โ† Back to Blog
GDPR & AI

AI for nutritionists: is it legal and ethical? A guide to GDPR and the AI Act

May 9, 2026Cibus
CibusTeam Cibus
Updated: May 20268 min read

Yes, a nutritionist can legally use artificial intelligence in their practice, under three conditions: (1) patient data must be processed on a correct legal basis under the GDPR, (2) the software provider must sign a data processing agreement (DPA under art. 28 GDPR) and not use the data to train its own models, (3) every clinical decision must remain under the professional's supervision.

What the GDPR says about patient data

The data you handle every day โ€” case histories, conditions, measurements, goals โ€” are health-related data, the category most protected by the GDPR (art. 9). In short, to process it with any digital tool you need:

  • An adequate legal basis: for processing for care purposes, art. 9.2.h applies; for tools that go beyond care in the strict sense, it's standard practice to collect the patient's explicit consent.
  • An up-to-date privacy notice, mentioning the digital tools and any AI features used.
  • Providers appointed as data processors with a DPA under art. 28: without that signed document, you're breaching the GDPR even if the software is excellent.
  • Adequate security measures: encryption, access control, servers in the European Union.

Why you should NOT paste patient data into ChatGPT

  1. 1No DPA: consumer versions of chatbots don't provide a data processing agreement with the healthcare professional. You are the data controller, and you're transferring health data to an unappointed party.
  2. 2Possible use for training: depending on the settings, the content you enter may be used to improve the models.
  3. 3Non-EU transfers without the required safeguards.

The difference isn't "AI yes / AI no": it's between consumer AI and professional AI. Serious healthcare software uses AI within a compliant perimeter: signed DPA, EU servers, no training on your patients' data, logs and access controls.

AI Act: what changes for those working in healthcare

  • Transparency: the patient must know when they're interacting with content generated with AI support.
  • Human oversight: systems that support decisions in the health field must keep the professional at the center. AI proposes, the professional decides.

Translated: if you use AI to generate the draft of a plan or a report, you review it, sign it and take professional responsibility for it โ€” exactly as you would with the work of a human assistant.

Ethics: does AI replace the nutritionist?

No โ€” and anyone who promises that is selling AI badly. A meal plan isn't a calculation: it's a professional act that takes into account conditions, tests, adherence, psychology and the patient's real life. AI does the mechanical part very well (structuring the draft, calculating macros, drafting the report) and the clinical and human part very badly.

  • Transparency with the patient: a line in the privacy notice and, if the patient asks, a simple explanation.
  • Systematic review: never deliver an AI output without professional review.
  • Up-to-date competence: AI doesn't erode your skills if you stay the one deciding; it erodes them if you abdicate.

How Cibus handles data (and why we're happy to explain it)

Cibus was born in Italy for Italian healthcare professionals, and compliance isn't an add-on: it's architecture. That's a substantial difference from many healthcare AI tools born in the United States and designed around American regulations like HIPAA: for a European professional, a non-EU provider means having to justify transfers of health data outside the Union.

  • Italian company, data in Europe: no non-EU transfers to justify.
  • DPA under art. 28 GDPR ready for every client.
  • Servers in the European Union.
  • No training of AI models on your patients' data.
  • Encryption and access control on all data.

Want to use AI on your patients in a compliant way?

Leave your contact details and we'll show you how Cibus holds AI and GDPR together, with ready-made DPA and privacy notice templates.

Frequently asked questions

Can I enter my patients' data into ChatGPT?

No, not in the consumer versions: they lack the DPA under art. 28, the safeguards on transfers and the exclusion from training. Use professional tools designed for health data.

Do I need specific consent to use AI with patients?

You need an up-to-date privacy notice mentioning the tools used; depending on the purposes, explicit consent may be necessary. For your specific case, consult your privacy advisor.

Who is responsible if AI gets a meal plan wrong?

The professional remains responsible for the professional act: that's why every AI output must be reviewed before delivery. It's the same principle as supervising a collaborator.

What is a DPA and why should I ask my provider for it?

It's the agreement (art. 28 GDPR) that appoints the provider as data processor and defines its obligations and limits. Without a signed DPA, using any software with patient data is a breach.

Can I use American AI software with my patients' data?

With great caution: tools born for the US market are designed around HIPAA, not the GDPR, and involve transfers of health data outside the EU that must be justified with specific safeguards. A European provider with EU servers removes the problem at the root.

Keep reading