GDPR · Healthtech

GDPR for Healthtech: Health Data, Art. 9 and DPIA

Health data are special categories under Art. 9 GDPR. Learn the legal bases (explicit consent, Art. 9(2)(h)/(i)), the mandatory DPIA and AEPD cases in the healthcare sector.

Does your Healthtech comply with the GDPR?

The GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018) regulate the processing of health data in the healthtech sector. The most critical aspects are:

Health data (Art. 9 GDPR): Data concerning health are special categories of data (Art. 9(1)). Their processing is prohibited by default, unless one of the Art. 9(2) exceptions applies. The most relevant in healthtech are:

  • Art. 9(2)(a): Explicit consent of the data subject
  • Art. 9(2)(h): Processing necessary for preventive medicine, medical diagnosis, healthcare provision or health service management
  • Art. 9(2)(i): Reasons of public interest in the area of public health

LOPDGDD (Arts. 7-11): Additionally regulates health data in Spain, setting specific requirements for healthcare processing, research, electronic medical records and genetic data.

DPIA (Art. 35): The DPIA is mandatory for large-scale processing of special categories of data (health, biometrics). In healthtech, almost any health data processing requires a DPIA.

Security (Art. 32): Security measures must be appropriate to the high risk of health data: encryption, strict access control, audit, resilience.

International transfers: If the healthtech uses cloud providers outside the EEA, it must comply with transfer rules (Arts. 44-49) with special rigour for health data.

  • Art. 9 analysis — We identify the appropriate legal basis for health data (explicit consent, 9(2)(h)/(i))
  • Healthcare DPIA — We carry out the Art. 35 Impact Assessment for health data
  • LOPDGDD compliance — We verify compliance with Arts. 7-11 for healthcare data
  • Enhanced security — We implement Art. 32 measures appropriate for health data
  • International transfers — SCCs, BCRs and TIA for cloud providers handling health data

GDPR obligations for Healthtech

GDPR obligations for a healthtech include:

Legal bases and transparency:

  • Identify the Art. 9 legal basis (explicit consent, 9(2)(h), 9(2)(i))
  • Identify the Art. 6 legal basis (consent, contract, legal obligation, vital interests, public task, legitimate interest)
  • Information to the data subject (Arts. 13-14): controller identity, purposes, legal basis, recipients, transfers, rights
  • Clear and accessible privacy policy, adapted to patients

Data subject rights:

  • Access, rectification, erasure, restriction, portability, objection (Arts. 15-21)
  • Special attention to the right of access to medical records
  • Right not to be subject to automated decisions (Art. 22) if diagnostic algorithms are used

Security and breaches:

  • Enhanced technical and organisational measures (Art. 32): encryption, pseudonymisation, strict access control
  • Breach notification within 72 hours (Art. 33)
  • Communication to affected persons (Art. 34) if there is a high risk (common with health data)

DPIA and DPO:

  • Mandatory DPIA for large-scale health data processing (Art. 35)
  • Mandatory DPO if core activities consist of large-scale processing of special categories (Art. 37)

International transfers:

  • If using cloud providers outside the EEA: SCCs, BCRs, adequacy decision or TIA
  • Special rigour for health data

Fines: Up to €20 million or 4% of global turnover (upper level). The AEPD fined Marina Salud €500,000 (2025) for unlawful sub-processor engagement.

Most relevant GDPR articles for Healthtech

ArticleTopicApplication in healthtech
Art. 9Special categoriesHealth data: explicit consent, 9(2)(h)/(i)
Art. 6Legal basesConsent, contract, vital interests, public task
Art. 13-14InformationPrivacy policy adapted to patients
Art. 22Automated decisionsDiagnostic algorithms
Art. 32SecurityEncryption, strict access, audit
Art. 35DPIALarge-scale health data processing
Art. 37DPOLarge-scale special categories processing
Arts. 44-49TransfersCloud providers handling health data
LOPDGDD 7-11Healthcare dataMedical records, research, genetic data

Real enforcement cases in the healthcare sector

  • Marina Salud, S.A., €500,000 (2025) — Unlawful sub-processor engagement under Art. 28 GDPR. Source: Enforcement Tracker
  • AEPD — Guide for healthcare professionals: AEPD
  • AEPD — Guide for patients and healthcare users: AEPD
  • AEPD — Technical note on mobile health apps: AEPD
  • EDPB — Guidelines 1/2026 on scientific research: EDPB

