Regulatory & Compliance

Is clinical AI GDPR compliant?

Is clinical AI GDPR compliant? How data residency, processing scope, and DPAs apply — and where Elna stands today on GDPR, ISO 27001, and ENS Alto.

Miquel Ferrer

Engineer at Elna

This post explains how GDPR applies to clinical AI tools in general terms, and how Elna approaches it. It isn't legal advice: if you're evaluating a tool for institutional deployment, your own DPO or counsel should review the specifics.

Does GDPR apply to clinical AI tools?

Yes. Clinical AI tools that touch patient information, or that clinicians use in the course of patient care, sit squarely inside GDPR's scope. Health data carries extra weight under Article 9 as a "special category" requiring a higher bar to process lawfully. Three questions matter most when evaluating any clinical AI tool.


Where does the data live, and who can access it?

GDPR expects clear answers on data residency, sub-processors, and retention. A tool hosted outside the EU, or that routes queries through infrastructure outside European jurisdiction, adds a layer of complexity institutions have to account for.


What's actually being processed?

A tool that ingests patient-identifying information carries different obligations than one that doesn't. Being precise about what a product does and doesn't collect, and enforcing that technically rather than only contractually, is what separates a real compliance posture from a claimed one.


Is there a signed Data Processing Agreement?

Any institution deploying a third-party tool needs a DPA defining roles, obligations, and breach procedures. If a vendor can't produce one, that's the question to stop on.


Is Elna GDPR compliant today?

Yes. Elna is GDPR compliant, with an external audit currently in progress. It runs on EU-sovereign infrastructure, including Barcelona Supercomputing Center's MareNostrum 5, keeping clinical data and compute inside Europe. By design, our pipeline rejects patient-identifying input before it's ever processed, and the clinical query data behind the product is pseudonymized, so the special-category risk that comes with patient data doesn't carry over to how we build and improve Elna. A Data Processing Agreement is available to institutional customers, and our Data Protection Officer can be reached directly at dpo@elna.health for any GDPR-specific query. ISO 27001 and ENS Alto certification (required for Spanish public-sector procurement) are both in progress; see the compliance roadmap on our Enterprise page for where each stands.

GDPR compliance isn't a badge you earn once. It's an ongoing practice, and one we treat as foundational rather than as a box to check before a sale.