AI in French Insurance: Health Data and GDPR
Health data is special-category data (GDPR art. 9). Pasting it into a consumer AI is risky. Anonymise before the prompt.
Yes, AI can help in insurance. But not with a health file in the clear. Pasting a health questionnaire, a claim file or a reimbursement statement into a consumer AI exposes health data. Under the GDPR, this data is sensitive. Its processing is prohibited by principle. As an insurer, you are the data controller. There is a clean method: anonymise before any prompt, then restore the values locally.
The problem: the file pasted into the AI
The scene is ordinary. A claims handler wants to summarise a complex claim. They open a consumer AI. They paste the file as-is to save time. The text holds a name, a date of birth, a policy number. It also holds a diagnosis, a sick leave, a reimbursement amount. In one copy-paste, all of it leaves your system.
Here is what an insurance file concentrates, and what a poorly prepared prompt can expose.
- The policyholder's identity: name, date of birth, contact details.
- The health data: diagnosis, medical questionnaire, sick leave.
- The financial data: policy number, bank details, reimbursement amount.
- The data of named third parties: beneficiaries, dependants, doctors.
The stake: data prohibited by principle
Health data is not ordinary data. The CNIL, France's data protection authority, classes it among sensitive data. These are the special categories. They also include origin, opinions, genetic and biometric data. This data touches the intimate. The law protects it more strongly.
The principle is simple. Article 9 of the GDPR states that processing this data “is prohibited”. The CNIL describes a model of prohibition with exceptions. You can process health data only if a specific case applies. The person's explicit consent is one. Safeguarding vital interests is another. Care purposes under professional secrecy too. Pasting a file into a consumer AI fits none of these boxes.
Each actor's role matters here. As an insurer, you are the data controller. You must be able to justify a legal basis and safeguards. A consumer AI offers you none. It acts as an uncontrolled third party. The data can be retained, reviewed, reused for training. You lose control of what you must protect.
Who oversees what: the CNIL and the ACPR
Two authorities frame your activity. They must be told apart. The CNIL oversees GDPR compliance and data protection. The ACPR (Autorité de contrôle prudentiel et de résolution), attached to the Banque de France, supervises the insurance sector. It watches over insurers and mutuals, alongside the CNIL's oversight. On health data, these two requirements stack up.
| Assumption | The reality |
|---|---|
| “A file pasted into the AI stays between us” | It is processing by an uncontrolled third party, outside GDPR safeguards |
| “Health data is data like any other” | The CNIL classes it as sensitive, prohibited by principle (GDPR art. 9) |
| “One authority is enough to oversee this” | The CNIL oversees the GDPR; the ACPR supervises the insurance sector |
| “AI is banned in insurance” | No; it is exposing uncontrolled data that is risky |
The fix: anonymise before the prompt
Good news: AI stays useful day to day. It summarises, rewrites, structures an argument. For that, it needs no real data. The idea is to remove identity and identifying health details before sending. The model then sees only text stripped of personal data. That text falls outside the scope of sensitive data. You keep control of your file.
In practice, the method takes four steps. It serves the data minimisation the GDPR requires. A caveat: anonymising reduces risk, but does not make you compliant on its own. Your other duties stay whole. It is a key control, not a blank cheque.
- 1Spot the sensitive data: identity, health, financial elements.
- 2Replace it with reversible tokens, in the browser.
- 3Send only the anonymised text to the AI.
- 4Restore the real values in the reply, locally.
Should you give up on AI in insurance?
No. Using AI in insurance is not prohibited in itself. What is risky is exposing uncontrolled health data. So the question is not choosing between AI and compliance. The question is what the model sees. If it sees only tokens, it sees neither the policyholder nor their diagnosis. Anonymising upstream is the key control for working with caution.
That's what ONYRI Sanitize is for. The engine detects sensitive data — identity, health, amounts, policy numbers — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. The AI finds only tokens, never your policyholders' identity or health. You get AI's help, while keeping control of the data the GDPR asks you to protect.
Frequently asked questions
- Is it risky to use AI in insurance with health data?
- Yes, if you paste a health file into a consumer AI. Health data is sensitive data, and its processing is prohibited by principle (Article 9 of the GDPR). As an insurer, you are the data controller and must justify safeguards. But AI stays useful: anonymise identity and health details before any prompt.
- Can I paste a health questionnaire into ChatGPT?
- Better to avoid it. A consumer AI is an uncontrolled third party; passing a health questionnaire to it exposes sensitive data outside GDPR safeguards. The CNIL classes this data among the special categories. If you must handle the case, first replace each identifying element with a token.
- Who oversees an insurer's use of AI?
- Two authorities, with distinct roles. The CNIL oversees GDPR compliance and data protection. The ACPR (Autorité de contrôle prudentiel et de résolution), attached to the Banque de France, supervises the insurance sector. On health data, these two requirements stack up.
Sources & references
- Sensitive data: definition and special categories — CNIL
- GDPR, chapter 2, article 9: processing of special categories of data — CNIL
- What is the ACPR? Overview and missions — ACPR / Banque de France
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.
Anonymize my prompt