GDPR and Doctors’ Personal Data Protection for CPD Providers: How to Avoid Fines

Cost of services:

from 2000 USD
Start
Negotiable
Court
from 600 USD
Problem solvement
Legal services for medical institutions
4.9
Based on 700 reviews in Google

Reviews of our Clients

Many Ukrainian CPD providers mistakenly believe that GDPR requirements apply only to companies registered in EU countries. However, the territorial scope of the General Data Protection Regulation (GDPR) is much broader.

Because our law firm provides services to healthcare institutions, including registration as a CPD provider, we can draw on current, practical experience to explain whether a doctor’s consent is required to process personal data for issuing a CPD certificate and how a provider can lawfully organize data collection.

If you are only planning to register as a CPD provider, you can learn about the entire procedure in our previous article: How to Become a CPD Provider.

For a Ukrainian CPD provider, the primary legislation governing personal data protection is the Law of Ukraine “On Personal Data Protection.” If a provider works exclusively with Ukrainian doctors, conducts training in Ukraine, and does not target its services at individuals in the EU, GDPR requirements generally do not apply to its activities.

GDPR applies alongside Ukrainian law when a provider’s activities have a connection to the EU within the meaning of Article 3 of the GDPR. For example, if the provider:

  • conducts online events for doctors located in the EU;
  • specifically offers CPD services to users in the EU;
  • cooperates with European organizations and processes personal data as part of that cooperation;
  • monitors the behavior of users located in the EU.

Accordingly, if your activities involve at least one of these factors, you will need to determine whether GDPR applies to your operations. If the answer is yes, your policies, registration forms, agreements with contractors, and actual data-processing practices must comply with both Ukrainian law and the GDPR.

Does GDPR Apply to a CPD Provider’s Activities?

GDPR applies not only to organizations established in the EU, but also to organizations outside the EU if they offer goods or services to individuals located in the EU or monitor their behavior online. For this reason, a Ukrainian CPD provider may also fall within the scope of the Regulation even if it operates entirely from Ukraine.

At the same time, even if GDPR does not formally apply to a particular CPD provider, following its principles is advisable. First, Ukrainian law also imposes requirements for the protection of personal data.

Second, applying GDPR standards demonstrates a high level of corporate governance and increases trust among partners, healthcare professionals, and international organizations.

Related: CPD Points and ECTS Credits: What Is the Difference for a Medical Course Organizer?

What Personal Data About Doctors May a CPD Provider Collect, and for What Purposes?

Organizing CPD activities is impossible without processing participants’ personal data. However, one of the core principles of GDPR is data minimization, which means that only information genuinely necessary to achieve a specific lawful purpose may be collected.

Depending on the training format, a CPD provider may process different categories of doctors’ personal data.

Identification data generally includes:

  • last name, first name, and patronymic;
  • date of birth;
  • contact telephone number;
  • email address;
  • place of work;
  • medical specialty;
  • position;
  • information about professional activities.

In addition, to properly document training outcomes, a provider may collect information needed to issue certificates and confirm participation in CPD activities, including information about successful completion of testing, knowledge-assessment results, the number of CPD points earned, the date of training, and other information required by the organizer’s internal procedures or applicable law.

When remote platforms are used, additional technical data may also be processed:

  • the user’s IP address;
  • device information;
  • login logs;
  • cookies;
  • data on the user’s activity on the learning platform;
  • recordings of online webinars or conferences where the event includes video recording.

Each category of personal data must be collected only for defined purposes. For a CPD provider, these purposes may include:

  • registering a doctor for a training event;
  • verifying the participant’s identity;
  • providing access to the educational platform;
  • organizing the learning process;
  • conducting testing;
  • preparing and issuing certificates;
  • maintaining internal records of completed events;
  • complying with legal requirements for organizing continuing professional development;
  • informing participants about changes to the event program or future educational events, where an appropriate legal basis exists.

A CPD provider must also comply with the purpose-limitation principle. This means that personal data collected to organize a training event cannot automatically be used for marketing communications, disclosure to partners, or other purposes unless there is a separate legal basis for doing so.

Related: Academic Integrity Policy for a CPD Provider: Requirements of the NHSU and the Ministry of Health

What Legal Bases Allow the Processing of Doctors’ Personal Data?

