If your telehealth platform or clinical call center transcribes patient-doctor conversations, standard GDPR compliance is no longer enough to protect your business from severe legal liability in France. The moment your speech-to-text API processes audio on a non-HDS-certified server, your compliance chain breaks, and the consequences are not hypothetical. Healthcare data breaches cost an average of $7.42 million, and French law imposes significant penalties for entities that fail to hold the required certification.
To scale a voice product in the French healthcare sector, every subcontractor in your audio pipeline must hold HDS (Hébergeur de Données de Santé) certification. This guide explains the legal mandates of French health data hosting, defines the boundaries of voice data residency, and provides a procurement checklist to verify your speech-to-text infrastructure.
HDS compliance: securing French healthcare voice data
HDS legal requirements in France
Article L.1111-8 of the French Public Health Code requires any person hosting personal health data (Données de Santé à Caractère Personnel) collected during preventive, diagnostic, care, or social and medico-social monitoring activities to hold a valid HDS certificate of compliance. The French Agence du Numérique en Santé (ANS) manages and enforces these standards. Failure to hold the certificate carries criminal sanctions under Article L.1115-1 of the Code de la santé publique of up to three years imprisonment and a fine of €45,000. For legal entities, Article 131-38 of the French Penal Code applies a standard fivefold multiplier to criminal fines, bringing the maximum exposure to €225,000.
The HDS v2.0 certification framework will replace v1.1, with all v1.1 certificates becoming invalid as of May 16, 2026. The framework incorporates amendments from the law of May 21, 2024 and upcoming regulatory changes, which will impose additional data sovereignty obligations. The framework focuses on improving the readability of guarantees provided by certified hosts and clarifying contractual obligations under the Public Health Code.
Liability risks for French health data
Healthcare data breaches carry a $7.42 million average cost according to 2025 breach cost data. For a Head of Product, the risk is also direct: an HDS compliance failure can invalidate enterprise contracts with hospital networks or insurance providers and trigger scrutiny from the ANS over your technical vendor decisions.
Mandatory HDS use cases in France
HDS certification applies to systems that host or process personal health data in a clinical context. Voice products in scope include:
- Telehealth and teleconsultation platforms transcribing patient-doctor consultations in real time or post-call.
- Clinical call centers routing, recording, and analyzing patient support calls.
- EHR (Electronic Health Record) and EMR (Electronic Medical Record) integration tools generating automated clinical notes from doctor dictation or voice input. If your voice product touches any of these workflows and routes audio through a third-party API, that provider is a subcontractor (sous-traitant) under French law and must hold active HDS certification.
Meeting HDS requirements for voice API processing
Voice data under French privacy law
Under GDPR, voice recordings constitute personal data. Whether they additionally qualify as personal health data under Article L.1111-8 (triggering HDS certification requirements) depends on the nature of the activity in which they were collected. Recordings from preventive, diagnostic, care, or medico-social monitoring contexts are the clearest in-scope cases, but classification should be confirmed with legal counsel before routing patient audio through any third-party API. Text redaction applied after transcription does not excuse non-compliant processing: if audio was processed on a non-HDS-certified server during inference, the violation already occurred regardless of downstream cleaning.
Defining HDS data residency boundaries
Understanding where your voice data lives at each stage of the pipeline is the foundation of HDS compliance. A compliant STT pipeline must account for three distinct layers:
- Data at rest (storage): The physical location where raw audio files and final transcripts are stored after processing.
- Data in transit (processing): Where the audio is streamed or uploaded during the transcription inference step. Many STT pipelines route audio through non-EEA (European Economic Area) API gateways during inference, even when final storage is in France.
- End-to-end pipeline integrity: The full data path, including all infrastructure components your vendor operates. HDS certification must cover the specific activities your vendor performs on health data, not just the storage endpoint. A vendor that stores output in France but runs inference through non-EEA infrastructure does not satisfy HDS requirements.
Subcontractor audits and HDS requirements
Under French law you, as the data controller, are responsible for ensuring every subcontractor in your audio pipeline holds active HDS certification. Subcontractor audits must confirm:
- An active HDS v2.0 certificate covering Scope 5 and Scope 6 (administration and backup).
