Health Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of health and medical data
Overview
28 sources · Aug 27, 2026Legal Framework
Health data falls under the special categories of personal data regulated by Article 9 GDPR, which generally prohibits processing unless a specific exception applies. The GDPR's definition of personal data itself encompasses health-related factors, identifying data "specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person" as inherently personal.
"physical, physiological, genetic, mental, economic, cultural or social identity of that natural person"
— GDPR Art. 4(1)
In the Netherlands, Article 30 UAVG implements the Article 9(2) exceptions for health data processing. It designates specific controllers — healthcare providers, insurers, employers, and government bodies — and limits each to narrowly defined purposes. The core healthcare exception permits processing by care providers where necessary for treatment or operational management:
Separate provisions govern processing by insurers for risk assessment and contract execution, by employers for occupational purposes, and by ministers for custodial measures. Each exception is controller-specific and purpose-limited — a insurer cannot rely on the healthcare provider exception, and vice versa.
Key Developments
Enforcement authorities across the EU consistently treat health data as warranting the highest tier of scrutiny. The Italian Garante fined a Tuscan health authority after finding that:
"the controller had neither implemented adequate technical and organizational measures to protect the processing nor conducted a data protection impact assessment, although this would have been necessary due to the nature of the data processed (health data)."
— Garante, Azienda Unità Sanitaria Locale Toscana Sud Est
The Norwegian Datatilsynet fined Moss municipality €49,200 after inadequate security measures in a combined IT system caused a breach affecting approximately 2,000 health service users, including pregnant women and immunization program participants. The Danish DPA similarly flagged Midtjylland Region for insufficient access controls, treating the large volume of health data as an aggravating factor.
Courts have also grappled with the accuracy dimension. In a case before the Raad van State, an appellant challenged a CIZ advisory report, arguing that medical data had been incompletely and incorrectly represented — including mischaracterizing an intellectual disability's severity. The court acknowledged that medical data constitutes personal data requiring complete and correct representation.
The EDPB's breach notification guidance underscores the elevated risk profile of health data:
"Breaches involving health data, identity documents, or financial data such as credit card details, can all cause harm on their own, but if used together they could be used for identity theft."
— EDPB Guidelines 9/2022 §108
Status of the Debate
This topic is actively contested in court. The boundaries of permissible health data processing remain in flux — particularly around the scope of "necessity" under Article 30 UAVG exceptions, the accuracy obligations for medical assessments used in administrative decisions, and the threshold for DPIA obligations when health data is incidental rather than central to a processing operation. Courts diverge on how narrowly to construe controller-specific exceptions and whether incidental exposure of health data (e.g., in a generic email) triggers Article 9 sanctions. A definitive ruling on the outer limits of the healthcare provider exception — particularly for non-clinical administrative processing within health institutions — would resolve the principal open question.
Practical Guidance
Map your controller category before selecting a legal basis: Article 30 UAVG exceptions are controller-specific. A hospital processing for treatment relies on Art. 30(3)(a); an insurer assessing risk must satisfy Art. 30(1) conditions instead. Misclassification is the most common compliance failure.
Conduct a DPIA for any processing involving health data: Enforcement from the Garante to Datatilsynet confirms that the nature of health data alone can trigger Article 35 obligations, regardless of scale.
Implement layered access controls and log them: The Moss and Midtjylland enforcement actions both centered on inadequate access restrictions after system migrations. Periodic testing and evaluation of security measures is not optional under Article 32 GDPR.
Ensure medical data in administrative proceedings is complete and accurate: The Raad van State litigation demonstrates that incomplete or mischaracterized medical records in government decision-making can be challenged as unlawful processing.
Assess breach notification thresholds with health data as a presumptive high-risk factor: Under EDPB guidance, health data breaches carry inherent harm potential. Document the assessment under Article 33(5) even if notification is ultimately not required.
why this is here
the expression ‘data concerning health’ used in Article 8(1) thereof must be given a wide interpretation so as to include information concerning all aspects, both physical and mental, of the health of an individual
The paragraph explicitly defines the scope of 'data concerning health' under the Data Protection Directive, making it a primary source for this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the processing of medical data is prohibited, in principle, subject to derogations laid down in Article 10(2).
The document directly addresses the protection and processing of medical/health data, a central topic of health data regulation.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the processing of medical data is, in principle, prohibited. Paragraph 2 of Article 10 provides inter alia that paragraph 1 does not apply if the data subject gives his or her consent
The central issue is whether the transfer of medical data could be justified under the exceptions to the prohibition on processing health data, making it a primary source for health data processing rules.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
special categories of personal data are involved
Health data is mentioned as a type of sensitive data that increases breach severity, but the document does not focus solely on health data.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the collection of health data concerned about 5 % of the tests
The document explicitly discusses health data collection, which is the core of this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
compliance checklist for controllers operating health data warehouses
The document's subject is specifically health data warehouses, making it directly about processing health data.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Nothing of this type on this topic.
This is the top of each pile — all 261 Enforcement · all 32 Literature · all 38 News