All articles

Patient records: retention periods and obligations in France

Patient record retention: active use, archiving, deletion and security obligations. CNIL reference points for private practitioners, with a downloadable factsheet.

Countries covered : France

‘How long should I keep a patient record?’ It is a common question, and the answer calls for some nuance. Retaining a record means more than simply not throwing it away: it means complying with retention periods, access rules and security requirements.

This page summarises the relevant reference points without replacing legal advice.

Retention has three stages

  • Active use: the period of routine use, when the record supports ongoing care.
  • Intermediate archiving: data is then retained outside routine use to meet potential needs, such as a dispute or an audit.
  • Deletion: at the end of the retention period, data is securely deleted or anonymised.

Reference retention periods

Under the CNIL's healthcare framework, health data is kept in active use for five years after the last entry or intervention in the record, then in intermediate archiving for 15 years: 20 years in total before deletion. Certain situations, such as records relating to minors, may justify specific retention periods.

Throughout retention: access and security

For as long as a record is retained, access must remain restricted to authorised people, in accordance with the GDPR and professional confidentiality. Security, including encryption, backups and traceability, applies throughout both active use and archiving.

Download the patient record retention factsheet

Active use, archiving and deletion: the key reference points on one page. Enter your email address to access the PDF:

PDF language: French.

Delete records properly

Deletion is not a minor detail: at the end of the retention period, data must be securely destroyed or anonymised so that it cannot be recovered. Poorly managed deletion creates a risk of data leakage.

Retention and digital tools

A well-designed tool makes retention periods easier to manage: it separates active use from archiving, restricts access and records operations. Delta uses HDS-certified hosting and complies with the GDPR: your documents and longitudinal patient information remain confidential, secure and under your control throughout their lifecycle.

Frequently asked questions

How long should a patient record be retained?

Under the CNIL healthcare framework, data is kept in active use for five years after the last entry or intervention, then in intermediate archiving for 15 years, making 20 years in total. Specific periods apply in certain cases, including records relating to minors.

What is the difference between active use and archiving?

Active use means routine use for ongoing care. Archiving retains data outside routine use for potential future needs, before deletion.

Must the record remain secure throughout retention?

Yes. Restricted access, encryption, backups and traceability apply throughout the entire period, during both active use and archiving.

How should a record be deleted at the end of the retention period?

Securely, through destruction or anonymisation that prevents recovery. Poorly managed deletion creates a risk of data leakage.

Where can I find the exact retention periods for my profession?

Consult the CNIL's resources and, where relevant, the rules specific to your profession. If you are unsure, seek appropriate advice.

Cookie policy