Every other sector answers one question before it processes personal data: which lawful basis in Art. 6 applies. A healthcare organisation answers two. Art. 9(1) prohibits the processing of data concerning health outright, and only a condition in Art. 9(2) lifts that prohibition. The condition sits on top of the Art. 6 basis — it does not replace it. Two justifications for the same operation, documented separately, and a processing record that names only one is incomplete on its face.
Most recurring failures in this sector trace back to that structure: a hospital that recorded “consent” and nothing else, a research team that assumed ethics approval was a lawful basis, a vendor that inherited controller obligations without noticing.
Key Takeaways
- Health data requires an Art. 6 lawful basis and an Art. 9(2) condition. Both, always, for each purpose.
- Art. 9(2)(h) — the care condition — only works subject to the professional secrecy requirement in Art. 9(3).
- Consent is usually the wrong instrument in a clinical setting: Recital 43 imbalance, and withdrawal under Art. 7(3) would oblige you to unwind a record national law requires you to keep.
- Art. 9(4) lets each member state add further conditions on health, genetic and biometric data. No EU-level answer is a complete answer.
- Breaches of Arts. 5, 6, 7 and 9 sit in the Art. 83(5) band: up to EUR 20 million or 4% of worldwide annual turnover.
The Double Basis, Applied
Pairing the two layers is the exercise that produces a defensible record. The combinations that carry most of a health organisation’s activity:
| Activity | Art. 6 basis | Art. 9(2) condition |
|---|---|---|
| Direct care, hospital or clinic record | © legal obligation or (e) public task; (b) contract in private care | (h) with the Art. 9(3) secrecy condition |
| Occupational health assessment | © legal obligation | (b) employment/social security law, or (h) |
| Emergency treatment, patient unable to consent | (d) vital interests | © vital interests |
| Communicable disease surveillance | © or (e) | (i) public health, on the basis of law |
| Clinical or observational research | (e) public task or (f) legitimate interests, depending on the sponsor | (j) research, with Art. 89(1) safeguards |
| Patient signs up to an optional third-party app | (a) consent | (a) explicit consent |
| Billing and reimbursement | (b) or © | (h), or national social-security law under (b) |
Two traps there. Legitimate interests under Art. 6(1)(f) is unavailable to public authorities in the performance of their tasks — the final subparagraph of Art. 6(1) says so, which removes it from public hospitals for their core activity. And satisfying an Art. 9(2) condition does not settle the Art. 6 layer: a private clinic treating a paying patient usually relies on Art. 6(1)(b) where a public one relies on Art. 6(1)(e), and those diverge on objection and erasure. Our breakdown of the six lawful bases in Art. 6 covers the first layer; the conditions in Art. 9 are treated separately.
Who Is the Controller Here?
Health delivery is a chain of organisations each holding a version of the same patient. Getting the controller and processor mapping right is the precondition for every contract signed afterwards.
Providers. A hospital is controller for the care record. Individual clinicians act under its authority rather than as separate controllers, which is why an unauthorised look-up by a member of staff is the hospital’s breach. A self-employed practitioner is controller in their own right.
Laboratories. Rarely the pure processors that referral contracts describe. A laboratory bound by its own accreditation, retention and professional obligations is determining purposes and means for the analytical record it holds. Decide it, record the reasoning, align the contract.
Insurers and payers. Independent controllers, never processors of the provider. Recital 54 is explicit that data processed for public-health reasons should not end up processed for other purposes by third parties such as employers or insurance companies. A flow from a clinical system to an insurer needs its own basis and its own Art. 9 condition.
Software and hosting vendors. EHR publishers, PACS operators, secure messaging providers and infrastructure hosts are processors under Art. 28. The data processing agreement is where sub-processor authorisation, breach timelines and end-of-contract deletion get resolved — or do not.
Device and SaMD manufacturers. The awkward case: typically a processor for data handled on a hospital’s instruction, and a controller for telemetry collected for its own purposes, including post-market surveillance duties product law imposes on it directly. That split, and the separate representative obligations catching non-EU manufacturers, are the subject of our page on GDPR for medical device manufacturers and SaMD.
Where two organisations genuinely determine purposes and means together — a hospital and a university running a joint registry — Art. 26 requires a transparent arrangement whose essence must reach patients.
Why Consent Is Usually the Wrong Instrument
Health organisations reach for consent because clinical practice already runs on it. That instinct imports an ethical concept into a legal slot it does not fit. Recital 43 states that consent should not provide a valid legal ground where there is a clear imbalance between the data subject and the controller, and a patient being admitted is not in a position to refuse freely.
The decisive argument is operational. Art. 7(3) gives the patient the right to withdraw at any time, as easily as consent was given. If consent were genuinely your basis for the care record, withdrawal would require you to stop processing it — while national law obliges you to retain that record for years, and clinical safety requires the same. A basis you cannot honour when the patient invokes it was never the real basis. Art. 9(2)(h) exists precisely so the care record does not depend on continuing permission.
