Skip to content
Topic Contested in court

Healthcare

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing of health data and medical information

897 linked items 16 Laws59 Case Law59 Guidance621 Enforcement96 News

Overview

23 sources · Sep 25, 2026

Legal Framework

Health data is among the most tightly regulated categories of personal data under EU law. Article 9(1) GDPR establishes a general prohibition on processing special categories, including health data, which can only be lifted through one of the exhaustively listed exceptions in Article 9(2). As the regulation states plainly:

"data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."
— GDPR Art. 9(1)

The primary gateways for lawful health data processing are Article 9(2)(h) (provision of health or social care, medical diagnosis, management of health care systems) and Article 9(2)(i) (public health interests). Both require an underlying legal basis in Union or Member State law and appropriate safeguards. Recital 53 frames the rationale:

"Special categories of personal data which merit higher protection should be processed for health-related purposes only where necessary to achieve those purposes for the benefit of natural persons and society as a whole"
— GDPR Recital 53

Recital 54 further specifies that public-interest health processing must be subject to suitable and specific measures and must not result in data being repurposed by third parties such as employers or insurers. The Dutch AVG mirrors these provisions identically, while national legislation such as the WGBO and the Wabvpz adds sector-specific access and logging requirements.

Key Developments

Dutch courts have actively shaped the contours of medical dossier access, particularly outside traditional treatment relationships. In the bedrijfsarts cases, the Rechtbank held that Article 7:456 BW applies by analogy to occupational health supervision even where the WGBO formally does not, granting patients full access to their medical file. The Gerechtshof went further in a post-mortem context, holding that bereaved parents demonstrated a zwaarwegend belang — a compelling interest — warranting full dossier disclosure to assess potential medical negligence:

"Daarmee is sprake van een zwaarwegend belang. Dat belang wordt geschaad door de geheimhouding en inzage in het medisch dossier is noodzakelijk ter behartiging van dat belang."
— Gerechtshof (Inzage medisch dossier na overlijden kind)

On the enforcement side, the Irish DPC's decision against Midlands Regional Hospital Tullamore underscores that inadequate security measures are aggravated when the data at issue is health data, heightening obligations under Articles 5(1)(f) and 32(1). The Austrian DPA has consistently confirmed that Article 9(2) provides a closed list of exceptions — no fallback basis exists outside those enumerated conditions.

Status of the Debate

This topic is actively contested in court. While the core framework — Article 9's prohibition and its exceptions — is well established, the boundaries of lawful health data processing are actively litigated. Courts diverge on how far access rights extend, particularly where medical confidentiality intersects with third-party interests (employers, insurers, surviving relatives). The tension between professional secrecy obligations and data subject access rights remains unresolved in several Member States, and no definitive CJEU ruling has yet drawn the outer limits. What would resolve the open question: a preliminary reference clarifying the proportionality test when Article 9(2)(h) or (i) conflicts with medical confidentiality under national law. Meanwhile, the emerging European Health Data Space regulation adds a secondary-use dimension that the EDPB has flagged as requiring careful calibration against GDPR safeguards.

Practical Guidance

  • Map every health data processing activity to a specific Article 9(2) exception. The list is exhaustive — if no exception applies, processing is unlawful. Document the legal basis in national law that authorizes each activity.
  • Implement sector-specific access controls. The Midlands Hospital enforcement confirms that the sensitivity of health data aggravates security failures. Access logging (as required under Article 15e Wabvpz in the Netherlands) is not optional; it is evidentially critical.
  • Prepare for full dossier disclosure requests, including from non-patient data subjects. Courts have granted access to bereaved relatives and employees whose occupational health files drove employment outcomes — the threshold is demonstrating a compelling, concrete interest.
  • Segregate health data from secondary use. Recital 54 prohibits repurposing health data processed for public-interest reasons by third parties such as employers or insurers. Build purpose-limitation controls into data flows.
  • Monitor EHDS developments. The European Health Data Space will introduce secondary-use obligations that intersect with GDPR requirements; assess readiness for cross-border health data sharing before the regulation's implementation deadline.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section

This is the top of each pile — all 59 Case Law · all 59 Guidance · all 621 Enforcement · all 46 Literature · all 96 News