Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847 (Text with EEA relevance)
(e) the identity and the contact details of the health data access body;
(f) who has been granted access to datasets of electronic health data and to which datasets they were granted access and details of the data permit regarding the purposes for processing such data as referred to in Article 53(1);
(g) the results or outcomes of the projects for which the electronic health data were used.
If a Member State has provided for the right to opt out pursuant to Article 71 to be exercised through the health data access bodies, the relevant health data access bodies shall provide public information about the procedure to opt out and facilitate the exercise of that right.
Where a health data access body is informed by a health data user of a significant finding related to the health of a natural person, as referred to in Article 61(5), the health data access body shall inform the health data holder about that finding. The health data holder shall, under the conditions laid down by national law, inform the natural person or health professional treating the natural person concerned. Natural persons shall have the right to request not to be informed of such findings.
Member States shall inform the public at large about the role and benefits of health data access bodies.
Article 59
Reporting by health data access bodies
Each health data access body shall publish an activity report every two years and make it publicly available on its website. If a Member State designates more than one health data access body, the coordinating body referred to in Article 55(1) shall be responsible for the activity report and request the necessary information from the other health data access bodies. That activity report shall follow a structure agreed by the EHDS Board pursuant to Article 94(2), point (d), and contain at least the following categories of information:
(a) information relating to the health data access applications and health data requests submitted, such as the types of health data applicants, number of data permits issued or refused, categories of purposes of access and categories of electronic health data accessed, and a summary of the results of the electronic health data uses, where applicable;
(b) information on the fulfilment of regulatory and contractual commitments by health data users and health data holders, as well as the number and amount of administrative fines imposed by health data access bodies;
(c) information on audits carried out on health data users to ensure compliance of the processing they carry out in the secure processing environment pursuant to Article 73(1), point (e);
(d) information on internal and third-party audits on compliance of secure processing environments with the defined standards, specifications and requirements, as referred to in Article 73(3);
(e) information on the handling of requests from natural persons relating to the exercise of their data protection rights;
(f) a description of the health data access body’s activities carried out in relation to engagement with and consultation of relevant stakeholders;
(g) revenues from data permits and health data requests;
(h) the average number of days between health data access applications or health data requests and access to data;
(i) the number of data quality labels issued by health data holders, disaggregated per quality category;
(j) the number of peer-reviewed research publications, policy documents and regulatory procedures using data accessed via the EHDS;
(k) the number of digital health products and services, including AI applications, developed using data accessed via the EHDS.
The activity report referred to in paragraph 1 shall be submitted to the Commission and the EHDS Board within six months of the end of the second year of the relevant reporting period. The activity report shall be accessible via the Commission’s website.
Article 60
Duties of health data holders
Health data holders shall make relevant electronic health data referred to in Article 51 available upon request to the health data access body, in accordance with a data permit issued pursuant to Article 68, or upon a health data request approved pursuant to Article 69.
Health data holders shall put the requested electronic health data referred to in paragraph 1 at the disposal of the health data access body within a reasonable time and no later than three months from the receipt of the request by the health data access body. In justified cases, the health data access body may extend that period by a maximum of three months.
The health data holder shall communicate to the health data access body a description of the dataset it holds in accordance with Article 77. The health data holder shall, at a minimum on an annual basis, check that its dataset description in the national dataset catalogue is accurate and up to date.
Where a data quality and utility label accompanies the dataset pursuant to Article 78, the health data holder shall provide sufficient documentation to the health data access body for that body to verify the accuracy of the label.
Health data holders of non-personal electronic health data shall provide access to data through trusted open databases to ensure unrestricted access for all users and data storage and preservation. Trusted open public databases shall have in place robust, transparent and sustainable governance and a transparent model of user access.
Article 61
Duties of health data users
Health data users may access and process the electronic health data referred to in Article 51 for secondary use only in accordance with a data permit issued pursuant to Article 68, a health data request approved pursuant to Article 69 or, in situations referred to in Article 67(3), an access approval from the relevant authorised participant in HealthData@EU referred to in Article 75.
When processing electronic health data within the secure processing environments referred to in Article 73, health data users shall not provide access to the electronic health data, or make those data available, to third parties not mentioned in the data permit.
Health data users shall not re-identify or attempt to re-identify the natural persons to whom the electronic health data obtained by the health data users on the basis of a data permit, a health data request or an access approval by an authorised participant in HealthData@EU relate.
Health data users shall make public the results or output of secondary use, including information relevant for the provision of healthcare, within 18 months of the completion of the processing of the electronic health data in the secure processing environment or of having received the response to the health data request referred to in Article 69.
In justified cases related to the permitted purposes of the processing of electronic health data, the period referred to in the first subparagraph may be extended by the health data access body, in particular in cases where the result is published in a scientific journal or other scientific publication.
The results or output of secondary use shall contain only anonymous data.
Health data users shall inform the health data access bodies from which a data permit was obtained about the results or output of secondary use and assist them to make that information public on health data access bodies’ websites. Such publication shall be without prejudice to publication rights in scientific journals or other scientific publications.
When health data users use electronic health data in accordance with this Chapter, they shall acknowledge the sources of the electronic health data and the fact that the electronic health data have been obtained in the framework of the EHDS.
Without prejudice to paragraph 2, health data users shall inform the health data access body of any significant finding related to the health of the natural person whose data are included in the dataset.
Health data users shall cooperate with health data access bodies in those bodies’ performance of their tasks.
Article 62
Fees
Health data access bodies, including the Union health data access service, or trusted health data holders referred to in Article 72 may charge fees for making electronic health data available for secondary use.
The fees shall be in proportion to the cost of making the data available and they shall not restrict competition.
The fees shall cover all or part of the costs related to the procedure for assessing a health data access application or a health data request, for issuing, refusing or amending a data permit pursuant to Articles 67 and 68 or for providing a response to a health data request submitted pursuant to Article 69, including costs related to the consolidation, preparation, pseudonymisation, anonymisation and provision of the electronic health data.
Member States may establish reduced fees for certain types of health data users located in the Union, such as public sector bodies or Union institutions, bodies, offices and agencies with a legal mandate in the field of public health, university researchers or microenterprises.
The fees referred to in paragraph 1 of this Article may include compensation for the costs incurred by the health data holder for compiling and preparing the electronic health data to be made available for secondary use. In such cases, the health data holder shall provide an estimate of such costs to the health data access body. Where the health data holder is a public sector body, Article 6 of Regulation (EU) 2022/868 shall not apply. The part of the fees linked to the health data holder’s costs shall be paid to the health data holder.
