Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847 (Text with EEA relevance)
(72) Given the sensitivity of electronic health data, it is necessary to reduce risks for the privacy of natural persons by applying the data minimisation principle. Therefore, non-personal electronic health data should be made available in all cases where the provision of such data is sufficient. If the health data user needs to use personal electronic health data, it should clearly indicate in its request the justification for the use of that type of data and the health data access body should assess whether that justification is valid. The personal electronic health data should only be made available in pseudonymised format. Taking into account the specific purposes of the processing, personal electronic health data should be pseudonymised or anonymised as early as possible in the process of making data available for secondary use. It should be possible for pseudonymisation and anonymisation to be carried out by health data access bodies or by health data holders. As controllers, health data access bodies and health data holders should be allowed to delegate those tasks to processors. When providing access to a pseudonymised or anonymised dataset, a health data access body should use state-of-the-art pseudonymisation or anonymisation technology and standards, ensuring to the maximum extent possible that natural persons cannot be re-identified by health data users. Such technology and standards for data pseudonymisation or anonymisation should be further developed. Health data users should not attempt to re-identify natural persons from the dataset provided under this Regulation, and where they do so they should be subject to administrative fines and enforcement measures laid down in this Regulation or possible criminal penalties, where national law so provides. Moreover, a health data applicant should be able to request a response to a health data request in an anonymised statistical format. In such cases, the health data user will only process non-personal data, and the health data access body will remain sole controller for any personal data necessary to provide the response to the health data request.
(73) In order to ensure that all health data access bodies issue data permits in a similar way, it is necessary to establish a standard common process for the issuance of data permits, with similar requests in different Member States. The health data applicant should provide health data access bodies with several elements of information that would help the body evaluate the health data access application and decide if the health data applicant can receive a data permit, and coherence should be ensured between different health data access bodies. The information provided as part of the health data access application should comply with the requirements established under this Regulation in order to enable it to be thoroughly assessed, as a data permit should only be issued if all the necessary conditions set out in this Regulation are met. In addition, where relevant, that information should include a declaration by the health data applicant that the intended use of the health data requested does not pose a risk of stigmatisation, or of causing harm to the dignity, of natural persons or groups to which the dataset requested relates. An ethical assessment could be requested based on national law. In that case, it should be possible for existing ethics bodies to carry out such assessments for the health data access body. Existing ethics bodies of Member States should make their expertise available to the health data access body for that purpose. Alternatively, Member States should be able to provide for ethics bodies to be part of the health data access body. The health data access body, and where relevant health data holders, should assist health data users in the selection of the suitable datasets or data sources for the intended purpose of secondary use. Where the health data applicant needs data in an anonymised statistical format, it should submit a health data request, requiring the health data access body to provide the result directly. A refusal of a data permit by the health data access body should not preclude the health data applicant from submitting a new health data access application. In order to ensure a harmonised approach between health data access bodies and to limit the administrative burden for the health data applicants, the Commission should support the harmonisation of health data access applications, as well as health data requests, including by establishing the relevant templates. In justified cases, such as in the case of a complex and burdensome request, the health data access body should be allowed to extend the time period for health data holders to make the requested electronic health data available to it.
(74) As their resources are limited, health data access bodies should be allowed to apply prioritisation rules, for instance prioritising public institutions over private entities, but they should not discriminate between the national organisations and organisations from other Member States within the same category of priorities. A health data user should be able to extend the duration of the data permit in order, for example, to allow access to the datasets to reviewers of scientific publications or to enable additional analysis of the dataset based on the initial findings. This should require an amendment of the data permit and could be subject to an additional fee. However, in all cases, the data permit should reflect such additional uses of the dataset. Preferably, the health data user should mention them in their initial health data access application. In order to ensure a harmonised approach between health data access bodies, the Commission should support the harmonisation of data permits.
(75) As the COVID-19 crisis has shown, the Union institutions, bodies, offices and agencies with a legal mandate in the field of public health, especially the Commission, need access to health data for a longer period and on a recurring basis. This may be the case not only for specific circumstances provided for in Union or national law in times of crisis but also to provide scientific evidence and technical support for Union policies on a regular basis. Access to such data could be required in specific Member States or throughout the whole territory of the Union. Such Union institutions, bodies, offices and agencies should be able to benefit from an accelerated procedure for having data made available, ordinarily in less than two months, with a possibility of prolonging the timeline by one month in more complex cases.
(76) Member States should be able to designate trusted health data holders for which the data permit issuing procedure can be performed in a simplified manner, in order to alleviate the administrative burden for health data access bodies of managing requests for the data processed by them. Trusted health data holders should be allowed to assess the health data access applications submitted under this simplified procedure, based on their expertise in dealing with the type of health data they are processing, and issue a recommendation regarding a data permit. The health data access body should remain responsible for issuing the final data permit and should not be bound by the recommendation provided by the trusted health data holder. Health data intermediation entities should not be designated as trusted health data holders.
(77) Given the sensitivity of electronic health data, health data users should not have unrestricted access to such data. All secondary use access to the requested electronic health data should be done through a secure processing environment. In order to ensure there are strong technical and security safeguards in place for the electronic health data, the health data access body or, where relevant, the trusted health data holder should provide access to such data in a secure processing environment, complying with the high technical and security standards set out pursuant to this Regulation. The processing of personal data in such a secure processing environment should comply with Regulation (EU) 2016/679, including, where the secure processing environment is managed by a third party, the requirements of Article 28 of that Regulation and, where applicable, Chapter V thereof. Such secure processing environment should reduce the privacy risks related to such processing activities and prevent the electronic health data from being transmitted directly to the health data users. The health data access body or the health data holder providing that service should remain at all times in control of the access to the electronic health data, and the access granted to the health data users should be determined by the conditions of the issued data permit. Only non-personal electronic health data which do not contain any personal electronic health data should be downloaded by the health data users from such secure processing environment. Thus, such a secure processing environment is an essential safeguard to preserve the rights and freedoms of natural persons in relation to the processing of their electronic health data for secondary use. The Commission should assist the Member States in developing common security standards in order to promote the security and interoperability of the various secure processing environments.
(78) Regulation (EU) 2022/868 sets out the general rules for the management of data altruism. Given that the health sector manages sensitive data, additional criteria should be established through the rulebook referred to in that Regulation. Where such rules provide for the use of a secure processing environment for that sector, such secure processing environment should comply with the criteria established in this Regulation. The health data access bodies should cooperate with the competent authorities designated under Regulation (EU) 2022/868 to supervise the activity of data altruism organisations in the health or care sector.
(79) For the processing of electronic health data in the scope of a data permit or a health data request, health data holders, including trusted health data holders, health data access bodies and health data users should be deemed each of them, in turn, controllers for a specific part of the process and according to their respective roles therein. Health data holders should be deemed controllers for the disclosure of the requested personal electronic health data to the health data access bodies, while the health data access bodies should in turn be deemed controllers for the processing of the personal electronic health data when preparing the data and making them available to the health data users. Health data users should be deemed controllers for the processing of personal electronic health data in pseudonymised form in the secure processing environment pursuant to their data permits. Health data access bodies should be deemed processors on behalf of the health data user for the processing carried out by the health data user pursuant to a data permit in the secure processing environment as well as for the processing to generate a response to a health data request. Similarly, trusted health data holders should be deemed controllers for their processing of personal electronic health data related to the provision of electronic health data to the health data user pursuant to a data permit or a health data request. The trusted health data holders should be deemed processors for the health data user when providing data through a secure processing environment.