- A signed Data Processing Agreement (DPA) that explicitly references HDS obligations.
- Documented access controls and audit trails for any remote administrative access to health data environments.
- Clear contractual commitments on data deletion timelines and zero-retention options.
Verification criteria for HDS-compliant STT
Data residency vs. data sovereignty
These terms describe different compliance properties:
- Data residency refers to the physical location where data is stored and processed.
- Data sovereignty refers to the legal jurisdiction governing that data, including which governments can compel access. The US CLOUD Act can require US-headquartered companies to produce data stored in Europe under a qualifying order.
EU residency is a baseline requirement for HDS compliance, but not a complete solution. A provider can host data in Paris and still be subject to US law if the parent company is US-incorporated. HDS v2.0 addresses this through data sovereignty provisions that require certified hosts to ensure data remains under EU legal jurisdiction, limiting extraterritorial access requests under frameworks like the US CLOUD Act.
Meeting French health data standards
HDS v2.0 introduces specific requirements across three areas:
- Remote access transparency: Under HDS v2.0's remote access transparency requirements, certified hosts must define and maintain a documented process for allocating, administering, and annually reviewing authentication and access rights for remote administrative access.
- Subcontractor monitoring: Certified hosts must maintain a current register of all subcontractors processing health data, each holding valid HDS certification.
- Contractual clarity: Agreements between the data controller and the certified host must define the scope of services, data processed, and the obligations of each party. A v1.1 certificate has not been valid since May 16, 2026. Treat HDS v2.0 certification as the minimum entry requirement in any vendor evaluation.
Data retention and HDS compliance
For voice products, data retention is the highest-risk compliance variable. Patient audio stored beyond the minimum necessary period expands the attack surface and increases breach exposure. A strong retention posture for clinical voice pipelines minimizes the window during which audio, transcripts, and metadata are held on vendor infrastructure.
Securing data beyond French borders
A Zero Trust architecture for STT pipelines treats every component as a potential breach point and applies continuous verification at every layer:
- Encrypted channels: All audio in transit uses TLS 1.2 or higher, with no unencrypted streams leaving the client environment.
- Logical isolation: Processing occurs in logically isolated cloud environments with strict workload segmentation, access controls, and continuous monitoring.
- Identity-based access controls: Administrative access to the processing environment is logged, time-limited, and governed by verified identity rather than network location.
- Routing verification: Confirm during proof of concept that your API calls remain within EEA-based infrastructure throughout processing, not just at the storage layer.
How we satisfy French healthcare data laws
Our HDS certification and compliance scope
We hold HDS certification, the full scope of which is documented at our compliance hub. Before signing any DPA, confirm directly with us, and verify against the ANS registry, that the certificate scope covers the specific activities your pipeline requires.
HDS Scope 5 covers the administration and operation of information systems containing health data, including managing access, monitoring systems, and carrying out technical interventions. Scope 6 covers outsourced data backup operations. When evaluating any STT vendor for French healthcare deployments, confirm that their certificate explicitly covers Scope 5 and Scope 6. A certificate covering only physical hosting does not satisfy the requirements for an API-based service performing operational processing on health data. One architectural constraint to state clearly: our HDS-compliant deployments run on dedicated cloud clusters in our EU region.
Meeting local data residency mandates
Our dedicated EU clusters route all audio processing, inference, and output delivery within the EEA, covering storage, processing, and end-to-end pipeline integrity within the certified cluster.
For French clinical and business audio, Solaria-3 is built for exactly the conditions that degrade generic STT, such as background noise, fast-paced conversation, accented speakers, and mixed-register medical terminology. The accuracy breakdown by language is in the table below.
Solaria-3 accuracy improvements on European conversational audio vs. Solaria-1:
| Language |
Improvement vs. Solaria-1 |
Best for |
| French |
18% lower WER |
Clinical notes, teleconsultation |
| English |
26% lower WER |
Business calls, contact centers |
| Italian |
10% lower WER |
Multilingual EU deployments |
| Spanish |
9% lower WER |
Multilingual EU deployments |
| German |
3% lower WER |
Business audio, financial calls |
Solaria-3 is async only. For real-time streaming or non-European languages, Solaria-1 covers 100+ supported languages and retains an advantage on clean read-speech.
