Skip to content
Topic Contested in court

Health Data

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing of health and medical data

396 linked items 4 Laws29 Case Law32 Guidance261 Enforcement38 News

Overview

28 sources · Aug 27, 2026

Legal Framework

Health data falls under the special categories of personal data regulated by Article 9 GDPR, which generally prohibits processing unless a specific exception applies. The GDPR's definition of personal data itself encompasses health-related factors, identifying data "specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person" as inherently personal.

"physical, physiological, genetic, mental, economic, cultural or social identity of that natural person"
— GDPR Art. 4(1)

In the Netherlands, Article 30 UAVG implements the Article 9(2) exceptions for health data processing. It designates specific controllers — healthcare providers, insurers, employers, and government bodies — and limits each to narrowly defined purposes. The core healthcare exception permits processing by care providers where necessary for treatment or operational management:

Separate provisions govern processing by insurers for risk assessment and contract execution, by employers for occupational purposes, and by ministers for custodial measures. Each exception is controller-specific and purpose-limited — a insurer cannot rely on the healthcare provider exception, and vice versa.

Key Developments

Enforcement authorities across the EU consistently treat health data as warranting the highest tier of scrutiny. The Italian Garante fined a Tuscan health authority after finding that:

"the controller had neither implemented adequate technical and organizational measures to protect the processing nor conducted a data protection impact assessment, although this would have been necessary due to the nature of the data processed (health data)."
— Garante, Azienda Unità Sanitaria Locale Toscana Sud Est

The Norwegian Datatilsynet fined Moss municipality €49,200 after inadequate security measures in a combined IT system caused a breach affecting approximately 2,000 health service users, including pregnant women and immunization program participants. The Danish DPA similarly flagged Midtjylland Region for insufficient access controls, treating the large volume of health data as an aggravating factor.

Courts have also grappled with the accuracy dimension. In a case before the Raad van State, an appellant challenged a CIZ advisory report, arguing that medical data had been incompletely and incorrectly represented — including mischaracterizing an intellectual disability's severity. The court acknowledged that medical data constitutes personal data requiring complete and correct representation.

The EDPB's breach notification guidance underscores the elevated risk profile of health data:

"Breaches involving health data, identity documents, or financial data such as credit card details, can all cause harm on their own, but if used together they could be used for identity theft."
— EDPB Guidelines 9/2022 §108

Status of the Debate

This topic is actively contested in court. The boundaries of permissible health data processing remain in flux — particularly around the scope of "necessity" under Article 30 UAVG exceptions, the accuracy obligations for medical assessments used in administrative decisions, and the threshold for DPIA obligations when health data is incidental rather than central to a processing operation. Courts diverge on how narrowly to construe controller-specific exceptions and whether incidental exposure of health data (e.g., in a generic email) triggers Article 9 sanctions. A definitive ruling on the outer limits of the healthcare provider exception — particularly for non-clinical administrative processing within health institutions — would resolve the principal open question.

Practical Guidance

  • Map your controller category before selecting a legal basis: Article 30 UAVG exceptions are controller-specific. A hospital processing for treatment relies on Art. 30(3)(a); an insurer assessing risk must satisfy Art. 30(1) conditions instead. Misclassification is the most common compliance failure.

  • Conduct a DPIA for any processing involving health data: Enforcement from the Garante to Datatilsynet confirms that the nature of health data alone can trigger Article 35 obligations, regardless of scale.

  • Implement layered access controls and log them: The Moss and Midtjylland enforcement actions both centered on inadequate access restrictions after system migrations. Periodic testing and evaluation of security measures is not optional under Article 32 GDPR.

  • Ensure medical data in administrative proceedings is complete and accurate: The Raad van State litigation demonstrates that incomplete or mischaracterized medical records in government decision-making can be challenged as unlawful processing.

  • Assess breach notification thresholds with health data as a presumptive high-risk factor: Under EDPB guidance, health data breaches carry inherent harm potential. Document the assessment under Article 33(5) even if notification is ultimately not required.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
CJEU Lindquist: foot injury and medical leave constitute health data under Art. 8(1) Health personal data: Reference to the fact that an individual has injured her foot and is on medical leave constitutes personal data concerning health , as the concept must be… Case Law CJEU Nov 2003 Definition of health data
why this is here
the expression ‘data concerning health’ used in Article 8(1) thereof must be given a wide interpretation so as to include information concerning all aspects, both physical and mental, of the health of an individual

The paragraph explicitly defines the scope of 'data concerning health' under the Data Protection Directive, making it a primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

ECLI:EU:F:2011:101 CJEU: Transferring medical data to third party constitutes interference with Art. 8 ECHR V. v. Parliament Case Law CJEU Jul 2011 sensitive medical data protection
why this is here
the processing of medical data is prohibited, in principle, subject to derogations laid down in Article 10(2).

The document directly addresses the protection and processing of medical/health data, a central topic of health data regulation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”) V. v. Parliament CJEU Case Law CJEU Jul 2011 processing of medical data under Article 10
why this is here
the processing of medical data is, in principle, prohibited. Paragraph 2 of Article 10 provides inter alia that paragraph 1 does not apply if the data subject gives his or her consent

The central issue is whether the transfer of medical data could be justified under the exceptions to the prohibition on processing health data, making it a primary source for health data processing rules.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 01/2021 Examples regarding Personal Data Breach Notification Guidelines ·EDPB Guidance EDPB Jan 2022 health data in breach risk assessment
why this is here
special categories of personal data are involved

Health data is mentioned as a type of sensitive data that increases breach severity, but the document does not focus solely on health data.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Health data and use of cookies: DOCTISSIMO fined €380,000 Background information Following a complaint by the PRIVACY INTERNATIONAL association, the CNIL carried out four investigations into DOCTISSIMO. The doctissimo.fr website mainly… News CNIL May 2023 health data collection via tests
why this is here
the collection of health data concerned about 5 % of the tests

The document explicitly discusses health data collection, which is the core of this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

CNIL publishes compliance checklist for health data warehouse controllers > France’s data protection authority, the Commission nationale de l'informatique et des libertés, created a compliance checklist for controllers operating health data warehouses.… News CNIL Sep 2022 health data warehouses
why this is here
compliance checklist for controllers operating health data warehouses

The document's subject is specifically health data warehouses, making it directly about processing health data.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 261 Enforcement · all 32 Literature · all 38 News