Short answer: in 2026, fax is neither banned by the GDPR nor compliant by nature. The European regulation says nothing about faxing — it talks about the processing of personal data and requires "appropriate technical and organisational measures" (Article 32). A fax becomes a GDPR problem at three specific points: at departure (one digit too many in the number and the document lands with a stranger), in transit (the analogue path and a good share of VoIP links are unencrypted), on arrival (an output tray sitting in a corridor is a disclosure to anyone walking past). All three can be fixed, and none of them requires giving up fax: a named receiving number, delivery by email to a controlled mailbox, systematic number checks and an up-to-date record of processing are enough to make a fax a defensible processing operation in the eyes of the regulator.
The topic has become sensitive precisely because fax survives where the most sensitive data circulates: medical practices, laboratories, pharmacies, notaries' offices, insurers, HR departments, public administrations. In other words, "health data" and "special categories of data" within the meaning of Article 9 of the GDPR — the kind whose disclosure costs the most, in penalties as much as in reputation. France's CNIL has issued several reminders about misdirected medical documents, and fax regularly appears there alongside the badly addressed email.

What the GDPR actually requires of a fax transmission
No article of the regulation mentions faxing. What applies are the general principles, and three of them bite particularly hard on fax.
Data minimisation (Article 5.1.c). You may only transmit the data necessary for the purpose. In practice, that means not faxing an entire file when a single page will do, and redacting anything that does not concern the recipient. A report sent to a fellow practitioner does not need to carry the full social security number if the name and date of birth are enough to identify the patient.
Security of processing (Article 32). The text calls for measures "appropriate to the risk", explicitly citing encryption and pseudonymisation among the options without making them mandatory. That is where the whole debate lies: an analogue fax is not encrypted, but it travels over a dedicated circuit that is hard to intercept without physical access to the line. A fax sent through a serious online service travels over TLS to the provider, then over T.38 on a carrier network. Neither is end-to-end encryption — and that is exactly why the fallback channel matters: for ultra-sensitive data, a secure health messaging system remains preferable, as we explained in our comparison fax or secure messaging.
Breach notification (Articles 33 and 34). A fax sent to the wrong number is a personal data breach under the regulation as soon as it contains personal data. The "let's call the recipient and say no more about it" reflex is precisely what regulators penalise when they uncover it during an audit.
The five leak points of a fax transmission
1. The mistyped number
By far the leading cause of incidents. A 3 instead of an 8, a forgotten international dialling code, a contact record never updated since the practice moved. Unlike email, fax does not bounce: a number assigned to someone else answers the call, prints the document, and you receive a perfectly reassuring "transmission successful" confirmation.
The safeguards come down to three habits:
- A centralised address book rather than sticky notes and fax-machine memories. Numbers are validated once, by an identified person, and corrected for everyone.
- Double entry for occasional recipients: type the number, read it back aloud digit by digit, then send.
- A test transmission of a blank cover sheet before a bulky send to a new correspondent. The transmission report confirms the remote unit's identifier (the CSID), often the name of the practice or company: a free check that prevents most errors.
2. The overly talkative cover sheet
A cover sheet displaying "HIV test results — Ms Dupont, born 14/03/1978" in plain sight discloses the sensitive data before anyone has even opened the file. It should identify the sender, the recipient by name, the number of pages and carry a confidentiality notice — not summarise the content. We detailed the useful wording in our fax cover sheet template.
3. The freely accessible output tray
The classic blind spot. The organisation encrypts its backups, locks its sessions… and lets a fax machine print continuously in an open space, sometimes accessible to visitors and cleaning contractors. On thermal paper, documents pile up over the weekend and nobody knows how many pages were taken.
There are two answers. The first is to switch to email reception: nothing prints any more, documents arrive in a named mailbox or a shared mailbox with traceable access — that is the principle of fax-to-email. The second, when printing remains necessary, means moving the machine into a locked room and adding a cross-cut shredder for erroneous or obsolete pages, which no one should simply drop into the wastepaper basket.
4. The provider and its hosting
As soon as you use an online fax service, that service becomes a processor within the meaning of Article 28 of the GDPR. Three checks are essential before signing:
| Point to check | What you need to obtain |
|---|---|
| Processing agreement | A written Article 28 contract (DPA), listing purposes, duration and security measures |
| Data location | EU hosting, or documented appropriate safeguards for any transfer outside the EU |
| Retention period | How long the PDF stays on the servers, and how to purge it |
| Health data | HDS certification (French health data hosting) if you handle patient records |
| Logging | Usable send/receive logs in case of an audit or a dispute |
HDS certification is not a marketing detail: for a medical practice, a laboratory or a care service, the hosting of health data by a third party is governed by the French Public Health Code. A provider unable to answer the question deserves to be passed over.
5. The fax machine at end of life
Professional multifunction devices carry a hard drive or flash memory that keeps images of the documents sent and received, sometimes several thousand pages. Reselling or discarding the machine without secure erasure means exporting a database. Before any device leaves the fleet, you must run the manufacturer's erasure function (often called "data overwrite" or "disk initialisation") and, on machines with a removable drive, physically take it out. We devoted an entire article to this step in fax machine end of life.

