Doctolib will entrust your data to an AI. Why? How can you oppose it?

Doctolib will entrust your data to an AI. Why? How can you object?

July 30, 2026

Doctolib is launching a scientific research program in August that will use the personal data of its 50 million users, intended to "improve healthcare pathways through artificial intelligence," a project that has outraged the League of Human Rights.

What data will be used, how, for what purpose, and can we object to it? What you need to know.

Read also Doctolib launches its artificial intelligence lab

What is it for?

Doctolib recently launched a research laboratory in "clinical AI" with several scientific institutions.

One of the first projects, which will last three years, will " to study how AI tools can help to better anticipate certain risks, based on medical history "patients, and to optimize their journey," says Doctolib.

It will take the form of a thesis carried out by a doctoral student, with two researchers from the HeKA team common to Inria, Inserm and Université Paris Cité, and two from Doctolib.

“ We are moving towards tools designed for healthcare professionals"This allows us, for example, to anticipate," explains Nicolas Barascud, data scientist (statistician) in charge of the unit, to AFP "the progression of a disease already diagnosed" in a patient for adjust its monitoring, its treatmentt”, or “ recommending the right test, referral to a specialist, based on thousands of similar cases“.

Others " possible outcomes" : alert on " an emergency situation" , " rexpect an increased risk "of the onset of a disease, such as diabetes, "within a horizon of one, five, ten years" or "helping caregivers on cases of rare diseases" from "thousands of other cases", according to him.

What data?

The team will be able to use all of the " demographic and health data "adult users" necessary for research purposes", those of their " relatives linked to the Doctolib account "(except for children)," explains Doctolib.

This can include data entered by the patient themselves, or by caregivers in their Doctolib software: Medical history, medications, general health status, diagnoses, treatment progress" , prescriptions, documents and images (imaging exams, blood tests…).

The data will be " pseudonymized"That is to say, dissociated from the patient's identity. They will be kept for a maximum of five years."

Read also Health data: anonymity cannot be guaranteed

What are the concerns about?

If they leaked, these " sensitive data"Intimate, they make people run around" a significant risk of stigmatization, discrimination and abusive profiling", warned the League of Human Rights in a statement, for whom "pseudonymization" is not safe because " various technical methods allow the person to be re-identified.

But cyberattacks are multiplying: the third-party payment platform Almerys had data from millions of customers stolen in May, and the administrative data of 15 million French people were leaked when Cegedim Santé software was hacked this winter…

Read also Social security number, health insurance provider: 33 million French people affected by a cyberattack on third-party payment.

And Doctolib hosts data with Amazon, an American company subject to US laws, which notably allow authorities to access data in the context of criminal investigations, the association argues.

Above all, patient consent is given by default, unless there is an explicit objection, as this scientific research is considered "of public interest", criticized the LDH, the Que Choisir association and internet users.

Read also Doctissimo fined 380,000 euros for collecting personal data

How can we oppose it?

Users were notified by email in early July and can refuse this use of their data, without affecting their use of the services, via an online form. They can also request the deletion of their data by writing to Doctolib (contact.dataprivacy@doctolib.com).

They will then be excluded from the base if they object before the launch of the " technical training phase "of the model, in September."

But " Can we consider that the patients are informed, that the consent given is free "when the information is sent" in the middle of summer"That we need to respond quickly? "That seems problematic to us," commented Juliette Alibert, lawyer and member of the Interhop collective of doctors and researchers, on France Culture on Monday, July 27.

Doctors, who are also notified by email, can also object. But they may not necessarily know that on their account, " An automatically checked box allows the data to be reused for research purposes.", regrets Ms. Alibert.

This option is one of the elements accepted by practitioners when approving the company's latest privacy policy in 2024, Doctolib specifies, indicating that it is possible to modify these settings "at any time".

What protections are available?

Doctolib says it complies with the framework set by the National Commission for Information Technology and Freedoms (MR-004 methodology).

The data, "encrypted", will only be accessible to researchers, in a "closed" and "secure" environment, hosted " in Europe, with trusted partners"The company specifies. They will not be shared for commercial purposes, nor used to train internal AI models."

“More than 10,000 projects” completed or underway, led in particular by university hospitals with “hospital data”, use this methodology, assures Mr. Barascud.

en_USEnglish