FranceLégifrance
Health-data hosting locked to EU/EEA with transfer map duty
Hosted health-data storage must sit exclusively in the EU/EEA, contracts gain compelled-transfer disclosure clauses, and hosts must publish a live map of third-country transfers and remote access.
By Taxxa AI OyPublished 26 September 2026
A new article R. 1111-9-1 of the code de la santé publique requires that where certified hosting of personal health data on digital media (articles R. 1111-8-8 and R. 1111-9) involves storage of that data, the storage sits exclusively on the territory of an EU Member State or a party to the EEA AgreementLegifrance.
Where the host's or a subcontractor's service involves a transfer — including remote access — of that data to a non-EU/EEA country, it may proceed under a Commission adequacy decision pursuant to article 45 of Regulation (EU) 2016/679Legifrance; absent such a decision, the controller or processor may still transfer under the appropriate safeguards of article 46 provided data subjects have enforceable rights and effective remedies
Legifrance. In that no-adequacy case the hosting contract under I of article L. 1111-8 must record the absence of an adequacy decision
Legifrance and describe precisely the safeguards put in place
Legifrance, plus any further measure securing protection equivalent to EU law
Legifrance.
Article R. 1111-11 on mandatory hosting-contract clauses is extended to match. Clause 4° now spells out data-subject rights in full — access, rectification, erasure and portability, restriction and objection where applicable, under articles 15 to 21 of Regulation 2016/679Legifrance — where the old text mentioned portability only. Clause 8° on access arrangements now also carries any third-country transfer information under the second paragraph of article R. 1111-9-1, including remote access from such a country
Legifrance. A new clause 15° applies where the host or a subcontractor in the hosting chain is subject to a non-EU/EEA country's legislation
Legifrance: the contract lists the extra-European rules that can compel a data transfer or unauthorised access within the meaning of article 48 of the Regulation — or states that no such legislation applies
Legifrance; cites the article 45 adequacy decision
Legifrance; and absent one, sets out the mitigation measures taken against those compelled-transfer risks
Legifrance and describes the residual risks despite them
Legifrance.
A new paragraph III of article R. 1111-11 obliges the host to publish and keep updated a map of transfers of personal health data to non-EU/EEA territory, of any remote access to that data, and of unauthorised-access risks under the 27 April 2016 RegulationLegifrance, in the manner specified by the certification framework under I of article R. 1111-10
Legifrance. Where a controller or patient uses an intermediary that itself relies on a certified host, the intermediary's contract must reproduce the clauses as they stand in the host contract
Legifrance (now paragraph II). The remaining diff is cosmetic renumbering and spacing.
Legal basis: new article R. 1111-9-1 and amended article R. 1111-11 (new clause 15°, new paragraph III) of the code de la santé publique; articles 45, 46 and 48 of Regulation (EU) 2016/679.
Certified health-data hosts and their controllers should move any health-data storage onto EU/EEA territory, insert the new compelled-transfer and adequacy clauses into hosting contracts, and publish the required transfer and remote-access map under the certification framework.