Defining your data retention lifecycle
Data usage policy varies by plan, and this distinction is critical for healthcare deployments:
- Starter plan: Customer data can be used for model training by default. This plan is not suitable for patient audio under any HDS deployment.
- Growth plan: Customer data is never used for model training, with no opt-out action required.
- Enterprise plan: Customer data is never used for model training. Enterprise customers can additionally configure Zero Data Retention (ZDR), ensuring audio is processed ephemerally and deleted immediately after the API response is delivered.
ZDR on the Enterprise plan means audio cannot be retrieved via the API or console after processing. Transcript delivery is configured at the application layer via the delete transcription endpoint, which allows explicit lifecycle management within your own infrastructure rather than relying on vendor-side retention defaults. Audio and transcript are deleted once transcription completes and the API response is delivered. Metadata retention behavior should be confirmed with our team during your compliance review, as deletion scope and timing may vary by configuration. Note that applicable retention timelines for patient audio vary by jurisdiction and use case. HIPAA does not prescribe a fixed retention period, and state-level regulations vary widely by state and record type, with no consistent range across jurisdictions. Consult legal counsel to determine whether ZDR is appropriate for your specific clinical workflow or whether a defined retention period with controlled deletion is required.
Our audio intelligence features, including speaker diarization (identifying who spoke when) and named entity recognition (NER), are included in the base rate with no add-on fees on Growth and Enterprise plans. Diarization is available in async mode, covering post-call clinical note generation and quality monitoring workflows.
Sample API request: Solaria-3 French transcription with PII redaction enabled
```json
{
"audio_url": "https://your-secure-storage.eu/patient-audio.wav",
"language_config": {
"languages": ["fr"],
"code_switching": false
},
"model": "solaria-3",
"diarization": true,
"pii_redaction": true,
"pii_redaction_config": {
"entity_types": [
"NAME",
"DOB",
"PHONE_NUMBER",
"HEALTHCARE_NUMBER"
],
"processed_text_type": "MARKER"
},
"callback_config": {
"url": "https://your-app.eu/transcription-webhook"
}
}
```
This request structure follows the pattern documented in our API reference documentation. PII redaction must be explicitly enabled in your API request. It does not activate by default, and failing to enable it on patient audio is a configuration error with compliance consequences.
Evaluating HDS vendors: a product leader's checklist
Verifying French HDS certification status
Request the vendor's official HDS certificate and confirm two things:
- The certificate is issued under HDS v2.0 (not the now-invalid v1.1 framework).
- The certificate explicitly covers Scope 5 (administration and operation) and Scope 6 (data backup) as defined by the ANS.
A certificate covering only physical hosting activities does not satisfy the requirements for an API-based STT subcontractor performing operational processing on health data. Verify the vendor's certification status directly with the French Agence du Numérique en Santé (ANS) registry at esante.gouv.fr rather than relying on vendor self-attestation.
Validate local data storage in France
Request documentation confirming that all API calls, including inference, are processed on EEA-based infrastructure. Ask the vendor to provide:
- IP ranges of all processing nodes used for your API calls.
- Confirmation that no non-EEA endpoints are activated for your account.
- Written confirmation that load balancing and routing remain within the EEA throughout the transcription pipeline.
Assess DPA clauses for HDS compliance
A Data Processing Agreement for a healthcare voice pipeline must include:
- Explicit reference to Article L.1111-8 and HDS certification obligations.
- Data retention timelines with contractually binding deletion guarantees.
- Subcontractor registers listing every downstream service that touches your audio.
- Audit rights allowing you to verify compliance during the contract term.
- Incident notification timelines meeting GDPR's 72-hour requirement and any additional HDS-specific reporting obligations.
During proof of concept, request audit logs showing data routing paths and have the vendor walk through their subcontractor list. Any gap in the subcontractor chain is your liability as the data controller.
Ensure permanent removal of French data
Confirm through contract language and technical documentation that zero-retention configurations are available at your chosen plan tier, deletion covers audio, transcript, and metadata immediately post-transcription, and no backup copies are retained in secondary storage outside your agreed data region.