A fax sent to the wrong number: the 72-hour procedure
The Article 33 countdown starts the moment you become aware of the breach, not when it occurred. Here is the sequence to follow, in order.
Hour 0 — Qualify. Note the number dialled, the correct number, the timestamp on the transmission report, the nature of the data (identity, contact details, health, banking) and the number of people affected. Keep the report: it is your evidence.
Hour 1 — Contain. Call the wrong number by voice. In most cases someone answers; ask for the document to be destroyed and note the person's name, the date and the time. It is not a legal guarantee, but it is a mitigation measure that weighs in the risk assessment.
Hour 2 — Record. Every breach, even one that is not notified, must appear in the breach register required by Article 33.5. A simple dated table is enough, provided it sets out the facts, the effects and the measures taken.
Within 72 hours — Notify if necessary. If the breach is likely to result in a risk to the rights and freedoms of individuals, it must be notified to the supervisory authority via its dedicated online service. With health or banking data, the answer is almost always yes. If the risk is high, Article 34 additionally requires informing the individuals concerned, individually and in clear terms.
Then — Fix the cause. A breach not followed by corrective action is an aggravating factor. Correcting the contact record, activating double entry, training the team: three lines in the register that change everything during an audit.
Organising compliance without weighing down daily work
Adding fax to your record of processing activities
The Article 30 record must describe processing operations, not tools — but if faxing is your main channel for sending reports or case files, it must appear in the "recipients" and "security measures" sections of the relevant processing entry. One line: "transmission by fax via provider X, EU hosting, 30-day retention". That is the line an inspector will look for.
Writing a one-page procedure
GDPR compliance for fax is not decided in a forty-page document but in a memo pinned up next to the machine: who is authorised to send, how a number is checked, what goes on the cover sheet, what to do about an error, where reports are filed. A lever arch file for paper reports and a dated folder on the server for PDFs handle the rest. Retention periods, for their part, follow the nature of the document and not the channel — a subject we covered in our archiving guide.
Training, briefly but genuinely
Fax incidents almost never come from an attack: they come from a routine gesture done too fast. Twenty minutes of awareness training a year, with two or three concrete cases, cuts errors more than any piece of equipment. For organisations without a DPO, a recent edition of a practical GDPR guide for small businesses provides enough of a framework to keep a proper register.
Protecting the viewing workstation
If faxes now arrive by email, the risk shifts to the screen. In a medical reception area or a desk open to the public, a privacy screen filter prevents side-on reading, and automatic session locking after three minutes handles the rest. On a mobile workstation, a hardware-encrypted USB drive keeps a file exported for a meeting from ending up unprotected in someone's pocket.
Frequently asked questions
Is fax safer than email for sending health data?
Neither safer nor less safe — just different. Ordinary email crosses several servers and leaves copies everywhere; fax follows a more direct route but is not end-to-end encrypted. For health data exchanged between professionals, a secure health messaging system remains the benchmark in France. Fax retains its usefulness with correspondents who are not connected to such systems — particularly abroad.
Do you need the patient's consent to fax their file?
Consent is only one of six legal bases. Between healthcare professionals involved in a patient's care, transmission generally rests on another basis and on shared professional secrecy. What remains mandatory: informing the individual about the recipients of their data, and transmitting only what is necessary.
Does a transmission receipt prove proper delivery?
It proves that a remote device answered and accepted the pages, with a timestamp and often a CSID identifier. It does not prove that the right recipient read them. That is why it should be archived with the transmitted document, not separately.
How long does an online fax provider keep my documents?
That depends on the contract, and it is precisely a question to ask before subscribing. A short, configurable period, with effective deletion on expiry, is the right signal. Insist that this point appears in the DPA.
Does faxing abroad change anything under the GDPR?
Transfers of data outside the European Union are governed by Chapter V of the regulation. In practice, a one-off transmission to an identified recipient in a third country may fall under a derogation, but a regular flow calls for documented safeguards. While you are at it, check the list of compatible destinations before setting up a recurring flow.
Key takeaways
- The GDPR says nothing about fax: it talks about risk, minimisation and appropriate security. Fax remains usable, under conditions.
- The three leak zones are the number dialled, the output tray and the provider. None is technical in the strict sense: they are handled through organisation.
- A misdirected fax is a personal data breach: qualify it, contain it, record it in the register, notify the supervisory authority within 72 hours if a risk exists.
- An online fax service must provide a DPA, EU hosting, a configurable retention period — and HDS certification as soon as health data is involved.
- A fax machine taken out of service without memory erasure carries months of documents away with it: secure erasure is part of the disposal procedure.
- Email reception removes the freely accessible tray, but shifts the risk to the screen and the shared mailbox: named access, session locking, privacy filter.
For practical questions about sending and receiving, our FAQ complements this guide; and if you simply want to test a clean transmission before overhauling your procedures, it all starts on the sending page.
Tagsfaxsecuritypaperless


