DPO PARTAGE
No Result
View All Result
  • Login
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Trouver un DPO
  • Secteurs d’activité
  • Contact
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Trouver un DPO
  • Secteurs d’activité
  • Contact
No Result
View All Result
DPO PARTAGE
No Result
View All Result
Home CNIL FRANCE

New Health Data Reference by CNIL

by Laurent de Cavel - DPO
7 March 2026
in CNIL FRANCE, Medical data
Reading Time: 3 mins read
0
Health data reference framework

Health data reference framework

A lire aussi sur DPO PARTAGE

Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies

Web Analytics and GDPR Compliance: How Website Hosts Can Adhere in France

Health data processing and Health Research Authorization: Key Criteria and Information.

Who are the research data collection authorization requests addressed to?

The grant criteria for a health research authorization stated in the article are general and apply to all research that involves the collection, processing, or storage of personal data for research purposes. However, it is important to note that some types of research, such as research on human subjects, research involving genetic data, or research involving vulnerable populations, may require additional and specific data protection and research ethics requirements. In these cases, it is important for researchers to comply with applicable legal and ethical requirements and take into account the specific needs of the populations concerned.

What the CNIL proposes

The National Commission on Informatics and Liberties has published a resolution on the availability and processing of the general beneficiary sample (EGB) and themed databases called datamarts of the National Health Insurance Information System (SNIIRAM), and it has established a new health data reference.

The resolution was taken in accordance with Regulation (EU) 2016/679 of the European Parliament and Council of 27 April 2016 on data protection, the public health code, the law No. 78-17 of 6 January 1978 as amended relating to information technology, files, and liberties, and resolution No. 2020-072 of 16 July 2020.

The general beneficiary sample (EGB) is a random sample of two percent of individuals whose data appears in the SNIIRAM. It contains the following SNIIRAM information:

the inter-regime consumption datamart (DCIR), also known as the « individual beneficiary database »;

data contained in the medicalization of information systems program (PMSI) on the fields of medicine, surgery, obstetrics and dentistry (MCO), rehabilitation and aftercare (SSR), medicalized information collection in psychiatry (RIM-P) and home hospitalization (HAD).

Aggregate data themed databases called « expense monitoring-oriented datamarts » (DAMIR) or « care offer analysis » (AMOS), as well as biology and pharmacy dashboards are also established from the SNIIRAM.

New health data reference

The resolution aims to replace the reference governing the availability of data from the EGB and themed databases called datamarts of the SNIIRAM established by resolution No. 2020-072 of 16 July 2020.

Treatments eligible for a single approval issued by the Health Data Platform are treatments implemented for research, study, or evaluation purposes in the field of health, justified by the public interest, and for which only access to ESND data and/or datamarts and dashboards of the SNIIRAM is necessary.

Access requests to ESND data and datamarts are submitted to the Health Data Platform and must include several elements, including the justification of the public interest, declarations of interest of the data controller and research laboratory or study office, as well as compliance of the processing registration and transmission of results to the methods defined by the HDP.

Data controllers must set up a transparency portal containing general information on the SNDS, as well as a specific information note for each study.

The HDP annually provides important information on the health of the French population. The data collected in this context allows for the conduct of epidemiological studies, monitoring the evolution of certain pathologies, evaluating the effectiveness of public health policies, and setting up prevention programs adapted to the needs of the population.

For example, the HDP can measure the prevalence of certain chronic diseases such as diabetes, hypertension, or obesity, monitor the evolution of vaccine coverage, detect flu or gastroenteritis outbreaks, identify risk factors for certain diseases such as cancer or cardiovascular diseases, or monitor the population’s exposure to toxic substances.

Voir le site de la CNIL
A lire aussi sur le meme sujet :

  • Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies
  • Health Data Hub : La Plateforme des Données de Santé en France
  • Health data processing and Health Research Authorization: Key Criteria and Information.
Tweet235Share66
Previous Post

Health data processing and Health Research Authorization: Key Criteria and Information.

Next Post

My iPhone has been stolen, what should I do?

Laurent de Cavel - DPO

Looking for a DPO? Entrust your mission to DPO PARTAGE - Contact us at +1 813 768 3616or by email at contact@dpo-partage.fr. DPO PARTAGE is the leader in DPO services for health and sensitive data.

Related Posts

health data hosting in France
Medical data

Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies

7 March 2026
Web Analytics and GDPR Compliance
CNIL FRANCE

Web Analytics and GDPR Compliance: How Website Hosts Can Adhere in France

7 March 2026
Health data processing
CNIL FRANCE

Health data processing and Health Research Authorization: Key Criteria and Information.

7 March 2026
analysis on pornographic sites
CNIL FRANCE

Facial analysis for accessing pornographic sites: CNIL is pragmatic and requires guarantees for the protection of personal data.

7 March 2026
Cnil and AI
CNIL

Cnil and AI: Finding the balance

8 March 2026
Next Post
Theft of my iPhone

My iPhone has been stolen, what should I do?

