A message sent by Doctolib this summer put an unusual question into millions of patients' inboxes: can their health data be used in an artificial-intelligence research programme? The project is due to begin in August 2026 and relies on individual information combined with a right to object.
The issue deserves more than two opposing shortcuts. Doctolib does not say that it sells medical records to advertisers or hands a named database to an American chatbot. But describing data as “secure” or “pseudonymised” does not make the decision trivial either. Medical history, medication, documents and information entered by healthcare professionals can reveal an intimate part of a person's life.
The short answer
| Question | Practical answer |
|---|---|
| Does the project concern appointments only? | No. Published information says health data held in Doctolib professional software may be included. |
| Is the research data directly named? | Doctolib describes measures intended to prevent direct identification; the correct term is pseudonymisation when controlled re-identification remains possible. |
| Is this a sale of data? | Doctolib says it does not sell personal data and funds its business through professional subscriptions. |
| Can users refuse? | Yes. An official form allows users to exercise the right to object before or after the project begins. |
| Does refusal prevent booking appointments? | The objection concerns this research use, not ordinary access to the service. |
This summary does not replace the information notice applying to an individual situation or legal advice. Scope may vary according to the software used by a healthcare professional and the data actually recorded.
What information may enter the project?
France Assos Santé says the programme may use information added by doctors to Doctolib software, including medical history, medication, general health, documents and images. Data about relatives whose appointments are managed through the same account also deserves careful attention.
Several layers are commonly grouped under the phrase “my Doctolib data”:
- account and contact information;
- appointment history and consulted specialties;
- documents sent before or after an appointment;
- clinical observations and data entered in professional software;
- data produced by consultation or dictation assistants.
A patient does not necessarily see every note retained in the professional tool. The relevant question is therefore not only “what did I enter into the app?” but also “what information does my healthcare professional store in the affected software?”.
Pseudonymised does not mean anonymous
Pseudonymisation replaces or separates direct identifiers such as a name or email address. Researchers then work with a technical identifier and the variables required by the study. A separate table or controlled process may still make it possible to identify the person under specific conditions.
Strongly anonymised data can no longer reasonably be linked back to an individual. The distinction matters: pseudonymised data remains personal data and is still governed by the GDPR.
Removing a name does not eliminate every risk. A rare combination of age, condition, location and dates can become distinctive. Security also depends on minimising variables, controlling access, separating systems, recording activity, setting retention periods and supervising research partners.
CNIL guidance explains that healthcare AI development can involve several stages: building a data warehouse, preparing a model-specific dataset, training, validation and evaluation. Each stage requires a purpose, a legal basis and appropriate security measures.
Scientific research and product improvement are not the same
Doctolib carries out several AI-related activities. Features such as telephone and consultation assistants are part of products used by healthcare professionals. The company's help centre says it requests authorisation and, where applicable, patients' explicit consent to use data to improve these products.
The programme starting in August is presented as health research. France Assos Santé explains that many public-interest research projects use information and an opt-out mechanism instead of systematically requesting consent. The framework is not unprecedented, but it requires understandable information and sufficiently specific purposes.
The two regimes should not be confused. Agreeing to a feature during a consultation does not automatically answer every research use, and objecting to the research project does not necessarily disable other processing. Users need to read the exact name and purpose shown in each notice or screen.
How to exercise the right to object
Doctolib provides an official research opt-out form. France Assos Santé says the right can be exercised before the project begins or later.
A cautious process is to:
- open Doctolib directly through the app or by typing
doctolib.fr, rather than following a suspicious message; - confirm that the displayed domain belongs to Doctolib;
- read the project's scope and identify affected people, including relatives attached to the account;
- complete the opt-out form if that is the preferred choice;
- retain the confirmation or a dated screenshot of the request;
- consult the privacy policy when exercising other rights such as access or correction.
The right to object is not a button that deletes all Doctolib data. The company may retain information required to operate the service, meet legal obligations or support other valid purposes. The objection targets the identified research processing.
Beware of fake forms
A widely reported health-data story is ideal material for phishing. A fraudulent email may claim that a medical file must be “protected” within 24 hours, then request a Doctolib password, payment card or identity document.
Never share a code received by text after following an unsolicited link. Open the app yourself, use official settings and inspect the domain. If a page requests disproportionate information, stop and contact support through the official website.
Objecting to research does not require another app, payment or remote access to a phone.
Questions the project will need to answer
Trust cannot rest solely on certification or a reassuring sentence. Patients should be able to understand:
- the precise medical objectives of the first studies;
- which data categories each study uses;
- which partners access data and in what role;
- how long research datasets are retained;
- how pseudonymisation and access controls work;
- what a later objection does to data already prepared;
- which results are published and how patients benefit.
France Assos Santé recognises the value of data-driven research while asking for explanations proportionate to the project's scale. That position avoids a false choice between rejecting every form of research and trusting without scrutiny.
Decide without rushing
Both decisions can be legitimate. Someone may agree that a controlled dataset should contribute to medical research. Someone else may consider their information too sensitive or the available explanation insufficient. The right to object exists precisely to preserve that choice.
The important step is to decide from the actual notice, not an alarming headline or a broad promise. Check the processing involved, distinguish pseudonymisation from anonymisation, use the official form and retain evidence. With health data, clear information is part of security rather than a formality at the end of an email.




Join the discussion
Comments
Loading comments…