(80) In order to achieve an inclusive and sustainable framework for multi-country secondary use, a cross-border infrastructure should be established (‘HealthData@EU’). HealthData@EU should accelerate secondary use while increasing legal certainty, respecting the privacy of natural persons and being interoperable. Due to the sensitivity of health data, principles such as ‘privacy by design’ and ‘privacy by default’ and the concept of bringing questions to data instead of moving those data should be respected whenever possible. Member States should designate national contact points for secondary use, as organisational and technical gateways for health data access bodies, and connect those contact points to HealthData@EU. The Union health data access service should also be connected to HealthData@EU. In addition, authorised participants in HealthData@EU could be research infrastructures established as a European Research Infrastructure Consortium (ERIC) under Council Regulation (EC) No 723/2009 (19), as a European digital infrastructure consortium (EDIC) under Decision (EU) 2022/2481 or similar infrastructures established under other Union legal acts, as well as other types of entities, including infrastructures under the European Strategy Forum on Research Infrastructures (ESFRI) or infrastructures federated under the European Open Science Cloud (EOSC). Third countries and international organisations could also become authorised participants in HealthData@EU, provided that they are compliant with the requirements in this Regulation. The Commission communication of 19 February 2020 entitled ‘A European strategy for data’ promoted the linking of the various common European data spaces. HealthData@EU should therefore enable the secondary use of different categories of electronic health data, including linking of the health data with data from other data spaces such as those relating to the environment, agriculture and social sector. Such interoperability between the health sector and other sectors such as the environmental, agricultural or social sectors could be relevant for obtaining additional insights on health determinants. The Commission could provide a number of services within HealthData@EU, including supporting the exchange of information amongst health data access bodies and authorised participants in HealthData@EU for the handling of cross-border access requests, maintaining catalogues of electronic health data available through the infrastructure, network discoverability and metadata queries, connectivity and compliance services. The Commission could also set up a secure processing environment, allowing data from different national infrastructures to be transmitted and analysed, at the request of the controllers. For the sake of IT efficiency, rationalisation and interoperability of data exchanges, existing systems for data sharing should be reused as much as possible, such as those being built for the exchange of evidence under the ‘once-only’ technical system of Regulation (EU) 2018/1724 of the European Parliament and of the Council (20).
(81) In addition, given that the connection to HealthData@EU could entail transfers of personal data related to the applicant or the health data user to third countries, relevant transfer instruments under Chapter V of Regulation (EU) 2016/679 need to be in place for such transfers.
(82) In the case of cross-border registries or databases, such as the registries of European Reference Networks for Rare Diseases, which receive data from different healthcare providers in several Member States, the health data access body of the Member State where the coordinator of the registry is located should be responsible for providing access to data.
(83) The authorisation process to gain access to personal electronic health data in different Member States can be repetitive and cumbersome for health data users. Whenever possible, synergies should be established to reduce the burden and barriers for health data users. One way to achieve that aim is to adhere to the ‘single application’ principle whereby, with one application, the health data user can obtain authorisation from multiple health data access bodies in different Member States or authorised participants in HealthData@EU.
(84) The health data access bodies should provide information about the available datasets and their characteristics so that health data users can be informed of elementary facts about the dataset and assess the possible relevance of those facts to those users. For this reason, each dataset should include, at least, information concerning the source and nature of the data and the conditions for making the data available. The health data holder should, at least every year, check that its dataset description in the national dataset catalogue is accurate and up to date. Therefore, an EU dataset catalogue should be established to: facilitate the discoverability of datasets available in the EHDS; help health data holders to publish their datasets; provide all stakeholders, including the general public, taking into account the specific needs of people with disabilities, with information about datasets placed on the EHDS, such as quality and utility labels and dataset information sheets; and provide health data users with up-to-date data quality and utility information about datasets.
(85) Information on the quality and utility of datasets increases the value of outcomes from data-intensive research and innovation significantly while, at the same time, promoting evidence-based regulatory and policy decision-making. Improving the quality and utility of datasets through informed customer choice and harmonising related requirements at Union level, taking into account existing Union and international standards, guidelines and recommendations for data collection and data exchange, such as FAIR principles, also benefits health data holders, health professionals, natural persons and the Union economy overall. A data quality and utility label for datasets would inform health data users about the quality and utility characteristics of a dataset and enable them to choose the datasets that best fit their needs. The data quality and utility label should not prevent datasets from being made available through the EHDS, but provide a transparency mechanism between health data holders and health data users. For example, a dataset that does not fulfil any requirement of data quality and utility should be labelled with the class representing the poorest quality and utility, but should still be made available. Expectations set by frameworks created pursuant to Article 10 of Regulation (EU) 2024/1689 and the relevant technical documentation specified in Annex IV to that Regulation should be taken into account when developing the data quality and utility framework. Member States should raise awareness about the data quality and utility label through communication activities. The Commission could support those activities. The use of datasets could be prioritised by their users according to their usefulness and quality.
(86) The EU dataset catalogue should minimise the administrative burden for the health data holders and other database users, be user-friendly, accessible and cost-effective, connect national dataset catalogues and avoid redundant registration of datasets. Without prejudice to the requirements set out in Regulation (EU) 2022/868, the EU dataset catalogue could be aligned with the data.europa.eu initiative. Interoperability should be ensured between the EU dataset catalogue, the national dataset catalogues and the dataset catalogues from European research infrastructures and other relevant data sharing infrastructures.
(87) Cooperation and work are ongoing between different professional organisations, the Commission and other institutions to set up minimum data fields and other characteristics of different datasets, for instance registries. That work is more advanced in areas such as cancer, rare diseases, cardiovascular and metabolic diseases, risk factor assessment and statistics, and should be taken into account when defining new standards and disease-specific harmonised templates for structured data elements. However, many datasets are not harmonised, raising comparability issues and making cross-border research difficult. Therefore, more detailed rules should be set out in implementing acts to ensure a harmonised coding and registration of electronic health data to enable the supply of such data for secondary use in a consistent way. Such datasets could include data from registries of rare diseases, orphan drugs databases, cancer registries and registries of highly relevant infectious diseases. Member States should work towards ensuring that European electronic health systems and services and interoperable applications deliver sustainable economic and social benefits, with a view to achieving a high level of trust and security, enhancing continuity of healthcare and ensuring access to safe and high-quality healthcare. Existing health data infrastructures and registries can provide models that are useful for defining and implementing data standards and interoperability and should be leveraged to enable continuity and to build on existing expertise.
(88) The Commission should support Member States in building capacity and enhancing effectiveness in the area of digital health systems for primary use and secondary use. Member States should be supported to strengthen their capacity. Activities at Union level, such as benchmarking and exchange of best practices, are relevant measures in that respect. Those activities should take into account the specific circumstances of different categories of stakeholders, such as representatives of civil society, researchers, medical societies and SMEs.
