Pharm CRM’s GDPR Compliance

What is the GDPR?

The General Data Protection Regulation is a European data protection law that became enforceable on May 25, 2018. It replaced the older EU Data Protection Directive and applied automatically across every EU member state, without each country needing to pass its own implementing legislation.

The regulation governs how organizations collect, use, store, share, and delete personal data, and gives individuals a set of enforceable rights over their own information. There is no grace period remaining — any organization within scope is expected to be compliant now.

Who does it affect?

The GDPR reaches well beyond companies physically located in the EU. It applies to any organization that either (1) has an establishment in the EU, regardless of where the actual data processing happens, or (2) offers goods or services to, or monitors the behavior of, people located in the EU — even if the organization itself is based entirely outside Europe.

In practice, this means any pharmacy, clinic, or healthcare business using PharmCRM to manage patients, prescribers, or contacts based in the EU should assume the GDPR applies to that data, regardless of where the business itself is headquartered.

Personal data

Any information that could identify a person, alone or combined with other data — names, email addresses, phone numbers, IP addresses, location data, and more. Pseudonymized data (a record with a name replaced by a code, for example) still counts as personal data if it can be linked back to an individual.

Data subject

The individual the data is about. This is not limited to EU citizens — anyone physically located in the EU, or whose data is processed in the context of an EU establishment, is protected.

Controller vs. processor

A controller decides why and how personal data is processed. A processor acts on the controller’s instructions. In the PharmCRM relationship, our customers are almost always the controller — you decide what patient and contact information goes into your account — and PharmCRM acts as your processor.

Health & special category data

The GDPR treats health information as a “special category” of data, requiring stronger protection than ordinary personal data. Because PharmCRM is built for pharmacies, we recognize that patient and prescription information — inherently health-related — is often exactly what our customers need to store and manage in the platform.

That means the responsibility sits on both sides:

  • As controller, your organization is responsible for having a valid legal basis under Article 9 for processing that health data — such as the patient’s explicit consent, or processing necessary for healthcare provision by a professional bound by confidentiality obligations.
  • processor, PharmCRM applies additional technical and organizational safeguards to special category data stored in our platform, including encryption, access controls limited to staff with a legitimate need, and audit logging.

Note: customers should still avoid uploading identifiers or details that go beyond what’s needed to deliver care or run the pharmacy — GDPR’s “data minimization” principle applies even to data PharmCRM is built to handle.

International data transfers

The GDPR doesn’t require personal data to stay physically within the EU, but it does require a valid legal mechanism before data leaves the EU for a country like the United States. PharmCRM relies on Standard Contractual Clauses with its sub-processors, and, where applicable, self-certification under the EU–U.S. Data Privacy Framework, which succeeded the earlier Privacy Shield arrangement after Privacy Shield was invalidated by the Court of Justice of the EU in the 2020 “Schrems II” ruling.

We’re aware that the Data Privacy Framework itself remains subject to ongoing legal challenges in European courts. We monitor guidance from the European Data Protection Board and relevant court decisions, and will update our transfer mechanisms if the legal landscape changes.

Your rights as a data subject

  1. Right of access — know what data we hold about you and how it’s used.
  2. to rectification — correct inaccurate or incomplete data.
  3. Right to erasure — request deletion of your data, subject to limited exceptions (for example, records we’re legally required to retain).

  4. Right to object — object to specific uses of your data, such as inclusion in analytics or data-science projects.
  5. Right to portability — request that your data be exported to another provider in a usable format.

To exercise any of these rights, contact our Privacy Officer using the details at the bottom of this page. We respond to verified requests without undue delay, and in any case within the timeframe the GDPR requires.

How PharmCRM upholds its obligations

We reviewed our internal processes, systems, and documentation ahead of the GDPR’s original effective date and continue to monitor changes to the law. Concretely, this includes:

  • Encrypting personal data in transit and at rest using AES-256.
  • Vetting every sub-processor before engagement and requiring contractual minimum security standards.
  • Maintaining a record of processing activities and performing Data Protection Impact Assessments where required.
  • Collecting only the personal data necessary to operate the platform.
  • Not knowingly collecting personal data from children.

An up-to-date list of our sub-processors is maintained on a separate page, which we update whenever it changes.

Breach notification

If PharmCRM becomes aware of a personal data breach affecting your account, we will notify you without undue delay so that you can meet your own obligation, as controller, to notify your supervisory authority within 72 hours where the breach poses a risk to individuals’ rights and freedoms. Our notification will include what happened, what data was affected, and the steps we’re taking in response.

Requirements at a glance

Requirement GDPR Reference Who’s responsible What happens in practice
Lawful Basis Art. 6, 9 Shared You establish the legal basis for processing (e.g. consent, healthcare provision); PharmCRM supports this with configurable consent tracking.
Children’s data Art. 8 Pharm CRM We do not knowingly collect children’s personal data.
Data protection by design Art. 25 Shared PharmCRM collects only what’s needed to run the platform; you control what content is entered.
Impact assessments Art. 35 Shared PharmCRM performs DPIAs on its own processing; you assess your own use where relevant.
Encryption Art. 33, 34 Shared PharmCRM notifies you promptly; you notify your supervisory authority and affected individuals as required.
Processing records Art. 30 Shared Both parties maintain records of processing activity for their respective roles.
Right to erasure Art. 17 Shared Our Privacy Officer processes verified deletion requests; you route data subject requests to us.
International transfers Art. 44–49 Shared SCCs and Data Privacy Framework self-certification with sub-processors, as applicable.

Contact & Privacy Officer

Questions about this page, requests to exercise your rights, or reports of a suspected data issue should go to our Privacy Officer:

Privacy Officer
PharmCRM
P.O. Box 600047
Jacksonville, FL 32260
Email: legal@pharmcrm.com

We aim to acknowledge all privacy-related inquiries promptly and to resolve verified requests within the timeframes the GDPR requires.

© 2026 PharmCRM. All rights reserved. This page is provided for informational purposes and does not constitute legal advice.