The General Data Protection Regulation is a European data protection law that became enforceable on May 25, 2018. It replaced the older EU Data Protection Directive and applied automatically across every EU member state, without each country needing to pass its own implementing legislation.
The regulation governs how organizations collect, use, store, share, and delete personal data, and gives individuals a set of enforceable rights over their own information. There is no grace period remaining — any organization within scope is expected to be compliant now.
The GDPR reaches well beyond companies physically located in the EU. It applies to any organization that either (1) has an establishment in the EU, regardless of where the actual data processing happens, or (2) offers goods or services to, or monitors the behavior of, people located in the EU — even if the organization itself is based entirely outside Europe.
In practice, this means any pharmacy, clinic, or healthcare business using PharmCRM to manage patients, prescribers, or contacts based in the EU should assume the GDPR applies to that data, regardless of where the business itself is headquartered.
Any information that could identify a person, alone or combined with other data — names, email addresses, phone numbers, IP addresses, location data, and more. Pseudonymized data (a record with a name replaced by a code, for example) still counts as personal data if it can be linked back to an individual.
The individual the data is about. This is not limited to EU citizens — anyone physically located in the EU, or whose data is processed in the context of an EU establishment, is protected.
A controller decides why and how personal data is processed. A processor acts on the controller’s instructions. In the PharmCRM relationship, our customers are almost always the controller — you decide what patient and contact information goes into your account — and PharmCRM acts as your processor.
The GDPR treats health information as a “special category” of data, requiring stronger protection than ordinary personal data. Because PharmCRM is built for pharmacies, we recognize that patient and prescription information — inherently health-related — is often exactly what our customers need to store and manage in the platform.
That means the responsibility sits on both sides:
Note: customers should still avoid uploading identifiers or details that go beyond what’s needed to deliver care or run the pharmacy — GDPR’s “data minimization” principle applies even to data PharmCRM is built to handle.
The GDPR doesn’t require personal data to stay physically within the EU, but it does require a valid legal mechanism before data leaves the EU for a country like the United States. PharmCRM relies on Standard Contractual Clauses with its sub-processors, and, where applicable, self-certification under the EU–U.S. Data Privacy Framework, which succeeded the earlier Privacy Shield arrangement after Privacy Shield was invalidated by the Court of Justice of the EU in the 2020 “Schrems II” ruling.
We’re aware that the Data Privacy Framework itself remains subject to ongoing legal challenges in European courts. We monitor guidance from the European Data Protection Board and relevant court decisions, and will update our transfer mechanisms if the legal landscape changes.
Right to erasure — request deletion of your data, subject to limited exceptions (for example, records we’re legally required to retain).
To exercise any of these rights, contact our Privacy Officer using the details at the bottom of this page. We respond to verified requests without undue delay, and in any case within the timeframe the GDPR requires.
We reviewed our internal processes, systems, and documentation ahead of the GDPR’s original effective date and continue to monitor changes to the law. Concretely, this includes:
An up-to-date list of our sub-processors is maintained on a separate page, which we update whenever it changes.
If PharmCRM becomes aware of a personal data breach affecting your account, we will notify you without undue delay so that you can meet your own obligation, as controller, to notify your supervisory authority within 72 hours where the breach poses a risk to individuals’ rights and freedoms. Our notification will include what happened, what data was affected, and the steps we’re taking in response.
| Requirement | GDPR Reference | Who’s responsible | What happens in practice |
|---|---|---|---|
| Lawful Basis | Art. 6, 9 | Shared | You establish the legal basis for processing (e.g. consent, healthcare provision); PharmCRM supports this with configurable consent tracking. |
| Children’s data | Art. 8 | Pharm CRM | We do not knowingly collect children’s personal data. |
| Data protection by design | Art. 25 | Shared | PharmCRM collects only what’s needed to run the platform; you control what content is entered. |
| Impact assessments | Art. 35 | Shared | PharmCRM performs DPIAs on its own processing; you assess your own use where relevant. |
| Encryption | Art. 33, 34 | Shared | PharmCRM notifies you promptly; you notify your supervisory authority and affected individuals as required. |
| Processing records | Art. 30 | Shared | Both parties maintain records of processing activity for their respective roles. |
| Right to erasure | Art. 17 | Shared | Our Privacy Officer processes verified deletion requests; you route data subject requests to us. |
| International transfers | Art. 44–49 | Shared | SCCs and Data Privacy Framework self-certification with sub-processors, as applicable. |
Questions about this page, requests to exercise your rights, or reports of a suspected data issue should go to our Privacy Officer:
Privacy Officer
PharmCRM
P.O. Box 600047
Jacksonville, FL 32260
Email: legal@pharmcrm.com
We aim to acknowledge all privacy-related inquiries promptly and to resolve verified requests within the timeframes the GDPR requires.
© 2026 PharmCRM. All rights reserved. This page is provided for informational purposes and does not constitute legal advice.