AuditXYZ

Compliance Framework

General Data Protection Regulation - Healthcare Applications (GDPR Health)

GDPR imposes heightened requirements on health data as a special category. This guide covers lawful bases for health data processing, DPIAs, patient rights, cross-border transfers, and healthcare-specific compliance.

$30,000–$300,0004–12 months2018 (enforcement date, with ongoing guidance from DPAs)
Issuing BodyEuropean Parliament and Council of the European Union
First Published2016-04-27
Latest Version2018 (enforcement date, with ongoing guidance from DPAs)
Typical Cost$30,000–$300,000
Typical Timeline4–12 months
Audit RequiredNo
Audit FrequencyNo mandatory audit, but Data Protection Impact Assessments (DPIAs) required for high-risk processing. DPAs conduct investigations and audits as needed.
Geographyeuropean-union, united-kingdom

GDPR for Healthcare: Health Data Protection Guide

The General Data Protection Regulation (GDPR) classifies health data as a "special category" of personal data, subjecting it to heightened protection requirements. For healthcare organizations, health tech companies, pharmaceutical firms, and clinical researchers operating in or serving EU residents, GDPR adds a significant compliance layer on top of existing healthcare regulations. With fines reaching EUR 20 million or 4% of global annual revenue, and data protection authorities (DPAs) actively investigating healthcare organizations, GDPR compliance is not optional for any organization touching EU patient data.

What GDPR Requires for Health Data and Who Issues It

GDPR (Regulation 2016/679) was adopted on April 27, 2016 and became enforceable on May 25, 2018. It is issued by the European Parliament and Council of the EU and applies directly as law across all EU member states without national transposition. Post-Brexit, the UK has retained a substantially equivalent UK GDPR through the Data Protection Act 2018.

GDPR is enforced by national data protection authorities (DPAs) in each EU member state — such as the CNIL in France, the BfDI in Germany, the ICO in the UK, and the DPC in Ireland (which supervises many US tech companies with EU headquarters in Ireland). For cross-border processing, the "lead supervisory authority" mechanism of the one-stop-shop applies: a company with its main EU establishment in a single member state is primarily regulated by that member state's DPA, though affected DPAs in other member states participate in decisions.

Health data is defined broadly under GDPR Article 4(15) as "personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status." This covers medical diagnoses and treatments, health records, mental health information, disability information, genetic data, biometric data used for health purposes, and clinical trial data.

Who Must Comply with GDPR Health Requirements

GDPR's extra-territorial scope means it applies regardless of where the organization is located:

Any organization processing health data of EU/EEA residents must comply, whether or not the organization has a physical presence in the EU. This includes:

  • EU and UK hospitals, clinics, and general practitioners
  • Health insurance companies and health plan administrators
  • Pharmaceutical companies conducting clinical trials in the EU
  • Contract research organizations (CROs) working with EU patient data
  • Health tech companies (SaaS platforms, medical device software) with EU healthcare customers
  • Genetic testing companies serving EU consumers
  • Health data analytics companies processing EU patient data
  • Researchers and academic institutions using EU health data

For non-EU health tech companies, GDPR applies the moment they process health data of EU residents — whether through direct patient relationships, clinical trial agreements, or providing software to EU healthcare providers that use the platform to process patient data.

Special Category Health Data Requirements

Article 9: Prohibition and Conditions

GDPR Article 9(1) establishes a general prohibition on processing "special categories" of personal data, which include health data, genetic data, biometric data, and data concerning sex life or sexual orientation. Article 9(2) then provides ten specific conditions under which health data processing is permitted:

  1. Explicit consent of the data subject
  2. Necessary for carrying out obligations in employment, social security, or social protection law
  3. Necessary to protect vital interests where the data subject cannot give consent
  4. Processing by a not-for-profit body with a political, philosophical, religious, or trade union aim, subject to conditions
  5. Health data manifestly made public by the data subject
  6. Necessary for the establishment, exercise, or defense of legal claims — relevant to litigation and insurance disputes involving health information
  7. Substantial public interest, subject to Union or member state law and proportionality
  8. Necessary for preventive or occupational medicine, medical diagnosis, provision of health or social care, or management of health or social care systems — the primary lawful basis for most healthcare processing
  9. Public interest in the area of public health
  10. Archiving, scientific or historical research, or statistical purposes subject to safeguards

