Article by Stavros Zoumpoulidis, Senior Associate in the Data Protection Department of our Law Firm on recent guidance issued by the CNIL – Commission Nationale de l’Informatique et des Libertés on AI_systems in healthcare. (published by NOMIKI BIBLIOTHIKI Daily, 20/03/2026)

 

 

 

In his new article, hosted by NOMIKI BIBLIOTHIKI Daily, Stavros Zoumpoulidis LLM, MSc, Senior Associate in the Data Protection Department of our Law Firm analyses recent guidance issued by the CNIL – Commission Nationale de l’Informatique et des Libertés on AI_systems in healthcare, highlighting how data_protection authorities are moving from general principles to practical compliance frameworks for highly regulated sectors.

Rather than treating compliance as an issue that arises only at the point of deployment, the CNIL structures its analysis across the full lifecycle of an AI system:

1. the creation of a health_dataset or data warehouse for future research,
2. the creation of a dataset specifically for AI_development,
3. the deployment of the AI system for its intended use, and
4. the evaluation of the post – deployment impact assessment, with a view to improving the system.

What makes this guidance particularly valuable is that it does not merely restate that health data deserve heightened protection. It organizes compliance in a staged, concrete and operationally useful way, offering a clear reference framework for organizations developing or evaluating AI systems in healthcare.

Read the full article below (in Greek):