Explicit consent under Art. 9(2)(a) is the right instrument where refusal is genuinely available and costless: enrolling in a study, sharing a record with a third-party application, communications beyond care. Reserve it for those, and see our worked consent wording for what “explicit” has to look like on the page. One further distinction trips up research teams: informed consent to a medical intervention, required by research ethics and by clinical-trial and device law, is a separate instrument from consent as a GDPR lawful basis. Neither substitutes for the other, and ethics approval is not an Art. 9(2) condition.
Art. 9(4): The EU Answer Is Never the Whole Answer
Art. 9(4) permits member states to maintain or introduce further conditions, including limitations, on the processing of genetic data, biometric data and data concerning health. More of this sector’s operative rules live in national law than in the GDPR itself.
Three areas where the national layer is decisive:
- Retention of medical records. Set nationally and varying widely. France requires hospital records to be kept 20 years from the last stay (Art. R.1112-7, Code de la santé publique), running from the eighteenth birthday for minors. These are legal obligations that override any general retention policy written centrally.
- Professional secrecy. Art. 9(3) refers back to national law and to rules set by national competent bodies. Who is bound, and what “under the responsibility of” covers for an administrator or contractor, is a national question.
- Hosting and certification. France requires health data hosting by an HDS-certified provider; other states impose localisation or approval requirements of their own.
Build the country matrix before standardising anything. Non-EU organisations reaching EU patients hit the same layer from outside — our guide for Canadian companies shows how scope is settled before this analysis begins.
The Rest of the Regime, Weighted for Health
An Art. 30 record of processing activities is mandatory: the under-250-employee relief in Art. 30(5) is disapplied where special categories are involved, so it never reaches a care provider. A DPO is required under Art. 37(1)© where core activities consist of large-scale processing of Art. 9 data — essentially every hospital and most digital-health platforms. A DPIA is not discretionary either: Art. 35(3)(b) names large-scale special-category processing explicitly, and our page on the DPIA for health data works through the Art. 35(7) content and the Art. 36 prior-consultation trigger.
Art. 32 security is assessed against the risk, and health data raises it: encryption at rest and in transit, access limited to the treating relationship, and — the point regulators keep making — access logging that someone actually reviews. On breach notification, the 72-hour clock under Art. 33 runs from awareness, and Recital 75 treats special-category data as inherently high risk, so the Art. 34 threshold for telling patients directly is reached more often here than anywhere else. Where records leave the EU, Chapter V transfer rules apply in addition, not instead.
On rights, Art. 15 access against clinical records is the most contested request, Art. 17(3)© restricts erasure where processing is necessary for public-health purposes under Art. 9(2)(h) and (i), and any triage or risk-scoring algorithm deciding without meaningful human involvement engages Art. 22.
What It Costs to Get Wrong
Art. 83(5) places infringements of Arts. 5, 6, 7 and 9 in the higher band — up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher. The Art. 83 criteria treat the categories of data affected as an aggravating factor in their own right.
Two decisions show where the sector actually gets caught. The CNIL fined Dedalus Biologie EUR 1.5 million (Deliberation SAN-2022-009, 15 April 2022) after medical and administrative data on close to 500,000 people leaked from laboratory software — findings under Arts. 28, 29 and 32, against a processor, not a hospital. The Dutch supervisory authority fined the Amsterdam hospital OLVG EUR 440,000 for failing to stop staff without a treating relationship opening patient records, an Art. 32 case turning on two-factor authentication and on log review that was not happening. Neither involved a novel legal theory. Both involved ordinary controls that nobody owned.
FAQ
Do we need consent from patients to process their medical records?
For care itself, generally no. Art. 9(2)(h) covers preventive and occupational medicine, diagnosis, the provision of health or social care and the management of health systems, provided the Art. 9(3) secrecy condition is met and there is a basis in Union or member-state law or a contract with a health professional. An Art. 6 basis is still needed alongside it. Consent belongs to processing outside care.
Is our EHR vendor a controller or a processor?
A processor for patient data handled on your instruction, under an Art. 28(3) contract. It becomes a controller for anything done on its own account — product analytics, cross-customer benchmarking, model training. Read the contract for those clauses specifically; Dedalus was a processor fined directly.
Does the GDPR set a retention period for medical records?
No. Art. 5(1)(e) requires that data not be kept longer than necessary, but the actual periods are set by national law in the Art. 9(4) space and differ by country and record type. Determine them per jurisdiction and record the legal source in your Art. 30 register.
We are a US or Asian digital-health company with EU patients. Does this apply to us?
If Art. 3(1) or Art. 3(2) brings you into scope, yes — in full, with no reduced tier. You will also need a written EU representative under Art. 27, and the Art. 27(2) exemption is closed to you because it excludes large-scale Art. 9 processing.
Where should a health organisation start?
With the Art. 30 record, purpose by purpose, naming both the Art. 6 basis and the Art. 9(2) condition. DPIA scope, vendor contracts, the retention schedule and the transfer file all derive from it, and until it exists you do not know the size of the problem.
Legiscope automates this for you
Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.
Start free trial