For most healthcare providers and health tech companies, Condition 8 (health/social care purposes) is the primary basis for processing patient data. Clinical researchers typically rely on Condition 10 (research purposes) with appropriate safeguards including pseudonymization and ethics committee oversight.

Explicit Consent vs. Implied Consent

Where Condition 1 (explicit consent) is relied upon for health data, the consent must meet a heightened standard: freely given, specific, informed, and unambiguous, with an explicit affirmative act (no pre-ticked boxes). For health data, this typically means a separate consent statement specifically identifying the health data categories being processed, not bundled with general terms and conditions.

Explicit consent is revocable at any time without detriment to the data subject. Organizations must maintain records of consent and implement processes to honor revocations promptly.

Key Compliance Requirements for Healthcare Organizations

Data Protection Impact Assessments (DPIAs)

DPIAs are mandatory before any processing that is "likely to result in a high risk" to individuals. For health data, this threshold is almost always met by:

  • Large-scale processing of health data (e.g., hospital systems, health insurance databases)
  • Systematic and extensive profiling based on health data
  • Processing of health data using new technologies with uncertain risk profiles (AI diagnostics, wearables)
  • Cross-border transfers of health data to third countries

A DPIA must describe the processing, assess necessity and proportionality, assess risks to data subjects, and identify measures to address those risks. If a DPIA indicates high residual risk that cannot be mitigated, the organization must consult with its DPA before proceeding.

DPAs publish lists of processing activities that always require a DPIA. Health data appears on virtually every DPA's mandatory DPIA list. DPIAs must be updated when the processing changes and reviewed when risks change.

Data Protection Officer (DPO) Appointment

A DPO must be appointed when core activities consist of large-scale processing of special category data, which health data processing almost always triggers. The DPO:

  • Must have expert knowledge of data protection law and practice
  • Must be provided with resources to carry out their tasks
  • Must be able to perform their tasks independently
  • Must report to the highest management level
  • Must not be dismissed or penalized for performing DPO duties
  • Must be accessible to data subjects and the DPA

The DPO can be an employee or an external advisor. Many smaller healthcare organizations engage an outsourced or fractional DPO. The DPO's contact details must be published and communicated to the supervisory authority.

Patient Rights Management

GDPR grants data subjects extensive rights over their health data:

  • Right of access: Patients can request a copy of all their personal health data processed by the organization, free of charge, within one month (extendable to three months for complex requests)
  • Right to rectification: Patients can request correction of inaccurate health data
  • Right to erasure ("right to be forgotten"): Patients can request deletion of their health data, subject to limitations where processing is necessary for health or legal purposes — which commonly override erasure requests in healthcare contexts
  • Right to restriction: Patients can request restriction of processing while accuracy is contested or objection is being considered
  • Right to data portability: For health data processed on the basis of consent or contract, patients can request their data in a machine-readable format for transfer to another provider — the basis for much of the EU's health data portability policy
  • Right to object: Patients can object to processing for direct marketing or legitimate interests grounds
  • Rights related to automated decision-making: Protections against purely automated decisions with significant effects, including AI-based clinical decision support systems

Organizations must establish processes to receive, verify, and respond to rights requests within the statutory timeframes. Failure to respond to access requests is one of the most common GDPR enforcement triggers in healthcare.

Breach Notification

GDPR Article 33 requires notification to the supervisory DPA within 72 hours of becoming aware of a personal data breach — a significantly shorter window than HIPAA's 60-day timeline. The notification must include the nature of the breach, categories and approximate number of individuals and records affected, likely consequences, and measures taken or proposed.

