Skip to content
Topic Contested in court

Health Data

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing of health and medical data

367 linked items 4 Laws25 Case Law27 Guidance240 Enforcement40 News

Overview

24 sources · Jul 23, 2026

Legal Framework

Article 9 GDPR establishes the general prohibition on processing special categories of personal data, including health data, which encompasses physical and mental health status, medical history, and treatment records. This prohibition reflects the heightened risk that misuse of health data poses to fundamental rights, particularly the right to privacy under Article 8 ECHR, which the Court has confirmed extends to the secrecy of one's medical condition.

The prohibition is not absolute. Article 9(2) GDPR enumerates ten exceptions, with consent under Article 9(2)(a) and public interest in public health under Article 9(2)(i) being the most relevant for health data processing. Recital 53 clarifies that special categories may be processed for health purposes where necessary to serve the interests of individuals and society as a whole, particularly in managing healthcare systems and social services. Recital 54 reinforces that public health grounds may justify processing without consent, provided appropriate and specific safeguards protect individuals' rights and freedoms.

Member states may also create national-law exceptions under Article 9(2) for reasons of substantial public interest, subject to the adoption of suitable protective measures. National implementing legislation, such as the Dutch UAVG Article 23, operationalizes these exceptions for compliance with international obligations and other public interest grounds.

Article 24 GDPR imposes accountability obligations on controllers, requiring them to implement data protection policies and demonstrate compliance with the processing principles. Controllers bear direct responsibility for adherence, including when engaging processors under Article 28. Approved codes of conduct under Article 40 and certification mechanisms under Article 42 serve as admissible evidence of compliance.

Key Developments

In V & EDPS v. European Parliament, the Court confirmed that medical data processing is prohibited in principle, with exceptions narrowly construed. The transfer of medical data to a third party constitutes interference with the right to private life regardless of the recipient's intended use, and absent the data subject's consent, such transfer requires a specific legal basis.

In Dennekamp v. European Parliament, the Court established that access-to-information rights and data protection rights carry equal weight, requiring full application of both regimes without automatic primacy for either.

The Dutch DPA has actively enforced health data rules, imposing fines of €25,000 on multiple municipalities including Ede and Eindhoven for unlawful processing of personal data in the context of government services. The Rotterdam District Court's rulings in the childcare benefits affair illustrate how medical and psychiatric data may be ordered disclosed in judicial proceedings, but only through structured expert examination with clearly defined questions.

Practical Guidance

  • Establish a specific Article 9(2) legal basis before any health data processing. Rely on consent only where it is genuinely freely given, as the V v. European Parliament ruling confirms that absence of consent renders processing unlawful absent an alternative ground.

  • Implement appropriate and specific safeguards as required by Article 9(1) and Recital 54. These must be proportionate to the sensitivity of health data and the processing context, including pseudonymization, access controls, and encryption.

  • Document accountability measures under Article 24 GDPR. Maintain internal policies, conduct DPIAs for high-risk health data processing, and ensure processor agreements under Article 28 impose equivalent obligations.

  • Treat any transfer of medical data to third parties as a separate processing operation requiring its own legal basis. The V v. European Parliament judgment makes clear that onward transfer constitutes distinct interference with fundamental rights.