Any fees charged to health data users pursuant to this Article shall be transparent and non-discriminatory.
Where health data holders and health data users do not agree on the level of the fees within one month of the data permit being issued, the health data access body may set the fees in proportion to the cost of making electronic health data available for secondary use. Where health data holders or health data users disagree with the fee set by the health data access body, they shall have access to dispute settlement bodies in accordance with Article 10 of Regulation (EU) 2023/2854.
Before issuing a data permit pursuant to Article 68 or providing a response to a health data request submitted pursuant to Article 69, the health data access body shall inform the health data applicant of the estimated fees. The health data applicant shall be informed about the option to withdraw the health data access application or health data request. If the health data applicant withdraws its application or request, the health data applicant shall only be charged the costs that have already been incurred.
The Commission shall, by means of implementing acts, lay down principles for the fee policies and fee structures, including deductions for the entities referred to in paragraph 1, fourth subparagraph, of this Article in order to support consistency and transparency between Member States regarding such fee policies and fee structures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Article 63
Enforcement by health data access bodies
When carrying out their monitoring and supervisory tasks, as referred to in Article 57(1), point (a)(ii), health data access bodies shall have the right to request and receive all the necessary information from health data users and health data holders to verify compliance with this Chapter.
Where health data access bodies find that a health data user or health data holder does not comply with the requirements of this Chapter, they shall immediately notify the health data user or health data holder of those findings and take appropriate measures. The health data access body concerned shall give the health data user or health data holder concerned the opportunity to state their views within a reasonable period that shall not exceed four weeks.
Where the finding of non-compliance concerns a possible breach of Regulation (EU) 2016/679, the health data access body concerned shall immediately inform the supervisory authorities under that Regulation and provide them with all relevant information concerning that finding.
With regard to non-compliance by health data users, health data access bodies shall have the power to revoke the data permit issued pursuant to Article 68 and stop without undue delay the affected electronic health data processing operation carried out by the health data user, and shall take appropriate and proportionate measures aimed at ensuring compliant processing by the health data user.
As part of such enforcement measures, the health data access bodies may also, where appropriate, exclude, or initiate proceedings to exclude, in accordance with national law, the health data user concerned from any access to electronic health data within the EHDS in the context of secondary use for a period of up to five years.
With regard to non-compliance by health data holders, where a health data holder withholds the electronic health data from health data access bodies with the manifest intention of obstructing the use of electronic health data, or does not respect the deadlines set out in Article 60(2), the health data access body shall have the power to fine the health data holder for each day of delay with a periodic penalty payment, which shall be transparent and proportionate. The amount of the fines shall be established by the health data access body in accordance with national law. In the event of repeated breaches by the health data holder of the obligation of cooperation with the health data access body, that body may exclude or initiate proceedings to exclude, in accordance with national law, the health data holder concerned from submitting health data access applications pursuant to this Chapter for a period of up to five years. During the period of that exclusion, the health data holder shall remain obliged to make data accessible under this Chapter, where applicable.
The health data access body shall communicate the enforcement measures taken pursuant to paragraphs 3 and 4, and the reasons on which they are based, to the health data user or health data holder concerned, without delay, and shall lay down a reasonable period for the health data user or health data holder to comply with those measures.
Any enforcement measures taken by the health data access body pursuant to paragraph 3 shall be notified to other health data access bodies through the IT tool referred to in paragraph 7. Health data access bodies may make that information publicly available on their websites.
The Commission shall, by means of implementing acts, set out the architecture of an IT tool, as part of the infrastructure of HealthData@EU referred to in Article 75, aimed at supporting and making transparent to other health data access bodies the enforcement measures referred to in this Article, especially periodic penalty payments, the revoking of data permits and exclusions. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
The Commission shall issue guidelines, by 26 March 2032, in close cooperation with the EHDS Board, on enforcement measures including periodic penalty payments and other measures to be taken by the health data access bodies.
Article 64
General conditions for the imposition of administrative fines by health data access bodies
Each health data access body shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements referred to in paragraphs 4 and 5 is effective, proportionate and dissuasive in each individual case.
Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, enforcement measures referred to in Article 63(3) and (4). Health data access bodies shall decide whether to impose an administrative fine and the amount of the administrative fine in each individual case by giving due regard to the following circumstances:
(a) the nature, gravity and duration of the infringement;
(b) whether any penalties or administrative fines have already been imposed by other competent authorities for the same infringement;
(c) the intentional or negligent character of the infringement;
(d) any action taken by the health data holder or health data user to mitigate the damage caused;
(e) the degree of responsibility of the health data user, taking into account technical and organisational measures implemented by that health data user pursuant to Article 67(2), point (g), and Article 67(4);
(f) any relevant previous infringements by the health data holder or health data user;
(g) the degree of cooperation of the health data holder or health data user with the health data access body as regards remedying the infringement and mitigating its possible adverse effects;
(h) the manner in which the health data access body became aware of the infringement, in particular whether, and to what extent, the health data user notified it of the infringement;
(i) compliance with any enforcement measures referred to in Article 63(3) and (4) which have been ordered previously against the controller or processor concerned with regard to the same subject matter;
(j) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained or losses avoided, directly or indirectly, through the infringement.
If a health data holder or a health data user intentionally or negligently infringes several provisions of this Regulation for the same or a linked data permit or health data request, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement.
In accordance with paragraph 2 of this Article, infringements of the duties of the health data holder or health data user pursuant to Article 60 and Article 61(1), (5) and (6) shall be subject to administrative fines of a maximum of EUR 10 000 000 or, in the case of an undertaking, of a maximum of 2 % of its total worldwide annual turnover in the preceding financial year, whichever is higher.
In accordance with paragraph 2, the following infringements shall be subject to administrative fines of a maximum of EUR 20 000 000 or, in the case of an undertaking, of a maximum of 4 % of its total worldwide annual turnover in the preceding financial year, whichever is higher:
(a) health data users processing electronic health data obtained via a data permit issued pursuant to Article 68 for the uses referred to in Article 54;
(b) health data users extracting personal electronic health data from secure processing environments;
(c) re-identifying or attempting to re-identify the natural persons to whom the electronic health data obtained by the health data users on the basis of a data permit or a health data request pursuant to Article 61(3) relate;
(d) non-compliance with enforcement measures taken by the health data access body pursuant to Article 63(3) and (4).
