Professional secrecy, psychologists and AI: what the law allows, what it forbids and where the fault lies
The law bans no tool, but it punishes letting what a patient confides in you reach someone who has no right to know it. Here are the exact texts, the question of software vendors, and three concrete situations analysed one by one.
Countries covered : Belgium, Switzerland, France
What French law says about secrecy
The criminal provision, article 226-13
Article 226-13 of the « Code pénal » (French Criminal Code) punishes “the disclosure of secret information” by a person who holds it because of their position, their profession, or a temporary role or mission. The penalty is one year in prison and a 15,000 euro fine.
The key word is “disclosure”. The text punishes making information covered by secrecy known to someone who has no right to know it, whatever the means used. Article 226-14 sets out cases where the law requires or allows this disclosure, such as certain reports of violence.
Does this apply to psychologists?
Yes. The title of psychologist does not create the obligation on its own, but the Ministry of Health confirmed it in an answer published in the « Journal officiel du Sénat » (the French Senate's official journal) on 12 January 2023 (page 209). A psychologist in private practice is bound by secrecy under article 226-13. Psychologists in the civil service are also bound by their status.
The « Code de déontologie des psychologues » (French code of ethics for psychologists), in its 2021 version (signed on 5 June 2021 by 21 professional organisations), points the same way. Three articles matter here.
- Article 7. The psychologist is bound by secrecy “under the conditions and within the limits” of articles 226-13 and 226-14 of the Criminal Code. Secrecy covers everything they learn in the course of their practice, “what is confided to them as well as what they see, hear or understand”.
- Article 6. They protect the data from their work against any indiscretion, “whatever its content and medium”. A note typed into an app is a medium like any other.
- Article 23. They collect, process, file and archive their personal notes in a way that preserves people's privacy. When this data is used for a publication or a presentation, it must be handled with “absolute respect for anonymity”.
Psychiatrists
A psychiatrist is a doctor. Their code of ethics is part of the « Code de la santé publique » (French Public Health Code). Article R.4127-4 states that secrecy “applies to every doctor” and covers “what they have seen, heard or understood”. Article L1110-4 of the Public Health Code adds to this. Every person receiving care has the right to secrecy of the information about them, and this secrecy “applies to all professionals working in the health system”.
What secrecy covers when we talk about AI
Secrecy covers all information about the person (article L1110-4). In practice, with an AI tool, this includes what is said in the session and its transcription, your notes, the summary the tool produces, your clinical hypotheses, and even the simple fact that a given person sees you. A sentence that is clinically harmless is still covered if it reveals who your patient is.
The GDPR, a second layer
Health data is a “special category” under article 9 of the GDPR. Processing it is forbidden in principle, with exceptions. One of them covers healthcare, provided the data is processed by a professional bound by secrecy or under their responsibility (article 9, paragraphs 2(h) and 3). Secrecy and the GDPR therefore work together. The Criminal Code also sets out penalties specific to personal data. Article 226-22 punishes disclosing data to a third party who is not entitled to receive it, including through carelessness (three years and 100,000 euros in that case, with prosecution only on the person's complaint). Article 226-17 punishes processing data without the measures the GDPR requires, including security measures, with five years in prison and a 300,000 euro fine.
For the details of sharing information between care providers (care team, personal notes and patient file), read our article on professional confidentiality for allied health practitioners. Here, we focus on AI tools.
Is a software vendor bound by secrecy?
This is the real question. When you use software, information leaves your head and your notebook and goes to a company. Everything depends on that company's role and on what obliges it to keep quiet.
The health data host, bound by secrecy by law
Article L1111-8 of the Public Health Code governs the hosting of health data collected during prevention, diagnosis, care or social and medico-social follow-up. Four points are useful for you.
- A host using digital media must hold a certificate of conformity (the HDS certification, « Hébergeur de données de santé », the French certification for health data hosting).
- The host and the people under its authority who have access to the data are “bound by professional secrecy”, under the penalties of article 226-13.
- It may not use the data “for purposes other than providing the hosting service”.
- Hosting takes place after the patient has been “duly informed”, unless they object on legitimate grounds.
So the law has planned for this case. When your data is with a certified host, the person on the other side is bound by secrecy too, under the same penalties as you. To find out how to check a certification, see our article on HDS hosting.
The vendor as processor, bound by contract and the GDPR
A software vendor is not always a host itself. It often relies on a certified host and on other providers, including the one that runs the AI model. In every case, article 28 of the GDPR applies. You are the data controller, the vendor is your processor, and a contract must cover the following points in particular.
- It only processes the data on your documented instructions.
- The people authorised to process the data commit to confidentiality (article 28, paragraph 3(b)).
