Doctolib, Jameda, and similar platforms: What is the status of data protection in appointment booking portals?

- Doctolib under scrutiny by Berlin's data protection commissioner over potential privacy violations.
- GDPR requires careful processing of highly sensitive health data.
- Security vulnerability at Doctolib allowed access to 150 million appointment bookings.
- Users should use secure passwords and review privacy policies.
- Only provide necessary information when submitting sensitive data to appointment booking portals.
Appointment booking portals for medical appointments promise users a simple and straightforward way to book and organize visits to the doctor. Whether it's a naturopath or an orthopedist, many medical practices are already using this service to simplify appointment management. But what happens to the customers' data? Recently, the appointment booking portal Doctolib has come under the scrutiny of the Berlin Commissioner for Data Protection. This raises the question: Is sensitive data being adequately protected, and what should we as consumers keep in mind when booking appointments online?
What does the GDPR say about handling data on appointment booking portals?
Most consumers are familiar with the procedure for creating a new user account: enter data, save it, and protect it with a custom password. By logging in with a password, the data is then accessible to the user at any time. Appointment booking portals collect personal data in order to transmit it to the relevant doctor when a booking is made. To do this, the appointment booking portal must store the data accordingly. In principle, the data entered and stored on appointment booking portals falls under special categories of personal data (see Art. 9 GDPR). This particularly sensitive data must be processed and stored with great care. The responsibility for data security clearly lies with the portals.
If a user deletes their account on an appointment booking portal, the contract between the customer and the portal or service provider is terminated. Consequently, user data must generally be deleted by the appointment booking portals thereafter. Deletion eliminates the purpose for data storage. This applies to almost all data, unless there is a legal retention obligation.
Data protection in the healthcare sector
In the healthcare and nursing industry, there is more to consider regarding data protection than in other sectors. This is primarily because work here involves sensitive information such as health data. We specialize in providing data protection advice for this industry.
The state of data protection at Doctolib
Doctolib has been making headlines regarding data protection since 2021. The trigger was the fact that data was being transmitted via the Doctolib app to Facebook and the platform Outbrain. Consequently, a data protection breach could not be ruled out. The Berlin Commissioner for Data Protection and Freedom of Information subsequently initiated an investigation into Doctolib. The current annual report of the Berlin Data Protection Commissioner also reports on investigations into the appointment booking portal. The company denies all allegations, but consumers are gradually beginning to wonder how secure their patient data really is.
By mid-2020, a dataset from Doctolib containing 150 million appointment bookings was allegedly accessible to unauthorized parties. This meant that it was possible to see which person was being treated by which doctor, how many appointments were kept there, and what treatment was performed. In some cases, appointments could be traced back to 1990. Anonymous discoverers of the security vulnerability claimed they were able to download the datasets through a simple sequence of various browser queries. Doctolib admitted at the time that appointments were affected and that a corresponding security leak existed, but the press office denies that it involved 150 million datasets.
How you can protect your data
In general, data can only be protected by portal users to a certain extent. If there is a security vulnerability on the company's side, unfortunately, even the best password for your personal account will not help.
However, there are a few rules you can follow:
- Ensure that the data on your end is as secure as possible. This means using strong passwords, logging out of your account after use, and ensuring that no one else has access to it.
- Take a look at the appointment booking portal's privacy policy. Every company is generally required to include a privacy policy on its website. For sensitive data, such as health information, transparent information on how this data is handled is particularly important. This allows you to better understand how your data is being processed.
- Be sparing with your data. Often, information is requested that is not necessary for using a service. Make sure to provide only the data that is actually required.
In general, appointment booking portals offer a great service. However, data protection must also be scrutinized more closely here. Consumers should take a closer look at service providers, especially when it comes to sensitive data.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