Digital driving license GDPR

What about the GDPR with the European Commission's proposal for a digital driving license?

APPLICATION RGPD

Démo gratuite

Découvrez DPO SUITE

Gérez votre conformité RGPD de A à Z avec une solution qui anticipe les évolutions réglementaires, sans effort supplémentaire.

Rappel par un expert dans les prochaines minutes

Vos données sont traitées pour répondre à votre demande. En savoir plus.

Demande envoyée !

Un expert DPO PARTAGE vous rappelle
dans les prochaines minutes.

Articles recommandés

Digital driving license GDPR

What about the GDPR with the European Commission’s proposal for a digital driving license?

7 March 2026
GDPR in EUROPE

GDPR in Europe: subtleties to know in France, Spain, and Germany.

8 March 2026
Retrieving a former employee's OneDrive

Retrieve the OneDrive of an employee who has left the company.

8 March 2026

Articles populaires

    DPO PARTAGE DPO externalisé

    DPO Partage se positionne comme un acteur clé dans le domaine de la protection des données personnelles, en offrant une gamme complète de services axés sur le Règlement Général sur la Protection des Données (RGPD). Notre structure fournit des informations régulières et pointues sur les dernières évolutions et exigences du RGPD, ce qui en fait une ressource précieuse pour les entreprises soucieuses de se conformer à la législation.

    Faites appel à DPO PARTAGE pour votre conformité RGPD.
    Contactez nous au 01 83 64 42 98
    En savoir plus »

    Recent Posts

    • Xerox Corp is reportedly the victim of a major cyberattack.
    • Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies
    • Turning GDPR Compliance into Competitive Advantage: Unveiling the New Guide for American Enterprises
    • Web Analytics and GDPR Compliance: How Website Hosts Can Adhere in France
    • Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon
    • Mentions Légales
    • Politique de confidentialité
    • Politique cookies DPO Partagé
    • Nous contacter
    SITE AUDITÉRGPDAudit automatiséby DPO-FRANCE

    © 2026 DPO PARTAGE - Pilote de votre conformité RGPD

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In
    Question ?

    Question ?

    Comment pouvons-nous vous aider ?

    Être rappelé

    Vos données sont traitées conformément au RGPD.

    Voir une démo

    Vos données sont traitées conformément au RGPD.

    Demander un devis

    Vos données sont traitées conformément au RGPD.

    Demande envoyée !

    Nous reviendrons vers vous très rapidement.

    Une erreur est survenue

    Veuillez réessayer ou nous contacter directement.

    Gérer le consentement aux cookies
    Pour offrir les meilleures expériences, nous utilisons des technologies telles que les cookies pour stocker et/ou accéder aux informations des appareils. Le fait de consentir à ces technologies nous permettra de traiter des données telles que le comportement de navigation ou les ID uniques sur ce site. Le fait de ne pas consentir ou de retirer son consentement peut avoir un effet négatif sur certaines caractéristiques et fonctions.
    Fonctionnel Always active
    Le stockage ou l’accès technique est strictement nécessaire dans la finalité d’intérêt légitime de permettre l’utilisation d’un service spécifique explicitement demandé par l’abonné ou l’utilisateur, ou dans le seul but d’effectuer la transmission d’une communication sur un réseau de communications électroniques.
    Préférences
    Le stockage ou l’accès technique est nécessaire dans la finalité d’intérêt légitime de stocker des préférences qui ne sont pas demandées par l’abonné ou l’utilisateur.
    Statistiques
    Le stockage ou l’accès technique qui est utilisé exclusivement à des fins statistiques. Le stockage ou l’accès technique qui est utilisé exclusivement dans des finalités statistiques anonymes. En l’absence d’une assignation à comparaître, d’une conformité volontaire de la part de votre fournisseur d’accès à internet ou d’enregistrements supplémentaires provenant d’une tierce partie, les informations stockées ou extraites à cette seule fin ne peuvent généralement pas être utilisées pour vous identifier.
    Marketing
    Le stockage ou l’accès technique est nécessaire pour créer des profils d’utilisateurs afin d’envoyer des publicités, ou pour suivre l’utilisateur sur un site web ou sur plusieurs sites web ayant des finalités marketing similaires.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    Voir les préférences
    • {title}
    • {title}
    • {title}

    Tapez votre recherche et appuyez sur Entree

    Conformite RGPD Externaliser mon DPO Audit cybersecurite Se preparer a l'IA Act Conformite NIS2 Conformite DORA

    Analyse en cours...

    Analyse IA

    Solution DPO FRANCE

    Devis 24h

    Articles

    Recevoir notre veille ""

    Newsletter via Brevo - desinscription a tout moment

    No Result
    View All Result
    • Accueil
    • Cybersécurité
    • Trouver un DPO
    • Secteurs d’activité
    • Contact

    © 2026 DPO PARTAGE - Pilote de votre conformité RGPD