Skip to content
Topic Contested in court

Healthcare

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing in healthcare and medical context

497 linked items 14 Laws36 Case Law35 Guidance332 Enforcement40 News

Overview

16 sources · Jul 15, 2026

Legal Framework

Health data receives heightened protection under Article 9(1) GDPR, which prohibits processing of personal data concerning health unless an Article 9(2) exception applies. Recital 35 defines health data broadly: it encompasses all data revealing past, present, or future physical or mental health status, including information collected during registration for or provision of healthcare services, as well as identifiers assigned for health purposes. This sweeping definition captures everything from clinical records to medical registration numbers.

The primary legal bases for healthcare processing typically arise under Article 9(2)(a) (explicit consent), Article 9(2)(h) (medical diagnosis, treatment, or health service management), and Article 9(2)(i) (public health). A separate Article 6 basis is always required alongside the Article 9 condition. The AI Act Recital 4 further signals that AI deployment in healthcare—spanning diagnostics, resource allocation, and personalized treatment—will face additional scrutiny, particularly where health data trains or operates AI systems.

Key Developments

The V v. European Parliament decision establishes that transferring medical data between institutions constitutes an interference with Article 8 ECHR rights regardless of the recipient's purpose. Critically, even where a legitimate employment-law obligation exists to assess fitness for duty, the transfer must be necessary—the institution must demonstrate that no less intrusive alternative was available. In that case, the Parliament could have verified fitness without receiving the full medical file, rendering the transfer unlawful.

The Rotterdam District Court (ROT 20/3286) awarded immaterial damages for unlawful retention and processing of medical reports, confirming that violations of health-data provisions trigger not only administrative fines but also civil liability. The same court's detailed psychiatric examination framework in the childcare benefits scandal illustrates how medical data processing in litigation contexts requires proportionality: requests for anamnesis, treatment history, and ADL limitations must be scoped to the specific legal question at issue.

Enforcement confirms regulators' focus on healthcare sector compliance. The Irish DPC fined Midlands Regional Hospital Tullamore €300,000 for violations spanning Articles 5(1)(f), 28, 30, 32(1), and 34 GDPR—covering integrity, processor contracts, records of processing, security measures, and breach notification. The Italian Garante's action against Copacabana s.r.l. reinforces that insufficient legal basis remains a foundational enforcement trigger even at lower fine levels.

Practical Guidance

  • Map each processing purpose to a specific Article 9(2) condition and a corresponding Article 6 basis. Healthcare providers relying on Article 9(2)(h) must confirm processing genuinely relates to health service management, not administrative convenience.

  • Apply the necessity test from V v. European Parliament to all inter-institutional transfers. Before sharing medical data with any third party—including employers, insurers, or other care providers—document why no less intrusive measure suffices.

  • Maintain executed Article 28 agreements with all processors and keep Article 30 records current. The Tullamore fine demonstrates that processor governance and processing inventories are independently enforceable in healthcare settings.

  • Implement Article 32 security measures calibrated to health data sensitivity and establish Article 34 breach notification protocols. The Dutch DPA's Woo-decision on healthcare data leaks signals active monitoring of breach response timelines.

