WORLDWIDE PATIENT DATA PROTECTION

Global compliance

Last updated · 10 February 2026

Physiogenic operates across the globe. Wherever your clinic and patients are based, we map the platform's behaviour to the strictest privacy + medical-record laws that apply. This page summarises the frameworks we comply with — and what each means for you in practice.

Privacy frameworks we comply with

  • European Union — GDPR (Regulation 2016/679). Articles 7, 12, 15, 17, 20 are all self-service from /account/security.
  • United Kingdom — UK GDPR + Data Protection Act 2018. Equivalent to EU GDPR; ICO is the supervisory authority.
  • United States — HIPAA + HITECH for protected health information; CCPA / CPRA for California residents; state-level breach notification laws.
  • Canada — PIPEDA federally + provincial laws (Quebec Law 25, Ontario PHIPA, Alberta PIPA).
  • Australia — Privacy Act 1988 + Australian Privacy Principles (APPs), My Health Records Act 2012.
  • New Zealand — Privacy Act 2020 + Health Information Privacy Code 2020.
  • Brazil — LGPD (Lei Geral de Proteção de Dados). Equivalent self-service rights to GDPR.
  • Switzerland — Federal Act on Data Protection (FADP, 2023 revision).
  • Singapore — PDPA (Personal Data Protection Act 2012).
  • UAE — DIFC Data Protection Law No. 5 of 2020.
  • South Africa — POPIA (Protection of Personal Information Act 4 of 2013).
  • India — Digital Personal Data Protection Act 2023.
  • Japan — APPI (Act on the Protection of Personal Information).

Medical record retention — varies by country

Patient records cannot be deleted before the retention window expires, even on a patient's request. We honour the strictest applicable law:

  • 🇵🇱 Poland: 20 years (Act on Patient Rights, Art. 29)
  • 🇫🇷 France: 20 years (Code de la santé publique R.1112-7)
  • 🇩🇪 Germany: 10 years (Patientenrechtegesetz §630f)
  • 🇬🇧 UK: 8–10 years (NHS Records Management Code 2021)
  • 🇪🇸 Spain: 5 years (Ley 41/2002 Art. 17)
  • 🇺🇸 US: 6 years (HIPAA minimum); 7–10 years in most states
  • 🇨🇦 Canada: 10 years (varies by province; Ontario PHIPA: 10)
  • 🇦🇺 Australia: 7 years (adult); until 25 (child)
  • 🇳🇿 New Zealand: 10 years (Health (Retention of Health Information) Regulations)
  • 🇮🇪 Ireland: 8 years (HSE Health Records Management Code)

What we do — regardless of jurisdiction

  • Data residency: every clinic's data sits in the EU (Frankfurt) by default; US/UK/AU regions are available on request for sovereignty-sensitive contracts.
  • Encryption: TLS 1.3 in transit; AES-256 at rest. Patient documents + AI scribe audio are bucket-encrypted with per-clinic keys.
  • Granular consent (7 keys): marketing email, AI scribe, anonymised research, GP outcome sharing, internal clinical audit, photo/video, emergency contact sharing.
  • Self-service: every patient on every plan can download all their data + delete their account from /patient/account.
  • Breach notification: 72 hours for EU/UK/CH/BR; "without unreasonable delay" for US/CA/AU/NZ. We notify clinics in <6 hours regardless.
  • Sub-processors: Stripe (payments), Resend (email), Backblaze B2 (backups), OpenAI/Anthropic/Google (AI). All under DPAs.
  • No data sale, ever: patient health information is never sold, traded, or used for marketing outside your clinic.

Country-specific clinic features

Invoice formats, tax exemptions, and government ID fields auto-render based on your clinic'scountry_code. Examples:

  • PL: NIP/REGON on invoices, KSeF-ready footer, VAT-exempt under VAT Act Art. 43(1)(19), PESEL on patient profile.
  • DE: USt-IdNr on invoices, VAT-exempt under UStG §4 Nr. 14, Versichertennummer on patient profile.
  • FR: SIRET on invoices, VAT-exempt under CGI Art. 261-4-1°, INS-NIR on patient profile.
  • UK: VAT Reg # on invoices, generally VAT-exempt for medical care, NHS number on patient profile.
  • US: EIN on invoices, state-by-state sales tax handling, SSN/Medicare # on patient profile.
  • ES: NIF/CIF on invoices, VAT-exempt under Ley 37/1992 Art. 20.Uno.3°.

If your country isn't listed, contact us — we add new jurisdictions on a 7-day SLA for paying clinics.

DATA PROTECTION CONTACT

For questions, rights requests, or to revoke consent, email our Data Protection Officer.

dpo@physiogenic.pl