HDS Certification and Compliance: Scope, Limitations and Sovereignty

hds Compliance
HDS certification attests to the security of health data hosting; it is not intended to provide immunity from extraterritorial laws such as the Cloud Act or FISA. Using a certified hosting provider does not, moreover, make an organisation “HDS compliant”: the certification status remains with the hosting provider, while some obligations continue to rest with the client.

This article distinguishes between three concepts that are often confused: what the certification guarantees, what it leaves out, and the points to check before entrusting health data to a provider.

HDS Certification and HDS Compliance: Two Distinct Concepts

Certification is a status granted to the hosting provider following an audit. Compliance, however, is an obligation that remains shared between the hosting provider and its client. Confusing the two creates a false sense of security: the belief that outsourcing to a certified provider is sufficient to cover all of an organisation’s own obligations.

What the Certified Hosting Provider Is Responsible For

Certification is issued by an accredited body following an audit covering the six activities defined in the HDS framework. It attests that the hosting provider maintains a defined level of security for hosting, operating and backing up personal health data.

What Remains the Client’s Responsibility

Using a certified hosting provider does not make the client itself certified. The certification remains that of the hosting provider; the client is brought into compliance only with regard to the hosting component. Its application-level obligations and its obligations under the GDPR remain its own. The framework also imposes a specific requirement: hosting health data requires a dedicated agreement between the client and the hosting provider, formalising the allocation of responsibilities.

What the Certification Attests to, and What It Does Not Cover

The Scope of the Six Activities: Partial Certification Leaves Areas Uncovered

The HDS framework distinguishes between six activities, ranging from the provision of physical sites to outsourced backup, as well as the administration and operation of the information system. An offering may be certified for only part of this scope, often limited to the infrastructure layers. In such cases, administration and operation or backup remain outside the certified scope, and the resulting gap becomes a compliance burden for the client. Checking the exact scope of the certification, activity by activity, is therefore a prerequisite, not a detail.

The Boundary Between Hosting Security and Legal Sovereignty

The certification attests to the technical and organisational security of the hosting service. It says nothing about the legal issue of who may be legally compelled to disclose the data. These are two separate matters. A hosting provider may meet the security requirements of the framework while remaining subject to non-European legislation. The French Court of Accounts states this unambiguously: at this stage, the HDS framework does not include the sovereignty requirements specific to the SecNumCloud qualification, particularly ownership control and protection against extraterritorial legislation. An HDS-certified hosting provider is therefore not automatically immune from these laws.

HDS Certification and Extraterritorial Laws (Cloud Act, FISA)

What HDS Regulations Actually Require

The framework was tightened in early 2026. Decree No. 2026-209 of 24 March 2026, published in the French Official Journal on 26 March and adopted pursuant to Article 32 of the SREN Act of 21 May 2024, incorporates into the French Public Health Code obligations that had previously existed only in the certification framework. Its new Article R. 1111-9-1 establishes the principle that health data must be stored exclusively within the territory of a Member State of the European Union or a state party to the Agreement on the European Economic Area (EEA). A transfer to a third country, including in the form of remote access, remains possible, but only under the conditions set out in the GDPR: an adequacy decision by the European Commission or, failing that, appropriate safeguards.

The decree also strengthens the hosting agreement and the information that must be provided to the client. The hosting provider must specify remote access from third countries, non-European legislation that may require the disclosure of data within the meaning of Article 48 of the GDPR, mitigation measures and residual risks. It also introduces a transparency obligation that did not previously exist: the publication and ongoing maintenance of a map of transfers outside the EEA, remote access and the risks of unauthorised access by third countries.

However, these structural provisions will only enter into force six months after publication, at the end of September 2026; the other amendments have applied since the day following the publication of the decree.

What HDS Certification Does Not Address

The extraterritorial risk itself. The regulations require the hosting provider to provide information, not to guarantee immunity. A hosting provider may be HDS certified, store data in France and still be within the reach of non-European legislation when its parent company is subject to that legislation. Microsoft Ireland illustrates this situation: the entity holds HDS certification and stores data in France, but cannot obtain the SecNumCloud qualification because it belongs to a group subject to US law. Storing data within national territory is necessary, but it is not sufficient to eliminate legal exposure.

Legal Immunity and Sovereignty: Two Distinct Requirements

For the most sensitive data—large health databases, data relating to minors and data concerning criminal offences—the CNIL recommends using either a hosting provider subject exclusively to European law or a provider holding a qualification such as SecNumCloud, which includes a criterion of immunity from non-European laws.

One nuance should be noted. The qualification provides legal immunity, but it may coexist with technological dependency: some qualified offerings rely on US components operated under licence. Sovereignty cannot therefore be inferred from a single certification or qualification; it also depends on the provider’s ownership structure and the origin of its technology.