- It does not bring in another processor without your authorisation, and it imposes the same obligations on them.
The Criminal Code does not expressly say that a vendor which does not host data “holds” the secret within the meaning of article 226-13. Its duty to keep quiet then comes from the contract and the GDPR. That is why the contract matters so much. Without it, nothing obliges the company to keep what you send it to itself.
The consumer chatbot without a contract, where nobody is bound
When you use a conversational assistant with a personal account, you accept terms of use. You have no data processing agreement under article 28, the company is not your health data host, and nothing binds it to secrecy towards you. For ChatGPT, according to the vendor's FAQ, conversations from a personal account may be used to train models as long as the model improvement setting (“Improve the model for everyone”) is not switched off, and even temporary chats may be kept for up to 30 days. For consumer generative AI services, the CNIL (the French data protection authority) recommends that you “never share confidential information such as personal data”. According to the same FAQ, ChatGPT's business plans (Business, Enterprise) do not use content for training by default. That is not enough. You also need a data processing agreement and, in France, HDS certified hosting, to be checked plan by plan.
- HDS certified host
- What obliges it to keep quiet. The law (article L1111-8, which imposes professional secrecy and forbids using the data for other purposes)
- What you check. A valid HDS certificate
- Software vendor acting as processor
- What obliges it to keep quiet. The data processing agreement and article 28 of the GDPR
- What you check. The signed agreement, the list of sub-processors and where they are located, and that the data is not used for training
- Consumer chatbot, personal account
- What obliges it to keep quiet. Nothing that protects you as a professional
- What you check. Do not put any patient data into it
The draft guide published by the HAS (« Haute Autorité de santé », the French national health authority) and the CNIL in February 2026 (a working document, open to consultation until 16 April 2026, not yet final) says it in one sentence, “introducing an AI system does not change the rules on professional secrecy set out in article L. 1110-4 of the CSP”. It also recommends asking for proof of HDS certification and having the contract list the sub-processors and where they are located.
Anonymise or pseudonymise, the difference that changes everything
Many practitioners think that removing the name makes the problem go away. That is only true in one specific case, full anonymisation. The two words do not mean the same thing in law.
- Pseudonymising means replacing the elements that directly identify the person (surname, first name, date of birth) with a code or alias. The GDPR defines it as processing that prevents data from being attributed to a specific person “without the use of additional information” kept separately (article 4, point 5). It is reversible. For the CNIL, pseudonymised data “therefore remains personal data”. The GDPR still applies.
- Anonymising means making it practically impossible to identify the person, by any means, and irreversibly. Truly anonymous data falls outside the scope of the GDPR.
The European authorities (Opinion 05/2014 of the G29, the Article 29 Working Party, adopted by the CNIL) give three criteria. It must not be possible to single out a person, to link information about the same person from different sources, or to infer new information about them with near certainty. If even one of these risks remains, you must show through a detailed analysis that the risk of re-identification is negligible.
A concrete example
Take a note from which you have removed the name. “34-year-old patient, night nurse at the only hospital in town, two children, lost her brother in the coach crash last March, difficult return to work.” The name has gone, but the job, the town, the recent tragedy and the family situation are enough for anyone who knows the area a little to recognise her. This is not an anonymous note. It is still health data and still covered by secrecy.
An anonymous version would look more like this. “How can I phrase, in a report, a difficult return to work for a bereaved person, without jargon?” There is no longer a patient behind the question. It is about a general clinical situation.
The five-question test
Before treating a text as anonymous, ask yourself these questions.
- Could the patient recognise themselves if they read this text?
- Could a relative, colleague or neighbour recognise them?
- Does the text mention a rare job, a specific place, a date, a well-known event or an unusual family make-up?
- Could an online search with two or three details from the text find the person?
- Does the text repeat the patient's own sentences, nicknames or details only they could have told you?
A single yes, and the text is not anonymous. In clinical practice, a session account is almost always identifiable, because it is the unique story of one person. A truly anonymous text is usually a general question, with no patient behind it.
Three situations, three analyses
The three cases below show where the fault lies. They are analyses based on the texts, not court decisions. None of the texts quoted expressly mentions AI, and the law does not settle everything.
Situation 1. You paste a named note into a consumer chatbot
What happens. After your sessions, you copy your session note, with the patient's first name and details of their story, into a chatbot on your personal account so it can tidy it up.
What the texts say. Information covered by secrecy leaves your practice and goes to a company that is not your HDS host, not bound to you by a data processing agreement, and not bound to secrecy towards you. None of these texts mentions AI. But this transfer comes very close to what article 226-13 targets, making secret information known to a third party. It may also fall within article 226-22 (disclosing data to a third party not entitled to receive it), and it does not meet the GDPR conditions on processors, since there is no contract. The CNIL recommends never putting personal data into these services.