Without prejudice to the powers of health data access bodies pursuant to Article 63, each Member State may lay down rules on whether and to what extent administrative fines may be imposed on public authorities and public sector bodies established in that Member State.
The exercise by a health data access body of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and national law, including effective judicial remedies and due process.
Where the legal system of a Member State does not provide for administrative fines, this Article may be applied in a manner that, in accordance with its national legal framework, ensures that those legal remedies are effective and have an equivalent effect to the administrative fines imposed by health data access bodies. In any event, the fines imposed shall be effective, proportionate and dissuasive. The Member State concerned shall notify the Commission of the provisions of the laws which it adopts pursuant to this paragraph by 26 March 2029 and, without delay, of any subsequent law amending such provisions or amendments affecting such provisions.
Article 65
Relationship with supervisory authorities under Regulation (EU) 2016/679
The supervisory authority or authorities responsible for monitoring and enforcing the application of Regulation (EU) 2016/679 shall also be competent for monitoring and enforcing the application of the right to opt out from the processing of personal electronic health data for secondary use pursuant to Article 71. Those supervisory authorities shall be empowered to impose administrative fines up to the amount referred to in Article 83 of Regulation (EU) 2016/679.
The supervisory authorities referred to in the first paragraph of this Article and the health data access bodies referred to in Article 55 of this Regulation shall, where relevant, cooperate in the enforcement of this Regulation, within the remit of their respective competences. The relevant provisions of Regulation (EU) 2016/679 shall apply mutatis mutandis.
SECTION 3
Access to electronic health data for secondary use
Article 66
Data minimisation and purpose limitation
Where health data access bodies receive a health data access application, they shall ensure that access is only provided to electronic health data that are adequate, relevant and limited to what is necessary in relation to the purpose of processing indicated in the health data access application by the health data user and in line with the data permit issued pursuant to Article 68.
Health data access bodies shall provide electronic health data in an anonymised format, where the purpose of processing by the health data user can be achieved with such data, taking into account the information provided by the health data user.
Where the health data user has sufficiently demonstrated that the purpose of processing cannot be achieved with anonymised data in accordance with Article 68(1), point (c), health data access bodies shall provide access to electronic health data in pseudonymised format. The information necessary to reverse the pseudonymisation shall be available only to the health data access body or an entity that acts as a trusted third party in accordance with national law.
Article 67
Health data access applications
A natural or legal person may submit a health data access application for the purposes referred to in Article 53(1) to a health data access body.
The health data access application shall include:
(a) the health data applicant’s identity, a description of that health data applicant’s professional functions and activities, including the identity of the natural persons who would have access to the electronic health data if a data permit were issued; the health data applicant shall notify the health data access body of any update of the list of natural persons;
(b) the purposes referred to in Article 53(1) for which access to data is applied for;
(c) a detailed explanation of the intended use of the electronic health data and expected benefit related to that use and how that benefit would contribute to the purposes referred to in Article 53(1);
(d) a description of the requested electronic health data, including their scope, time range, format, sources and, where possible, the geographical coverage where such data are requested from health data holders in several Member States or from authorised participants in HealthData@EU referred to in Article 75;
(e) a description explaining whether the electronic health data need to be made available in a pseudonymised or anonymised format; in the case of a pseudonymised format, a justification as to why the processing cannot be carried out using anonymised data;
(f) where the health data applicant intends to bring datasets already held by that health data applicant into the secure processing environment, a description of those datasets;
(g) a description of the safeguards, which are to be proportionate to the risks, planned to prevent any misuse of the electronic health data, as well as to protect the rights and interests of the health data holder and of the natural persons concerned, including to prevent any re-identification of natural persons in the dataset;
(h) a justified indication of the period during which the electronic health data are needed for processing in a secure processing environment;
(i) a description of the tools and computing resources needed for a secure processing environment;
(j) where applicable, information on any assessment of ethical aspects of the processing, required under national law, which may serve to replace the health data applicant’s own ethics assessment;
(k) where the health data applicant intends to make use of an exception under Article 71(4), the justification required by national law pursuant to that Article.
When seeking access to electronic health data held by health data holders established in more than one Member State or from the relevant authorised participants in HealthData@EU referred to in Article 75, the health data applicant shall submit a single health data access application through the health data access body of the Member State where the main establishment of the health data applicant is located, through the health data access body of the Member State in which one of those health data holders is established or through the services provided by the Commission in HealthData@EU referred to in Article 75. The health data access application shall be automatically forwarded to the relevant authorised participants in HealthData@EU and to the health data access bodies of the Member States where the health data holders identified in the health data access application are established.
When seeking access to the personal electronic health data in a pseudonymised format, the health data applicant shall provide, together with the health data access application, a description of how the processing would comply with applicable Union and national law on data protection and privacy, in particular with Regulation (EU) 2016/679 and, more specifically, with Article 6(1) thereof.
Public sector bodies and Union institutions, bodies, offices and agencies shall provide the same information as required under paragraphs 2 and 4, except for paragraph 2, point (h), in which case they shall submit instead information concerning the period for which the electronic health data can be accessed, the frequency of that access or the frequency of the data updates.
Article 68
Data permit
For the purposes of granting access to electronic health data, the health data access bodies shall assess whether all the following criteria are fulfilled:
(a) the purposes described in the health data access application correspond to one or more of the purposes listed in Article 53(1);
(b) the requested data are necessary, adequate and proportionate for the purposes described in the health data access application, taking into account data minimisation and purpose limitation requirements provided for in Article 66;
(c) the processing complies with Article 6(1) of Regulation (EU) 2016/679 and, in the case of pseudonymised data, there is sufficient justification that the purpose cannot be achieved with anonymised data;
(d) the health data applicant is qualified in relation to the intended purposes of data use and has appropriate expertise, including professional qualifications in the areas of healthcare, care, public health or research, consistent with ethical practice and applicable laws and regulations;
(e) the health data applicant demonstrates sufficient technical and organisational measures to prevent the misuse of the electronic health data and to protect the rights and interests of the health data holder and of the natural persons concerned;
(f) the information on the assessment of ethical aspects of the processing, referred to in Article 67(2), point (j), where applicable, complies with national law;
(g) where the health data applicant intends to make use of an exception under Article 71(4), the justification required by national law adopted pursuant to that Article has been provided;
(h) all other requirements in this Chapter are fulfilled by the health data applicant.
The health data access body shall also take into account the following:
(a) risks for national defence, security, public security and public order;
(b) the risk of undermining the confidentiality of data in governmental databases of regulatory authorities.
