongside adult medical records—excluding children—such as diagnoses, prescriptions, consultation reasons, and medical histories. Doctolib retains these records for a five-year period.

To establish legal backing under the European Union’s General Data Protection Regulation (GDPR), Doctolib relies on the legal basis of legitimate interest and adheres to the French data protection authority CNIL methodology MR-004. The company states that the initiative excludes commercial usage, utilizes encryption standards, and hosts all data within European servers. However, the choice of Amazon Web Services (AWS) as a hosting partner has intensified scrutiny regarding potential foreign data access under extraterritorial laws.

Datenschutz Opposition and Opt-Out Concerns

Privacy advocates and consumer protection groups, including the French League for Human Rights (LDH) and consumer association Que Choisir, have condemned the initiative. Critics argue that pseudonymization techniques do not constitute true data anonymization, as distinct data points can be correlated to re-identify individual patients. Observers also note Doctolib’s past scrutiny regarding data handling practices, recalling a previous Big Brother Award given to the company.

The implementation relies on an opt-out framework, requiring users who object to their health data feeding the AI models to take manual action. Privacy organizations contend that timing the announcement during the summer holiday period risks causing many users to miss the brief window to object.

Regulatory Compliance Frameworks

The project highlights the expanding intersection between commercial healthcare platforms and evolving European technology regulations. Organizations handling sensitive medical information must navigate strict compliance standards, including data protection impact assessments and mandatory record-keeping under privacy frameworks. While the current research program directly impacts users in France, similar expansions have previously been evaluated for other European markets such as Germany.

Doctolib is using YOUR health data to train its AI
About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”