What we can conclude. This is the situation where the risk of fault is clearest. If there is a fault, it lies in the transfer itself, whether or not there is a leak afterwards, and whether or not the patient finds out. Switching off training or paying for a personal subscription does not change the analysis, since the company remains a third party with no contract binding it to you. For useful ways to use these tools without patient data, see our article on ChatGPT for psychologists.
Situation 2. You use a tool designed for healthcare, with a contract and pseudonymisation
What happens. You use note-taking software for practitioners. The data is with an HDS certified host, the vendor has signed a data processing agreement with you, the patient's name and identifying information are pseudonymised before going through the AI, and the data is not used to train models.
What the texts say. This is the framework the law has set up. The host is bound by secrecy under article L1111-8. The vendor is bound to confidentiality by the contract (article 28 of the GDPR). Pseudonymisation reduces what is exposed at each step. But it does not make the health data disappear, and the GDPR still applies.
What we can conclude. You remain the data controller. That means checking the documents (HDS certificate, contract, list of sub-processors, place of processing, use of the data), informing the patient, respecting any objection they raise, and reviewing what the tool produces. This framework does not protect you from everything, but it matches what the texts provide for.
Situation 3. You ask an AI to rephrase a fully anonymised text
What happens. You want to improve the wording of a general paragraph for a psychoeducation handout, or ask how to structure a report. The text contains no information about any specific patient.
What the texts say. If the text meets the three anonymisation criteria, it contains no personal data and the GDPR does not apply. Nor does it contain secret information about a person, since it cannot be attributed to anyone. Article 23 of the code of ethics requires precisely this “absolute respect for anonymity” when data is used for a presentation.
What we can conclude. Everything depends on the quality of the anonymisation. If the text is truly anonymous, this does not appear to be a breach of secrecy. If it is a session account with only the name removed, you are back in situation 1. If in doubt, apply the five-question test, and prefer a general question to a rewritten case.
- Named note in a consumer chatbot
- Data involved. Identifying health data
- Who is bound by secrecy on the other side. Nobody
- Cautious reading. Outside the legal framework, risk of fault from the moment of transfer
- Health tool with HDS, contract, pseudonymisation
- Data involved. Pseudonymised health data
- Who is bound by secrecy on the other side. The host (by law) and the vendor (by contract)
- Cautious reading. Framework provided by the texts, to be checked on the documents, patient informed
- Truly anonymous text
- Data involved. No personal data
- Who is bound by secrecy on the other side. Not applicable
- Cautious reading. No secrecy at stake if the anonymisation is real
What to tell the patient
Secrecy protects the patient. It makes sense for them to know how their information is handled. Several texts point this way. Article L1111-8 provides that their health data is hosted after they have been duly informed, and that they can object on legitimate grounds. The GDPR requires people to be informed about how their data is used. The French code of ethics for psychologists asks practitioners to seek the free and informed consent of the people who consult them and to explain clearly how the work will be carried out (article 9). The HAS and CNIL draft guide considers that clear information, with a right to object, is generally enough for routine care use, while noting that some acts require consent.
In practice, the information covers four simple points. The tool used and what it is for, where the data is, who can access it, and the fact that the patient can refuse without it changing their care. Here is a possible wording, to say at the start of the first session with the tool.
“For my notes, I use a tool that transcribes what is said during the session and helps me prepare a summary that I review. The data is hosted in Europe by a host certified for health data, your name is replaced by a code before processing, and nothing is used to train AI. If you would rather I did not use it, just tell me. I will take my notes another way and it changes nothing about our work.”
Adapt the text to the tool you actually use. Only announce what you have checked. If the patient refuses, note it in their file and do not use the tool with them. For practical questions (poster, information sheet, minors, couples therapy), read our article on consent to AI note-taking.
Checklist before using an AI tool
- Is the data hosted by an HDS certified host? Ask for the certificate.
- Do you have a signed data processing agreement (article 28 of the GDPR), and not just terms of use?
- Does the agreement list the sub-processors, including the one that runs the AI, and the country where the data is processed?
- Does the agreement rule out using your data to train models?
- Are the name and identifying information removed or replaced before going through the AI?
- How long is the data kept, and is any audio deleted?
- Can you retrieve and delete a patient's data if they ask?
- Have you planned how to inform your patients and note a refusal?
If you cannot answer yes to the first three questions, do not put patient data into it.