Where the health data access body concludes that the requirements in paragraph 1 are fulfilled and the risks referred to in paragraph 2 are sufficiently mitigated, the health data access body shall grant access to electronic health data by issuing a data permit. Health data access bodies shall refuse all health data access applications where the requirements in this Chapter are not fulfilled.
Where the requirements for issuing a data permit are not met, but the requirements to provide a response in an anonymised statistical format under Article 69 are, the health data access body may decide to provide such response, on condition that providing that response would mitigate the risks and, if the purpose of the health data access application can be fulfilled in this manner, that the health data applicant agrees to receiving a response in an anonymised statistical format under Article 69.
By way of derogation from Regulation (EU) 2022/868, the health data access body shall issue or refuse a data permit within three months of receiving a complete health data access application. If the health data access body finds that the health data access application is incomplete, it shall notify the health data applicant, which shall be given the possibility of completing that application. If the health data applicant does not complete the health data access application within four weeks, the data permit shall not be issued.
The health data access body may extend the period for responding to a health data access application by three additional months where necessary, taking into account the urgency and complexity of the health data access application and the volume of health data access applications submitted for decision. In such cases, the health data access body shall notify the health data applicant as soon as possible that more time is needed for examining the health data access application, together with the reasons for the delay.
When handling a health data access application for cross-border access to electronic health data referred to in Article 67(3), health data access bodies and relevant authorised participants in HealthData@EU referred to in Article 75 shall remain responsible for adopting decisions to grant or refuse access to electronic health data within their remit in accordance with this Chapter.
The health data access bodies and authorised participants in HealthData@EU concerned shall inform each other of their decisions. They may take that information into consideration when deciding on granting or refusing access to electronic health data.
A data permit issued by one health data access body may benefit from mutual recognition by the other health data access bodies.
Member States shall provide for an accelerated health data access application procedure for public sector bodies and Union institutions, bodies, offices and agencies with a legal mandate in the field of public health if the processing of electronic health data is to be carried out for the purposes established in Article 53(1), points (a), (b) and (c).
When such accelerated procedure applies, the health data access body shall issue or refuse a data permit within two months of receiving a complete health data access application. The health data access body may extend the period for responding to a health data access application by one additional month where necessary.
Following the issuance of the data permit, the health data access body shall immediately request the electronic health data from the health data holder. The health data access body shall make available the electronic health data to the health data user within two months of receiving them from the health data holders, unless the health data access body specifies that the data are to be provided within a longer specified timeframe.
In cases referred to in paragraph 5, first subparagraph, of this Article, the health data access bodies and authorised participants in HealthData@EU which issued a data permit or access approval, respectively, may decide to provide access to the electronic health data in the secure processing environment provided by the Commission as referred to in Article 75(9).
Where the health data access body refuses to issue a data permit, it shall provide a justification for that refusal to the health data applicant.
When issuing a data permit, the health data access body shall set out in that data permit the general conditions applicable to the health data user. The data permit shall contain the following:
(a) the categories, specification and format of the electronic health data to be accessed, which are covered by the data permit, including their sources and an indication of whether the electronic health data are to be accessed in a pseudonymised format in the secure processing environment;
(b) a detailed description of the purpose for which the electronic health data are made available;
(c) where a mechanism to implement an exception is provided for and applicable under Article 71(4), information on whether it has been applied and the reason for the related decision;
(d) the identity of authorised persons, in particular the identity of the principal investigator, with access rights to the electronic health data in the secure processing environment;
(e) the duration of the data permit;
(f) information about the technical characteristics and tools available to the health data user within the secure processing environment;
(g) the fees to be paid by the health data user;
(h) any specific conditions.
Health data users shall have the right to access and process the electronic health data in a secure processing environment in accordance with the data permit issued to them on the basis of this Regulation.
A data permit shall be issued for the duration necessary to fulfil the requested purposes and that duration shall not exceed 10 years. That duration may be extended once, for a period which does not exceed 10 years, at the request of the health data user, based on arguments and documents to justify that extension which shall be provided one month before the expiry of the data permit. The health data access body may charge fees which increase to reflect the costs and risks of storing electronic health data for a period exceeding the initial period. In order to reduce such costs and fees, the health data access body may also propose to the health data user to store the dataset in a storage system with reduced capabilities. Such reduced capabilities shall not affect the security of the processed dataset. The electronic health data within the secure processing environment shall be deleted within six months of the expiry of the data permit. At the request of the health data user, the formula for the creation of the requested dataset may be stored by the health data access body.
If the data permit needs to be updated, the health data user shall submit a request for an amendment of the data permit.
The Commission may, by means of an implementing act, develop a logo for acknowledging the contribution of the EHDS. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Article 69
Health data request
The health data applicant may submit a health data request for the purposes referred to in Article 53 with the aim of obtaining a response only in an anonymised statistical format. A health data access body shall not provide a response to a health data request in any other format and the health data user shall have no access to the electronic health data used to provide that response.
A health data request as referred to in paragraph 1 shall include the following information:
(a) the identity of the health data applicant and a description of that health data applicant’s professional functions and activities;
(b) a detailed explanation of the intended use of the electronic health data, including the purposes referred to in Article 53(1) for which the health data request is submitted;
(c) a description of the requested electronic health data, their format and the sources of those data, where possible;
(d) a description of the statistical content;
(e) a description of the safeguards planned to prevent any misuse of the requested electronic health data;
(f) a description of how the processing would comply with Article 6(1) of Regulation (EU) 2016/679 or Article 5(1) and Article 10(2) of Regulation (EU) 2018/1725;
(g) where the health data applicant intends to make use of an exception under Article 71(4), the justification required in that regard by national law pursuant to that Article.
The health data access body shall assess if the health data request is complete and take into account the risks referred to in Article 68(2).
The health data access body shall assess the health data request within three months of receipt of the request and, where possible, subsequently provide the response to the health data user within a further three months.
Article 70
Templates to support access to electronic health data for secondary use
By 26 March 2027, the Commission shall, by means of implementing acts, set out the templates for the health data access application, the data permit and the health data request referred to in Articles 67, 68 and 69, respectively. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Article 71
Right to opt out from the processing of personal electronic health data for secondary use
Natural persons shall have the right to opt out at any time, and without providing any reason, from the processing of personal electronic health data relating to them for secondary use under this Regulation. The exercise of that right shall be reversible.
Member States shall provide for an accessible and easily understandable opt-out mechanism to exercise the right established in paragraph 1, whereby natural persons may explicitly state that they do not wish to have their personal electronic health data processed for secondary use.
