GDPR Compliance

Health Data Under Article 9 GDPR: Lawful Conditions

Which Art. 9(2) conditions health organisations actually rely on and how each one fails: explicit consent, 9(2)(h) with the Art. 9(3) secrecy trap, public health, and research under Art. 89(1).

Art. 9(2) offers ten conditions. A health organisation will use four of them, and each one fails in a specific, predictable way. The failures are not exotic: a consent that cannot lawfully be withdrawn, a care condition relied on by staff nobody bound to secrecy, a research condition invoked without the national law it depends on. This page works through the four in the order they come up, and starts with the boundary question that decides whether you are in Art. 9 at all.

Key Takeaways

  • Art. 4(15) and Recital 35 define data concerning health broadly, and the CJEU reads it broadly again: data merely capable of revealing health status is caught.
  • 9(2)(a) explicit consent demands an express statement, and Union or member-state law can remove the option entirely.
  • 9(2)(h) does not stand alone. Art. 9(3) requires the data be processed by, or under the responsibility of, someone bound by professional secrecy.
  • 9(2)(i) and 9(2)(j) both require a basis in Union or member-state law. Without one, they are unavailable — the GDPR does not supply it.
  • Every one of these still needs an Art. 6 lawful basis underneath it.

What Counts as Data Concerning Health

Art. 4(15) defines it as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about that person’s health status. Recital 35 expands the perimeter: a number, symbol or particular assigned to identify someone for health purposes; information derived from testing or examining a body part or bodily substance, including genetic data and biological samples; and information about disease, disability, disease risk, medical history, clinical treatment or physiological state — independent of its source, whether a physician, a hospital, a medical device or an in vitro diagnostic test.

Two judgments settle how far this reaches. In C-184/20 (OT v Vyriausioji tarnybinės etikos komisija, Grand Chamber, 1 August 2022) the Court held that publishing data that indirectly discloses a special category — there, sexual orientation inferred from a partner’s name — is processing of special-category data under Art. 9(1). Inference is enough. In C-21/23 (Lindenapotheke, Grand Chamber, 4 October 2024) it held that data supplied when ordering pharmacy-only medicines online is data concerning health, even where the medicine needs no prescription, because the processing is capable of revealing information about the customer’s health status.

That is the standard to apply to wellness products. The Article 29 Working Party’s letter to the Commission of 5 February 2015 on lifestyle and wellbeing apps set out the same logic before the GDPR existed, distinguishing inherently medical data, raw sensor data that can support a conclusion about health status alone or in combination, and conclusions drawn about health status regardless of their accuracy. A step counter in isolation may sit outside; the same data reconciled with weight, sleep and heart rate to flag an arrhythmia risk does not, and neither does a fertility tracker, a mental-health journalling app or a symptom checker. If the product’s value proposition is telling the user something about their health, you are in Art. 9 and the special-categories regime applies in full.

Explicit consent is ordinary consent plus an express statement. Standard consent under Art. 4(11) needs an unambiguous indication by a clear affirmative action; a tick box does that. Explicit consent needs the data subject to state the agreement — a signed or electronically signed declaration, a two-step confirmation, a recorded oral statement in a documented context. All the Art. 7 conditions still apply on top: freely given, specific, informed, granular, withdrawable, and demonstrable by the controller.

Where it fails:

  • Imbalance. Recital 43 removes consent as a valid ground where there is a clear imbalance between subject and controller. A patient in a hospital bed is the paradigm case; so is an employee facing occupational health.
  • Withdrawal you cannot honour. If the record must survive withdrawal because national law requires retention, consent was never operative. Choose a condition that reflects reality.
  • Bundling. Consent conditioned on receiving a service that does not require the processing is not freely given under Art. 7(4).
  • The law can close it. The final words of Art. 9(2)(a) allow Union or member-state law to provide that the prohibition may not be lifted by the data subject. In those cases consent is not merely weak, it is unavailable.

Where it works: enrolment in a study, sharing a record with a third-party application, a patient portal feature the patient can decline without consequence, and any secondary use that a reasonable patient would not expect. See our consent wording examples for the drafting.

9(2)(h) — Healthcare Provision, and the Art. 9(3) Condition

This is the condition that carries clinical care. It covers processing necessary for preventive or occupational medicine, assessment of an employee’s working capacity, medical diagnosis, the provision of health or social care or treatment, and the management of health or social care systems and services. It needs a foundation: Union or member-state law, or a contract with a health professional.

The part that gets forgotten is Art. 9(2)(h)'s own cross-reference. It applies only subject to the conditions in Art. 9(3): the data must be processed by, or under the responsibility of, a professional subject to an obligation of professional secrecy under Union or member-state law or rules set by national competent bodies, or by another person also subject to an equivalent obligation of secrecy.

That sentence has operational consequences most organisations have never worked through:

  • Non-clinical staff. Billing clerks, IT administrators, data analysts and outsourced support desks are not health professionals. Relying on 9(2)(h) for their access requires them to be bound by an equivalent secrecy obligation — contractually, statutorily, or through national rules — and requires you to be able to show it.
  • Processors. A hosting provider or EHR vendor with access to identifiable records sits inside the same requirement. The obligation belongs in the Art. 28 contract and needs to name secrecy, not just confidentiality boilerplate.
  • Purely administrative platforms. A scheduling or claims product with no clinical involvement often cannot satisfy Art. 9(3) at all and needs a different condition.