  • Monitor national implementing legislation for sector-specific health data rules. Member states may impose additional conditions or exceptions beyond the GDPR baseline, as reflected in Dutch legislative amendments to healthcare data processing provisions.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 4
Art. 4(15) ‘data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care serv… GDPR rec 54 Recital 54 — public interest health data processing safeguards GDPR Apr 2016 rec 53 Recital 53 — special health data processing conditions GDPR Apr 2016 rec 68 Recital 68 — data access for high-risk AI development AI Act Jun 2024 rec 63 Recital 63 — data subject right of access GDPR Apr 2016
Case Law 25
¶23 Taking the view that data concerning his health data had thus been unlawfully processed by his employer, the applicant in the main proceedings asked t… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal ¶53 As regards, specifically, the right of access provided for in Article 15 of the GDPR, it is apparent from the case-law of the Court that that right mu… Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor ¶68 In that regard, it should be recalled that, pursuant to recital 4 of the GDPR, the right to the protection of personal data is not an absolute right a… Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor ¶4 Wetboek van Strafvordering 4.1 In deze zaak zijn in het bijzonder de volgende bepalingen uit het Wetboek van Strafvordering (hierna: Sv) van belang. -… Hoge Raad, 18-03-2025 (22/03889) 667/21 Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal Court of Justice of the European Union Dec 2023 203/22 Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor Court of Justice of the European Union Feb 2025 184/20 Judgment of the Court (Grand Chamber) of 1 August 2022.#OT v Vyriausioji tarnybinės etikos komisija.#Request for a preliminary ruling from the Vilniaus apygardos administracinis teismas.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Charter of Fundamental Rights of the European Union – Articles 7, 8 and 52(1) – Directive 95/46/EC – Article 7(c) – Article 8(1) – Regulation (EU) 2016/679 – Point (c) of the first subparagraph of Court of Justice of the European Union Aug 2022 416/23 Judgment of the Court (First Chamber) of 9 January 2025.#Österreichische Datenschutzbehörde v F R.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(f) and Article 57(4) – Tasks of the supervisory authority – Concepts of a ‘request’ and ‘excessive requests’ – Charging of a reasonable fee or refusal to act on requests in the e Court of Justice of the European Union Jan 2025 362/14 Maximillian Schrems v Data Protection Commissioner CJEU Oct 2015 Supreme Administrative Court NSS - 1 As 183/2023-62 Supreme Administrative Court Aug 2026 115/22 Judgment of the Court (Grand Chamber) of 7 May 2024.#SO.#Request for a preliminary ruling from the Unabhängige Schiedskommission Wien.#Reference for a preliminary ruling – Admissibility – Article 267 TFEU – Concept of ‘court or tribunal’ – National arbitration committee competent to combat doping in sport – Criteria – Independence of the body making the reference – Principle of effective judicial protection – Inadmissibility of the request for a preliminary ruling.#Case C-115/22. Court of Justice of the European Union May 2024 343/13 Judgment of the General Court (Sixth Chamber) of 3 December 2015.#CN v European Parliament.#Non-contractual liability — Petition addressed to the Parliament — Dissemination of certain personal data on the Parliament’s website — Absence of a sufficiently serious breach of a rule of law conferring rights on individuals.#Case T-343/13. General Court Dec 2015 ECLI:EU:F:2011:101 V & EDPS v. EUROPEAN PARLAMENT CJEU Jul 2011 GDPRhub CJEU - C-667/21 - Krankenversicherung Nordrhein GDPRhub Dec 2023 21/23 Judgment of the Court (Grand Chamber) of 4 October 2024.#ND v DR.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Chapter VIII – Remedies – Medicinal products marketed by a pharmacist on an online platform – Action brought before the national civil courts by a competitor of that pharmacist on the basis of the prohibition of unfair commercial practices for infringement by the pharmacist of t Court of Justice of the European Union Oct 2024 CJEU V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”) CJEU Jul 2011 CJEU WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”) CJEU May 2013 CJEU LINDQUIST, 6.11.2003 (“LINDQUIST”) CJEU Nov 2003 CJEU DENNEKAMP V. EUROPEAN PARLIAMENT, 23.11.2011 (“DENNEKAMPI”) CJEU Nov 2011 GDPRhub CJEU - C‑474/24 - NADA Austria and Others GDPRhub Jul 2026 Regional Administrative Court Bratislava X - BA-6S/221/2019 Regional Administrative Court Bratislava Jun 2025 CE CE - 439360 CE Apr 2021 101/01 CJEU - C-101/01 - Lindqvist GDPRhub Nov 2003 GDPRhub CJEU - C-205/21 - Ministerstvo na vatreshnite raboti GDPRhub Jan 2023 Show 5 more →
Guidance 27
032020 on the processing of data concerning health for the purpose Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 042020 on the use of location data and contact tracing tools in the Guidelines 04/2020 on the use of location data and contact tracing tools in the context of the COVID-19 outbreak EDPB Apr 2020 edps joint opinion 032022 on the proposal for a regulation on EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space EDPB Jul 2022 edps joint opinion 12019 on the processing of patients data and EDPB-EDPS Joint Opinion 1/2019 on the processing of patients’ data and the role of the European Commission within the eHealth Digital Service Infrastructure (eHDSI) EDPB Jul 2019 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 32019 concerning the questions and answers on the interplay Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) EDPB Jan 2019 72018 on the draft list of the competent supervisory Opinion 7/2018 on the draft list of the competent supervisory authority of Greece regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) EDPB Oct 2018 22018 on the draft list of the competent supervisory Opinion 2/2018 on the draft list of the competent supervisory authority of Belgium regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) EDPB Oct 2018 182018 on the draft list of the competent supervisory Opinion 18/2018 on the draft list of the competent