Does your Healthtech comply with the GDPR?
The GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018) regulate the processing of health data in the healthtech sector. The most critical aspects are:
Health data (Art. 9 GDPR): Data concerning health are special categories of data (Art. 9(1)). Their processing is prohibited by default, unless one of the Art. 9(2) exceptions applies. The most relevant in healthtech are:
- Art. 9(2)(a): Explicit consent of the data subject
- Art. 9(2)(h): Processing necessary for preventive medicine, medical diagnosis, healthcare provision or health service management
- Art. 9(2)(i): Reasons of public interest in the area of public health
LOPDGDD (Arts. 7-11): Additionally regulates health data in Spain, setting specific requirements for healthcare processing, research, electronic medical records and genetic data.
DPIA (Art. 35): The DPIA is mandatory for large-scale processing of special categories of data (health, biometrics). In healthtech, almost any health data processing requires a DPIA.
Security (Art. 32): Security measures must be appropriate to the high risk of health data: encryption, strict access control, audit, resilience.
International transfers: If the healthtech uses cloud providers outside the EEA, it must comply with transfer rules (Arts. 44-49) with special rigour for health data.
- Art. 9 analysis — We identify the appropriate legal basis for health data (explicit consent, 9(2)(h)/(i))
- Healthcare DPIA — We carry out the Art. 35 Impact Assessment for health data
- LOPDGDD compliance — We verify compliance with Arts. 7-11 for healthcare data
- Enhanced security — We implement Art. 32 measures appropriate for health data
- International transfers — SCCs, BCRs and TIA for cloud providers handling health data
GDPR obligations for Healthtech
GDPR obligations for a healthtech include:
Legal bases and transparency:
- Identify the Art. 9 legal basis (explicit consent, 9(2)(h), 9(2)(i))
- Identify the Art. 6 legal basis (consent, contract, legal obligation, vital interests, public task, legitimate interest)
- Information to the data subject (Arts. 13-14): controller identity, purposes, legal basis, recipients, transfers, rights
- Clear and accessible privacy policy, adapted to patients
Data subject rights:
- Access, rectification, erasure, restriction, portability, objection (Arts. 15-21)
- Special attention to the right of access to medical records
- Right not to be subject to automated decisions (Art. 22) if diagnostic algorithms are used
Security and breaches:
- Enhanced technical and organisational measures (Art. 32): encryption, pseudonymisation, strict access control
- Breach notification within 72 hours (Art. 33)
- Communication to affected persons (Art. 34) if there is a high risk (common with health data)
DPIA and DPO:
- Mandatory DPIA for large-scale health data processing (Art. 35)
- Mandatory DPO if core activities consist of large-scale processing of special categories (Art. 37)
International transfers:
- If using cloud providers outside the EEA: SCCs, BCRs, adequacy decision or TIA
- Special rigour for health data
Fines: Up to €20 million or 4% of global turnover (upper level). The AEPD fined Marina Salud €500,000 (2025) for unlawful sub-processor engagement.
Most relevant GDPR articles for Healthtech
| Article | Topic | Application in healthtech |
|---|---|---|
| Art. 9 | Special categories | Health data: explicit consent, 9(2)(h)/(i) |
| Art. 6 | Legal bases | Consent, contract, vital interests, public task |
| Art. 13-14 | Information | Privacy policy adapted to patients |
| Art. 22 | Automated decisions | Diagnostic algorithms |
| Art. 32 | Security | Encryption, strict access, audit |
| Art. 35 | DPIA | Large-scale health data processing |
| Art. 37 | DPO | Large-scale special categories processing |
| Arts. 44-49 | Transfers | Cloud providers handling health data |
| LOPDGDD 7-11 | Healthcare data | Medical records, research, genetic data |
Real enforcement cases in the healthcare sector
- Marina Salud, S.A., €500,000 (2025) — Unlawful sub-processor engagement under Art. 28 GDPR. Source: Enforcement Tracker
- AEPD — Guide for healthcare professionals: AEPD
- AEPD — Guide for patients and healthcare users: AEPD
- AEPD — Technical note on mobile health apps: AEPD
- EDPB — Guidelines 1/2026 on scientific research: EDPB
GDPR compliance checklist for Healthtech
- Identify all health data processing operations
- Determine the Art. 9 legal basis (explicit consent, 9(2)(h), 9(2)(i))
- Determine the Art. 6 legal basis
- Draft patient-adapted privacy policy (Arts. 13-14)
- Implement data subject rights mechanisms (Arts. 15-21)
- Carry out DPIA for large-scale health data processing (Art. 35)
- Designate DPO where appropriate (Art. 37)
- Implement enhanced security measures (Art. 32): encryption, strict access
- Establish 72-hour breach notification procedure (Art. 33)
- Verify international transfers (Arts. 44-49) and TIA
- Comply with LOPDGDD Arts. 7-11 (healthcare data)
- Comply with medical records legislation (retention periods)
- Coordinate with AEPD and regional healthcare authorities
- Conduct periodic compliance audits
Related resources
- GDPR Hub — Resource centre on the GDPR
- GDPR Glossary — 45+ key terms with article references
- AI Act vs GDPR — Comparative table of both regulations
- GDPR Compliance Checker — Self-assess your compliance
- AI & Data Regulation Service — Integrated advisory
- AI Act for Healthtech — Sectoral AI Act guide for healthtech
- DPO as a Service — External Data Protection Officer
This page is general information, not legal or medical advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.