This recommendation applies to the most sensitive processing operations. Outside these cases, using a non-sovereign HDS hosting provider remains permitted: the CNIL states that no penalty has been imposed solely on the grounds that a non-sovereign hosting provider was used. The appropriate approach is not to decide on principle, but to assess the risk according to the sensitivity of the data being processed.

Assessing a Hosting Provider’s Actual Compliance

Certificate Validity and Accreditation

An expired certificate, a certificate undergoing renewal or one issued by a non-accredited body does not provide the expected assurance. Two straightforward checks should be carried out: is the certificate currently valid, and is the body that issued it accredited by COFRAC for the HDS framework? A hosting provider’s status can also be checked in the official register of certified hosting providers maintained by the French Digital Health Agency.

Location of Storage and Operations

Storing data in France is necessary, but it does not eliminate the risk on its own. Remote access for administration or operations from a third country reintroduces exposure, even when the data remains stored within France. The appropriate questions to ask the provider therefore cover both aspects: where is the data stored, and from which country and by which teams is the platform administered?

Reversibility and Transparency of Transfers

A lack of reversibility creates a technical dependency that may prevent future compliance, for example if a migration to a sovereign solution becomes necessary. In terms of transparency, the map of transfers outside the EEA made mandatory by the regulations provides a direct control point: its absence is a warning sign.

These points can be assessed systematically using our ten-point assessment framework for evaluating the sovereignty of an HDS hosting provider.

Clever Cloud’s Position

Clever Cloud is HDS certified across the entire scope of the framework. Regarding extraterritorial exposure, our guarantee is not based on holding our own SecNumCloud qualification, but on our legal status: French ownership and registered office, no subsidiary in the United States, hosting and operations carried out in France, and a commitment not to transfer any health data outside the European Economic Area. This structure places the company exclusively under European law.

FAQ

Does HDS Certification Provide Protection Against the Cloud Act?

No. The certification attests to the security of health data hosting. It is not intended to provide immunity from extraterritorial laws. Depending on its ownership structure, a certified hosting provider may remain subject to non-European legislation.

Can an HDS-Certified Hosting Provider Be Subject to US Law?

Yes, when its parent company is subject to US law. An entity may hold HDS certification and store data in France while remaining within the reach of the Cloud Act or FISA.

Must health data be stored in France?

No. The French HDS framework and Decree No. 2026-209 of 24 March 2026 require storage exclusively within the European Economic Area (the EU plus Norway, Iceland and Liechtenstein) rather than on French territory specifically. The rule is codified in Article R. 1111-9-1 of the French Public Health Code. Remote access from a third country remains possible, but only under the conditions set out in Chapter V of the GDPR (adequacy decision or appropriate safeguards), and it must be disclosed to the customer in the hosting agreement. Hosting located in France is therefore a contractual commitment made by the provider, not a regulatory requirement.

Does Using a Certified Provider Make Me “HDS Compliant”?

No. The certification remains that of the hosting provider. The client is brought into compliance only with regard to the hosting component; its application-level and GDPR obligations remain, as does the requirement to sign a dedicated hosting agreement.

HDS and SecNumCloud: What Is the Difference?

HDS certification is mandatory for hosting health data and attests to the security of that hosting. The SecNumCloud qualification, issued by the ANSSI, is voluntary and notably includes a criterion of immunity from non-European laws. To date, the HDS framework does not include the sovereignty requirements specific to SecNumCloud.

Blog

À lire également

Clever Cloud’s partnership strategy: building an open ecosystem for strategic autonomy

When we launched our PaaS, Clever Cloud, our mission was clear: to create a cloud platform that developers would trust and enjoy using, something reliable, intuitive, and well-suited to the evolving demands of modern software development.
Company

HDS Certification and Compliance: Scope, Limitations and Sovereignty

HDS certification attests to the security of health data hosting; it is not intended to provide immunity from extraterritorial laws such as the Cloud Act or FISA. Using a certified hosting provider does not, moreover, make an organisation “HDS compliant”: the certification status remains with the hosting provider, while some obligations continue to rest with the client.
Features

HDS migration: migrate your healthcare data with no perceptible downtime

An HDS migration consists of transferring an application and its healthcare data from one hosting provider to another while maintaining the required certification and service continuity. When properly planned and executed, the perceived interruption can be reduced to a simple DNS switch. For example, when Madietenligne, a provider of an e-health solution for dietitians, migrated to Clever Cloud, its test and production environments were moved in less than fifteen days, covering 500 GB of data, with no downtime perceived by users.
Features