supervisory authority of Portugal regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) EDPB Oct 2018 document on response to the request from the european commission for EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research EDPB Feb 2021 edps joint opinion 042021 on the proposal for a regulation of EDPB-EDPS Joint Opinion 04/2021 on the Proposal for a Regulation of the European Parliament and of the Council on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery EDPB Mar 2021 on the processing of personal data in the context of reopening of Statement on the processing of personal data in the context of reopening of borders following the COVID-19 outbreak EDPB Jun 2020 on the processing of personal data in the context of the covid 19 Statement on the processing of personal data in the context of the COVID-19 outbreak EDPB Mar 2020 recommendations 202501 wada 2027 world anti doping code Recommendations 1/2025 on the 2027 WADA World Anti-Doping Code EDPB Feb 2025 on stakeholder event on anonymisation and Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 EDPB Feb 2026 Show 7 more →
Enforcement 240
Garante per la protezione dei dati personali (Italy) Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order Garante per la protezione dei dati personali (Italy) Jul 2026 VDAI (Lithuania) VDAI (Lithuania) - 3R-1143 VDAI (Lithuania) Jun 2026 AEPD (Spain) AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data AEPD (Spain) Jul 2026 AEPD (Spain) AEPD investigates University of Navarra over student COVID-19 vaccination status requests AEPD (Spain) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray Garante per la protezione dei dati personali (Italy) May 2026 UODO (Poland) UODO (Poland) - DKN.5131.27.2023 UODO (Poland) May 2026 UODO (Poland) UODO (Poland) - DKN.5131.12.2022 UODO (Poland) Jun 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 DSB (Austria) DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis DSB (Austria) Jan 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Veenendaal: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Gooise Meren: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Haarlemmermeer: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Huizen: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Tilburg: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Eindhoven: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Zoetermeer: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Dutch Supervisory Authority for Data Protection (AP) Municipality of Hilversum: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Natural Person: Non-compliance with general data processing principles Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Jan 2026 DSB (Austria) Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR DSB (Austria) Dec 2025 Dutch Supervisory Authority for Data Protection (AP) Municipality of Delft: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Feb 2026 Show 220 more →
News 40
GDPRhub DPC (Ireland) - IN-19-9-4 GDPRhub Aug 2026 noyb - European Center for Digital Rights EU Commission internal draft would wreck core principles of the GDPR noyb - European Center for Digital Rights Nov 2025 Electronic Frontier Foundation 🏃 Fitness Tracker Privacy Fails | EFFector 38.14 Electronic Frontier Foundation Jul 2026 Electronic Frontier Foundation Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features Electronic Frontier Foundation Jul 2026 Government Status of implementation of the European Health Data Space Government Mar 2026 GDPRhub KHO - KHO:2025:86 GDPRhub Jan 2026 Autoriteit Persoonsgegevens The AP (Autoriteit Persoonsgegevens, the Dutch Data Protection Authority) will be conducting checks on data security in the healthcare sector. Autoriteit Persoonsgegevens Dec 2025 EDPB Support the EDPB’s work as an expert EDPB Nov 2025 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 Politico Europe Public sector AI readiness: closing the gap between ambition and execution in Europe Politico Europe Feb 2026 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 Electronic Frontier Foundation EFF's Investigations Expose Flock Safety's Surveillance Abuses: 2025 in Review Electronic Frontier Foundation Dec 2025 Electronic Frontier Foundation EFF investigations reveal abuse of surveillance by Flock Safety: a look back at 2025. Electronic Frontier Foundation Dec 2025 Legislation Tweede nader gewijzigd amendement van de leden Claassen en De Korte ter vervanging van nr. 34 over een opt-out voor de verwerking van medische gegevens van patiënten Legislation May 2025 NL Legislation Second revised amendment proposed by members Claassen and De Korte, to replace item 34, regarding an opt-out option for the processing of patient medical data. Legislation May 2025 Government Please note that this is not about opting out of the European Health Data Space (EHDS) itself, but rather about the opt-out mechanism that is provided for within the EHDS. Government Apr 2025 Legislation Law on the quality registration of healthcare services. Legislation Apr 2025 CNIL Health data and use of cookies: DOCTISSIMO fined €380,000 CNIL May 2023 IT en Recht Court of Audit points out obstacles in implementation of GDPR in Netherlands in letter to Chamber IT en Recht Apr 2023 AEPD AEPD publishes GDPR Risk Assessment AEPD Oct 2022 Show 20 more →
Literature 31
Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 ORBELIANI LAW REVIEW Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law ORBELIANI LAW REVIEW Mar 2025 Law and Society LEGAL REGULATION OF THE PROTECTION OF PERSONAL DATA OF EMPLOYEES UNDER THE GDPR Law and Society Jan 2023 International Journal of Population Data Science ‘Leading by Science’ through Covid-19: the GDPR Automated Decision-Making International Journal of Population Data Science Feb 2021 Frontiers in Genetics Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40 Frontiers in Genetics Nov 2021 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 Journal of Data Protection Privacy Does de-identification require consent under the GDPR and English common law? Journal of Data Protection Privacy Jun 2020 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Greece: The New Data Protection Framework European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 Show 11 more →