Health Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of health and medical data
Overview
24 sources · Jul 23, 2026Legal Framework
Article 9 GDPR establishes the general prohibition on processing special categories of personal data, including health data, which encompasses physical and mental health status, medical history, and treatment records. This prohibition reflects the heightened risk that misuse of health data poses to fundamental rights, particularly the right to privacy under Article 8 ECHR, which the Court has confirmed extends to the secrecy of one's medical condition.
The prohibition is not absolute. Article 9(2) GDPR enumerates ten exceptions, with consent under Article 9(2)(a) and public interest in public health under Article 9(2)(i) being the most relevant for health data processing. Recital 53 clarifies that special categories may be processed for health purposes where necessary to serve the interests of individuals and society as a whole, particularly in managing healthcare systems and social services. Recital 54 reinforces that public health grounds may justify processing without consent, provided appropriate and specific safeguards protect individuals' rights and freedoms.
Member states may also create national-law exceptions under Article 9(2) for reasons of substantial public interest, subject to the adoption of suitable protective measures. National implementing legislation, such as the Dutch UAVG Article 23, operationalizes these exceptions for compliance with international obligations and other public interest grounds.
Article 24 GDPR imposes accountability obligations on controllers, requiring them to implement data protection policies and demonstrate compliance with the processing principles. Controllers bear direct responsibility for adherence, including when engaging processors under Article 28. Approved codes of conduct under Article 40 and certification mechanisms under Article 42 serve as admissible evidence of compliance.
Key Developments
In V & EDPS v. European Parliament, the Court confirmed that medical data processing is prohibited in principle, with exceptions narrowly construed. The transfer of medical data to a third party constitutes interference with the right to private life regardless of the recipient's intended use, and absent the data subject's consent, such transfer requires a specific legal basis.
In Dennekamp v. European Parliament, the Court established that access-to-information rights and data protection rights carry equal weight, requiring full application of both regimes without automatic primacy for either.
The Dutch DPA has actively enforced health data rules, imposing fines of €25,000 on multiple municipalities including Ede and Eindhoven for unlawful processing of personal data in the context of government services. The Rotterdam District Court's rulings in the childcare benefits affair illustrate how medical and psychiatric data may be ordered disclosed in judicial proceedings, but only through structured expert examination with clearly defined questions.
Practical Guidance
Establish a specific Article 9(2) legal basis before any health data processing. Rely on consent only where it is genuinely freely given, as the V v. European Parliament ruling confirms that absence of consent renders processing unlawful absent an alternative ground.
Implement appropriate and specific safeguards as required by Article 9(1) and Recital 54. These must be proportionate to the sensitivity of health data and the processing context, including pseudonymization, access controls, and encryption.
Document accountability measures under Article 24 GDPR. Maintain internal policies, conduct DPIAs for high-risk health data processing, and ensure processor agreements under Article 28 impose equivalent obligations.
Treat any transfer of medical data to third parties as a separate processing operation requiring its own legal basis. The V v. European Parliament judgment makes clear that onward transfer constitutes distinct interference with fundamental rights.
Monitor national implementing legislation for sector-specific health data rules. Member states may impose additional conditions or exceptions beyond the GDPR baseline, as reflected in Dutch legislative amendments to healthcare data processing provisions.