Audit your subcontractor data flows
Map every third-party API your STT vendor uses during the inference pipeline. Common hidden subcontractors include cloud infrastructure providers, inference services routed through a third party, and logging platforms that may capture audio metadata. Each must hold active HDS v2.0 certification or be excluded from the health data processing path entirely.
Audit medical terminology accuracy
Generic STT benchmarks do not predict performance on clinical French audio. The blind STT comparison tool strips provider branding so you select the better transcript before seeing which vendor produced it. Use it as an initial test, then follow with a reproducible benchmark on your full audio distribution before making a production commitment. For French medical terminology, also evaluate custom vocabulary support for institution-specific drug names, diagnostic codes, and anatomical terms not covered by the base model.
Compliance risks when scaling health data storage
The decision to self-host or buy HDS-certified infrastructure comes down to speed, cost, and accuracy:
| Evaluation criteria |
Self-hosted open-source (build) |
Our HDS-certified API (buy) |
| Time to production |
Months of compliance and infra setup |
Under 24 hours (technical integration) |
| Upfront compliance cost |
Full HDS audit and certification process |
Vendor holds active HDS v2.0 certification. No separate audit burden on your team |
| Annual maintenance |
DevOps overhead plus audit renewal |
Infrastructure and HDS certification renewal managed on our side. No DevOps overhead or audit process on yours |
| French conversational accuracy (Solaria-3) |
Baseline varies by model and configuration |
Highest accuracy on French conversational audio in the language breakdown above |
| Data sovereignty guarantee |
Depends on your hosting provider's certifications |
Dedicated EU clusters, HDS certified |
| Diarization for multi-speaker audio |
Requires additional setup and tuning |
Included, async |
| Pricing structure |
Infrastructure plus DevOps plus audit costs |
Public per-hour pricing, all features included |
Self-hosting shifts the compliance problem rather than solving it: you must obtain HDS certification for your own infrastructure, which requires a formal audit process before you can touch patient audio in production. Our async benchmark provides a reproducible methodology to evaluate transcription accuracy on your own audio distribution before committing.
Distinguishing GDPR from HDS requirements
GDPR governs general personal data privacy across the EU. HDS is a specialized security framework mandated by French law specifically for health data. They overlap but are not interchangeable:
- GDPR defines rights, legal bases, and breach notification obligations.
- HDS specifies the technical and organizational security requirements for infrastructure processing health data.
A product can be GDPR-compliant and HDS-non-compliant simultaneously. Providers like Deepgram and AssemblyAI offer low-latency English transcription and EU data storage options, but have not publicly stated HDS certification, which ends the evaluation before accuracy or pricing enter the conversation. Our call recording compliance guide covers how GDPR, HIPAA, and HDS interact for regulated audio environments.
Validating subcontractor HDS compliance
A major cloud provider's HDS certification does not automatically extend to every service running on their infrastructure. Certification covers the provider's own hosting services, not the applications or APIs deployed on top of them. The STT vendor must hold their own independent HDS certificate covering the specific activities they perform on health data. Verify this directly with the ANS registry.
Speechmatics offers on-premises deployment as an alternative path to sovereignty, removing the subcontractor compliance question by keeping data within your own infrastructure. The trade-off is integration complexity and the absence of Solaria-3's French conversational accuracy on the same timeline.
Risks of non-compliant STT hosting
Operating a French health voice product on non-HDS-certified STT infrastructure carries three distinct risk categories:
- Regulatory: French regulators can suspend your product's ability to operate in the French healthcare market and impose criminal sanctions on individuals who authorized the non-compliant setup.
- Contractual: Hospital networks, insurance companies, and government healthcare agencies typically include HDS compliance as a contract condition. Non-compliance voids these agreements and can trigger clawback provisions.
- Reputational: A compliance breach involving patient audio in France generates regulatory publication of the incident, creating lasting damage that affects future procurement decisions across the European healthcare market.