How Delta works
Delta is an AI assistant for mental health and allied health practitioners. During the session, Delta transcribes what is said, then prepares a session summary that you review. You can also dictate your observations just after the session. The summary takes your speciality and therapeutic approach into account, and it is added to the patient's file, so you can find the whole follow-up and how it has evolved in one place.
On secrecy, Delta was designed for situation 2 of this article. The data is hosted in France on infrastructure certified for health data (HDS), AI processing takes place on servers located in France, the patient's name and identifying information are pseudonymised before going through the AI, no audio file is kept, the data is never used to train models, and it is encrypted in transit and at rest. Delta also drafts your assessment reports, letters and certificates.
Frequently asked questions
Is it a breach of professional secrecy to put a session note into ChatGPT?
If the note identifies the patient and you use a personal account, the information goes to a company that is bound to secrecy neither by law nor by a contract with you. The texts do not mention AI, but this comes very close to the disclosure that article 226-13 of the French Criminal Code punishes. Removing the name is not enough if other details make the person recognisable.
Does switching off training or using a temporary chat solve the problem?
No. These settings limit how the data is reused, but the information has still been sent to a third party. According to the vendor's FAQ, a temporary chat may also be kept for up to 30 days. And there is still no data processing agreement and no HDS certified hosting.
Is a health software vendor bound by professional secrecy?
An HDS certified host is, by law (article L1111-8 of the French Public Health Code), under the penalties of article 226-13. A vendor that does not host data itself is bound to confidentiality by the data processing agreement required by article 28 of the GDPR. That is why you should ask for this agreement.
Is pseudonymised data still covered by secrecy?
Yes. The CNIL points out that pseudonymised data is still personal data, because the person can be identified with additional information. It is still health data and still covered by secrecy. Pseudonymisation reduces the risk, it does not release you from any obligation.
What does a psychologist risk for a breach of secrecy?
Under criminal law, one year in prison and a 15,000 euro fine (article 226-13). Disclosing personal data to a third party not entitled to receive it is punished separately (article 226-22, three years and 100,000 euros if it results from carelessness, with prosecution only on the person's complaint).
Should you tell the patient when you use an AI tool?
Yes, they must be informed. Article L1111-8 provides for informing the patient about the hosting of their data, the GDPR requires people to be informed, and the French code of ethics for psychologists asks for free and informed consent to the work. The practical details are covered in our article on consent.
Are the rules the same in Belgium and Switzerland?
The principle is the same, the texts differ. In Belgium, secrecy falls under article 352 of the new Criminal Code since 1 September 2026 (formerly article 458). In Switzerland, article 321 of the Criminal Code expressly names psychologists, doctors and their auxiliaries. HDS certification is specific to France.
Sources
- Code pénal, article 226-17 (Légifrance)
- Code pénal, article 226-22 (Légifrance)
- Code de la santé publique, article R4127-4 (Légifrance)
- Code pénal, article 226-13 (Légifrance)
- AP-HP, Affaires juridiques, le secret médical (articles 226-13 and 226-14)
- Code de la santé publique, article L1110-4 (Légifrance)
- Code de la santé publique, article L1111-8 (Légifrance)
- Code de déontologie des psychologues, consolidated version as of 9 September 2021
- Syndicat national des psychologues, le secret professionnel
- FFPP, les psychologues et le secret professionnel
- Conseil national de l'Ordre des médecins, article 4, secret professionnel (R.4127-4 CSP)
- CNIL, GDPR, chapter 1 (article 4, definitions)
- CNIL, GDPR, chapter 2 (article 9, health data)
- CNIL, GDPR, chapter 4 (article 28, processor)
- CNIL, les sanctions pénales (articles 226-17 and 226-22)
- CNIL, l'anonymisation de données personnelles
- CNIL, le G29 publie un avis sur les techniques d'anonymisation
- CNIL, questions and answers on using a generative AI system
- HAS and CNIL, Accompagner le bon usage des systèmes d'IA en contexte de soins (working document, 16 February 2026)
- CNIL, HAS and CNIL public consultation on the draft guide on AI and health
- OpenAI, Data Controls FAQ
- Union des Villes et Communes de Wallonie, the new Criminal Code and professional secrecy
- Droits Quotidiens, nouveau Code pénal, quels changements pour le secret professionnel
- Belgian police, entry into force of the new Criminal Code
- Commission des Psychologues, code de déontologie des psychologues (Belgium)
- Swiss Criminal Code, article 321 (text reproduced)
- FMH, guide concernant les conventions de confidentialité et de traitement des données en sous-traitance (March 2023)
Try Delta for 14 days
Try Delta in your next sessions and find a summary ready to review after each appointment.
Try it free