Healthcare
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of health data and medical information
Overview
16 sources · Jul 15, 2026Legal Framework
Health data constitutes a special category of personal data under Article 9(1) GDPR, with processing prohibited in principle. Article 9(2) GDPR enumerates narrow exceptions, most notably explicit consent under Article 9(2)(a) and processing necessary for preventive or occupational medicine, medical diagnosis, health or social care provision, and treatment management under Article 9(2)(h), subject to the conditions in Article 9(3). Recital 63 GDPR reinforces data subjects' right to access health data, including diagnoses, examination results, physician assessments, and treatment records.
The AI Act introduces additional layers for healthcare AI systems. Recital 68 AI Act envisages European common data spaces to facilitate access to high-quality datasets for developing and assessing high-risk AI systems, including in healthcare contexts. High-risk AI systems used in medical settings will trigger conformity assessment obligations under the AI Act alongside existing GDPR requirements.
Article 10 of Regulation 45/2001 (the predecessor EU institutions regulation) mirrors the Article 9 prohibition, permitting medical data processing only with data subject consent or where necessary for specific employment law rights and obligations.
Key Developments
The CJEU's decision in V & EDPS v. European Parliament established that confidentiality of health information constitutes a fundamental right under the EU legal order, rooted in Article 8 ECHR. The court confirmed that transferring medical data between EU institutions without the data subject's consent violates the prohibition principle, even where employment-law obligations are invoked — the consent exception requires actual, demonstrable consent, not implied authorization.
In Bara, the CJEU held that national law permitting data transfers does not itself satisfy the information obligation under Articles 10–11 of Directive 95/46. Controllers must affirmatively inform data subjects of recipients, even where transfers occur under statutory authority. This principle carries forward to Article 13 GDPR in healthcare contexts.
The Rynes judgment confirmed that legitimate interests under Article 7(f) of Directive 95/46 (now Article 6(1)(f) GDPR) can encompass protecting the health and life of the controller's family, though this does not override the Article 9 prohibition absent a valid exemption.
Enforcement remains aggressive. CNIL imposed a €5,000,000 fine on IQVIA Operations France for non-compliance with general processing principles in health data handling. The Hungarian NAIH fined the Electronic Health Service Space €1,400, signaling that even government-operated health data platforms face scrutiny for compliance failures.
The Dutch AP has issued position papers on the European Health Data Space (EHDS), with interim rapporteur reports from March 2025 addressing implementation challenges.
Practical Guidance
Document the Article 9(2) basis explicitly for every processing activity involving health data. Relying on consent requires it to be explicit, freely given, and demonstrable — V v. European Parliament confirms that presumed or implied consent fails the threshold.
Map all recipients of health data and disclose them to data subjects. Bara establishes that statutory authorization for transfers does not discharge the Article 13 GDPR information obligation; patients must be told who receives their data.
Implement separate governance for AI systems trained on health data. Recital 68 AI Act signals that access to healthcare datasets for AI development will increasingly flow through structured data spaces, requiring contractual and technical safeguards distinct from standard care-delivery processing.
Conduct Data Protection Impact Assessments for all health data processing, particularly involving secondary use. The IQVIA enforcement demonstrates that general principles under Article 5 GDPR — minimization, purpose limitation, storage limitation — are actively policed in the health sector with substantial financial consequences.
Prepare for EHDS implementation by distinguishing primary use (care delivery) from secondary use (research and policy). The AP's position papers indicate that the EHDS will create distinct legal pathways for each, requiring separate legal bases, access controls, and transparency mechanisms.