  • Scope medical examinations and data requests in litigation to the specific legal question. The Rotterdam court's structured questionnaire approach shows that proportionality in data collection is judicially enforceable and excess collection risks damages liability.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 14
rec 35 Recital 35 — health personal data definition scope GDPR Apr 2016 rec 50 Recital 50 — high-risk classification of safety-related AI systems AI Act Jun 2024 rec 64 Recital 64 — mandatory requirements for high-risk AI systems AI Act Jun 2024 rec 58 Recital 58 — AI essential public services access AI Act Jun 2024 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024 rec 53 Recital 53 — special health data processing conditions GDPR Apr 2016 rec 63 Recital 63 — data subject right of access GDPR Apr 2016 rec 84 Recital 84 — Third parties becoming high-risk AI providers AI Act Jun 2024 rec 29 Recital 29 — prohibition of manipulative AI systems AI Act Jun 2024 rec 33 Recital 33 — law enforcement biometric identification exceptions AI Act Jun 2024 rec 147 Recital 147 — access to testing and experimentation facilities AI Act Jun 2024 rec 44 Recital 44 — prohibition of emotion detection AI AI Act Jun 2024 rec 4 Recital 4 — AI benefits and competitive advantages AI Act Jun 2024 rec 157 Recital 157 — registry research value and safeguards GDPR Apr 2016
Case Law 36
¶2 The request has been made in proceedings between ZQ and his employer, the Medizinischer Dienst der Krankenversicherung Nordrhein (medical service of t… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal ¶9 Article 9 of that regulation, entitled ‘Processing of special categories of personal data’, is worded as follows: ‘1. Processing of personal data reve… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal ¶17 Under Paragraph 275(1) of the Sozialgesetzbuch, Fünftes Buch (Book V of the Social Code), in the version applicable to the dispute in the main proceed… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal ¶18 Paragraph 278(1) of that code provides that such a medical service is to be established in every federal state in the form of a body governed by publi… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal 667/21 Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal Court of Justice of the European Union Dec 2023 203/22 Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor Court of Justice of the European Union Feb 2025 416/23 Judgment of the Court (First Chamber) of 9 January 2025.#Österreichische Datenschutzbehörde v F R.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(f) and Article 57(4) – Tasks of the supervisory authority – Concepts of a ‘request’ and ‘excessive requests’ – Charging of a reasonable fee or refusal to act on requests in the e Court of Justice of the European Union Jan 2025 362/14 Maximillian Schrems v Data Protection Commissioner CJEU Oct 2015 Supreme Administrative Court NSS - 1 As 183/2023-62 Supreme Administrative Court Aug 2026 710/21 Judgment of the General Court (Eighth Chamber, Extended Composition) of 27 April 2022.#Robert Roos and Others v European Parliament.#Public health – Requirement to present a valid EU digital COVID-19 certificate to access the Parliament’s buildings – Legal basis – Freedom and independence of Members of the European Parliament – Obligation to ensure the health of staff in the service of the European Union – Parliamentary immunity – Processing of personal data – Right to respect for private life – General Court Apr 2022 PVN Personvernnemnda (Norway) - 2018-14 (15/01355) PVN Jan 2019 Federal Administrative Court BVwG - W252 2247042-1 Federal Administrative Court Jan 2024 169/23 Judgment of the Court (Third Chamber) of 28 November 2024.#Nemzeti Adatvédelmi és Információszabadság Hatóság v UC.#Request for a preliminary ruling from the Kúria.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data and the free movement of such data – Regulation (EU) 2016/679 – Data processed when drawing up a COVID-19 certificate – Data not collected from the data subject – Information to be provided – Exception to the obligation t Court of Justice of the European Union Nov 2024 343/13 Judgment of the General Court (Sixth Chamber) of 3 December 2015.#CN v European Parliament.#Non-contractual liability — Petition addressed to the Parliament — Dissemination of certain personal data on the Parliament’s website — Absence of a sufficiently serious breach of a rule of law conferring rights on individuals.#Case T-343/13. General Court Dec 2015 ECLI:EU:F:2011:101 V & EDPS v. EUROPEAN PARLAMENT CJEU Jul 2011 LG Köln LG Köln - 28 O 168/22 LG Köln Jul 2022 GDPRhub CJEU - C-667/21 - Krankenversicherung Nordrhein GDPRhub Dec 2023 247/23 CJEU - C-247/23 - Deldits GDPRhub Mar 2025 21/23 Judgment of the Court (Grand Chamber) of 4 October 2024.#ND v DR.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Chapter VIII – Remedies – Medicinal products marketed by a pharmacist on an online platform – Action brought before the national civil courts by a competitor of that pharmacist on the basis of the prohibition of unfair commercial practices for infringement by the pharmacist of t Court of Justice of the European Union Oct 2024 CJEU WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”) CJEU May 2013 CJEU V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”) CJEU Jul 2011 CJEU LINDQUIST, 6.11.2003 (“LINDQUIST”) CJEU Nov 2003 GDPRhub CJEU - C‑474/24 - NADA Austria and Others GDPRhub Jul 2026 101/01 CJEU - C-101/01 - Lindqvist GDPRhub Nov 2003 Show 16 more →
Guidance 35
guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 032020 on the processing of data concerning health for the purpose Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 042020 on the use of location data and contact tracing tools in the Guidelines 04/2020 on the use of location data and contact tracing tools in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 29 working party guidelines on transparency under regulation 2016679 Article 29 Working Party - Guidelines on transparency under Regulation 2016/679 EDPB Apr 2018 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 edps joint opinion 032022 on the proposal for a regulation on EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space EDPB Jul 2022 edps joint opinion 22022 on the proposal of the european EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act) EDPB May 2022 guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 edps joint opinion 12019 on the processing of patients data and EDPB-EDPS Joint Opinion 1/2019 on the processing of patients’ data and the role of the European Commission within the eHealth Digital Service Infrastructure (eHDSI) EDPB Jul 2019 32019 concerning the questions and answers on the interplay Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) EDPB Jan 2019 guidelines 202402 article48 v2 Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on virtual voice assistants Guidelines 02/2021 on virtual voice assistants EDPB Jul 2021 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 Show 15 more →
