Health is not just another sector. It is the only one where poorly governed data becomes a vital risk.

KDPO does not apply a generic method to health as an afterthought. The practice was built within this sector — European-scale pharmacovigilance, digital medical devices, health and prevention data in insurance — before it was formalised into a method.

Why health is a special case

Cross-application of the offers to the health sector

DPO in health — registers and DPIAs on high-risk processing (patient data, clinical research data), digital health vendor audits, breach procedures adapted to the criticality of health data

Cybersecurity in health — HDS hosting verification, security audits of digital medical devices, security by design on health and remote monitoring applications

AI in health — AI Act compliance for medical devices and decision-support software, governance of AI use cases on health data warehouses, scoping of research projects using health data

The transparency portal — making compliance visible

In health, trust cannot be declared — it must be shown. Patients, authorities (CNIL, HAS), partners and funders increasingly expect to see how data is processed, not just that a privacy policy exists. The RGPD requires transparency (art. 12-14), but a dense legal document reassures no one.

KDPO maps your health data processing, identifies what must be made visible, and builds a portal that presents it clearly — which data, why, for how long, with which rights. A trust tool, not a ticked box.

Discover the transparency portal →

Four priority environments

Pharmaceutical companies

Patient programmes, clinical trials, pharmacovigilance, data/AI partnerships, digital solutions.

Health startups

Patient apps, telemedicine, digital health platforms, connected devices.

Medical devices / AI

SaMD, AI health solutions, CE marking, training datasets, algorithmic traceability.

Health, prevention & life insurers

Medical questionnaires, risk selection, health scoring, prevention, sick leave, claims, life underwriting with medical component.

What you get

  • A map of health data flows across the chain, including rank-2 subcontractors
  • An integrated regulatory dossier: RGPD Art. 9 × HDS × MDR × AI Act
  • DPIAs on high-risk health processing, with remediation plan
  • HDS hosting verification and a documented, defensible product lifecycle

Track record

Steering of compliance programmes in a European pharmaceutical environment, DPIAs and security audits on digital medical devices (including a remote monitoring device reimbursed by French national health insurance), data and AI governance on a multi-division datahub in health and prevention insurance. Participation in health data challenges (medical imaging, genomic data, dental).