Article 34 requires notification to affected individuals "without undue delay" where the breach is likely to result in a high risk to their rights and freedoms. For health data breaches, this threshold is almost always met, making individual notification the norm rather than the exception.

Cross-Border Data Transfers

Health data cannot be transferred outside the EU/EEA without an appropriate transfer safeguard. Options include:

  • Adequacy decisions: The European Commission has recognized certain countries as providing adequate protection (including the UK under a time-limited adequacy decision, Israel, New Zealand, Japan, and others)
  • Standard Contractual Clauses (SCCs): GDPR-compliant contracts between the EU data exporter and the non-EU data importer, including mandatory due diligence on importer security practices
  • Binding Corporate Rules (BCRs): Intra-group transfer mechanisms for multinational organizations

US healthcare organizations receiving EU patient data — through clinical trials, telemedicine, or SaaS platforms used by EU healthcare providers — must ensure appropriate transfer mechanisms are in place. The EU-US Data Privacy Framework (DPF), adopted in 2023, provides an adequacy-equivalent mechanism for US companies that self-certify, but may not cover all health data transfers and has faced legal challenges.

Data Minimization, Purpose Limitation, and Storage Limitation

Three foundational GDPR principles are particularly important for health data:

Data minimization: Only personal health data that is adequate, relevant, and limited to what is necessary for the specified purpose should be collected and processed. Healthcare organizations that collect extensive health history for single-visit interactions, or health apps that request location and contact data when not needed for health functions, face data minimization scrutiny.

Purpose limitation: Health data collected for one purpose cannot be used for an incompatible secondary purpose without explicit consent. Clinical data collected for treatment cannot be used for commercial purposes without consent, even if the commercial analysis might eventually benefit healthcare.

Storage limitation: Health data should not be retained longer than necessary for the stated purpose, subject to legal retention requirements (which in healthcare often require long retention periods for medical records). Organizations must have documented retention schedules and deletion procedures.

Audit and Assessment Process

GDPR has no mandatory third-party certification. Compliance is demonstrated through:

ActivityFrequencyPurpose
DPIABefore high-risk processing and when processing changesAssess and mitigate processing risks
Records of processing activities (Article 30)Maintained continuouslyDocument all processing activities
DPO annual reportAnnualDPO reporting to board on program status
DPA investigationTriggered by complaint or breachEnforcement and investigation
Data protection auditRecommended annuallyInternal or external compliance review

DPA enforcement in healthcare has been significant. The Spanish DPA (AEPD) has imposed fines on healthcare providers for unauthorized access to patient records. The German DPAs have taken action against hospitals for inadequate security measures. The Irish DPC has investigated major pharmaceutical and health tech companies for health data processing.

Costs and Timeline

Organization TypeTypical TimelineEstimated Cost Range
Small clinic or health app4–6 months$30,000–$80,000
Health tech SaaS company6–9 months$80,000–$150,000
Large hospital or health system9–12 months$150,000–$300,000
Pharmaceutical company9–12 months$150,000–$300,000

Ongoing annual costs include DPO fees, DPIA updates, consent management platform maintenance, and training.

  • HIPAA: About 40% overlap. Both protect patient health information, but the frameworks differ in structure. HIPAA is US-specific, sectoral, and organized around covered entities. GDPR applies across all sectors globally and follows a broader data subject rights model. Organizations serving both US and EU patients must maintain compliance with both. See the HIPAA guide.
  • ISO 27701: Approximately 70% overlap. ISO 27701 is a privacy information management extension to ISO 27001 that directly addresses GDPR compliance for data controllers and processors. ISO 27701 certification provides a strong foundation for demonstrating GDPR compliance.
  • NHS DSPT: About 55% overlap for UK healthcare organizations, where UK GDPR and NHS DSPT operate in parallel. See the NHS DSPT guide.
  • PIPEDA Health: Canadian health organizations serving EU residents face both PIPEDA and GDPR obligations. See the PIPEDA Health guide.

How Automation Helps

GDPR health compliance requires continuous management of subject rights requests, consent records, breach notification workflows, and DPIA documentation:

  • Consent management platforms track patient consent for different processing activities and honor revocations automatically
  • Subject rights request management tools receive, log, verify, and respond to access and erasure requests within statutory timelines
  • Data mapping tools maintain the Article 30 records of processing activities with current and accurate information
  • Breach notification workflows track incidents through the 72-hour DPA notification process
  • Training management platforms document ongoing GDPR awareness training

LowerPlane supports GDPR health compliance alongside HIPAA, HITRUST, and 50-plus additional frameworks. At $4,000 per year entry pricing with a free tier available, and rated 9.4/10 on AuditXYZ, LowerPlane helps healthcare technology companies manage overlapping EU and US health data compliance requirements in a unified platform. For health technology companies, see /for/healthtech. Compare platforms at /compare/best-compliance-automation-platforms.

Frequently Asked Questions

What is the difference between health data under GDPR and PHI under HIPAA?

HIPAA's "protected health information" (PHI) is individually identifiable health information held or transmitted by covered entities and business associates. GDPR's "health data" is any personal data related to the physical or mental health of a natural person. Both are broad definitions, but they operate differently. HIPAA is sectoral — it only applies to covered entities and their business associates. GDPR is universal — it applies to any organization processing health data of EU residents, regardless of sector. Key practical differences: GDPR requires explicit consent as a lawful basis in many scenarios where HIPAA permits disclosure without patient authorization; GDPR grants broader subject access rights with a shorter response timeline; and GDPR's 72-hour breach notification is substantially faster than HIPAA's 60-day window.

Does a health app need a DPO under GDPR?

A health app that processes health data on a large scale almost certainly needs a DPO. The DPO obligation is triggered when core activities consist of large-scale processing of special category data. Health apps that collect detailed health metrics, medical symptoms, or activity data from many users likely meet this threshold. Even apps with smaller user bases that process health data systematically as a core function should assess DPO requirements carefully. Many health app companies appoint a DPO proactively given the sensitivity of health data and DPA expectations in the sector.

How does GDPR affect clinical trials with EU participants?

Clinical trials involving EU participants must identify a lawful basis for processing participant health data — typically Condition 9(j) of Article 9 (scientific research purposes) implemented through member state law. Researchers must provide trial participants with a transparent data processing notice, implement appropriate safeguards including pseudonymization and access controls, and ensure that data transfers to sponsors or CROs outside the EU are covered by appropriate transfer mechanisms. EU clinical trial regulations and the EU Clinical Trials Regulation (CTR 536/2014) provide the research framework, while GDPR governs the data protection aspects. Ethics committee approval is typically required and interacts with GDPR obligations.

What are the biggest GDPR enforcement risks for healthcare organizations?

The highest-risk areas in healthcare GDPR enforcement are: (1) failure to have a lawful basis for processing health data under Article 9; (2) inadequate security measures leading to health data breaches; (3) failure to conduct DPIAs before high-risk processing; (4) inadequate response to data subject rights requests; and (5) unauthorized cross-border transfers of health data. DPAs have imposed significant fines in all of these categories. Health organizations should prioritize risk assessment, staff training, and technical security controls as the highest-impact compliance investments.

How does the EU Health Data Space affect GDPR compliance?

The European Health Data Space (EHDS) Regulation, adopted by the EU in 2024, establishes a new framework for the secondary use of health data across the EU. It creates a right for patients to access their own health data in electronic format, an obligation for healthcare providers to share health data for cross-border care, and a framework for authorized entities to access de-identified health data for research, public health, and policy purposes. The EHDS operates alongside GDPR — organizations using health data under EHDS must still comply with GDPR requirements for the personal data involved. Healthcare organizations should assess how EHDS affects their data sharing obligations and whether they need to apply for authorized secondary use status.

Request a GDPR Health consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27701Medium70%
NHS DSPTMedium55%
HIPAALow40%

Get matched with a GDPR Health auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.