A CPD provider may process doctors’ personal data only where one of the legal bases set out in Article 6 of the GDPR applies. The most commonly used bases are:

  • Performance of a contract: where data processing is necessary to register the doctor, organize the training, communicate with the participant, and issue a certificate.
  • Legitimate interests: for information security, fraud prevention, administration of information systems, and other legitimate purposes, provided that the rights of the data subject are not overridden.
  • Consent of the data subject: where processing cannot be carried out on another legal basis, for example for marketing communications or the use of photographs and video materials.

If a CPD provider processes special categories of personal data, such as health information, it must also comply with the additional requirements of Article 9 of the GDPR.

For example, when a CPD provider registers a doctor for an educational event, it may need the participant’s first and last name, contact details, place of work, and professional specialty. Such data may be processed to register the participant, organize the training, confirm participation, and issue a certificate where an appropriate legal basis exists, including performance of a contract or compliance with legal obligations.

If, however, the provider wants to use a doctor’s contact details for marketing communications, that purpose requires a separate legal basis. In other words, consent to participate in an event does not automatically constitute consent to receive advertising messages.

A provider should not collect data “just in case.” For example, if information about a doctor’s health is not needed for registration or issuance of a certificate, collecting it is not properly justified merely by a desire to have more information about the participant.

What Documents Should a CPD Provider Have for Lawful Personal Data Processing?

To process doctors’ personal data, a CPD provider should develop a set of internal documents governing how information is collected, used, stored, and protected. The key documents include:

  • Privacy Policy: Defines what personal data is collected, the purposes for which it is used, the legal bases for processing, and the rights of data subjects.
  • Internal Personal Data Processing Policy: Establishes rules for employees handling personal data, access procedures, security measures, and the response process in the event of a personal data security incident.
  • Record of Processing Activities: Contains information about processing activities, data categories, purposes, legal bases, retention periods, and the safeguards applied.
  • Data Processing Agreement: Entered into with providers of CRM systems, distance-learning platforms, cloud services, and other processors that process personal data on behalf of the CPD provider.
  • Data Retention Policy: Defines how long information is retained and the procedures for archiving, deleting, or anonymizing it after the processing purpose has been achieved.
  • Incident Response Procedure: Governs the identification, documentation, and remediation of personal data security breaches, as well as notification of competent authorities and data subjects where required by the GDPR.

Having these documents helps a CPD provider demonstrate that personal data is processed in accordance with the GDPR principles of lawfulness, transparency, security, and accountability.

Having ready-made templates does not mean that the documentation reflects the CPD provider’s actual processes. For example, when preparing a Record of Processing Activities, it is important to document not only the categories of doctors’ data, but also the specific purposes for which the data is used, the legal bases, retention periods, the persons who have access to the information, and the services through which it is processed.

In practice, the same information may be used for different purposes and may therefore rely on different legal bases. For example, a doctor’s email address may be necessary to organize training, while its subsequent use for marketing communications requires a separate justification.

When developing the document package, we analyze the CPD provider’s actual processes—from doctor registration and delivery of training to certificate issuance and the use of CRM and other services. This makes it possible to align policies, records, consent forms, agreements, and internal procedures rather than simply prepare a set of formal documents.

Related: How to Organize a CPD Event Without Mistakes: From Registration to Certificates

How to Collect Data Lawfully Through a Website, Google Forms, and a CRM

When collecting personal data, a CPD provider must comply with the GDPR principles of lawfulness, transparency, data minimization, purpose limitation, and appropriate protection. Particular attention should be paid to each tool through which information is processed.

Registration Through a Website

On the registration page, the user should receive information about what personal data is collected, the purposes for which it is used, the legal bases for processing, and the rights available to the user. A link to the Privacy Policy should also be provided.

The registration form should contain only the fields genuinely necessary to organize the CPD event. If the email address will be used for marketing communications, separate consent must be obtained for that purpose.

Using Google Forms

Before creating a form, the provider should determine the minimum amount of personal data required to register participants. The form should include:

  • a link to the Privacy Policy;
  • a personal data processing notice;
  • separate consent to processing, where required;
  • contact details for inquiries regarding personal data protection.

Access to responses in Google Forms and Google Sheets should also be restricted to authorized employees only.

Using CRM Systems

A CRM can automate the administration of CPD activities, but it also accumulates a significant amount of doctors’ personal data. Access to the system should therefore be granted only to employees who need it to perform their job duties.

If a CRM processes personal data on behalf of the CPD provider, it is advisable to enter into a Data Processing Agreement with the CRM provider.

