What a Healthtech AI Opt-Out Teaches SMEs About GDPR
By Alexandre Saint-Jean

Audio version
Audio version produced by text-to-speech from the article. Our AI charter
In July 2026, Doctolib, France's largest healthcare booking platform, emailed several million patients: their health data would be used for an AI research project, unless they opted out before 1 August. This case goes well beyond healthcare. It illustrates a mechanism any SaaS provider can switch on one day for your own customer data, and one every SME should know how to spot before connecting an AI tool to its own data.
What happened at Doctolib?
On 8 July 2026, Doctolib told its users that a research project run with Inria, Inserm and Université Paris Cité would use their health data to train or evaluate AI models (Leto Legal, 26 July 2026).
The form attached to the email allowed users to object to this use. The effective date was set at 1 August 2026: after that deadline, no objection meant implied authorisation (Leto Legal, 26 July 2026, corroborated by DoctoVox).
An important technical point: the data used is pseudonymised, not anonymised. Pseudonymised data, by its nature, remains potentially re-identifiable under certain conditions. It therefore stays personal data under GDPR, with all the obligations that come with it.
Why does choosing opt-out over opt-in raise questions?
Two consent logics sit in opposition. Opt-in requires explicit prior agreement before any processing. Opt-out assumes agreement and puts the burden of refusal on the user, within a given deadline.
For health data, subject to a particularly strict GDPR regime, choosing an opt-out mechanism over explicit prior consent is a choice that raises legal questions (source: Leto Legal, corroborated by dpo-partage.fr). This is precisely the kind of high-risk processing that, in principle, should trigger a Data Protection Impact Assessment (DPIA) beforehand.
This is not unique to Doctolib. Many consumer or business SaaS tools use the same pattern: a general clause in the terms of service, an informational email, a quiet opt-out. The difference between a compliant case and a questionable one often comes down to how clear the consent is and how sensitive the data involved is.
What should an SME check before connecting an AI tool to customer data?
The Doctolib case gives a checklist directly transferable to any SME considering connecting an AI tool (chatbot, AI-enriched CRM, document processing agent) to customer data.
Do the terms of service allow your data to be reused for AI?
Look for a clause specifying whether your data can be used for "service improvement", "model training" or "research". A vague clause, without a stated purpose or duration, should be clarified in writing with the provider before any connection to an AI tool.
Is the consent mechanism opt-in or opt-out?
Explicit opt-in (a checkbox, a positive user action) is the strongest legal basis. Opt-out (silence means agreement) is weaker, particularly for sensitive data (health, financial data, data about minors). For your own customers, default to opt-in whenever you introduce a new AI use of their data.
Is the processing documented in your GDPR register?
Any new personal data processing through an AI tool must appear in your record of processing activities, with the purpose, legal basis, retention period and recipients. Without an up-to-date register, you cannot demonstrate compliance in an audit. The detail of GDPR obligations specific to generative AI is covered in our dedicated article.
Is a DPIA needed?
According to the CNIL (France's data protection authority), processing health data, biometric data or data at large scale almost always carries a high risk and triggers the DPIA requirement. For routine customer data processed by AI, a DPIA is not always mandatory, but it remains good practice once volume or sensitivity increases.
What should an SME using AI tools already take away from this?
Three habits are enough to avoid reproducing, at a smaller scale, what happened at Doctolib:
- Re-read the terms of service of every AI tool connected to customer data, especially after a product update (adding an AI feature often comes with a new reuse clause).
- Default to opt-in whenever you introduce AI processing on your own customers' data, rather than relying on a legally weaker opt-out.
- Keep your GDPR register up to date for every new AI use, before it goes live, not after.
These three points connect to a broader question: knowing how to tell apart data residency, legal sovereignty and regulatory compliance before choosing an AI provider. That is the full subject of using AI without losing control of your data.
The Doctolib case is not an isolated healthcare story: it is a reminder that the pace of AI adoption often outruns the clarity of the consent that comes with it. Checking these points before signing takes an hour. Discovering them afterwards costs far more.
Frequently asked questions
- Can a SaaS provider use customer data for AI without explicit consent?
- It depends on the legal basis chosen and the sensitivity of the data. Some providers rely on an opt-out mechanism (assumed consent, with the burden of refusal on the user) rather than explicit prior consent (opt-in). The validity of opt-out for sensitive data is legally debatable, but it remains what many terms of service allow unless a user actively objects.
- Does pseudonymised mean anonymous?
- No. Pseudonymised data can, under certain conditions, be re-linked to an identified person. Genuinely anonymised data cannot be re-linked at all, ever. GDPR still treats pseudonymised data as personal data.
- Does an SME need a DPIA before connecting an AI tool?
- A Data Protection Impact Assessment (DPIA) is mandatory when the processing carries a high risk for the people concerned, which is almost always the case for health data or other sensitive data processed by AI. For routine customer data, you must at minimum document the processing in your GDPR register.
- How do you spot an AI reuse clause in terms of service?
- Look for wording such as 'service improvement', 'model training', 'research' or 'partners' linked to your data. If the clause does not specify the exact purpose, the duration, or the opt-out mechanism, that is a warning sign to have checked before signing or continuing to use the tool.