Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847 (Text with EEA relevance)

Type Regulation
Publication 2025-02-11
Last updated 2026-04-15
State In force
Department Council of the European Union, European Parliament
Source EUR-Lex
articles 106
Reform history JSON API

The supervisory authority or supervisory authorities responsible for monitoring and enforcing the application of Regulation (EU) 2016/679 shall also be competent for monitoring and enforcing the application of Articles 3 and 5 to 10 of this Regulation. The relevant provisions of Regulation (EU) 2016/679 shall apply mutatis mutandis. Supervisory authorities shall be empowered to impose administrative fines up to the amount referred to in Article 83(5) of Regulation (EU) 2016/679.

The supervisory authorities referred to in the first paragraph of this Article and digital health authorities referred to in Article 19 shall, where relevant, cooperate in the enforcement of this Regulation, within the remit of their respective competences.

SECTION 3

Cross-border infrastructure for primary use of personal electronic health data

Article 23
MyHealth@EU
1.

The Commission shall establish a central interoperability platform for digital health (‘MyHealth@EU’) to provide services to support and facilitate the exchange of personal electronic health data between the national contact points for digital health of the Member States.

2.

Each Member State shall designate one national contact point for digital health, as an organisational and technical gateway for the provision of services linked to the cross-border exchange of personal electronic health data in the context of primary use. Each national contact point for digital health shall be connected to all other national contact points for digital health in other Member States and to the central interoperability platform for digital health in the cross-border infrastructure MyHealth@EU. Where a national contact point for digital health is an entity consisting of multiple organisations responsible for implementing different services, the Member State concerned shall communicate to the Commission a description of the distribution of tasks between the organisations. Each Member State shall inform the Commission of the identity of its national contact point for digital health by 26 March 2027. The national contact point for digital health may be designated within the digital health authority referred to in Article 19. Member States shall inform the Commission of any subsequent modification of the identity of those national contact points for digital health. The Commission and the Member States shall make that information publicly available.

3.

Each national contact point for digital health shall enable the exchange of the personal electronic health data referred to in Article 14(1) with national contact points for digital health in other Member States through MyHealth@EU. That exchange shall be based on the European electronic health record exchange format.

Where Member States provide for additional categories of personal electronic health data under Article 14(1), third subparagraph, the national contact point for digital health shall enable the exchange of the additional categories of personal electronic health data referred to in Article 14(1), third subparagraph, insofar as the Member State concerned has provided for those additional categories of personal electronic health data to be accessed and exchanged in accordance with Article 14(1), third subparagraph.

4.

By 26 March 2027, the Commission shall, by means of implementing acts, adopt the necessary measures for the technical development of MyHealth@EU, detailed rules concerning the security, confidentiality and protection of personal electronic health data and the conditions for compliance checks necessary to join and remain connected to MyHealth@EU. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

5.

Member States shall ensure the connection of all healthcare providers to their national contact points for digital health. Member States shall ensure that connected healthcare providers are able to perform two-way exchanges of electronic health data with the national contact point for digital health.

6.

Member States shall ensure that pharmacies operating on their territories, including online pharmacies, are able to dispense electronic prescriptions issued in other Member States, under the conditions laid down in Article 11 of Directive 2011/24/EU.

Pharmacies shall access and accept electronic prescriptions transmitted to them from other Member States through MyHealth@EU, provided that the conditions laid down in Article 11 of Directive 2011/24/EU are fulfilled.

Following the dispensation of medicinal products based on an electronic prescription from another Member State, the pharmacy concerned shall report through MyHealth@EU such dispensation to the national contact point for digital health of the Member State in which that prescription was issued.

7.

The national contact points for digital health shall act as joint controllers of the personal electronic health data communicated through MyHealth@EU for the processing operations in which they are involved. The Commission shall act as processor.

8.

The Commission shall, by means of implementing acts, lay down the rules regarding the requirements of cybersecurity, technical interoperability, semantic interoperability, operations and service management in relation to the processing by the processor referred to in paragraph 7 of this Article and its responsibilities towards the controllers, in accordance with Chapter IV of Regulation (EU) 2016/679. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

9.

The national contact points for digital health shall fulfil the conditions to join and to remain connected to MyHealth@EU as laid down in the implementing acts referred to in paragraph 4. The compliance of the national contact points for digital health with those conditions shall be verified by the Commission through compliance checks.

Article 24
Supplementary cross-border digital health services and infrastructures
1.

Member States may provide through MyHealth@EU supplementary services that facilitate telemedicine, mobile health, access by natural persons to existing translations of their health data, exchange or verification of health-related certificates, including vaccination card services supporting public health and public health monitoring or digital health systems, services and interoperable applications, with a view to achieving a high level of trust and security, enhancing continuity of care and ensuring access to safe and high-quality healthcare. The Commission shall, by means of implementing acts, set out the technical aspects of such supplementary services. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

2.

The Commission and Member States may facilitate the exchange of personal electronic health data with other infrastructures, such as the Clinical Patient Management System or other services or infrastructures in the health, care or social security fields which may become authorised participants in MyHealth@EU. The Commission shall, by means of implementing acts, set out the technical aspects of such exchanges. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

The connection and disconnection of another infrastructure to or from the central platform for digital health shall be subject to a decision of the Commission adopted by means of an implementing act, based on the result of compliance checks of the technical aspects of exchanges as referred to in the first subparagraph of this paragraph. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).

3.

A national contact point for digital health of a third country or a system established at international level by an international organisation may become an authorised participant in MyHealth@EU, provided that it fulfils the requirements of MyHealth@EU for the purposes of the personal electronic health data exchange as referred to in Article 23, that the transfer stemming from the connection to MyHealth@EU complies with the rules in Chapter V of Regulation (EU) 2016/679, and that the requirements concerning legal, organisational, operational, semantic, technical and cybersecurity measures are equivalent to those applicable to Member States in the operation of MyHealth@EU services. Those requirements shall be verified by the Commission through compliance checks.

Based on the outcome of the compliance checks referred to in the first subparagraph of this paragraph, the Commission may, by means of implementing acts, decide to connect or disconnect the national contact point for digital health of the third country or the system established at international level by an international organisation, as applicable, to or from MyHealth@EU. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

The Commission shall establish and maintain a list of national contact points for digital health of third countries or of systems established at international level by international organisations which are connected to MyHealth@EU pursuant to this paragraph and shall make that list publicly available.

CHAPTER III

EHR SYSTEMS AND WELLNESS APPLICATIONS

SECTION 1

Scope and general provisions for EHR systems

Article 25
Harmonised software components of EHR systems
1.

EHR systems shall include a European interoperability software component for EHR systems and a European logging software component for EHR systems (the ‘harmonised software components of EHR systems’), in accordance with the provisions laid down in this Chapter.

2.

This Chapter shall not apply to general purpose software used in a healthcare environment.

Article 26
Placing on the market and putting into service
1.

EHR systems shall be placed on the market or put into service only if they comply with the provisions laid down in this Chapter.

2.

EHR systems that are manufactured and used within health institutions established in the Union, as well as EHR systems offered as a service as defined in Article 1(1), point (b), of Directive (EU) 2015/1535 of the European Parliament and of the Council (33) to a natural or legal person established in the Union, shall be considered as having been put into service.

3.

Member States shall not prohibit or restrict the placing on the market of EHR systems which comply with this Regulation, on account of considerations relating to aspects concerning the harmonised software components of EHR systems regulated by this Regulation.

Article 27
Relation to Union law governing medical devices, in vitro diagnostic medical devices and AI systems
1.

Manufacturers of medical devices or in vitro diagnostic medical devices, as defined in Article 2, point (1), of Regulation (EU) 2017/745 and Article 2, point (2), of Regulation (EU) 2017/746, respectively, that claim interoperability of those medical devices or in vitro diagnostic medical devices with the harmonised software components of EHR systems shall prove compliance with the essential requirements on the European interoperability software component for EHR systems and the European logging software component for EHR systems, laid down in Section 2 of Annex II to this Regulation. Article 36 of this Regulation shall apply to those medical devices and in vitro diagnostic medical devices.

2.

Providers of AI systems considered to be high-risk in accordance with Article 6 of Regulation (EU) 2024/1689 (the ‘high-risk AI system’) and which do not fall within the scope of Regulation (EU) 2017/745 or (EU) 2017/746, that claim interoperability of those high-risk AI systems with the harmonised software components of EHR systems, shall prove compliance with the essential requirements on the European interoperability software component for EHR systems and the European logging software component for EHR systems, as laid down in Section 2 of Annex II to this Regulation. Article 36 of this Regulation shall apply to those high-risk AI systems.

Article 28
Claims

In the information sheet, instructions for use or other information accompanying EHR systems, and in the advertising of EHR systems, it shall be prohibited to use text, names, trademarks, pictures and figurative or other signs that may mislead the professional user as defined in Article 3, point (8), of Regulation (EU) 2018/1807 of the European Parliament and of the Council (34) with regard to their intended purpose, interoperability and security by:

(a) ascribing functions and properties to the EHR system which it does not have;

(b) failing to inform the professional user of likely limitations related to interoperability or security features of the EHR system in relation to its intended purpose;

(c) suggesting uses for the EHR system other than those stated to form part of the intended purpose in the technical documentation.

Article 29
Procurement, reimbursement and financing

Member States may maintain or define specific rules for the procurement or financing of, or reimbursement for, EHR systems in the context of the organisation, delivery or financing of healthcare services, provided that such rules are compliant with Union law and do not affect the functioning or compliance of the harmonised software components of EHR systems.

SECTION 2

Obligations of economic operators with regard to EHR systems

Article 30
Obligations of manufacturers of EHR systems
1.

Manufacturers of EHR systems shall:

(a) ensure that the harmonised software components of their EHR systems and the EHR systems themselves, to the extent that this Chapter establishes requirements for them, are in conformity with the essential requirements laid down in Annex II and with the common specifications in accordance with Article 36;

(b) ensure that the harmonised software components of their EHR systems are not adversely affected by other software components of the same EHR system;

(c) draw up the technical documentation of their EHR systems in accordance with Article 37 before placing those EHR systems on the market, and subsequently keep it up to date;

(d) ensure that their EHR systems are accompanied, free of charge for the user, by the information sheet provided for in Article 38 and clear and complete instructions for use;

(e) draw up the EU declaration of conformity in accordance with Article 39;

(f) affix the CE marking of conformity in accordance with Article 41;

(g) indicate the name, registered trade name or registered trade mark, the postal address, and the website, email address or other digital contact details through which they can be contacted, in the EHR system; indicate in the contact details a single point at which the manufacturer can be contacted; the contact details shall be in a language that is easily understood by users and market surveillance authorities;

(h) comply with the registration obligations in Article 49;

(i) take without undue delay any necessary corrective action in respect of their EHR systems, where they consider or have reason to believe that such systems are not or are no longer in conformity with the essential requirements laid down in Annex II, or recall or withdraw such systems; the manufacturers of EHR systems shall subsequently inform the national authorities of the Member States in which they made their EHR systems available on the market or put them into service of the non-conformity, of any corrective action taken, including the timetable for implementation, and of the date at which the harmonised software components of their EHR systems have been brought into conformity or been recalled or withdrawn;

(j) inform the distributors of their EHR systems and, where applicable, the authorised representative, importers and users of the non-conformity and of any corrective action, recall or withdrawal of those EHR systems;

(k) inform the distributors of their EHR systems and, where applicable, the authorised representative, importers and users of any mandatory preventive maintenance of the EHR systems and its frequency;

(l) upon request, provide, in an official language of the Member State concerned, market surveillance authorities in that Member State with all the information and documentation necessary to demonstrate the conformity of the EHR systems which they have placed on the market or put into service with the essential requirements laid down in Annex II;

(m) cooperate with market surveillance authorities, at their request, on any action taken to bring the EHR systems which they have placed on the market or put into service into conformity with the essential requirements laid down in Annex II and with any requirements adopted pursuant to Article 42 in an official language of the Member State concerned;

(n) establish channels of complaint and keep distributors informed thereof;

(o) keep a register of complaints and a register of non-conforming EHR systems and keep distributors informed thereof.

2.

Manufacturers of EHR systems shall ensure that procedures are in place to ensure that the design, development and deployment of the harmonised software components of an EHR system continue to comply with the essential requirements laid down in Annex II and the common specifications referred to in Article 36. Changes in EHR system design or characteristics with regard to the harmonised software components of an EHR system shall be adequately taken into account and reflected in the technical documentation.

3.

Manufacturers of EHR systems shall keep the technical documentation referred to in Article 37 and the EU declaration of conformity referred to in Article 39 for 10 years after the EHR system covered by the EU declaration of conformity has been placed on the market.

Manufacturers of EHR systems shall make available the source code or the programming logic included in the technical documentation, upon a reasoned request, to the relevant authorities, if that source code or programming logic is necessary in order for those authorities to be able to check compliance with the essential requirements laid down in Annex II.

4.

A manufacturer of EHR systems established outside the Union shall ensure that its authorised representative has the necessary documentation readily available in order to fulfil the tasks referred to in Article 31(2).

5.

Manufacturers of EHR systems shall, upon a reasoned request from a market surveillance authority, provide it with all the information and documentation, in paper or electronic form, necessary to demonstrate the conformity of the EHR system with the essential requirements laid down in Annex II and the common specifications referred to in Article 36, in a language which can be easily understood by that market surveillance authority. The manufacturers of EHR systems shall cooperate with the market surveillance authority, at its request, on any measures taken to eliminate the risks posed by an EHR system which they have placed on the market or put into service.

Article 31
Authorised representatives
1.

Prior to making an EHR system available on the Union market, a manufacturer of an EHR system established outside of the Union shall, by written mandate, appoint an authorised representative which is established in the Union.

2.

An authorised representative shall perform the tasks specified in the mandate agreed with the manufacturer. The mandate shall allow the authorised representative to do at least the following:

(a) keep the EU declaration of conformity and the technical documentation referred to in Article 37 at the disposal of market surveillance authorities for the period referred to in Article 30(3);

(b) further to a reasoned request from a market surveillance authority, provide authorities of the Member State concerned with a copy of the mandate and all the information and documentation necessary to demonstrate the conformity of an EHR system with the essential requirements laid down in Annex II as well as the common specifications referred to in Article 36;

(c) inform without undue delay the manufacturer if the authorised representative has reason to believe that an EHR system is no longer in conformity with the essential requirements laid down in Annex II;

(d) inform without undue delay the manufacturer about any complaint received from consumers or professional users;

(e) cooperate with the market surveillance authorities, at their request, on any corrective action taken in relation to the EHR systems covered by their mandate;

(f) terminate the mandate if the manufacturer does not comply with its obligations under this Regulation;

(g) ensure that the technical documentation referred to in Article 37 can be made available to relevant authorities, upon request.

3.

In the event of a change of the authorised representative, the detailed arrangements for such change shall address at least the following:

(a) the date of termination of the mandate of the outgoing authorised representative and the date of the beginning of the mandate of the incoming authorised representative;

(b) the transfer of documents, including confidentiality aspects and property rights.

4.

Where the manufacturer is established outside the Union and has not complied with the obligations laid down in Article 30, the authorised representative shall be jointly and severally liable for non-compliance with this Regulation on the same basis as the manufacturer.

Article 32
Obligations of importers
1.

Importers shall place on the Union market only EHR systems which are in conformity with the essential requirements laid down in Annex II as well as the common specifications referred to in Article 36.

2.

Before making an EHR system available on the market, importers shall ensure that:

(a) the manufacturer has drawn up the technical documentation referred to in Article 37 and the EU declaration of conformity;

(b) the manufacturer is identified and an authorised representative has been appointed in accordance with Article 31;

(c) the EHR system bears the CE marking of conformity referred to in Article 41 after the conformity assessment procedure has been completed;

(d) the EHR system is accompanied by the information sheet referred to in Article 38 with clear and complete instructions for use, including for its maintenance, in accessible formats.

3.

Importers shall indicate their name, registered trade name or registered trade mark, the postal address, website, email address or other digital contact details through which they can be contacted in a document accompanying the EHR system. The contact details shall indicate a single point at which the manufacturer can be contacted and shall be in a language which can be easily understood by users and market surveillance authorities. Importers shall ensure that any additional label does not conceal or obscure any of the information provided by the manufacturer that appears on any original label which is provided for the EHR system.

4.

Importers shall ensure that, while an EHR system is under their responsibility, the EHR system is not altered in such a way that its conformity with the essential requirements laid down in Annex II and with any requirements adopted pursuant to Article 42 is jeopardised.

5.

Where an importer considers or has reason to believe that an EHR system is not or is no longer in conformity with the essential requirements laid down in Annex II and with any requirements adopted pursuant to Article 42, it shall not make that EHR system available on the market, or, if that EHR system was already placed on the market, shall recall or withdraw it, until the EHR system has been brought into conformity. In the event of such recall or withdrawal, the importer shall inform without undue delay the manufacturer of such EHR system, the users and the market surveillance authorities of the Member State in which it made the EHR system available on the market of such recall or withdrawal, giving details, in particular, of the non-conformity and of any corrective measures taken.

Where an importer considers or has reason to believe that an EHR system presents a risk to the health or safety of natural persons, it shall without undue delay inform the market surveillance authorities of the Member State in which it is established, as well as the manufacturer and, where applicable, the authorised representative.

6.

Importers shall keep a copy of the EU declaration of conformity at the disposal of the market surveillance authorities for the period referred to in Article 30(3) and ensure that the technical documentation referred to in Article 37 can be made available to those authorities, upon request.

7.

Importers shall, further to a reasoned request from market surveillance authorities of the Member States concerned, provide them with all the information and documentation necessary to demonstrate the conformity of an EHR system. Importers shall cooperate with those authorities, at their request, and with the manufacturer and, where applicable, with the authorised representative in an official language of the Member State where the market surveillance authority is located. Importers shall cooperate with those authorities, at their request, on any action taken to bring their EHR systems into conformity with the essential requirements in relation to the harmonised software components as laid down in Annex II or to ensure that the EHR systems which are not in conformity with those essential requirements are recalled or withdrawn.

8.

Importers shall establish reporting channels and ensure that they are accessible to allow users to submit complaints, and shall keep a register of complaints, of non-conforming EHR systems and EHR system recalls and withdrawals. Importers shall verify whether the channels of complaint established pursuant to Article 30(1), point (n), are publicly available, allowing users to submit complaints and to receive any communication concerning any risk related to their health and safety or to other aspects of public interest protection and allowing users to be informed of any serious incident involving an EHR system. Where such channels of complaint were not established, the importers shall establish them and take into account the accessibility needs of vulnerable groups and persons with disabilities.

9.

Importers shall investigate complaints and follow up on information received on incidents involving an EHR system they made available on the market. Importers shall register those complaints, any recalls or withdrawals of EHR systems and any corrective measure taken to bring the EHR system into conformity, in the register referred to in Article 30(1), point (o), or in their own internal register. Importers shall keep the manufacturer, distributors and, where relevant, authorised representatives informed in a timely manner of the investigation and follow-up carried out and of the results of the investigation and follow-up.

Article 33
Obligations of distributors
1.

Before making an EHR system available on the market, distributors shall verify that:

(a) the manufacturer has drawn up the EU declaration of conformity;

(b) the EHR system bears the CE marking of conformity;

(c) the EHR system is accompanied by the information sheet referred to in Article 38 with clear and complete instructions for use in accessible formats;

(d) where applicable, the importer has complied with the requirements set out in Article 32(3).

2.

Distributors shall ensure that, while an EHR system is under their responsibility, the EHR system is not altered in such a way that its conformity with the essential requirements laid down in Annex II and with any requirements adopted pursuant to Article 42 is jeopardised.

3.

Where a distributor considers or has reason to believe that an EHR system is not in conformity with the essential requirements laid down in Annex II and with any requirements adopted pursuant to Article 42, it shall not make that EHR system available on the market until it has been brought into conformity. The distributor shall inform without undue delay the manufacturer or the importer, as well as the market surveillance authorities of the Member States where the EHR system has been or is to be made available on the market, to that effect. Where a distributor considers or has reason to believe that an EHR system presents a risk to the health or safety of natural persons, it shall inform the market surveillance authorities of the Member State in which the distributor is established, as well as the manufacturer and the importer.

4.

Distributors shall, further to a reasoned request from a market surveillance authority, provide it with all the information and documentation necessary to demonstrate the conformity of an EHR system. They shall cooperate with that authority, at its request, and with the manufacturer, the importer and, where applicable, with the manufacturer’s authorised representative on any action taken to bring an EHR system into conformity with the essential requirements laid down in Annex II and with any requirements adopted pursuant to Article 42 or to recall or withdraw it.

Article 34
Cases in which obligations of manufacturers of an EHR system apply to other entities or individuals

An importer, distributor or user shall be considered a manufacturer for the purposes of this Regulation and shall be subject to the obligations laid down in Article 30 where they:

(a) make an EHR system available on the market under their own name or trademark;

(b) modify an EHR system already placed on the market in such a way that conformity with the applicable requirements might be affected; or

(c) modify an EHR system in such a way that it leads to changes in the intended purpose declared by the manufacturer.

Article 35
Identification of economic operators

Economic operators shall, on request, identify the following to the market surveillance authorities, for 10 years from the date when the last EHR system covered by the EU declaration of conformity has been placed on the market:

(a) any economic operator that has supplied them with an EHR system; and

(b) any economic operator to which they have supplied an EHR system.

SECTION 3

Conformity of the harmonised software components of EHR systems

Article 36
Common specifications
1.

By 26 March 2027, the Commission shall, by means of implementing acts, adopt common specifications in respect of the essential requirements laid down in Annex II, including a common template and a time limit for implementing those common specifications. Where relevant, those common specifications shall take into account the specificities of medical devices and high-risk AI systems referred to in Article 27(1) and (2), respectively, including the state-of-the-art standards for health informatics and the European electronic health record exchange format. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

2.

The common specifications referred to in paragraph 1 shall include the following information and elements:

(a) their scope;

(b) their applicability to different categories of EHR systems or functions included in them;

(c) their version;

(d) their validity period;

(e) a normative part;

(f) an explanatory part, including any relevant implementation guidelines.

3.

The common specifications referred to in paragraph 1 may include elements related to the following:

(a) datasets containing electronic health data and defining structures, such as data fields and data groups for the representation of clinical content and other parts of the electronic health data;

(b) coding systems and values to be used in datasets containing electronic health data, taking due account of both potential future harmonisation of terminologies and their compatibility with existing national terminologies;

(c) other requirements related to data quality, such as the completeness and accuracy of electronic health data;

(d) technical specifications, standards and profiles for the exchange of electronic health data;

(e) requirements and principles related to patient safety and the security, confidentiality, integrity and protection of electronic health data;

(f) specifications and requirements related to identification management and the use of electronic identification.

4.

EHR systems, medical devices, in vitro diagnostic medical devices and high-risk AI systems referred to in Articles 25 and 27 that are in conformity with the common specifications referred to in paragraph 1 of this Article shall be considered to be in conformity with the essential requirements covered by those common specifications or parts thereof, laid down in Annex II, and covered by those common specifications or the relevant parts thereof.

5.

Where common specifications covering interoperability and security requirements of EHR systems affect medical devices, in vitro diagnostic medical devices or high-risk AI systems falling under other legal acts, such as Regulation (EU) 2017/745, (EU) 2017/746 or (EU) 2024/1689, the adoption of those common specifications may be preceded by a consultation with the Medical Device Coordination Group (MDCG) established by Article 103 of Regulation (EU) 2017/745 or the European Artificial Intelligence Board established by Article 65 of Regulation (EU) 2024/1689 and the European Data Protection Board (EDPB), as applicable.

6.

Where common specifications covering interoperability and security requirements of medical devices, in vitro diagnostic medical devices or high-risk AI systems falling under other legal acts, such as Regulation (EU) 2017/745, (EU) 2017/746 or (EU) 2024/1689, affect EHR systems, the Commission shall ensure that the adoption of those common specifications is preceded by a consultation with the EHDS Board and the EDPB, as applicable.

Article 37
Technical documentation
1.

Manufacturers shall draw up technical documentation before the EHR system is placed on the market or put into service, and shall keep that documentation up to date.

2.

The technical documentation referred to in paragraph 1 of this Article shall demonstrate that the EHR system complies with the essential requirements laid down in Annex II and provide market surveillance authorities with all the necessary information to assess the conformity of the EHR system with those requirements. That technical documentation shall contain, as a minimum, the elements set out in Annex III and a reference to the results obtained from a European digital testing environment referred to in Article 40.

3.

The technical documentation referred to in paragraph 1 shall be drawn up in an official language of the Member State concerned or a language that is easily understandable in that Member State. Following a reasoned request from the market surveillance authority of a Member State, the manufacturer shall provide a translation of the relevant parts of the technical documentation into an official language of that Member State.

4.

When a market surveillance authority requests the technical documentation or a translation of parts thereof from a manufacturer, the manufacturer shall provide such technical documentation or translation within 30 days of the date of the request, unless a shorter deadline is justified because of a serious and immediate risk. If the manufacturer does not comply with the requirements of paragraphs 1, 2 and 3 of this Article, the market surveillance authority may require it to have a test performed by an independent body at its own expense within a specified period in order to verify the conformity with the essential requirements laid down in Annex II and the common specifications referred to in Article 36.

Article 38
Information sheet accompanying the EHR system
1.

EHR systems shall be accompanied by an information sheet that includes concise, complete, correct and clear information that is relevant, accessible and comprehensible to professional users.

2.

The information sheet referred to in paragraph 1 shall specify:

(a) the identity, registered trade name or registered trademark, and contact details of the manufacturer and, where applicable, of its authorised representative;

(b) the name and version of the EHR system and date of its release;

(c) the intended purpose of the EHR system;

(d) the categories of electronic health data that the EHR system has been designed to process;

(e) the standards, formats and specifications supported by the EHR system and versions of those standards, formats and specifications.

3.

As an alternative to supplying the information sheet referred to in paragraph 1 of this Article with the EHR system, manufacturers may enter the information referred to in paragraph 2 of this Article into the EU database for registration of EHR systems and wellness applications referred to in Article 49.

Article 39
EU declaration of conformity
1.

The EU declaration of conformity referred to in Article 30(1), point (e), shall state that the manufacturer of an EHR system has demonstrated that the essential requirements laid down in Annex II have been fulfilled.

2.

Where an EHR system is subject to other Union legal acts in respect of aspects not covered by this Regulation, which also require an EU declaration of conformity by the manufacturer in which it is stated that the fulfilment of the requirements of those legal acts has been demonstrated, a single EU declaration of conformity shall be drawn up in respect of all Union legal acts applicable to the EHR system. That EU declaration of conformity shall contain all the information required for the identification of the Union legal acts to which it relates.

3.

The EU declaration of conformity shall contain the information set out in Annex IV and shall be translated into one or more official Union languages determined by the Member States in which the EHR system is made available.

4.

Where an EU declaration of conformity is drawn up in a digital format, it shall be made accessible online for the expected lifetime of the EHR system and, in any event, for at least 10 years from the placing on the market or the putting into service of the EHR system.

5.

By drawing up the EU declaration of conformity, the manufacturer shall assume responsibility for the compliance of the harmonised software components of the EHR system with the requirements laid down in this Regulation when it is placed on the market or put into service.

6.

The Commission shall publish a standard uniform template for the EU declaration of conformity and make it available in a digital format in all official languages of the Union.

Article 40
European digital testing environment
1.

The Commission shall develop a European digital testing environment for the assessment of harmonised software components of EHR systems. The Commission shall make the software supporting the European digital testing environment available as open-source.

2.

Member States shall operate digital testing environments for the assessment of harmonised software components of EHR systems. Such digital testing environments shall comply with the common specifications for the European digital testing environment laid down pursuant to paragraph 4. Member States shall inform the Commission about their digital testing environments.

3.

Before placing EHR systems on the market, manufacturers shall use the digital testing environments referred to in paragraphs 1 and 2 of this Article for the assessment of harmonised software components of EHR systems. The results of that assessment shall be included in the technical documentation referred to in Article 37. The elements in relation to which the results of the assessment are positive shall be presumed to be in conformity with this Regulation.

4.

The Commission shall, by means of implementing acts, lay down the common specifications for the European digital testing environment. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

Article 41
CE marking of conformity
1.

The CE marking of conformity shall be affixed visibly, legibly and indelibly to the accompanying documents of the EHR system and, where applicable, to the packaging of the EHR system.

2.

The CE marking of conformity shall be affixed before placing the EHR system on the market.

3.

The CE marking of conformity shall be subject to the general principles set out in Article 30 of Regulation (EC) No 765/2008.

Article 42
National requirements and reporting to the Commission
1.

Member States may adopt national requirements for EHR systems and provisions on their conformity assessment in relation to aspects other than the harmonised software components of EHR systems.

2.

The national requirements or provisions referred to in paragraph 1 shall not adversely affect the harmonised software components of EHR systems.

3.

When Member States adopt requirements or provisions in accordance with paragraph 1, they shall inform the Commission thereof.

SECTION 4

Market surveillance of EHR systems

Article 43
Market surveillance authorities
1.

Regulation (EU) 2019/1020 shall apply to EHR systems in relation to the requirements applicable to, and risks posed by, EHR systems covered by this Chapter.

2.

Member States shall designate the market surveillance authority or authorities responsible for the implementation of this Chapter. Member States shall entrust their market surveillance authorities with the necessary powers and shall provide them with the human, financial and technical resources, the equipment and the knowledge necessary for the proper performance of their tasks pursuant to this Regulation. Market surveillance authorities shall be empowered to take the market surveillance measures referred to in Article 16 of Regulation (EU) 2019/1020 to enforce the obligations laid down in this Chapter. Member States shall communicate the identity of the market surveillance authorities they designate to the Commission. The Commission and the Member States shall make that information publicly available.

3.

Market surveillance authorities designated pursuant to paragraph 2 of this Article may be the same authorities as the digital health authorities designated pursuant to Article 19. Where a digital health authority carries out tasks of a market surveillance authority, Member States shall ensure that any conflicts of interest are avoided.

4.

Market surveillance authorities shall report to the Commission on a yearly basis the outcomes of relevant market surveillance activities.

5.

Where a manufacturer or another economic operator fails to cooperate with a market surveillance authority or where the information and documentation they have provided is incomplete or incorrect, the market surveillance authority may take all appropriate measures to prohibit or restrict the relevant EHR system from being made available on the market until the manufacturer or the economic operator concerned cooperates or provides complete and correct information, or to recall or withdraw such EHR system from the market.

6.

The market surveillance authorities of the Member States shall cooperate with each other and with the Commission. The Commission shall enable the organisation of exchanges of information necessary for such cooperation.

7.

For medical devices, in vitro diagnostic medical devices or high-risk AI systems referred to in Article 27(1) and (2), the responsible authorities for market surveillance shall be those referred to in Article 93 of Regulation (EU) 2017/745, Article 88 of Regulation (EU) 2017/746 or Article 70 of Regulation (EU) 2024/1689, as applicable.

Article 44
Handling of risks posed by EHR systems and of serious incidents
1.

Where a market surveillance authority of one Member State has reason to believe that an EHR system poses a risk to the health, safety or rights of natural persons or to the protection of personal data, that market surveillance authority shall carry out an evaluation in relation to the EHR system concerned covering all relevant requirements laid down in this Regulation. The manufacturer, the manufacturer’s authorised representative and all other relevant economic operators shall cooperate as necessary with the market surveillance authority for that purpose and take all appropriate measures to ensure that the EHR system concerned no longer poses that risk when placed on the market or to recall or withdraw the EHR system from the market within a reasonable period.

2.

Where the market surveillance authorities of a Member State consider that the non-compliance of the EHR system is not limited to their national territory, they shall inform the Commission and the other Member States’ market surveillance authorities of the results of the evaluation referred to in paragraph 1 of this Article and of the corrective action which they have required the economic operator to take pursuant to Article 16(2) of Regulation (EU) 2019/1020.

3.

Where a market surveillance authority finds that an EHR system has caused harm to the health or safety of natural persons or to certain aspects of public interest protection, the manufacturer shall immediately provide information and documentation, as applicable, to the affected natural person or user and, where applicable, other third parties affected by that harm, without prejudice to data protection rules.

4.

The economic operator concerned referred to in paragraph 1 shall ensure that corrective action is taken in respect of all the EHR systems concerned that it has placed on the market throughout the Union.

5.

The market surveillance authority shall without undue delay inform the Commission and the market surveillance authorities, or, if applicable, the supervisory authorities under Regulation (EU) 2016/679, of other Member States of the corrective action referred to in paragraph 2. That information shall include all available details, in particular the data necessary for the identification of the EHR system concerned, the origin and the supply chain of the EHR system, the nature of the risk involved and the nature and duration of the national measures taken.

6.

Where a finding of a market surveillance authority, or a serious incident it is informed of, concerns personal data protection, that market surveillance authority shall without undue delay inform the relevant supervisory authorities under Regulation (EU) 2016/679 and cooperate with them.

7.

Manufacturers of EHR systems placed on the market or put into service shall report any serious incident involving an EHR system to the market surveillance authorities of the Member States where such serious incident occurred and of the Member States where such EHR systems are placed on the market or put into service. That reporting shall also include a description of the corrective action taken or envisaged by the manufacturer. Member States may provide for users of EHR systems placed on the market or put into service to be able to report such incidents.

The reporting required pursuant to the first subparagraph of this paragraph shall be carried out, without prejudice to incident notification requirements under Directive (EU) 2022/2555, immediately after the manufacturer has established a causal link between the EHR system and the serious incident or the reasonable likelihood of such a link and, in any event, not later than three days after the manufacturer becomes aware of the serious incident involving the EHR system.

8.

The market surveillance authorities referred to in paragraph 7 shall inform the other market surveillance authorities, without delay, of the serious incident and the corrective action taken or envisaged by the manufacturer or required of it to minimise the risk of recurrence of the serious incident.

9.

Where its tasks are not performed by the digital health authority, the market surveillance authority shall cooperate with the digital health authority. The market surveillance authority shall inform the digital health authority of any serious incidents, of EHR systems presenting a risk, including risks related to interoperability, security and patient safety, of any corrective action and of any recall or withdrawal of such EHR systems.

10.

In the event of incidents putting at risk patient safety or information security, the market surveillance authorities may take immediate action and require the manufacturer of the EHR system concerned, its authorised representative and other economic operators, if applicable, to take immediate corrective action.

Article 45
Handling of non-compliance
1.

Where a market surveillance authority makes a finding of non-compliance, it shall require the manufacturer of the EHR system concerned, its authorised representative and all other relevant economic operators to take, by a specific deadline, adequate corrective action to bring the EHR system into conformity. Such findings of non-compliance include, but are not limited to, the following:

(a) the EHR system is not in conformity with essential requirements laid down in Annex II or with the common specifications referred to in Article 36;

(b) the technical documentation is not available, not complete or not in accordance with Article 37;

(c) the EU declaration of conformity has not been drawn up or has not been drawn up correctly in accordance with Article 39;

(d) the CE marking of conformity has been affixed in breach of Article 41 or has not been affixed;

(e) the registration obligations of Article 49 have not been fulfilled.

2.

Where the manufacturer of the EHR system concerned, its authorised representative or any other relevant economic operator does not take adequate corrective action within a reasonable period, the market surveillance authorities shall take all appropriate provisional measures to prohibit or restrict the EHR system from being made available on the market of their Member States, or to recall or withdraw the EHR system from that market.

The market surveillance authorities shall inform the Commission and the other Member States’ market surveillance authorities, without delay, of those provisional measures. That information shall include all available details, in particular the data necessary for the identification of the non-compliant EHR system, the origin of that EHR system, the nature of the non-compliance alleged and the risk involved, the nature and duration of the measures taken by the market surveillance authorities and the arguments put forward by the relevant economic operator. In particular, the market surveillance authorities shall indicate whether the non-compliance is due to any of the following:

(a) failure of the EHR system to meet the essential requirements set out in Annex II;

(b) shortcomings regarding the common specifications referred to in Article 36.

3.

Market surveillance authorities other than the market surveillance authorities initiating the procedure under this Article shall inform without delay the Commission and the other Member States’ market surveillance authorities of any measures adopted, of any additional information at their disposal relating to the non-compliance of the EHR system concerned and, in the event of disagreement with the adopted national measure, of their objections.

4.

Where, within three months of receipt of the information referred to in the second subparagraph of paragraph 2, no objection has been raised by either a market surveillance authority from another Member State or the Commission in respect of a provisional measure taken by a market surveillance authority, that measure shall be deemed justified.

5.

Where the non-compliance referred to in paragraph 1 persists, the market surveillance authority concerned shall take all appropriate measures to prohibit or restrict the EHR system from being made available on the market or ensure that it is recalled or withdrawn from the market.

Article 46
Union safeguard procedure
1.

Where, under Article 44(2) and Article 45(3), objections are raised against a national measure taken by a market surveillance authority, or where the Commission considers a national measure to be contrary to Union law, the Commission shall without delay enter into consultations with that market surveillance authority and the relevant economic operators and shall evaluate the national measure concerned. On the basis of the results of that evaluation, the Commission shall adopt an implementing decision determining whether the national measure is justified. That implementing decision shall be adopted in accordance with the examination procedure referred to in Article 98(2). The Commission shall address its implementing decision to all Member States and shall immediately communicate it to them and to the relevant economic operators.

2.

If the national measure referred to in paragraph 1 is considered justified by the Commission, all Member States concerned shall take the necessary measures to ensure that the non-compliant EHR system is withdrawn from their market, and shall inform the Commission accordingly.

If the national measure referred to in paragraph 1 is considered unjustified by the Commission, the Member State concerned shall revoke that measure.

SECTION 5

Other provisions on interoperability

Article 47
Labelling of wellness applications
1.

Where a manufacturer of a wellness application claims interoperability with an EHR system in relation to the harmonised software components of EHR systems and therefore compliance with the common specifications referred to in Article 36 and essential requirements laid down in Annex II, such wellness application shall be accompanied by a label, clearly indicating its compliance with those specifications and requirements. That label shall be issued by the manufacturer of the wellness application.

2.

The label referred to in paragraph 1 shall indicate the following information:

(a) the categories of electronic health data for which compliance with essential requirements laid down in Annex II has been confirmed;

(b) a reference to common specifications to demonstrate compliance;

(c) the validity period of the label.

3.

The Commission shall, by means of implementing acts, determine the format and content of the label referred to in paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

4.

The label shall be drawn-up in one or more official languages of the Union or in an easily understandable language determined by the Member State in which the wellness application is placed on the market or put into service.

5.

The validity of the label shall not exceed three years.

6.

If the wellness application is an integral part of a device or is embedded in a device after it has been put into service, the accompanying label shall be shown in the application itself or placed on that device. Where the wellness application consists only of software, the label shall have a digital format and shall be shown in the application itself. Two-dimensional (2D) barcodes may also be used to display the label.

7.

The market surveillance authorities shall check the compliance of wellness applications with the essential requirements laid down in Annex II.

8.

Each supplier of a wellness application for which a label has been issued shall ensure that the wellness application that is placed on the market or put into service is accompanied by the label for each individual unit, free of charge.

9.

Each distributor of a wellness application for which a label has been issued shall make the label available to customers at the point of sale in electronic form.

Article 48
Interoperability of wellness applications with EHR systems
1.

Manufacturers of wellness applications may claim interoperability with an EHR system, provided that the relevant common specifications and essential requirements referred to in Article 36 and Annex II, respectively, are met. In the event of such claim, those manufacturers shall duly inform users of the interoperability of such wellness applications and the effects of such interoperability.

2.

The interoperability of wellness applications with EHR systems shall not entail the automatic sharing of all or part of the health data from the wellness application with, or automatic transmission of all or part of such data to, the EHR system. The sharing or transmission of such data shall only be possible if it is in accordance with Article 5 and after consent is given by the natural person concerned and interoperability shall be limited exclusively to those purposes. The manufacturers of wellness applications claiming interoperability with an EHR system shall ensure that the natural person concerned is able to choose which categories of health data from the wellness application are to be inserted in the EHR system and the circumstances for the sharing or transmission of those categories of data.

SECTION 6

Registration of EHR systems and wellness applications

Article 49
EU database for registration of EHR systems and wellness applications
1.

The Commission shall establish and maintain a publicly available EU database with data on EHR systems for which an EU declaration of conformity has been issued pursuant to Article 39 and wellness applications for which a label has been issued pursuant to Article 47 (the ‘EU database for registration of EHR systems and wellness applications’).

2.

Before placing on the market or putting into service an EHR system referred to in Article 26 or a wellness application referred to in Article 47, the manufacturer of such EHR system or wellness application or, where applicable, its authorised representative shall enter the required data as referred to in paragraph 4 of this Article into the EU database for registration of EHR systems and wellness applications, including, in the case of EHR systems, the results of the assessment referred to in Article 40.

3.

Medical devices, in vitro diagnostic medical devices or high-risk AI systems referred to in Article 27(1) and (2) of this Regulation shall also be registered in the databases established pursuant to Regulation (EU) 2017/745, (EU) 2017/746 or (EU) 2024/1689, as applicable. In such cases, the data to be entered shall also be forwarded to the EU database for registration of EHR systems and wellness applications.

4.

The Commission is empowered to adopt delegated acts in accordance with Article 97 to supplement this Regulation by determining the list of required data to be entered into the EU database for registration of EHR systems and wellness applications by the manufacturers of EHR systems and wellness applications pursuant to paragraph 2 of this Article.

CHAPTER IV

SECONDARY USE

SECTION 1

General conditions with regard to secondary use

Article 50
Applicability to health data holders
1.

The following categories of health data holders shall be exempt from the obligations on health data holders laid down in this Chapter:

(a) natural persons, including individual researchers;

(b) legal persons that qualify as microenterprises as defined in Article 2(3) of the Annex to Commission Recommendation 2003/361/EC.

2.

Member States may provide in their national law that the obligations of health data holders laid down in this Chapter apply to the health data holders referred to in paragraph 1 which fall under their jurisdiction.

3.

Member States may provide in their national law that the duties of certain categories of health data holders are to be fulfilled by health data intermediation entities. In that case, the data shall nevertheless be considered as being made available by several health data holders.

4.

Member States shall notify to the Commission the national law referred to in paragraphs 2 and 3 by 26 March 2029. Any subsequent law or amendment affecting such law shall be notified to the Commission without delay.

Article 51
Minimum categories of electronic health data for secondary use
1.

Health data holders shall make the following categories of electronic health data available for secondary use in accordance with this Chapter:

(a) electronic health data from EHRs;

(b) data on factors impacting on health, including socioeconomic, environmental and behavioural determinants of health;

(c) aggregated data on healthcare needs, resources allocated to healthcare, the provision of and access to healthcare, healthcare expenditure and financing;

(d) data on pathogens that impact human health;

(e) healthcare-related administrative data, including on dispensations, reimbursement claims and reimbursements;

(f) human genetic, epigenomic and genomic data;

(g) other human molecular data such as proteomic, transcriptomic, metabolomic, lipidomic and other omic data;

(h) personal electronic health data automatically generated through medical devices;

(i) data from wellness applications;

(j) data on professional status, and on the specialisation and institution of health professionals involved in the treatment of a natural person;

(k) data from population-based health data registries such as public health registries;

(l) data from medical registries and mortality registries;

(m) data from clinical trials, clinical studies, clinical investigations and performance studies subject to Regulation (EU) No 536/2014, Regulation (EU) 2024/1938 of the European Parliament and of the Council (35), Regulation (EU) 2017/745 and Regulation (EU) 2017/746;

(n) other health data from medical devices;

(o) data from registries for medicinal products and medical devices;

(p) data from research cohorts, questionnaires and surveys related to health, after the first publication of the related results;

(q) health data from biobanks and associated databases.

2.

Member States may provide in their national law that additional categories of electronic health data are to be made available for secondary use pursuant to this Regulation.

3.

Member States may establish rules for the processing and use of electronic health data containing improvements related to the processing of those data, such as correction, annotation or enrichment, based on a data permit pursuant to Article 68.

4.

Member States may introduce stricter measures and additional safeguards at national level aimed at safeguarding the sensitivity and value of the data that fall under paragraph 1, points (f), (g), (i) and (q). Member States shall notify the Commission of those measures and safeguards and, without delay, of any subsequent amendment affecting them.

Article 52
Intellectual property rights and trade secrets
1.

Electronic health data protected by intellectual property rights, trade secrets or covered by the regulatory data protection right laid down in Article 10(1) of Directive 2001/83/EC of the European Parliament and of the Council (36) or Article 14(11) of Regulation (EC) No 726/2004 of the European Parliament and of the Council (37) shall be made available for secondary use in accordance with the rules laid down in this Regulation.

2.

Health data holders shall inform the health data access body of any electronic health data containing content or information protected by intellectual property rights, trade secrets or covered by the regulatory data protection right laid down in Article 10(1) of Directive 2001/83/EC or Article 14(11) of Regulation (EC) No 726/2004. Health data holders shall identify which parts of the datasets are concerned and justify the need for the specific protection of the data. Health data holders shall provide that information when communicating to the health data access body the description of the dataset they hold pursuant to Article 60(3) of this Regulation or, at the latest, following a request received from the health data access body.

3.

Health data access bodies shall take all specific appropriate and proportionate measures, including of a legal, organisational and technical nature, they deem necessary to protect the intellectual property rights, trade secrets or the regulatory data protection right laid down in Article 10(1) of Directive 2001/83/EC or Article 14(11) of Regulation (EC) No 726/2004. Health data access bodies shall remain responsible for determining whether such measures are necessary and appropriate.

4.

When issuing data permits in accordance with Article 68, health data access bodies may make the access to certain electronic health data conditional on legal, organisational and technical measures, which may include contractual arrangements between health data holders and health data users for the sharing of data containing information or content protected by intellectual property rights or trade secrets. The Commission shall develop and recommend non-binding models of contractual terms for such arrangements.

5.

Where the granting of access to electronic health data for secondary use entails a serious risk of infringing intellectual property rights, trade secrets or the regulatory data protection right laid down in Article 10(1) of Directive 2001/83/EC or Article 14(11) of Regulation (EC) No 726/2004 which cannot be addressed in a satisfactory manner, the health data access body shall refuse access to the health data applicant to such data. The health data access body shall inform the health data applicant of, and provide to the health data applicant a justification for, that refusal. Health data holders and health data applicants shall have the right to lodge a complaint in accordance with Article 81 of this Regulation.

Article 53
Purposes for which electronic health data can be processed for secondary use
1.

Health data access bodies shall only grant access to electronic health data referred to in Article 51 for secondary use to a health data user where the processing of the data by that health data user is necessary for one of the following purposes:

(a) the public interest in the areas of public or occupational health, such as activities to protect against serious cross-border threats to health, public health surveillance or activities ensuring high levels of quality and safety of healthcare, including patient safety, and of medicinal products or medical devices;

(b) policymaking and regulatory activities to support public sector bodies or Union institutions, bodies, offices or agencies, including regulatory authorities, in the health or care sector to carry out their tasks defined in their mandates;

(c) statistics as defined in Article 3, point (1), of Regulation (EC) No 223/2009, such as national, multi-national and Union-level official statistics, related to health or care sectors;

(d) education or teaching activities in health or care sectors at vocational or higher education level;

(f) improvement of the delivery of care, of the optimisation of treatment and of the provision of healthcare, based on the electronic health data of other natural persons.

2.

Access to electronic health data for the purposes referred to in paragraph 1, points (a), (b) and (c), shall be reserved for public sector bodies and Union institutions, bodies, offices and agencies exercising the tasks conferred on them by Union or national law, including where processing of data for carrying out those tasks is done by a third party on behalf of those public sector bodies or of Union institutions, bodies, offices and agencies.

Article 54
Prohibited secondary use

Health data users shall only process electronic health data for secondary use on the basis of and in accordance with the purposes contained in a data permit issued pursuant to Article 68, health data requests approved pursuant to Article 69 or, in situations referred to in Article 67(3), an access approval from the relevant authorised participant in HealthData@EU referred to in Article 75.

In particular, seeking access to and processing electronic health data obtained via a data permit issued pursuant to Article 68 or a health data request approved pursuant to Article 69 for the following uses shall be prohibited:

(a) taking decisions detrimental to a natural person or a group of natural persons based on their electronic health data; in order to qualify as ‘decisions’ for the purposes of this point, they have to produce legal, social or economic effects or similarly significantly affect those natural persons;

(b) taking decisions in relation to a natural person or a group of natural persons in relation to job offers, offering less favourable terms in the provision of goods or services, including exclusion of such persons or groups from the benefit of an insurance or credit contract, the modification of their contributions and insurance premiums or conditions of loans, or taking any other decisions in relation to a natural person or a group of natural persons which result in discriminating against them on the basis of the health data obtained;

(c) carrying out advertising or marketing activities;

(d) developing products or services that may harm individuals, public health or society at large, such as illicit drugs, alcoholic beverages, tobacco and nicotine products, weaponry or products or services which are designed or modified in such a way that they create addiction, contravene public order or cause a risk for human health;

(e) carrying out activities in conflict with ethical provisions laid down in national law.

SECTION 2

Governance and mechanisms for secondary use

Article 55
Health data access bodies
1.

Member States shall designate one or more health data access bodies responsible for carrying out the tasks and obligations set out in Articles 57, 58 and 59. Member States may either establish one or more new public sector bodies or rely on existing public sector bodies or on internal services of public sector bodies that fulfil the conditions set out in this Article. The tasks set out in Article 57 may be distributed between different health data access bodies. Where a Member State designates several health data access bodies, it shall designate one health data access body to act as coordinator, with responsibility for coordinating tasks with the other health data access bodies both within the territory of that Member State and in other Member States.

Each health data access body shall contribute to the consistent application of this Regulation throughout the Union. For that purpose, health data access bodies shall cooperate with each other, with the Commission and, for concerns regarding data protection, with the relevant supervisory authorities.

2.

In order to support the effective performance of the tasks and the exercise of the powers of the health data access bodies, Member States shall ensure that each health data access body is provided with the following elements:

(a) the necessary human, financial and technical resources;

(b) the necessary expertise; and

(c) the necessary premises and infrastructure.

Where an assessment by ethics bodies is required under national law, those bodies shall make expertise available to the health data access body. As an alternative, Member States may provide for ethics bodies to form part of the health data access body.

3.

Member States shall ensure that any conflicts of interest between the organisational parts of health data access bodies performing the different tasks of such bodies is avoided by, for example, providing for organisational safeguards such as segregation between health data access bodies’ different functions, including assessing applications, the reception and preparation of datasets, for example pseudonymisation and anonymisation of datasets, and the provision of data in secure processing environments.

4.

In the performance of their tasks, health data access bodies shall actively cooperate with relevant stakeholders’ representatives, especially with representatives of patients, health data holders and health data users and shall avoid any conflicts of interest.

5.

In the performance of their tasks and exercise of their powers, health data access bodies shall avoid any conflicts of interest. Health data access bodies’ staff shall act in the public interest and in an independent manner.

6.

Member States shall inform the Commission of the identity of the health data access bodies designated pursuant to paragraph 1 by 26 March 2027. They shall also inform the Commission of any subsequent modification of the identity of those bodies. The Commission and the Member States shall make that information publicly available.

Article 56
Union health data access service
1.

The Commission shall perform the tasks set out in Articles 57 and 59 where the health data holders are Union institutions, bodies, offices or agencies.

2.

The Commission shall ensure that the necessary human, technical and financial resources, premises and infrastructure are allocated for the effective performance of the tasks set out in Articles 57 and 59 and the exercise of its duties.

3.

Unless otherwise explicitly excluded, references to health data access bodies in this Regulation in relation to the performance of tasks and exercise of duties shall be understood to also apply to the Commission, where the health data holders are Union institutions, bodies, offices or agencies.

Article 57
Tasks of health data access bodies
1.

Health data access bodies shall carry out the following tasks:

(b) processing electronic health data referred to in Article 51 such as by receiving, combining, preparing and compiling such data when requested from health data holders and the pseudonymisation or anonymisation of those data;

(c) taking all measures necessary to preserve the confidentiality of intellectual property rights, for regulatory data protection and to preserve the confidentiality of trade secrets as provided for in Article 52, taking into account the relevant rights of both the health data holder and health data user;

(d) cooperating with and supervising health data holders to ensure the consistent and accurate implementation of the provisions on data quality and utility label in Article 78;

(e) maintaining a management system to record and process health data access applications, health data requests, decisions on those applications and requests and the data permits issued and health data requests handled, providing at least information on the name of the health data applicant, the purpose of access, the date of issuance, the duration of the data permit and a description of the health data access application or the health data request;

(f) maintaining a public information system to comply with the obligations laid down in Article 58;

(g) cooperating at Union and national level to lay down common standards, technical requirements and appropriate measures for accessing electronic health data in a secure processing environment;

(h) cooperating at Union and national level and providing advice to the Commission on techniques and best practices for secondary use and the management of electronic health data;

(i) facilitating cross-border access to electronic health data for secondary use hosted in other Member States through HealthData@EU referred to in Article 75 and cooperating closely with each other and with the Commission;

(k) fulfilling obligations towards natural persons pursuant to Article 58;

(l) fulfilling any other tasks related to making possible the secondary use of electronic health data in the context of this Regulation.

The national dataset catalogue referred to in point (j)(i) of this paragraph shall also be made available to single information points under Article 8 of Regulation (EU) 2022/868.

2.

In the exercise of their tasks, health data access bodies shall:

(a) cooperate with supervisory authorities under Regulation (EU) 2016/679 in relation to personal electronic health data and the EHDS Board;

(b) cooperate with all relevant stakeholders, including patient organisations, representatives of natural persons, health professionals, researchers, and ethics committees, where applicable in accordance with Union or national law;

(c) cooperate with other national competent bodies, including the national competent authorities supervising data altruism organisations under Regulation (EU) 2022/868, the competent authorities under Regulation (EU) 2023/2854 and the national competent authorities under Regulations (EU) 2017/745, (EU) 2017/746 and (EU) 2024/1689, where relevant.

3.

Health data access bodies may provide assistance to public sector bodies where those public sector bodies access electronic health data in accordance with Article 14 of Regulation (EU) 2023/2854.

4.

Health data access bodies may provide support to a public sector body where it obtains data in the circumstances referred to in Article 15, point (a) or (b), of Regulation (EU) 2023/2854, in accordance with the rules laid down in that Regulation, by providing technical support to process those data or combining them with other data for joint analysis.

Article 58
Obligations of health data access bodies towards natural persons
1.

Health data access bodies shall make information on the conditions under which electronic health data are made available for secondary use publicly available, easily searchable through electronic means and accessible for natural persons. That information shall cover the following:

(a) the legal basis under which access to electronic health data is granted to the health data user;

(b) the technical and organisational measures taken to protect the rights of natural persons;

(c) the applicable rights of natural persons in relation to secondary use;

(d) the arrangements for natural persons to exercise their rights in accordance with Chapter III of Regulation (EU) 2016/679;

Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.

This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence. EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.