Distance-Learning Platforms and Video Conferencing Services

When using LMS platforms, Zoom, Microsoft Teams, Google Meet, and other services, it is advisable to check:

  • what personal data they collect;
  • where the information is stored;
  • whether international data transfers take place;
  • what security measures the provider applies;
  • whether the provider offers a Data Processing Agreement.

If an event is recorded, participants must be informed about the recording, its purpose, and the retention period.

Organizational and Technical Security Measures

To support GDPR compliance, a CPD provider should:

  • restrict employees’ access to personal data;
  • use multi-factor authentication;
  • use encryption when transmitting information;
  • regularly review access settings for cloud services;
  • create data backups;
  • train employees on the rules for handling personal data.

It is important to remember that regulators assess not only whether the required documentation exists, but also whether GDPR requirements are actually followed in practice. A CPD provider should therefore regularly review its personal-data collection and processing practices, monitor access and security settings in digital services, and collect only the information necessary to organize CPD activities.

What Common Mistakes Do CPD Providers Make When Processing Personal Data?

In practice, most GDPR violations arise not from major data breaches or deliberate misconduct, but from deficiencies in how personal data processing is organized.

The most common issues include:

  • Collecting excessive personal data: Registration forms request information that is not necessary to organize the CPD event, contrary to the data-minimization principle.
  • Insufficient notice to participants: Doctors do not receive complete information about who processes their personal data, for what purpose, for how long, and to whom the data may be disclosed.
  • Inadequate access controls: Employees who do not need the information to perform their job duties often have access to CRM systems, Google Sheets, or other databases.
  • Indefinite retention of personal data: Participant information continues to be stored after the event without defined deletion or archiving periods, contrary to the storage-limitation principle.
  • Using third-party services without proper documentation: Providers use CRM systems, cloud services, or distance-learning platforms without entering into the required data processing agreements.

Most of these violations can be prevented when personal data processing is being organized. Regular audits of internal procedures, reviews of digital-service settings, and employee training help minimize risks and support the CPD provider’s compliance with GDPR requirements.

We provide companies with both this type of audit and comprehensive assistance in preparing for registration as a CPD provider.

What Liability Applies for Violations of GDPR and Personal Data Protection Law?

Noncompliance with GDPR can have legal, financial, and reputational consequences for a CPD provider. The amount of any potential penalty depends on the nature and duration of the violation, the number of individuals affected, and whether the controller took measures to minimize adverse consequences.

Article 83 of the GDPR provides for two levels of administrative fines. For less serious infringements, the maximum penalty may be up to EUR 10 million or up to 2% of the company’s total worldwide annual turnover for the preceding financial year. For the most serious infringements, including violations of the core principles of personal data processing or data-subject rights, the fine may reach EUR 20 million or 4% of worldwide annual turnover, whichever amount is higher.

Financial liability is not the only risk. Supervisory authorities may require an organization to stop unlawful processing of personal data, restrict the use of specific information systems, delete unlawfully collected information, or bring internal processes into compliance with GDPR requirements. In some cases, such measures can significantly affect the organization’s operations and make certain processes impossible until the violations are remedied.

How Can a CPD Provider Bring Its Activities Into Compliance With GDPR and Avoid Fines?

Assessing all personal data processing activities, identifying the legal bases for using the data, and preparing the necessary documentation can be difficult without professional support, especially where the provider uses multiple online platforms, CRM systems, video conferencing services, and other digital tools.

We provide comprehensive legal support covering every stage of organizing personal data processing. Our services include:

  • conducting a legal audit of personal data processing activities;
  • determining whether GDPR requirements apply to your organization’s activities;
  • analyzing the legal bases for processing different categories of personal data;
  • preparing internal policies and procedures for personal data processing;
  • preparing a Record of Processing Activities where maintaining one is mandatory;
  • advising on the lawful use of Google Forms, CRM systems, distance-learning platforms, Zoom, Microsoft Teams, and other digital services;
  • analyzing risks associated with international transfers of personal data;
  • developing procedures for responding to security incidents and personal data breaches;
  • preparing for inspections and providing support in communications with supervisory authorities;
  • providing legal advice on all aspects of GDPR application to a CPD provider’s activities.

Planning to organize CPD activities in compliance with GDPR? Contact us. We will help protect your legal interests.

Publication date: 18/09/2026


Our clients



We are ready to help you!

Contact us by mail [email protected] or by filling out the form: