Further Information on the HDS Framework
Overview
The French HDS (Health Data Hosting) certification applies to any entity that provides hosting services for personal health data, acting as a processor under GDPR Article 28. ElevenLabs holds this certification as a Host, which demonstrates its compliance with the strict requirements for securing and managing sensitive health data. This certification helps customers in the French healthcare sector by ensuring that ElevenLabs' infrastructure and services meet the necessary legal and security standards for hosting health data, thereby facilitating their own compliance and protecting patient information.
Representation of Guarantees
This section aims to provide ElevenLabs' customers with clear visibility into the services covered by HDS certification. It allows you to understand all the different parties involved in delivering your service and how they contribute to the processing of health data, ensuring transparency and compliance.
You can find the ElevenLabs Representation of Guarantees here.
Customer’s Obligations
- HDS Customers must nominate a Customer Point of Contact (CPOC) to ElevenLabs. Such CPOC must:
- be able to designate to the Host a healthcare professional authorised to access the DSCPs where necessary
- be responsible for requesting and processing the Host and Processors’ HDS certificates on behalf of the Customer.
- Customers must request ElevenLabs’ latest HDS certification audit report by submitting a request for the document on ElevenLabs’ Compliance Portal.
- Customers may also wish to view Google’s Information about HDS, GCP HDS Certificate and Representation of Guarantees.
- Customers are required to use ElevenLabs’ EU Data Residency option, with Zero Retention Mode enabled and API access only, in order to be covered by our HDS certification. Processing of personal health data submitted to the Services is restricted to the EU with such configurations, provided the Customer’s use of optional integrations (Ex. custom LLMs) may cause such information to be processed outside of the EU.