Enforcement 332
VDAI (Lithuania) VDAI (Lithuania) - 3R-1143 VDAI (Lithuania) Jun 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray Garante per la protezione dei dati personali (Italy) May 2026 AEPD (Spain) AEPD investigates University of Navarra over student COVID-19 vaccination status requests AEPD (Spain) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.12.2022 UODO (Poland) Jun 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 DSB (Austria) DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis DSB (Austria) Jan 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Enna Health Authority violated GDPR by publishing judicial data Garante per la protezione dei dati personali (Italy) Jul 2026 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 Persónuvernd (Island) Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive Persónuvernd (Island) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met Garante per la protezione dei dati personali (Italy) May 2026 Slovak Data Protection Office Sociale verzekeringsinstantie: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Slovak Data Protection Office Dec 2025 NL Spanish Data Protection Authority (aepd) APARELLS ORTOPEDICS CURTO, S.L: Onvoldoende naleving van de rechten van betrokkenen. Spanish Data Protection Authority (aepd) Oct 2025 NL Data Protection Authority of Ireland Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland Jun 2026 Spanish Data Protection Authority (aepd) MALAGASUITE SHOWROOM, S.L.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) Mar 2026 Spanish Data Protection Authority (aepd) IDCQ HOSPITALES Y SANIDAD, S.L.U.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Nov 2025 Hellenic Data Protection Authority (HDPA) Headquarter of a Fire Brigade: Insufficient legal basis for data processing Hellenic Data Protection Authority (HDPA) Jan 2026 Italian Data Protection Authority (Garante) Ospedaliero-Universitaria Careggi: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Italian Data Protection Authority (Garante) Aug 2025 NL Italian Data Protection Authority (Garante) Casa di Cura Città di Roma: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Italian Data Protection Authority (Garante) Sep 2025 NL Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Dr. Max SRL: Onvoldoende naleving van de rechten van betrokkenen. Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Sep 2025 NL Italian Data Protection Authority (Garante) Orde van Verpleegkundigen van Pisa: Onvoldoende wettelijke basis voor gegevensverwerking. Italian Data Protection Authority (Garante) Oct 2025 NL Show 312 more →
News 40
Electronic Frontier Foundation Meta Must Stop Silencing Reproductive Health Information Electronic Frontier Foundation Aug 2026 Electronic Frontier Foundation "We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care Electronic Frontier Foundation Jul 2026 Electronic Frontier Foundation Four Years After Dobbs, Anti-Abortion Lawmakers Keep Coming for Online Speech Electronic Frontier Foundation Jun 2026 Politico Europe Public sector AI readiness: closing the gap between ambition and execution in Europe Politico Europe Feb 2026 EDPB Support the EDPB’s work as an expert EDPB Nov 2025 GDPRhub CAA - 23VE02156 GDPRhub Jan 2026 Autoriteit Persoonsgegevens The AP (Autoriteit Persoonsgegevens, the Dutch Data Protection Authority) will be conducting checks on data security in the healthcare sector. Autoriteit Persoonsgegevens Dec 2025 Electronic Frontier Foundation EFF's Investigations Expose Flock Safety's Surveillance Abuses: 2025 in Review Electronic Frontier Foundation Dec 2025 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 Electronic Frontier Foundation EFF investigations reveal abuse of surveillance by Flock Safety: a look back at 2025. Electronic Frontier Foundation Dec 2025 Legislation Tweede nader gewijzigd amendement van de leden Claassen en De Korte ter vervanging van nr. 34 over een opt-out voor de verwerking van medische gegevens van patiënten Legislation May 2025 NL Legislation Second revised amendment proposed by members Claassen and De Korte, to replace item 34, regarding an opt-out option for the processing of patient medical data. Legislation May 2025 Legislation Law on the quality registration of healthcare services. Legislation Apr 2025 IT en Recht Court of Audit points out obstacles in implementation of GDPR in Netherlands in letter to Chamber IT en Recht Apr 2023 AEPD AEPD publishes GDPR Risk Assessment AEPD Oct 2022 NL EU Court Expert EU-wetgeving inzake datagovernance definitief vastgesteld NL EU Court Expert Jun 2022 NL ECHR Collection and retention, by the French blood donation service (EFS), of personal data reflecting applicant’s presumed sexual orientation without proven factual basis: violation of Article 8 of the Convention ECHR Sep 2022 AEPD De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). AEPD Oct 2022 NL Belgian DPA Belgian SA fined a medical laboratory EUR 20k due to a lack of security and a privacy policy Belgian DPA Aug 2022 Show 20 more →
Literature 40
Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 Athens Journal of Law Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation” Athens Journal of Law Jan 2025 International Journal of Population Data Science ‘Leading by Science’ through Covid-19: the GDPR Automated Decision-Making International Journal of Population Data Science Feb 2021 Open Science Framework Health AI Governance, Medical Devices Health Data Open Science Framework Jul 2026 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 Frontiers in Genetics Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40 Frontiers in Genetics Nov 2021 International Data Privacy Law Anonymization in healthcare AI under GDPR: measurable privacy protection and global implications International Data Privacy Law Feb 2026 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 AFMN Biomedicine REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT AFMN Biomedicine Jul 2026 Zbornik radova. Aktualnosti građanskog i trgovačkog zakonodavstva i pravne prakse POJAM OSOBNOG PODATKA U TUMAČENJU SUDA EUROPSKE UNIJE Zbornik radova. Aktualnosti građanskog i trgovačkog zakonodavstva i pravne prakse Jul 2026 ORBELIANI LAW REVIEW Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law ORBELIANI LAW REVIEW Mar 2025 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021 European Data Protection Law Review GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 Show 20 more →