GDPR compliance checklist for Healthtech

  • Identify all health data processing operations
  • Determine the Art. 9 legal basis (explicit consent, 9(2)(h), 9(2)(i))
  • Determine the Art. 6 legal basis
  • Draft patient-adapted privacy policy (Arts. 13-14)
  • Implement data subject rights mechanisms (Arts. 15-21)
  • Carry out DPIA for large-scale health data processing (Art. 35)
  • Designate DPO where appropriate (Art. 37)
  • Implement enhanced security measures (Art. 32): encryption, strict access
  • Establish 72-hour breach notification procedure (Art. 33)
  • Verify international transfers (Arts. 44-49) and TIA
  • Comply with LOPDGDD Arts. 7-11 (healthcare data)
  • Comply with medical records legislation (retention periods)
  • Coordinate with AEPD and regional healthcare authorities
  • Conduct periodic compliance audits

This page is general information, not legal or medical advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.

Featured Services

Frequently Asked Questions

Which Art. 9 legal basis applies to health data?

The most common legal bases in healthtech are: explicit consent (Art. 9(2)(a)) for health apps and research; processing necessary for preventive medicine, medical diagnosis or healthcare provision (Art. 9(2)(h)) for healthcare facilities and professionals; and reasons of public interest in the area of public health (Art. 9(2)(i)) for health authorities. The choice depends on the context: direct healthcare, research, public health.

When is the DPIA mandatory in healthtech?

The DPIA (Art. 35 GDPR) is mandatory for high-risk processing, including large-scale processing of special categories of data (health, biometrics). In healthtech, almost any large-scale health data processing requires a DPIA. It must document the risk analysis, mitigation measures and residual assessment. It is a prerequisite before starting the processing.

What does the LOPDGDD say about health data?

The LOPDGDD (Arts. 7-11) additionally regulates health data in Spain. It sets specific requirements for healthcare processing, research, electronic medical records, genetic data and biological data. For example, Art. 11 regulates the processing of health data for scientific research purposes, requiring anonymisation or pseudonymisation where possible.

What security measures does Art. 32 require for health data?

Art. 32 GDPR requires technical and organisational measures appropriate to the risk. For health data, measures must be enhanced: encryption of data at rest and in transit, strict access control (role-based access, multi-factor authentication), access logging, resilience, backups, periodic audits, and incident response procedures. The ENS (National Security Scheme) sets additional requirements for public healthcare systems.

What fines has the AEPD imposed in the healthcare sector?

The AEPD fined Marina Salud, S.A. €500,000 (2025) for unlawful sub-processor engagement under Art. 28 GDPR. Although not specifically a health data case, it illustrates the AEPD's active supervision in the healthcare sector. The AEPD has also published guides for healthcare professionals and for patients and users, and a technical note on mobile health apps.

How are international transfers of health data made?

If your healthtech uses cloud providers outside the EEA, it must comply with transfer rules (Arts. 44-49): adequacy decision (EU-US Framework 2023), Standard Contractual Clauses (SCCs 2021), Binding Corporate Rules (BCRs), or codes of conduct/certifications. In addition, a TIA (Transfer Impact Assessment) must be carried out with special rigour for health data, considering the third country's surveillance laws and supplementary measures.

What rights do patients have over their health data?

Patients have the same rights as any data subject (Arts. 15-21): access, rectification, erasure, restriction, portability, objection. Especially relevant is the right of access to medical records, additionally regulated by healthcare legislation. The right to erasure has limits: medical record data must be retained according to legal retention periods (generally 5-10 years depending on regional legislation).

Which authorities supervise the GDPR in healthtech in Spain?

The AEPD supervises the GDPR. Regional healthcare authorities supervise medical records and healthcare facilities. The AEMPS supervises medical devices. In medical AI cases, the AESIA (AI Act), the AEMPS (MDR/IVDR) and the AEPD (GDPR) may all intervene. The AEPD has published specific guides for healthcare professionals, patients and mobile health apps.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us