Once natural persons have exercised the right to opt out, and where personal electronic health data relating to them can be identified in a dataset, personal electronic health data relating to those natural persons shall not be made available or otherwise processed pursuant to data permits issued under Article 68 or health data requests under Article 69 approved after the natural person has exercised the right to opt out.
The first subparagraph of this paragraph shall not affect the processing for secondary use of personal electronic health data relating to those natural persons pursuant to data permits or health data requests that were issued or approved before the natural persons exercised their right to opt out.
By way of exception from the right to opt out provided for in paragraph 1, a Member State may provide in its national law for a mechanism to make data for which a right to opt out has been exercised available, provided that all the following conditions are fulfilled:
(b) those data cannot be obtained by alternative means in a timely and effective manner under equivalent conditions;
(c) the health data applicant has provided the justification referred to in Article 68(1), point (g), or in Article 69(2), point (g).
The national law providing for such a mechanism shall provide for specific and suitable measures in order to protect the fundamental rights and the personal data of natural persons.
Where a Member State has provided in its national law for the possibility to request access to data for which a right to opt out has been exercised and the conditions referred to in the first subparagraph of this paragraph are fulfilled, those data may be included when carrying out the tasks under Article 57(1), points (a)(i), (a)(iii) and (b).
The rules on any mechanism to implement exceptions provided for under paragraph 4 by way of exception from paragraph 1 shall respect the essence of the fundamental rights and freedoms and shall be a necessary and proportionate measure in a democratic society to fulfil purposes of public interest in the area of legitimate scientific and societal objectives.
Any processing carried out in accordance with a mechanism to implement exceptions provided for under paragraph 4 of this Article shall comply with the requirements of this Chapter, in particular the prohibition on re-identifying or attempting to re-identify natural persons in accordance with Article 61(3). Any legislative measure providing for a mechanism in national law as referred to in paragraph 4 of this Article shall include specific provisions for the safety, and the protection of the rights, of natural persons.
Member States shall notify without delay the Commission of the provisions of their national law which they adopt pursuant to paragraph 4 and of any subsequent amendment affecting them.
When the purposes of the processing of personal electronic health data by a health data holder do not or no longer require the identification of a data subject by the controller, that health data holder shall not be obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with the right to opt out under this Article.
Article 72
Simplified procedure for access to electronic health data from a trusted health data holder
Where a health data access body receives a health data access application pursuant to Article 67 or a health data request pursuant to Article 69 that only covers electronic health data held by a trusted health data holder designated in accordance with paragraph 2 of this Article, the procedure set out in paragraphs 4 to 6 of this Article shall apply.
Member States may establish a procedure whereby health data holders can apply to be designated as trusted health data holders, provided the health data holders meet the following conditions:
(a) they are able to provide access to health data through a secure processing environment that complies with Article 73;
(b) they have the necessary expertise to assess health data access applications and health data requests;
(c) they provide the necessary guarantees to ensure compliance with this Regulation.
Member States shall designate trusted health data holders following an assessment of the fulfilment of those conditions by the relevant health data access body.
Member States shall establish a procedure to regularly review whether the trusted health data holder continues to fulfil those conditions.
Health data access bodies shall indicate the trusted health data holders in the dataset catalogue referred to in Article 77.
Health data access applications and health data requests referred to in paragraph 1 shall be submitted to the health data access body, which may forward them to the relevant trusted health data holder.
Following receipt of a health data access application or health data request pursuant to paragraph 3 of this Article, the trusted health data holder shall assess the health data access application or health data request against the criteria listed in Article 68(1) and (2) or Article 69(2) and (3), as applicable.
The trusted health data holder shall submit the assessment it carries out pursuant to paragraph 4, accompanied by a proposal for decision, to the health data access body within two months of receipt of the health data access application or health data request from the health data access body. Within two months of receipt of the assessment, the health data access body shall issue a decision on the health data access application or health data request. The health data access body shall not be bound by the proposal submitted by the trusted health data holder.
Following the health data access body’s decision to issue the data permit or to approve the health data request, the trusted health data holder shall carry out the tasks referred to in Article 57(1), points (a)(i) and (b).
The Union health data access service referred to in Article 56 may designate health data holders that are Union institutions, bodies, offices or agencies which comply with the conditions laid down in paragraph 2, first subparagraph, points (a), (b) and (c), of this Article as trusted health data holders. Where it does so, paragraph 2, third and fourth subparagraphs, and paragraphs 3 to 6 of this Article shall apply mutatis mutandis.
Article 73
Secure processing environment
Health data access bodies shall provide access to electronic health data pursuant to a data permit only through a secure processing environment which is subject to technical and organisational measures and security and interoperability requirements. In particular, the secure processing environment shall comply with the following security measures:
(a) the restriction of access to the secure processing environment to authorised natural persons listed in the data permit issued pursuant to Article 68;
(b) the minimisation of the risk of the unauthorised reading, copying, modification or removal of electronic health data hosted in the secure processing environment through state-of-the-art technical and organisational measures;
(c) the limitation of the input of electronic health data and the inspection, modification or deletion of electronic health data hosted in the secure processing environment to a limited number of authorised identifiable individuals;
(d) ensuring that health data users have access only to the electronic health data covered by their data permit, by means of individual and unique user identities and confidential access modes only;
(e) the keeping of identifiable logs of access to and activities in the secure processing environment for the period necessary to verify and audit all processing operations in that environment; logs of access shall be kept for at least one year;
(f) ensuring compliance and monitoring the security measures referred to in this paragraph to mitigate potential security threats.
Health data access bodies shall ensure that electronic health data from health data holders in the format specified in the data permit can be uploaded by those health data holders and can be accessed by the health data user in a secure processing environment.
Health data access bodies shall review the electronic health data included in a download request to ensure that health data users are only able to download non-personal electronic health data, including electronic health data in an anonymised statistical format, from the secure processing environment.
Health data access bodies shall ensure that audits of the secure processing environments are carried out on a regular basis, including by third parties, and shall take corrective action for any shortcomings, risks or vulnerabilities identified by those audits in the secure processing environments.
Where recognised data altruism organisations under Chapter IV of Regulation (EU) 2022/868 process personal electronic health data using a secure processing environment, those environments shall also comply with the security measures set out in paragraph 1, points (a) to (f), of this Article.
By 26 March 2027, the Commission shall, by means of implementing acts, lay down the technical, organisational, information security, confidentiality, data protection and interoperability requirements for the secure processing environments, including with regard to the technical characteristics and tools available to the health data user within the secure processing environments. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Article 74
Controllership
The health data holder shall be deemed controller for the making available of personal electronic health data requested pursuant to Article 60(1) to the health data access body.
The health data access body shall be deemed controller for the processing of the personal electronic health data when fulfilling its tasks pursuant to this Regulation.
Notwithstanding the second subparagraph of this paragraph, the health data access body shall be deemed to act as a processor on behalf of the health data user acting as a controller for the processing of the personal electronic health data pursuant to a data permit issued under Article 68 in the secure processing environment when providing data through such environment or for the processing of such data pursuant to a health data request approved under Article 69 for a response to be generated.
In situations referred to in Article 72(6), the trusted health data holder shall be deemed controller for its processing of personal electronic health data related to the provision of electronic health data to the health data user pursuant to a data permit or a health data request. The trusted health data holder shall be deemed to act as a processor on behalf of the health data user when providing data through a secure processing environment.
The Commission may, by means of implementing acts, establish a template for agreements between controllers and processors under paragraphs (1) and (2) of this Article. Those implementing acts shall be adopted in accordance with the examination procedure set out in Article 98(2).
SECTION 4
Cross-border infrastructure for secondary use
Article 75
HealthData@EU
Each Member State shall designate one national contact point for secondary use. That national contact point for secondary use shall be an organisational and technical gateway, enabling and responsible for the making available of electronic health data for secondary use in a cross-border context. The national contact point for secondary use may be the coordinator health data access body referred to in Article 55(1). Each Member State shall inform the Commission of the name and contact details of the national contact point for secondary use by 26 March 2027. The Commission and the Member States shall make that information publicly available.
The Union health data access service shall act as the contact point of the Union’s institutions, bodies, offices and agencies for secondary use and shall be responsible for making electronic health data available for secondary use.
The national contact points for secondary use referred to in paragraph 1 and the Union health data access service referred to in paragraph 2 shall connect to the cross-border infrastructure for secondary use, namely HealthData@EU. The national contact points for secondary use and the Union health data access service shall facilitate the cross-border access to electronic health data for secondary use for different authorised participants in HealthData@EU. The national contact points for secondary use shall cooperate closely with each other and with the Commission.
Health-related research infrastructures or similar infrastructures whose functioning is based on Union law and which provide support for the use of electronic health data for research, policymaking, statistical, patient safety or regulatory purposes may become authorised participants in HealthData@EU and connect to it.
Third countries or international organisations may become authorised participants in HealthData@EU where they comply with the rules of this Chapter and provide access to health data users located in the Union, on equivalent terms and conditions, to the electronic health data available to their health data access bodies, subject to compliance with Chapter V of Regulation (EU) 2016/679.
The Commission may, by means of implementing acts, determine that a national contact point for secondary use of a third country or a system established at international level by an international organisation is compliant with the requirements of HealthData@EU for the purposes of secondary use of health data, is compliant with this Chapter and provides access to health data users located in the Union to the electronic health data it has access to on terms and conditions equivalent to those of HealthData@EU. Compliance with those legal, organisational, technical and security requirements, including with the requirements for secure processing environments provided for in Article 73, shall be checked under the control of the Commission. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2). The Commission shall make the list of implementing acts adopted pursuant to this paragraph publicly available.
Each national contact point for secondary use and each authorised participant in HealthData@EU shall acquire the required technical capability to connect to and participate in HealthData@EU. They shall comply with the requirements and technical specifications needed to operate HealthData@EU and to allow them to connect to it.
The Member States and the Commission shall set up HealthData@EU to support and facilitate the cross-border access to electronic health data for secondary use, connecting the national contact points for secondary use and authorised participants in HealthData@EU and the central platform referred to in paragraph 8.
The Commission shall develop, deploy and operate a central platform for HealthData@EU by providing information technology services needed to support and facilitate the exchange of information between health data access bodies as part of HealthData@EU. The Commission shall only process electronic health data on behalf of the controllers as a processor.
Where requested by two or more national contact points for secondary use, the Commission may provide a secure processing environment which is compliant with the requirements of Article 73 for data from more than one Member State. Where two or more national contact points for secondary use or authorised participants in HealthData@EU put electronic health data in the secure processing environment managed by the Commission, they shall be joint controllers and the Commission shall be processor for the purpose of processing data in that environment.
The national contact points for secondary use shall act as joint controllers of the processing operations carried out in HealthData@EU in which they are involved and the Commission shall act as processor on behalf of those national contact points for secondary use, without affecting the tasks of health data access bodies prior to and following those processing operations.
Member States and the Commission shall seek to ensure that HealthData@EU is interoperable with other relevant common European data spaces as referred to in Regulations (EU) 2022/868 and (EU) 2023/2854.
By 26 March 2027, the Commission shall, by means of implementing acts, set out:
(a) requirements, technical specifications and the IT architecture of HealthData@EU, which shall ensure state-of-the-art data security, confidentiality, and protection of electronic health data in HealthData@EU;
(b) conditions and compliance checks required to be able to join and remain connected to HealthData@EU and conditions for temporary disconnection or definitive exclusion from HealthData@EU, including specific provisions for cases of serious misconduct or repeated infringements;
(c) the minimum criteria that need to be met by the national contact points for secondary use and the authorised participants in HealthData@EU;
(d) the responsibilities of the controllers and processors participating in HealthData@EU;
(e) the responsibilities of the controllers and processors for the secure processing environment managed by the Commission;
(f) common specifications for the architecture of HealthData@EU and for its interoperability with other common European data spaces.
The implementing acts referred to in the first subparagraph of this paragraph shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Where there is a positive outcome of the compliance check referred to in paragraph 5 of this Article, the Commission may, by means of implementing acts, take decisions to connect individual authorised participants to HealthData@EU. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Article 76
Access to cross-border registries or databases of electronic health data for secondary use
In the case of cross-border registries and databases, the health data access body with which the health data holder for the specific registry or database is registered shall be competent to decide on health data access applications to provide access to electronic health data pursuant to a data permit. Where such registries or databases have joint controllers, the health data access body that decides on the health data access applications to be used to provide access to electronic health data shall be the health data access body of the Member State where one of the joint controllers is established.
Where registries or databases from a number of Member States organise themselves into a single network of registries or databases at Union level, the associated registries or databases may designate a coordinator to ensure the provision of data from the registries’ or databases’ network for secondary use. The health data access body of the Member State in which the coordinator of the network is established shall be competent to decide on the health data access applications to be used to provide access to electronic health data for the network of registries or databases.