Note also what 9(2)(h) does not cover. It is a care and system-management condition. Product improvement, marketing, benchmarking against other providers and training a commercial model are not the provision of health care, and stretching the condition to cover them is one of the more common findings against digital-health companies.

9(2)(i) — Public Health

Available for processing necessary for reasons of public interest in the area of public health — the text names protecting against serious cross-border threats to health, and ensuring high standards of quality and safety of health care and of medicinal products and medical devices. That second limb matters to manufacturers running vigilance and post-market obligations, and is treated in our page on GDPR for medical device manufacturers and SaMD.

It fails on its condition rather than its scope: it requires a basis in Union or member-state law providing suitable and specific measures to safeguard rights and freedoms, in particular professional secrecy. A private organisation cannot self-declare a public-health purpose. Identify the instrument, cite it, and check it actually authorises what you propose. Recital 54 adds a limit worth quoting in any assessment: processing for public-health reasons should not result in the data being processed for other purposes by third parties such as employers, insurance companies or banks.

9(2)(j) — Scientific Research

Research, archiving in the public interest and statistical purposes are covered, again on the basis of Union or member-state law, which must be proportionate to the aim pursued, respect the essence of the right to data protection, and provide suitable and specific safeguards. And it must be in accordance with Art. 89(1), which requires technical and organisational measures ensuring respect for data minimisation, and names pseudonymisation as the mechanism — with the instruction that where the purpose can be achieved without identification, it must be.

Recital 159 reads scientific research broadly enough to include privately funded and applied research, so commercial sponsors are not excluded. Recital 33 contemplates consent given to areas of research where the specific purpose cannot be identified in advance, but supervisory authorities read that narrowly and it dispenses with none of the other consent conditions. The EDPB’s Guidelines 03/2020 on processing health data for scientific research, adopted 21 April 2020, remain the clearest statement of how transparency, storage limitation and transfers apply to research datasets.

The most common error is relying on 9(2)(j) with no identified national research provision, because the derogations in Art. 89(2) — limiting access, rectification, restriction and objection — exist only where Union or member-state law creates them. No law, no derogation, and a research dataset that must answer subject access requests it was never built to answer.

The Conditions People Reach for and Cannot Use

9(2)© vital interests is confined to cases where the data subject is physically or legally incapable of giving consent. It covers the unconscious patient in the emergency department; it does not cover a routine appointment. 9(2)(e), data manifestly made public by the data subject, is narrow: a post in a closed patient support group is not manifestly public. 9(2)(b) is an employment and social-security condition and belongs to occupational health, not to care. And legitimate interests under Art. 6(1)(f) never lifts the Art. 9(1) prohibition — it is a first-layer basis only, and pairing it with a special category is where a great many records quietly fall apart.

Art. 9(4): Check the Member State

Art. 9(4) allows member states to maintain or introduce further conditions, including limitations, on the processing of genetic data, biometric data and data concerning health. Consent may be excluded, secrecy rules may be stricter, hosting may be certified, retention may be fixed by statute. A condition that is available in one member state may be qualified or closed in the next, and an EU-level analysis is a starting point rather than a conclusion. Our pillar guide for healthcare organisations sets out the wider compliance picture, and any large-scale processing on these conditions also triggers the health DPIA under Art. 35(3)(b).

FAQ

Not stronger — different, and in a care setting usually weaker. Consent must be freely given and withdrawable; a care record must be retained. Choosing consent where 9(2)(h) applies creates an obligation you cannot meet the first time a patient invokes Art. 7(3).

Do wellness and fitness data fall under Art. 9?

Once the data is used, alone or in combination, to draw a conclusion about health status or risk, yes. That is the WP29 test from 2015 and it fits the reasoning in Lindenapotheke: what matters is whether the processing is capable of revealing health information, not how the product is marketed.

Our IT administrators can see patient records. Is that a problem under Art. 9(3)?

It is a question you must answer in writing. Art. 9(3) requires processing by or under the responsibility of someone bound by professional secrecy, or another person under an equivalent obligation. Access alone is processing. Bind them explicitly, document how, and restrict access to what the role requires.

Can we rely on Art. 9(2)(j) for a commercial research programme?

Potentially — Recital 159 does not exclude privately funded research. But you need the Union or member-state legal basis 9(2)(j) requires, the Art. 89(1) safeguards in place, and an honest view of whether the work is scientific research or product development described as research.

Do we need both Art. 6 and Art. 9 in the processing record?

Yes, separately and per purpose. An Art. 30 record naming one layer is incomplete, and it is the first document a supervisory authority asks for.

Legiscope automates this for you

Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.

Start free trial
TD
Written by
Fondateur de Legiscope et expert RGPD

Docteur en droit de l'Université Panthéon-Assas (Paris II), 23 ans d'expérience en droit du numérique et conformité RGPD. Ancien conseiller de l'administration du Premier ministre sur la mise en œuvre du RGPD. Thiébaut est le fondateur de Legiscope, plateforme de conformité RGPD automatisée par l'IA.

View full author profile →