(89) Improving digital health literacy for both natural persons and health professionals is essential to trust and safety and appropriate use of health data and thus is essential to achieving a successful implementation of this Regulation. Health professionals are faced with profound changes in the context of digitalisation and will be offered further digital tools as part of the implementation of the EHDS. Consequently, health professionals need to develop their digital health literacy and digital skills and Member States should provide access for health professionals to digital literacy courses so that they can prepare to work with EHR systems. Such courses should allow health professionals and IT operators to receive sufficient training in working with new digital infrastructures to ensure cybersecurity and ethical management of health data. The training courses should be developed and reviewed, and kept up to date, on a regular basis in consultation and cooperation with relevant experts. Improving digital health literacy is fundamental in order to empower natural persons to have true control over their health data, actively manage their health and care, and understand the implications of the management of such data for both primary use and secondary use. Different demographic groups have varying degrees of digital literacy, which can affect natural persons’ ability to exercise their rights to control their electronic health data. Member States, including regional and local authorities, should therefore support digital health literacy and public awareness, while ensuring that the implementation of this Regulation contributes to reducing inequalities and does not discriminate against people lacking digital skills. Particular attention should be given to persons with disabilities and vulnerable groups including migrants and the elderly. Member States should create targeted national digital literacy programmes, including programmes to maximise social inclusion and to ensure all natural persons can effectively exercise their rights under this Regulation. Member States should also provide patient-centric guidance to natural persons in relation to the use of electronic health records and primary use of their personal electronic health data. Guidance should be tailored to the patient’s level of digital health literacy, with specific attention to be given to the needs of vulnerable groups.
(90) The use of funds should also contribute to attaining the objectives of the EHDS. Public procurers, national competent authorities in the Member States, including digital health authorities and health data access bodies, and the Commission should make references to applicable technical specifications, standards and profiles on interoperability, security and data quality, as well as other requirements developed under this Regulation, when defining the conditions for public procurement, calls for proposals and allocation of Union funds, including structural and cohesion funds. Union funds need to be distributed transparently among the Member States, taking into account the different levels of health system digitalisation. Making data available for secondary use requires additional resources for healthcare systems, in particular public healthcare systems. That additional burden should be addressed and minimised during the implementation phase of the EHDS.
(91) The implementation of the EHDS requires appropriate investment in capacity-building and training and a well-funded commitment to public consultation and engagement both at Union and national level. The economic costs of implementing this Regulation will need to be borne at both Union and national level, and a fair sharing of that burden between Union and national funds will need to be found.
(92) Certain categories of electronic health data can remain particularly sensitive even when they are in anonymised format and thus non-personal, as already specifically provided for in Regulation (EU) 2022/868. Even where state-of-the-art anonymisation techniques are used, there remains a residual risk that the capacity to re-identify could be or become available, beyond the means reasonably likely to be used. Such residual risk is present in relation to rare diseases, that is to say a life-threatening or chronically debilitating condition affecting not more than 5 in 10 000 persons in the Union, where the limited numbers of cases reduce the possibility of fully aggregating the published data in order to preserve the privacy of natural persons while also maintaining an appropriate level of granularity in order to remain meaningful. Such residual risk can affect different categories of health data and can lead to the re-identification of the data subjects using means that are beyond those reasonably likely to be used. Such risk depends on the level of granularity, on the description of the characteristics of data subjects, on the number of people affected, for instance in cases of data included in electronic health records, disease registries, biobanks and person-generated data, where the range of identification characteristics is broader, and on the possible combination with other information, for example in very small geographical areas, or through the technological evolution of methods which had not been available at the moment of anonymisation. Such re-identification of natural persons would present a major concern and would be likely to put the acceptance of the rules on secondary use provided for in this Regulation at risk. Furthermore, aggregation techniques are less tested for non-personal data containing for example trade secrets, as is the case in the reporting on clinical trials and clinical investigations, and enforcement of breaches of trade secrets outside the Union is more difficult in the absence of a sufficient international protection standard. Therefore, for those categories of health data, there remains a risk of re-identification after the anonymisation or aggregation, which cannot be reasonably mitigated initially. This falls within the criteria indicated in Article 5(13) of Regulation (EU) 2022/868. Those types of health data would thus fall within the empowerment set out in Article 5(13) of that Regulation for transfer to third countries. The special conditions provided for under the empowerment set out in Article 5(13) of Regulation (EU) 2022/868 will be detailed in the context of the delegated act adopted under that empowerment, and need to be proportional to the risk of re-identification and to take into account the specificities of different data categories or of different anonymisation or aggregation techniques.
(93) The processing of large amounts of personal electronic health data for the purposes of the EHDS, as part of data processing activities in the context of handling health data access applications, data permits and health data requests entails higher risks of unauthorised access to such personal data, as well as the possibility of cybersecurity incidents. Personal electronic health data are particularly sensitive as they often contain information covered by medical secrecy, the disclosure of which to unauthorised third parties can cause significant distress. Taking fully into consideration the principles outlined in the case law of the Court of Justice of the European Union, this Regulation ensures full respect for fundamental rights, for the right to privacy and for the principle of proportionality. In order to ensure the full integrity and confidentiality of personal electronic health data under this Regulation, to guarantee a particularly high level of protection and security, and to reduce the risk of unlawful access to those personal electronic health data, this Regulation allows Member States to require that personal electronic health data be stored and processed solely within the Union for the purpose of carrying out the tasks provided for in this Regulation, unless an adequacy decision adopted pursuant to Article 45 of Regulation (EU) 2016/679 applies.
(94) Access to electronic health data for health data users established in third countries or for international organisations should take place only on the basis of the reciprocity principle. Making electronic health data available to a third country should be allowed to take place only where the Commission has established, by means of an implementing act, that the third country concerned allows access to electronic health data originating from that third country by Union entities under the same conditions and with the same safeguards as would be the case if they were accessing electronic health data within the Union. The Commission should monitor and carry out a periodic review of the situation in those third countries and for international organisations and list those implementing acts. Where the Commission finds that a third country no longer ensures access on the same terms, it should revoke the corresponding implementing act.
(95) In order to promote the consistent application of this Regulation, including as regards cross-border interoperability of electronic health data, a European Health Data Space Board should be set up. The Commission should participate in its activities and co-chair it. The EHDS Board should be able to issue written contributions related to the consistent application of this Regulation throughout the Union, including by helping Member States to coordinate the use of electronic health data for healthcare and certification, but also concerning secondary use, and the funding for those activities. This could also include sharing information on risks and incidents in the secure processing environments. The sharing of that kind of information does not affect obligations under other legal acts, such as data breach notifications under Regulation (EU) 2016/679. More generally, the activities of the EHDS Board are without prejudice to the powers of the supervisory authorities pursuant to Regulation (EU) 2016/679. Given that, at national level, digital health authorities dealing with primary use may be different from the health data access bodies dealing with secondary use, the functions are different and there is a need for distinct cooperation in each of those areas, the EHDS Board should be able to set up subgroups dealing with those two functions, as well as other subgroups, as needed. In order for there to be an efficient working method, the digital health authorities and health data access bodies should create networks and links at national level with other bodies and authorities, but also at Union level. Such bodies could comprise data protection authorities, cybersecurity, eID and standardisation bodies, as well as bodies and expert groups under Regulations (EU) 2022/868, (EU) 2023/2854 and (EU) 2024/1689 and Regulation (EU) 2019/881 of the European Parliament and of the Council (21). The EHDS Board should operate independently, in the public interest and in line with its code of conduct.
(96) Where issues that are considered by the EHDS Board to be of specific relevance are discussed, it should be able to invite observers, for instance the EDPS, representatives of Union institutions, including of the European Parliament, and other stakeholders.
(97) A stakeholder forum should be set up to advise the EHDS Board in the fulfilment of its tasks by providing stakeholder input on matters pertaining to this Regulation. The stakeholder forum should be composed, inter alia, of representatives of patient and consumer organisations, health professionals, industry, scientific researchers and academia. It should have a balanced composition and represent the views of different relevant stakeholders. Both commercial and non-commercial interests should be represented.
(98) In order to ensure proper day-to-day management of the cross-border infrastructures for primary use and secondary use, it is necessary to create steering groups consisting of Member State representatives. These steering groups should take operational decisions on the technical day-to-day management of the cross-border infrastructures and their technical development, including on technical changes to the infrastructures, improving functionalities or services, or ensuring interoperability with other infrastructures, digital systems or data spaces. Their activities should not include contributing to the development of implementing acts affecting those infrastructures. The steering groups should also be able to invite representatives of other authorised participants in HealthData@EU as observers to their meetings and should consult relevant experts when carrying out their tasks.
(99) Without prejudice to any other administrative, judicial or non-judicial remedy, any natural or legal person should have the right to lodge a complaint with a digital health authority or with a health data access body, if the natural or legal person considers that his or her rights or interests under this Regulation have been affected. The investigation following a complaint should be carried out, subject to judicial review, to the extent appropriate in the specific case. The digital health authority or health data access body should inform the natural or legal person of the progress and the outcome of the complaint within a reasonable period. If the case requires further investigation or coordination with another digital health authority or health data access body, information on the progress made in dealing with the complaint should be given to the natural or legal person. In order to facilitate the submission of complaints, each digital health authority and health data access body should take measures such as providing a complaint submission form which can also be completed electronically, without excluding the possibility of using other means of communication. Where the complaint concerns the rights of natural persons related to the protection of their personal data, the digital health authority or health data access body should transmit the complaint to the supervisory authorities under Regulation (EU) 2016/679. Digital health authorities or health data access bodies should cooperate to handle and resolve complaints, including by exchanging all relevant information by electronic means, without undue delay.
(100) Where a natural person considers that his or her rights under this Regulation have been infringed, he or she should have the right to mandate a not-for-profit body, organisation or association constituted in accordance with national law, having statutory public interest objectives and active in the field of the protection of personal data, to lodge a complaint on his or her behalf.
(101) The digital health authority, health data access body, health data holder or health data user should compensate any damage which a natural or legal person suffers as a result of an infringement of this Regulation. The concept of damage should be broadly interpreted in the light of the case law of the Court of Justice of the European Union, in a manner which fully reflects the objectives of this Regulation. This is without prejudice to any claims for damage deriving from the violation of other provisions in Union or national law. Natural persons should receive full and effective compensation for the damage they have suffered.
(102) In order to strengthen the enforcement of the rules of this Regulation, penalties, including administrative fines, should be imposed for any infringement of this Regulation, in addition to, or instead of, appropriate measures imposed by health data access bodies pursuant to this Regulation. The imposition of penalties, including administrative fines, should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter of Fundamental Rights of the European Union, including effective judicial protection and due process.
(103) It is appropriate to lay down provisions enabling health data access bodies to apply administrative fines for certain infringements of this Regulation which should be considered under this Regulation to be serious infringements, such as the re-identification of natural persons, downloading personal electronic health data outside of the secure processing environment or processing of data for prohibited uses or uses not covered by a data permit. This Regulation should specify those infringements and the upper limit and criteria for setting the related administrative fines, which should be determined by the competent health data access body in each individual case, taking into account all the relevant circumstances of the specific situation, having due regard in particular to the nature, gravity and duration of the infringement and its consequences and the measures taken to ensure compliance with the obligations under this Regulation and to prevent or mitigate the consequences of the infringement. For the purposes of the imposition of administrative fines under this Regulation, the concept of undertaking should be understood in accordance with Articles 101 and 102 TFEU. It should be for the Member States to determine whether and to what extent public authorities should be subject to administrative fines. Imposing an administrative fine or giving a warning should not affect the enforcement of other powers of the health data access bodies or of other penalties under this Regulation.
(104) In order to ensure that the EHDS fulfils its objectives, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission in respect of the modification, addition or removal in Annex I of the main characteristics of the priority categories of personal electronic health data, the list of required data to be entered by the manufacturers of EHR systems and wellness applications into the EU database for registration of EHR systems and wellness applications as well as the modification, addition or removal of elements to be covered by the data quality and utility label. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Inter-institutional Agreement of 13 April 2016 on Better Law-Making (22). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.
(106) Member States should take all measures necessary to ensure that the provisions of this Regulation are implemented, including by laying down effective, proportionate and dissuasive penalties for their infringement. When deciding on the amount of the penalty for each individual case, Member States should take into account the limits and criteria set out in this Regulation. Re-identification of natural persons should be considered a serious breach of this Regulation.
(107) Implementing the EHDS will require significant development work across Member States and central services. To track the progress made in that regard, the Commission should, until the full application of this Regulation, report annually on that progress, taking into account information provided by the Member States. Those reports could include recommendations for remedial measures, as well as an assessment of the progress made.
(108) In order to assess whether this Regulation reaches its objectives effectively and efficiently, is coherent and still relevant and provides added value at Union level, the Commission should carry out an evaluation of this Regulation. The Commission should carry out a targeted evaluation of this Regulation within eight years of its entry into force, and an overall evaluation within 10 years of its entry into force. The Commission should submit reports on its main findings following each evaluation to the European Parliament and to the Council, the European Economic and Social Committee and the Committee of the Regions.
(109) For a successful cross-border implementation of the EHDS, the European Interoperability Framework, the scope of which was updated and extended by the Commission communication of 23 March 2017 entitled ‘European Interoperability Framework – Implementation Strategy’ to take on board new or revised interoperability requirements, should be considered as a common reference to ensure legal, organisational, semantic and technical interoperability.
(110) Since the objectives of this Regulation, namely to empower natural persons by providing them with increased control over their personal electronic health data and supporting their freedom of movement by ensuring that their health data follow them, to foster a genuine internal market for digital health services and products and to ensure a consistent and efficient framework for the reuse of natural persons’ health data for research, innovation, policymaking and regulatory activities, cannot be sufficiently achieved by the Member States through coordination measures alone, as shown by the evaluation of the digital aspects of Directive 2011/24/EU, but can rather, by reason of harmonising measures for rights of natural persons in relation to their electronic health data, interoperability of electronic health data and a common framework and safeguards for the primary use and secondary use, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve those objectives.
(111) The evaluation of the digital aspects of Directive 2011/24/EU shows that the effectiveness of the eHealth Network is limited, but also that there is strong potential for work at Union level in the area of digital health, as demonstrated by the work carried out during the COVID-19 pandemic. Directive 2011/24/EU should therefore be amended accordingly.
(112) This Regulation complements the essential cybersecurity requirements laid down in Regulation (EU) 2024/2847. EHR systems which are products with digital elements within the meaning of Regulation (EU) 2024/2847 should therefore also comply with the essential cybersecurity requirements set out in that Regulation. The manufacturers of those EHR systems should demonstrate conformity as required by this Regulation. To facilitate that conformity, manufacturers should be allowed to draw up a single set of technical documents containing the elements required by both legal acts. It should be possible to demonstrate conformity of EHR systems with essential cybersecurity requirements laid down in Regulation (EU) 2024/2847 through the assessment framework under this Regulation. However, the parts of the conformity assessment procedure under this Regulation which relate to the use of testing environments should not be applied, since those testing environments do not allow for an assessment of conformity with the essential cybersecurity requirements. As Regulation (EU) 2024/2847 does not cover Software as a Service (SaaS) directly as such, EHR systems offered through the SaaS licensing and delivery model do not fall within the scope of that Regulation. Similarly, EHR systems that are developed and used in-house do not fall within the scope of that Regulation, as they are not placed on the market.
(113) The EDPS and the EDPB were consulted in accordance with Article 42(1) and (2) of Regulation (EU) 2018/1725 and delivered their joint opinion on 12 July 2022.
(114) This Regulation should not affect the application of the rules of competition, and in particular Articles 101 and 102 TFEU. The measures provided for in this Regulation should not be used to restrict competition in a manner contrary to the TFEU.
(115) Given the need for technical preparation, this Regulation should apply from 26 March 2027. In order to support the successful implementation of the EHDS and the creation of effective conditions for European health data cooperation, the implementation should take place in stages,
HAVE ADOPTED THIS REGULATION:
CHAPTER I
GENERAL PROVISIONS
Article 1
Subject matter and scope
This Regulation establishes the European Health Data Space (EHDS) by providing for common rules, standards and infrastructures and a governance framework, with a view to facilitating access to electronic health data for the purposes of primary use of electronic health data and secondary use of those data.
This Regulation:
(a) specifies and complements the rights laid down in Regulation (EU) 2016/679 of natural persons in relation to the primary use and secondary use of their personal electronic health data;
(b) lays down common rules for electronic health record systems (‘EHR systems’) in relation to two mandatory harmonised software components, namely the European interoperability software component for EHR systems and the European logging software component for EHR systems, as defined in Article 2(2), points (n) and (o), respectively, and for wellness applications which are claimed to be interoperable with EHR systems in relation to those two harmonised software components, as regards primary use of electronic health data;
(c) lays down common rules and mechanisms for primary use of electronic health data and secondary use of electronic health data;
(d) establishes a cross-border infrastructure enabling the primary use of personal electronic health data across the Union;
(e) establishes a cross-border infrastructure for secondary use of electronic health data;
(f) establishes governance and coordination mechanisms at Union and national level for both primary use of electronic health data and secondary use of electronic health data.
This Regulation shall be without prejudice to other Union legal acts regarding access to, and sharing of or secondary use of, electronic health data, or Union requirements related to the processing of data in relation to electronic health data, in particular Regulations (EC) No 223/2009 (24), (EU) No 536/2014 (25), (EU) 2016/679, (EU) 2018/1725, (EU) 2022/868 and (EU) 2023/2854 of the European Parliament and of the Council and Directives 2002/58/EC (26) and (EU) 2016/943 (27) of the European Parliament and of the Council.
References in this Regulation to the provisions of Regulation (EU) 2016/679 shall be understood also as references to the corresponding provisions of Regulation (EU) 2018/1725, where relevant, as regards Union institutions, bodies, offices and agencies.
This Regulation shall be without prejudice to Regulations (EU) 2017/745, (EU) 2017/746 and (EU) 2024/1689, as regards the security of medical devices, in vitro diagnostic medical devices and artificial intelligence (AI) systems that interact with EHR systems.
This Regulation shall be without prejudice to Union or national law regarding electronic health data processing for the purposes of reporting, complying with access to information requests or demonstrating or verifying compliance with legal obligations, or to Union or national law regarding the granting of access to and disclosure of official documents.
This Regulation shall be without prejudice to specific provisions in Union or national law providing for access to electronic health data for further processing by Member States’ public sector bodies, by Union institutions, bodies, offices and agencies, or by private entities entrusted under Union or national law with a task of public interest, for the purpose of carrying out such task.
This Regulation shall not affect access to electronic health data for secondary use agreed in the framework of contractual or administrative arrangements between public or private entities.
This Regulation does not apply to the processing of personal data in the following cases:
(a) where the processing is carried out in the course of an activity which falls outside the scope of Union law;
(b) where the processing is carried out by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.
Article 2
Definitions
For the purposes of this Regulation, the following definitions apply:
(a) the definitions of ‘personal data’, ‘processing’, ‘pseudonymisation’, ‘controller’, ‘processor’, ‘third party’, ‘consent’, ‘genetic data’, ‘data concerning health’ and ‘international organisation’ laid down in Article 4, points (1), (2), (5), (7), (8), (10), (11), (13), (15) and (26), respectively, of Regulation (EU) 2016/679;
(b) the definitions of ‘healthcare’, ‘Member State of affiliation’, ‘Member State of treatment’, ‘health professional’, ‘healthcare provider’, ‘medicinal product’ and ‘prescription’ laid down in Article 3, points (a), (c), (d), (f), (g), (i) and (k), respectively, of Directive 2011/24/EU;
(c) the definitions of ‘data’, ‘access’, ‘data altruism’, ‘public sector body’ and ‘secure processing environment’ laid down in Article 2, points (1), (13), (16), (17) and (20), respectively, of Regulation (EU) 2022/868;
(d) the definitions of ‘making available on the market’, ‘placing on the market’, ‘market surveillance’, ‘market surveillance authority’, ‘non-compliance’, ‘manufacturer’, ‘importer’, ‘distributor’, ‘economic operator’, ‘corrective action’, ‘recall’ and ‘withdrawal’ laid down in Article 3, points (1), (2), (3), (4), (7), (8), (9), (10), (13), (16), (22) and (23), respectively, of Regulation (EU) 2019/1020;
(e) the definitions of ‘medical device’, ‘intended purpose’, ‘instructions for use’, ‘performance’, ‘health institution’ and ‘common specifications’ laid down in Article 2, points (1), (12), (14), (22), (36) and (71), respectively, of Regulation (EU) 2017/745;
(f) the definitions of ‘electronic identification’ and ‘electronic identification means’ laid down in Article 3, points (1) and (2), respectively, of Regulation (EU) No 910/2014;
(g) the definition of ‘contracting authorities’ laid down in Article 2(1), point (1), of Directive 2014/24/EU of the European Parliament and of the Council (28);
(h) the definition of ‘public health’ laid down in Article 3, point (c), of Regulation (EC) No 1338/2008 of the European Parliament and of the Council (29).
In addition, for the purposes of this Regulation the following definitions apply:
(a) ‘personal electronic health data’ means data concerning health and genetic data, processed in an electronic form;
(b) ‘non-personal electronic health data’ means electronic health data other than personal electronic health data, including both data that have been anonymised so that they no longer relate to an identified or identifiable natural person (the ‘data subject’) and data that have never related to a data subject;
(c) ‘electronic health data’ means personal or non-personal electronic health data;
(d) ‘primary use’ means the processing of electronic health data for the provision of healthcare, in order to assess, maintain or restore the state of health of the natural person to whom those data relate, including the prescription, dispensation and provision of medicinal products and medical devices, as well as for relevant social, administrative or reimbursement services;
(e) ‘secondary use’ means the processing of electronic health data for the purposes set out in Chapter IV of this Regulation, other than the initial purposes for which they were collected or produced;
(f) ‘interoperability’ means the ability of organisations, as well as of software applications or devices from the same manufacturer or different manufacturers, to interact through the processes they support, involving the exchange of information and knowledge, without changing the content of the data, between those organisations, software applications or devices;
(g) ‘registration of electronic health data’ means the recording of health data in an electronic format, through the manual entry of such data, through the collection of such data by a device, or through the conversion of non-electronic health data into an electronic format, to be processed in an EHR system or a wellness application;
(h) ‘electronic health data access service’ means an online service, such as a portal or an application for mobile devices, that enables natural persons not acting in a professional capacity to access their own electronic health data or the electronic health data of those natural persons whose electronic health data they are legally authorised to access;
(i) ‘health professional access service’ means a service, supported by an EHR system, that enables health professionals to access data of natural persons under their treatment;
(j) ‘electronic health record’ or ‘EHR’ means a collection of electronic health data related to a natural person and collected in the health system, processed for the purpose of the provision of healthcare;
(k) ‘electronic health record system’ or ‘EHR system’ means any system whereby the software, or a combination of the hardware and the software of that system, allows personal electronic health data that belong to the priority categories of personal electronic health data established under this Regulation to be stored, intermediated, exported, imported, converted, edited or viewed, and intended by the manufacturer to be used by healthcare providers when providing patient care or by patients when accessing their electronic health data;
(l) ‘putting into service’ means the first use, for its intended purpose, in the Union of an EHR system covered by this Regulation;
(m) ‘software component’ means a discrete part of software which provides a specific functionality or performs specific functions or procedures and which can operate independently or in conjunction with other components;
(n) ‘European interoperability software component for EHR systems’ means a software component of the EHR system which provides and receives personal electronic health data under a priority category for primary use established under this Regulation in the European electronic health record exchange format provided for in this Regulation and which is independent of the European logging software component for EHR systems;
(o) ‘European logging software component for EHR systems’ means a software component of the EHR system which provides logging information related to access by health professionals or other individuals to priority categories of personal electronic health data established under this Regulation, in the format defined in point 3.2. of Annex II thereto, and which is independent of the European interoperability software component for EHR systems;
(p) ‘CE marking of conformity’ means a marking by which the manufacturer indicates that the EHR system is in conformity with the applicable requirements set out in this Regulation and other applicable Union law providing for its affixing pursuant to Regulation (EC) No 765/2008 of the European Parliament and of the Council (30);
(q) ‘risk’ means the combination of the probability of an occurrence of a hazard causing harm to health, safety or information security and the degree of severity of such harm;
(s) ‘care’ means a professional service the purpose of which is to address the specific needs of a natural person who, on account of impairment or other physical or mental conditions, requires assistance, including preventive and supportive measures, to carry out essential activities of daily living in order to support his or her personal autonomy;
(u) ‘health data user’ means a natural or legal person, including Union institutions, bodies, offices or agencies, which has been granted lawful access to electronic health data for secondary use pursuant to a data permit, a health data request approval or an access approval by an authorised participant in HealthData@EU;
(v) ‘data permit’ means an administrative decision issued to a health data user by a health data access body to process certain electronic health data specified in the data permit for specific secondary use purposes, based on conditions laid down in Chapter IV of this Regulation;
(w) ‘dataset’ means a structured collection of electronic health data;
(x) ‘dataset of high impact for secondary use’ means a dataset the re-use of which is associated with significant benefits due to its relevance for health research;
(y) ‘dataset catalogue’ means a collection of dataset descriptions, arranged in a systematic manner and including a user-oriented public part, in which information concerning individual dataset parameters is accessible by electronic means through an online portal;
(z) ‘data quality’ means the degree to which the elements of electronic health data are suitable for their intended primary use and secondary use;
(aa) ‘data quality and utility label’ means a graphic diagram, including a scale, describing the data quality and conditions of use of a dataset;
(ab) ‘wellness application’ means any software, or any combination of hardware and software, intended by the manufacturer to be used by a natural person, for the processing of electronic health data, specifically for providing information on the health of natural persons, or the delivery of care for purposes other than the provision of healthcare.
CHAPTER II
PRIMARY USE
SECTION 1
Rights of natural persons in relation to the primary use of their personal electronic health data, and related provisions
Article 3
Right of natural persons to access their personal electronic health data
Natural persons shall have the right to access at least personal electronic health data relating to them that belong to the priority categories referred to in Article 14 and are processed for the provision of healthcare through the electronic health data access services referred to in Article 4. Access shall be provided immediately after the personal electronic health data have been registered in an EHR system, while respecting the need for technological practicability, and shall be provided free of charge and in an easily readable, consolidated and accessible format.
Natural persons, or their representatives referred to in Article 4(2), shall have the right to download free of charge an electronic copy of at least the personal electronic health data in the priority categories referred to in Article 14 related to those natural persons, through the electronic health data access services referred to in Article 4, in the European electronic health record exchange format referred to in Article 15.
In accordance with Article 23 of Regulation (EU) 2016/679, Member States may restrict the scope of rights provided for in paragraphs 1 and 2 of this Article, in particular whenever those restrictions are necessary to protect natural persons, on the basis of patient safety and ethical considerations by delaying access to their personal electronic health data for a limited period of time until a health professional is able to properly communicate and explain to the natural persons concerned information that can have a significant impact on their health.
Article 4
Electronic health data access services for natural persons and their representatives
Member States shall ensure that one or more electronic health data access services at national, regional or local level are established, thereby enabling natural persons to access their personal electronic health data and exercise their rights provided for in Articles 3 and 5 to 10. Such electronic health data access services shall be free of charge for the natural persons and their representatives referred to in paragraph 2 of this Article.
Member States shall ensure that one or more proxy services are established as a functionality of electronic health data access services which enables:
(a) natural persons to authorise other natural persons of their choice to access their personal electronic health data, or part thereof, on their behalf for a limited or unlimited period and, if needed, for a specific purpose only, and to manage those authorisations; and
(b) legal representatives of natural persons to access personal electronic health data of those natural persons whose affairs they administer, in accordance with national law.
Member States shall establish rules regarding the authorisations referred to in point (a) of the first subparagraph and actions of guardians and other legal representatives.
The proxy services referred to in paragraph 2 shall provide authorisations in a transparent and easily understandable way, free of charge, and electronically or on paper. Natural persons and their representatives shall be informed about their authorisation rights, including about how to exercise those rights, and about the authorisation process.
The proxy services shall provide an easy complaint mechanism for natural persons.
The proxy services referred to in paragraph 2 of this Article shall be interoperable among Member States. The Commission shall, by means of implementing acts, lay down the technical specifications for the interoperability of the proxy services of the Member States. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
The electronic health data access services and the proxy services shall be easily accessible for persons with disabilities, vulnerable groups and persons with low digital literacy.
Article 5
Right of natural persons to insert information in their own EHR
Natural persons, or their representatives referred to in Article 4(2), shall have the right to insert information in the EHR of those natural persons through electronic health data access services or applications linked to those services as referred to in that Article. That information shall be clearly distinguishable as having been inserted by the natural person or by his or her representative. Natural persons, or their representatives referred to in Article 4(2), shall not be able to directly alter the electronic health data and related information inserted by health professionals.
Article 6
Right of natural persons to rectification
Electronic health data access services referred to in Article 4 shall enable natural persons to easily request online the rectification of their personal electronic health data in accordance with Article 16 of Regulation (EU) 2016/679. Where appropriate, the controller shall verify with a relevant health professional the accuracy of the information provided in the request.
Member States may also enable natural persons to exercise online other rights pursuant to Chapter III of Regulation (EU) 2016/679 through electronic health data access services.
Article 7
Right to data portability for natural persons
Natural persons shall have the right to give access to, or to request a healthcare provider to transmit, all or part of their personal electronic health data to another healthcare provider of their choice immediately, free of charge and without hindrance from the healthcare provider or from the manufacturers of the systems used by that healthcare provider.
Natural persons shall have the right, where the healthcare providers are located in different Member States, to request the transmission of their personal electronic health data in the European electronic health record exchange format referred to in Article 15 through the cross-border infrastructure referred to in Article 23. The receiving healthcare provider shall accept such data and shall be able to read them.
Natural persons shall have the right to request a healthcare provider to transmit a part of their personal electronic health data to a clearly identified recipient in the social security or reimbursement services sector. Such transmission shall be carried out immediately, free of charge and without hindrance from the healthcare provider or from the manufacturers of the systems used by that healthcare provider, and shall be one-way only.
Where natural persons have downloaded an electronic copy of their priority categories of personal electronic health data in accordance with Article 3(2), they shall be able to transmit those data to healthcare providers of their choice in the European electronic health record exchange format referred to in Article 15. The receiving healthcare provider shall accept such data and be able to read them, as applicable.
Article 8
Right to restrict access
Natural persons shall have the right to restrict the access of health professionals and healthcare providers to all or parts of their personal electronic health data as referred to in Article 3.
When exercising the right referred to in the first paragraph, natural persons shall be made aware that restricting access might impact the provision of healthcare to them.
The fact that a natural person has restricted access under the first paragraph shall not be visible to healthcare providers.
Member States shall establish the rules and specific safeguards regarding such restriction mechanisms.
Article 9
Right to obtain information on accessing data
Natural persons shall have the right to obtain information, including through automatic notifications, on any access to their personal electronic health data through the health professional access service obtained in the context of healthcare, including access provided in accordance with Article 11(5).
The information referred to in paragraph 1 shall be provided, free of charge and without delay, through electronic health data access services and shall be available for at least three years from each date of access to the data. That information shall include at least the following:
(a) information on the healthcare provider or other individuals who accessed the personal electronic health data;
(b) the date and time of access;
(c) which personal electronic health data were accessed.
Member States may provide for restrictions to the right referred to in paragraph 1 in exceptional circumstances, where there are factual indications that disclosure would endanger the vital interests or rights of the health professional or the care of the natural person.
Article 10
Right of natural persons to opt out in primary use
Member States’ laws may provide that natural persons have the right to opt out from the access to their personal electronic health data registered in an EHR system through the electronic health data access services referred to in Articles 4 and 12. In such cases, Member States shall ensure that the exercise of that right is reversible.
If a Member State provides for a right referred to in paragraph 1 of this Article, it shall establish the rules and specific safeguards regarding the opt-out mechanism. In particular, Member States may provide for a healthcare provider or health professional to be able to get access to the personal electronic health data in cases where processing is necessary in order to protect the vital interests of the data subject or of another natural person as referred to in Article 9(2), point (c), of Regulation (EU) 2016/679, even if the patient has exercised the right to opt out in primary use.
Article 11
Access by health professionals to personal electronic health data
Where health professionals process data in an electronic format, they shall have access to the relevant and necessary personal electronic health data of natural persons under their treatment through the health professional access services referred to in Article 12, irrespective of the Member State of affiliation and the Member State of treatment.
Where the Member State of affiliation of the natural person under treatment and the Member State of treatment of such natural person differ, cross-border access to the personal electronic health data of the natural person under treatment shall be provided through the cross-border infrastructure referred to in Article 23.
The access referred to in paragraphs 1 and 2 of this Article shall include at least the priority categories of personal electronic health data referred to in Article 14.
In line with the principles provided for in Article 5 of Regulation (EU) 2016/679, Member States shall establish rules providing for the categories of personal electronic health data accessible by different categories of health professionals or for different healthcare tasks. Such rules shall take into account the possibility of restrictions imposed under Article 8 of this Regulation.
In the case of treatment in a Member State other than the Member State of affiliation, the rules referred to in paragraph 3 shall be those of the Member State of treatment.
Where access to personal electronic health data has been restricted by a natural person pursuant to Article 8, the healthcare provider or health professional shall not be informed of the restricted content of those data.
By way of derogation from the first paragraph of Article 8, where necessary in order to protect the vital interests of the data subject, the healthcare provider or health professional may be granted access to the restricted electronic health data. Such cases shall be logged in a clear and understandable format and shall be easily accessible for the data subject.
Member States may provide for additional safeguards.
Article 12
Health professional access services
For the provision of healthcare, Member States shall ensure that health professionals are able to access free of charge the priority categories of personal electronic health data referred to in Article 14, including for cross-border care, through health professional access services.
The services referred to in the first paragraph of this Article shall be accessible only to health professionals who are in possession of electronic identification means which are recognised pursuant to Article 6 of Regulation (EU) No 910/2014 or other electronic identification means compliant with common specifications referred to in Article 36 of this Regulation.
Personal electronic health data shall be presented in a user-friendly manner in the electronic health records to allow for easy use by health professionals.
Article 13
Registration of personal electronic health data
Member States shall ensure that, where electronic health data are processed for the provision of healthcare, healthcare providers register the relevant personal electronic health data falling fully or partially under at least the priority categories of personal electronic health data referred to in Article 14 in an electronic format in an EHR system.
When processing data in an electronic format, healthcare providers shall ensure that the personal electronic health data of the natural persons under their treatment are updated with information related to the healthcare.
Where personal electronic health data are registered in a Member State of treatment that differs from the Member State of affiliation of the natural person concerned, the Member State of treatment shall ensure that the registration is performed under the identification data of the natural person in the Member State of affiliation.
By 26 March 2027, the Commission shall, by means of implementing acts, determine data quality requirements, including in relation to semantics, uniformity, consistency, accuracy and completeness, for the registration of personal electronic health data in an EHR system as relevant. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
When personal electronic health data are registered or updated, the electronic health records shall identify the health professional and healthcare provider that carried out such registration or update, and the time at which such registration or update was carried out. Member States may require other aspects of data registration to be recorded.
Article 14
Priority categories of personal electronic health data for primary use
For the purposes of this Chapter, where data are processed in electronic format the priority categories of personal electronic health data shall be the following:
(a) patient summaries;
(b) electronic prescriptions;
(c) electronic dispensations;
(d) medical imaging studies and related imaging reports;
(e) medical test results, including laboratory and other diagnostic results and related reports; and
(f) discharge reports.
The main characteristics of the priority categories of personal electronic health data for primary use shall be as set out in Annex I.
Member States may provide in their national law for additional categories of personal electronic health data to be accessed and exchanged for primary use pursuant to this Chapter.
The Commission may, by means of implementing acts, lay down cross-border specifications for the categories of personal electronic health data referred to in the third subparagraph of this paragraph pursuant to Article 15(3) and Article 23(8). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
The Commission is empowered to adopt delegated acts in accordance with Article 97 to amend this Regulation by amending Annex I through the addition, modification or removal of the main characteristics of the priority categories of personal electronic health data as referred to in paragraph 1, provided that the amendments are aimed at adapting the priority categories of personal electronic health data to technical developments and international standards. Moreover, additions and modifications of those characteristics shall satisfy both of the following criteria:
(a) the characteristic is relevant for healthcare provided to natural persons;
(b) the characteristic is used in the majority of Member States according to the most recent information.
Article 15
European electronic health record exchange format
By 26 March 2027, the Commission shall, by means of implementing acts, lay down the technical specifications for the priority categories of personal electronic health data referred to in Article 14(1), setting out the European electronic health record exchange format. Such format shall be commonly used, machine-readable and allow transmission of personal electronic health data between different software applications, devices and healthcare providers. Such format shall support transmission of structured and unstructured health data and shall include the following elements:
(a) harmonised datasets containing electronic health data and defining structures, such as data fields and data groups for the representation of clinical content and other parts of the electronic health data;
(b) coding systems and values to be used in datasets containing electronic health data;
(c) technical interoperability specifications for the exchange of electronic health data, including its content representation, standards and profiles.
The implementing acts referred to in the first subparagraph of this paragraph shall be adopted in accordance with the examination procedure referred to in Article 98(2).