SECTION 5
Health data quality and utility for secondary use
Article 77
Dataset description and dataset catalogue
Health data access bodies shall, through a publicly available and standardised machine-readable dataset catalogue, provide a description in the form of metadata of the available datasets and their characteristics. The description of each dataset shall include information concerning the source, scope, main characteristics, and nature of the electronic health data in the dataset and the conditions for making those data available.
The dataset descriptions in the national dataset catalogue shall be available in at least one official language of the Union. The dataset catalogue for Union institutions, bodies, offices and agencies provided by the Union health data access service shall be available in all official languages of the Union.
The dataset catalogue shall be made available to single information points established or designated under Article 8 of Regulation (EU) 2022/868.
By 26 March 2027, the Commission shall, by means of implementing acts, set out the minimum elements health data holders are to provide for datasets and the characteristics of those elements. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Article 78
Data quality and utility label
Datasets made available through health data access bodies may have a Union data quality and utility label applied by the health data holders.
Datasets with electronic health data collected and processed with the support of Union or national public funding shall have a data quality and utility label covering the elements set out in paragraph 3.
The data quality and utility label shall cover the following elements, where applicable:
(a) for data documentation: metadata, support documentation, the data dictionary, the format and standards used, the source of the data and, where applicable, the data model;
(b) for assessment of technical quality: the completeness, uniqueness, accuracy, validity, timeliness and consistency of the data;
(c) for data quality management processes: the level of maturity of the data quality management processes, including review and audit processes, and bias examination;
(d) for assessment of coverage: the period, population coverage and, where applicable, representativity of the population sampled, and the average timeframe in which a natural person appears in a dataset;
(e) for information on access and provision: the time between the collection of the electronic health data and their addition to the dataset and the time needed to provide electronic health data following the issuing of a data permit or a health data request approval;
(f) for information on data modifications: merging and adding data to an existing dataset, including links with other datasets.
Where a health data access body has reason to believe that a data quality and utility label might be inaccurate, it shall assess whether the dataset covered by the label meets the quality requirements forming part of the elements of the data quality and utility label as referred to in paragraph 3 and, in the event the dataset does not meet the quality requirements, shall revoke the label.
The Commission is empowered to adopt delegated acts in accordance with Article 97 to amend this Regulation by modifying, adding or removing elements to be covered by the data quality and utility label provided for in paragraph 3 of this Article.
By 26 March 2027, the Commission shall, by means of implementing acts, set out the visual characteristics and technical specifications of the data quality and utility label, based on the elements referred to in paragraph 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2) of this Regulation. Those implementing acts shall take into account the requirements in Article 10 of Regulation (EU) 2024/1689 and any adopted common specifications or harmonised standards supporting those requirements, where applicable.
Article 79
EU dataset catalogue
The Commission shall establish an EU dataset catalogue connecting the national dataset catalogues established by the health data access bodies in each Member State as well as the dataset catalogues of authorised participants in HealthData@EU.
The EU dataset catalogue, the national dataset catalogues and the dataset catalogues of authorised participants in HealthData@EU shall be made publicly available.
Article 80
Minimum specifications for datasets of high impact
The Commission may, by means of implementing acts, determine the minimum specifications for datasets of high impact for secondary use, taking into account existing Union infrastructures, standards, guidelines and recommendations. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
SECTION 6
Complaints
Article 81
Right to lodge a complaint with a health data access body
Without prejudice to any other administrative or judicial remedy, natural and legal persons shall have the right to lodge a complaint in relation to the provisions laid down in this Chapter, individually or, where relevant, collectively, with a health data access body, provided that their rights or interests are negatively affected.
The health data access body with which the complaint has been lodged shall inform the complainant of the progress made in dealing with the complaint and of the decision taken on the complaint.
Health data access bodies shall provide easily accessible tools for the submission of complaints.
Where the complaint concerns the rights of natural persons pursuant to Article 71 of this Regulation, the complaint shall be transmitted to the competent supervisory authority under Regulation (EU) 2016/679. The relevant health data access body shall provide the necessary information at its disposal to that supervisory authority under Regulation (EU) 2016/679 in order to facilitate the assessment and investigation of the complaint.
CHAPTER V
ADDITIONAL ACTIONS
Article 82
Capacity building
The Commission shall support the sharing of best practices and expertise to build capacity within Member States to strengthen digital health systems for primary use and secondary use taking into account the specific circumstances of the different categories of stakeholders involved. To support that capacity building, the Commission shall in close cooperation and consultation with Member States establish indicators for self-assessment for primary use and secondary use.
Article 83
Training programmes and information for health professionals
Member States shall develop and implement or provide access to training programmes and provide access to information for health professionals in order for them to understand and effectively carry out their role in the primary use of and in the accessing of electronic health data, including in relation to Articles 11, 13 and 16. The Commission shall support Member States in that regard.
The training programmes and information shall be accessible to and affordable for all health professionals, without prejudice to the organisation of healthcare systems at national level.
Article 84
Digital health literacy and digital health access
Member States shall promote and support digital health literacy and the development of relevant competences and skills for patients. The Commission shall support Member States in this regard. Awareness-raising campaigns or programmes shall aim, in particular, to inform patients and the public at large about primary use and secondary use in the framework of the EHDS, including the rights arising from it, as well as the advantages, risks and potential gains for science and society of primary use and secondary use.
The awareness-raising campaigns and programmes referred to in paragraph 1 shall be tailored to the needs of specific groups and shall be developed, reviewed and, where necessary, updated.
Member States shall promote access to the infrastructure necessary for the effective management of natural persons’ electronic health data, both for primary use and secondary use.
Article 85
Additional requirements for public procurement and Union funding
Contracting authorities, including digital health authorities and health data access bodies and Union institutions, bodies, offices or agencies, shall make reference to the applicable technical specifications, standards and profiles as referred to in Articles 15, 23, 36, 73, 75 and 78 for public procurement procedures and when formulating their tender documents or calls for proposals, as well as when defining the conditions for Union funding regarding this Regulation, including enabling conditions for the structural and cohesion funds.
The criteria for obtaining funding from the Union shall take into account the requirements developed in the framework of Chapters II, III and IV.
Article 86
Storage of personal electronic health data for primary use
In accordance with the general principles of Union law, which include the fundamental rights enshrined in Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, Member States shall ensure that a particularly high level of protection and security is in place when processing personal electronic health data for primary use, by means of appropriate technical and organisational measures. In this respect, this Regulation shall not preclude a requirement under national law, taking into account the national context, that, in cases where personal electronic health data are processed by healthcare providers for the provision of healthcare or by the national contact points for digital health connected to MyHealth@EU, the storage of personal electronic health data referred to in Article 14 of this Regulation for the purpose of primary use be located within the Union, in compliance with Union law and international commitments.
Article 87
Storage of personal electronic health data by health data access bodies and secure processing environments
Health data access bodies, trusted health data holders and the Union health data access service shall store and process personal electronic health data in the Union when performing pseudonymisation, anonymisation and any other personal data processing operations referred to in Articles 67 to 72, through secure processing environments within the meaning of Article 73 and Article 75(9) or through HealthData@EU. That requirement shall apply to any entity performing those tasks on behalf of such bodies, holders or service.
By way of exception from paragraph 1 of this Article, the data referred to in that paragraph may be stored and processed in a third country, or a territory or one or more specified sectors within that third country, where such country, territory or sector is covered by an adequacy decision adopted pursuant to Article 45 of Regulation (EU) 2016/679.
Article 88
Third-country transfer of non-personal electronic data
Non-personal electronic health data made available by health data access bodies to a health data user in a third country under a data permit issued pursuant to Article 68 of this Regulation or a health data request approved pursuant to Article 69 of this Regulation, to authorised participants in a third country or to an international organisation, and based on a natural person’s electronic health data falling within one of the categories referred to in Article 51 of this Regulation, shall be deemed highly sensitive within the meaning of Article 5(13) of Regulation (EU) 2022/868 where the transfer of such non-personal electronic data to third countries presents a risk of re-identification through means going beyond those reasonably likely to be used, in particular in view of the limited number of natural persons to whom those data relate, the fact that they are geographically scattered or the technological developments expected in the near future.
The protective measures for the categories of data mentioned in paragraph 1 of this Article shall be detailed in a delegated act referred to in Article 5(13) of Regulation (EU) 2022/868.
Article 89
International governmental access to non-personal electronic health data
Digital health authorities, health data access bodies, authorised participants in the cross-border infrastructures provided for in Articles 23 and 75 and health data users shall take all reasonable technical, legal and organisational measures, including contractual arrangements, in order to prevent the transfer of non-personal electronic health data held in the Union to a third country or an international organisation, including for governmental access in a third country, where such transfer would create a conflict with Union law or the national law of the relevant Member State.
Any judgment of a third-country court or tribunal and any decision of a third-country administrative authority requiring a digital health authority, health data access body or health data users to transfer or give access to non-personal electronic health data within the scope of this Regulation held in the Union shall be recognised or enforceable in any manner only if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union, or any such agreement between the requesting third country and a Member State.
In the absence of an international agreement as referred to in paragraph 2, where a digital health authority, a health data access body or a health data user is the addressee of a decision or judgment of a third-country court or tribunal or of a decision of a third-country administrative authority requiring them to transfer or to give access to non-personal data within the scope of this Regulation held in the Union, and compliance with such a decision or judgment would risk putting the addressee in conflict with Union law or with the national law of the relevant Member State, the transfer to, or accessing of such data by, that third-country court, tribunal or administrative authority shall only take place or be provided where:
(a) the third-country legal system requires the reasons and proportionality of such a decision or judgment to be set out and requires such a decision or judgment to be specific in character, for instance by establishing a sufficient link to certain suspected persons or infringements;
(b) the reasoned objection of the addressee is subject to a review by a competent third-country court or tribunal; and
(c) the competent third-country court or tribunal issuing the decision or judgment or reviewing the decision of an administrative authority is empowered by the national law of the third country to take duly into account the relevant legal interests of the provider of the data protected under Union law or the national law of the relevant Member State.
If the conditions laid down in paragraph 2 or 3 are met, a digital health authority, a health data access body or a data altruism organisation shall provide the minimum amount of data permissible in response to a request, based on a reasonable interpretation of the request.
The digital health authorities, health data access bodies and health data users shall inform the health data holder about the existence of a request of a third-country administrative authority to access its data before complying with that request, except where the request serves law enforcement purposes and for as long as compliance is necessary to preserve the effectiveness of the law enforcement activity.
Article 90
Additional conditions for transfer of personal electronic health data to a third country or an international organisation
Transfer of personal electronic health data to a third country or an international organisation shall be granted in accordance with Chapter V of Regulation (EU) 2016/679. Member States may maintain or introduce further conditions on international access to, and transfer of, personal electronic health data, including limitations, in accordance with Article 9(4) of Regulation (EU) 2016/679, in addition to the requirements laid down in Article 24(3) and Article 75(5) of this Regulation and in Chapter V of Regulation (EU) 2016/679.
Article 91
Health data access applications and health data requests from third countries
Without prejudice to Articles 67, 68 and 69, health data access applications and health data requests submitted by a health data applicant established in a third country shall be considered eligible by health data access bodies and the Union health data access service if the third country concerned:
(a) is an authorised participant on the basis of having a national contact point for secondary use covered by an implementing act referred to in Article 75(5); or
(b) allows Union health data applicants access to electronic health data in that third country under conditions that are not more restrictive than those provided for in this Regulation, and therefore such access is covered by an implementing act referred to in paragraph 2 of this Article.
By means of implementing acts, the Commission may determine that a third country meets the requirement set out in paragraph 1, point (b), of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2). The Commission shall make the list of implementing acts adopted pursuant to this paragraph publicly available.
The Commission shall monitor developments in third countries and international organisations that could affect the application of the implementing acts adopted pursuant to paragraph 2, and shall provide for a periodic review of the application of this Article.
Where the Commission considers that a third country no longer meets the requirement laid down in paragraph 1, point (b), of this Article, it shall adopt an implementing act repealing the implementing act referred to in paragraph 2 of this Article relating to that third country that benefits from access. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).
CHAPTER VI
EUROPEAN GOVERNANCE AND COORDINATION
Article 92
European Health Data Space Board
A European Health Data Space Board (the ‘EHDS Board’) is hereby established to facilitate cooperation and the exchange of information among Member States and the Commission. The EHDS Board shall be composed of two representatives per Member State, namely one representative for primary use purposes and one for secondary use purposes, nominated by each Member State. Each Member State shall have one vote. Members of the EHDS Board shall undertake to act in the public interest and in an independent manner.
A representative of the Commission and one of the representatives of the Member States referred to in paragraph 1 shall co-chair the meetings of the EHDS Board.
Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.
This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence.
EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.