For CCaaS platforms and clinical call centers processing French audio at scale, getting this right is measurable. Gravite, a French CCaaS quality-monitoring platform, achieved a 93% reduction in review time processing 50,000 hours of audio per year, dropping a 15-minute review to under one minute per call. That level of automation is only viable when the underlying transcription is accurate enough to trust without manual verification of every record.
Start building on HDS-certified infrastructure
Start with €50 in free credits and have your integration in production in less than a day. Contact our sales team to configure a dedicated, HDS-compliant EU cluster on our Growth or Enterprise plan. The same dedicated EU infrastructure and compliance posture that covers healthcare audio also applies to multilingual contact center deployments outside the clinical context.
FAQs
Is HDS certification required if we only transcribe audio but do not store it?
Yes. Article L.1111-8 requires certification for hosting personal health data, and HDS requirements typically extend to processing activities performed on that data during transcription workflows, so transcription without long-term storage still requires HDS certification from your STT provider.
Can we use US-based STT providers if they host data in Europe?
Only if they hold active HDS v2.0 certification and can confirm that no audio routes outside the EEA during processing, including at the inference layer. European data storage alone does not satisfy HDS requirements.
How do we handle PII redaction in a compliant voice pipeline?
We offer optional, configurable PII redaction that removes names, dates of birth, and phone numbers from transcripts. It must be explicitly enabled in your API request and does not activate by default.
What is the difference between HDS Scopes 5 and 6?
Scope 5 covers the administration and operation of information systems containing health data, including access management and technical interventions. Scope 6 covers outsourced backup operations. Both are relevant when evaluating an API-based STT vendor that manages its own processing infrastructure on your behalf.
Does our data train Gladia's models on the Growth or Enterprise plan?
No. On Growth and Enterprise plans, your audio is never used for model training and no opt-out action is required. On the Starter plan, data can be used for training by default, making Starter unsuitable for patient audio under any HDS-compliant deployment.
Key terms glossary
HDS (Hébergeur de Données de Santé): France's mandatory certification framework for any entity hosting personal health data, governed by Article L.1111-8 of the French Public Health Code. Certification is issued and enforced by the Agence du Numérique en Santé (ANS). HDS v2.0 replaced v1.1 as of May 16, 2026. Any vendor still operating under a v1.1 certificate is non-compliant for new healthcare deployments. HDS covers both technical security requirements and contractual obligations between the data controller and every subcontractor in the processing chain.
WER (Word Error Rate): The standard metric for measuring transcription accuracy, calculated as the number of substitutions, deletions, and insertions in a predicted transcript divided by the total number of words in the reference transcript. A lower WER indicates fewer errors. For clinical audio, WER must be evaluated on domain-representative recordings.
Diarization: The process of segmenting an audio recording by speaker identity, answering "who spoke when" across a multi-speaker conversation. Diarization is a distinct layer from transcription and requires a separate model. In our pipeline, diarization is powered by pyannoteAI's Precision-2 model and is available in async (batch) mode only.
Code-switching: The practice of alternating between two or more languages within a single conversation, or within a single utterance. Code-switching is common in multilingual clinical environments, and requires explicit model support to transcribe accurately without degrading WER across both languages.
DPA (Data Processing Agreement): A legally binding contract between a data controller and a data processor defining the scope of personal data processed, retention timelines, deletion obligations, subcontractor registers, audit rights, and breach notification procedures. Under GDPR and HDS, a signed DPA that explicitly references Article L.1111-8 obligations is mandatory with every subcontractor in your audio pipeline before any patient audio is processed.
Data residency: The requirement that data be stored and processed within a specified geographic jurisdiction. For HDS compliance, audio, inference, and output delivery must remain within the EEA throughout the full pipeline, including at the inference layer during transcription, not only at the final storage endpoint. A vendor that stores output in France but routes inference through non-EEA infrastructure does not satisfy this requirement.
PII redaction: The process of detecting and removing personally identifiable information from transcripts, replacing sensitive entities such as names, dates of birth, and phone numbers with structured placeholder tokens (for example, [NAME_1], [DOB_1]). PII redaction is an optional feature that must be explicitly enabled in each API request. It does not activate by default, and omitting it on patient audio constitutes a configuration error with direct compliance consequences.