The Commission shall, by means of implementing acts, provide regular updates of the European electronic health record exchange format to integrate relevant revisions of the healthcare coding systems and nomenclatures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
The Commission may, by means of implementing acts, lay down technical specifications to extend the European electronic health record exchange format to additional categories of personal electronic health data referred to in Article 14(1), third subparagraph. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Member States shall ensure that the priority categories of personal electronic health data referred to in Article 14 are issued in the European electronic health record exchange format referred to in paragraph 1 of this Article. Where such data are transmitted by automated means for primary use, the receiving provider shall accept the format of the data and be able to read them.
Article 16
Identification management
Where natural persons use electronic health data access services referred to in Article 4, those natural persons shall have the right to identify themselves electronically using any electronic identification means which are recognised pursuant to Article 6 of Regulation (EU) No 910/2014. Member States may provide complementary mechanisms to ensure appropriate identity matching in cross-border situations.
The Commission shall, by means of implementing acts, determine the requirements for the interoperable, cross-border identification and authentication mechanism for natural persons and health professionals, in accordance with Regulation (EU) No 910/2014. That mechanism shall facilitate the transferability of personal electronic health data in a cross-border context. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
The Commission, in cooperation with Member States, shall implement services required by the interoperable, cross-border identification and authentication mechanism referred to in paragraph 2 of this Article at Union level, as part of the cross-border infrastructure referred to in Article 23.
The Member States’ competent authorities and the Commission shall implement the interoperable, cross-border identification and authentication mechanism at Member State and Union level, respectively.
Article 17
Requirements for technical implementation
The Commission shall, by means of implementing acts, determine the requirements for the technical implementation of the rights set out in this Section.
Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Article 18
Compensation for making personal electronic health data available
Providers receiving data under this Chapter shall not be required to compensate the healthcare provider for making personal electronic health data available. A healthcare provider or a third party shall not directly or indirectly charge data subjects a fee or costs, or require compensation, for sharing or accessing data.
SECTION 2
Governance for primary use
Article 19
Digital health authorities
Each Member State shall designate one or more digital health authorities responsible for the implementation and enforcement of this Chapter at national level. The Member States shall inform the Commission of the identity of the digital health authorities by 26 March 2027. Where a Member State designates more than one digital health authority or where the digital health authority consists of multiple organisations, the Member State concerned shall communicate to the Commission a description of the distribution of tasks between those various authorities or organisations. Where a Member State designates several digital health authorities, it shall designate one digital health authority to act as coordinator. The Commission shall make that information publicly available.
Each digital health authority shall be entrusted with the following tasks and powers:
(a) ensuring the implementation of the rights and obligations provided for in this Chapter and Chapter III by adopting necessary national, regional or local technical solutions and by establishing relevant rules and mechanisms;
(b) ensuring that complete and up-to-date information about the implementation of rights and obligations provided for in this Chapter and Chapter III is made readily available to natural persons, health professionals and healthcare providers;
(c) in the implementation of technical solutions referred to in point (a) of this paragraph, ensuring that such technical solutions comply with this Chapter, Chapter III and Annex II;
(d) contributing at Union level to the development of technical solutions enabling natural persons and health professionals to exercise their rights and comply with their obligations set out in this Chapter;
(e) facilitating persons with disabilities to exercise their rights under this Chapter in accordance with Directive (EU) 2019/882 of the European Parliament and of the Council (31);
(f) supervising the national contact points for digital health and cooperating with other digital health authorities and the Commission on further development of MyHealth@EU;
(g) ensuring the implementation at national level of the European electronic health record exchange format, in cooperation with national authorities and stakeholders;
(h) contributing at Union level to the development of the European electronic health record exchange format, to the elaboration of common specifications, in accordance with Article 36, which address quality, interoperability, security, safety, ease of use, accessibility, non-discrimination or fundamental right concerns, and to the elaboration of the specifications of the EU database for registration of EHR systems and wellness applications referred to in Article 49;
(i) where applicable, performing market surveillance activities in accordance with Article 43, while ensuring that any conflicts of interest are avoided;
(j) building national capacity for implementing requirements concerning interoperability and security of electronic health data for primary use and participating in information exchanges and capacity building activities at Union level;
(k) cooperating with market surveillance authorities, participating in the activities related to handling of risks posed by EHR systems and of serious incidents and supervising the implementation of corrective action in accordance with Article 44;
(l) cooperating with other relevant entities and bodies at local, regional, national or Union level, to ensure interoperability, portability and security of electronic health data;
(m) cooperating with supervisory authorities in accordance with Regulations (EU) No 910/2014 and (EU) 2016/679 and Directive (EU) 2022/2555 of the European Parliament and of the Council (32) and with other relevant authorities, including those competent for cybersecurity and electronic identification.
Each Member State shall ensure that each digital health authority is provided with the human, technical and financial resources, premises and infrastructure necessary for the effective performance of its tasks and exercise of its powers.
In the performance of its tasks, each digital health authority shall avoid any conflicts of interest. Each member of staff of the digital health authority shall act in the public interest and in an independent manner.
In the performance of their tasks, the relevant digital health authorities shall actively cooperate and consult with relevant stakeholders’ representatives, including patients’ representatives, healthcare providers and health professionals’ representatives, including health professional associations, as well as consumer organisations and industry associations.
Article 20
Reporting by digital health authorities
Digital health authorities designated pursuant to Article 19 shall publish an activity report every two years, which shall contain a comprehensive overview of their activities. If a Member State designates more than one digital health authority, one of them shall be responsible for the drawing up of the report and, in doing so, it shall request the necessary information from the other digital health authorities. That activity report shall follow a structure agreed at Union level within the European Health Data Space Board (the ‘EHDS Board’) referred to in Article 92. That activity report shall contain at least information concerning:
(a) the measures taken to implement this Regulation;
(b) the percentage of natural persons having access to the various data categories of their electronic health records;
(c) the handling of requests from natural persons regarding the exercise of their rights pursuant to this Regulation;
(e) the volumes of electronic health data of different categories shared across borders through MyHealth@EU;
(f) the number of cases of non-compliance with mandatory requirements.
Article 21
Right to lodge a complaint with a digital health authority
Without prejudice to any other administrative or judicial remedy, natural and legal persons shall have the right to lodge a complaint in relation to the provisions laid down in this Chapter, individually or, where relevant, collectively, with the competent digital health authority, provided that their rights or interests are negatively affected.
Where the complaint concerns the rights of natural persons pursuant to Articles 3 and 5 to 10 of this Regulation, the digital health authority shall transmit the complaint to the competent supervisory authorities under Regulation (EU) 2016/679. The digital health authority shall provide the necessary information at its disposal to the competent supervisory authority under Regulation (EU) 2016/679 in order to facilitate the assessment and investigation of the complaint.
The competent digital health authority with which the complaint has been lodged shall inform, in accordance with national law, the complainant of the progress made in dealing with the complaint, of the decision taken on the complaint, of any referral of the complaint to the competent supervisory authority under Regulation (EU) 2016/679 and, in cases of such a referral, that that supervisory authority is, from that moment on, to be the sole point of contact for the complainant in that matter.
Digital health authorities in the Member States concerned shall cooperate to handle and resolve complaints related to cross-border exchange of and access to personal electronic health data, including by exchanging all relevant information by electronic means, without undue delay.
Digital health authorities shall facilitate the submission of complaints and provide easily accessible tools for the submission of complaints.
Article 22
Relationship with supervisory authorities under Regulation (EU) 2016/679
Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.
This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence.
EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.