Skip to main content
Category: Special Category Data

Data Concerning Health

Also known as: Health Data
Simply put

Data concerning health is personal information about a person's physical or mental health, including the health care services they receive. This can cover a wide range of information, such as details about allergies, smoking or drinking habits, or membership of a patient support group, where these reveal something about the person's health status. Because it is sensitive, it generally receives extra protection under data protection law.

Formal definition

Data concerning health means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about that person's health status. According to Recital 35 (a non-binding interpretive recital), this should include all data pertaining to a data subject's health status revealing information about their past, current, or future health. It falls within the special categories of personal data, meaning that in addition to identifying an Article 6 legal basis, a controller must generally satisfy a separate Article 9 condition before processing. The scope can extend to information that indirectly reveals health status (for example, lifestyle habits, allergies, or support group membership), and its boundaries are subject to context and to regulator and court interpretation; readers should verify article references and current guidance against the official text, and note the position may differ under national implementing law and derogations.

Why it matters

Data concerning health is classified as a special category of personal data, which means it generally attracts a higher level of protection than ordinary personal data. Where an organisation processes health data, identifying an Article 6 legal basis is not sufficient on its own; a separate Article 9 condition must generally also be satisfied. This dual requirement significantly narrows the circumstances in which such data may lawfully be processed, and getting the classification wrong can leave an organisation without a valid basis for processing at all.

The practical difficulty is that the category is broader than many organisations expect. Beyond obvious clinical records, information such as smoking or drinking habits, allergy data, or membership of a patient support group may amount to data concerning health where it reveals something about a person's health status. This means data that appears innocuous, or that was collected for another purpose, can fall within the special category regime once its capacity to reveal health status is recognised. Employers, wellness programmes, and service providers can therefore find themselves handling health data without having designed their processing to meet the heightened Article 9 requirements.

The boundaries of the concept remain context-dependent and subject to interpretation by regulators and courts, and the position may differ under national implementing law and derogations. Because of this uncertainty, organisations should assess whether particular data reveals health status in the specific context rather than relying on fixed lists, and should verify article references and current guidance against the official text.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams must identify where health data arises across their organisation, including in contexts where data reveals health status only indirectly. They are responsible for ensuring that both an Article 6 legal basis and an appropriate Article 9 condition are documented before processing, and for accounting for context-dependent classification and any variation under national implementing law.
Employers and HR Functions
Organisations handling worker information may process health data through sickness records, occupational health, workplace wellness initiatives, or details such as allergies. As guidance on workers' health information indicates, this data generally requires additional protection, so HR functions should assess whether the information they hold reveals health status and whether the heightened conditions for special category data are met.
Healthcare Providers and Digital Health Services
Providers of health care services process health data as a core part of their activity, including data revealing a person's past, current, or future health status. They should ensure processing operations are designed around the special category regime and reassess classification as regulator and court interpretation of the category's boundaries develops.
Privacy Counsel and Legal Advisers
Lawyers advising on data protection need to determine whether particular datasets fall within data concerning health, given that the category can extend to lifestyle habits or group membership that reveal health status. Because the boundaries are subject to interpretation and may differ under national derogations, counsel should verify article references and current guidance against the official text before advising.

Inside Data Concerning Health

Statutory definition
Under the GDPR, data concerning health is defined as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about that person's health status. It is treated as a special category of personal data under Article 9.
Scope of health status information
Encompasses information that reveals a data subject's past, current, or future physical or mental health condition. This can include data derived from testing or examination of a body part or bodily substance, and information about disease, disability, disease risk, medical history, clinical treatment, or physiological or biomedical state, independent of its source.
Special category status and additional condition
Because health data is a special category under Article 9, processing generally requires both a lawful basis under Article 6 and a separate Article 9 condition (for example, explicit consent, or a health or social care condition). Consent is only one of several possible conditions and is not always the applicable route.
Contextual and inferred data
Data may qualify as health data not only when it is explicitly medical but also where it reveals health status through inference or combination with other information. Whether a given data point amounts to health data can be context-dependent and subject to assessment.
Relationship to related categories
Health data sits alongside, but is distinct from, genetic data and biometric data used for unique identification, which are separately defined special categories. A single data set may implicate more than one category.

Common questions

Answers to the questions practitioners most commonly ask about Data Concerning Health.

Does data concerning health only cover formal medical records from healthcare providers?
No. Data concerning health is not limited to clinical or medical records generated by healthcare providers. It generally covers any personal data related to the physical or mental health of an individual, including the provision of health care services, that reveals information about their health status. This can include data that indirectly reveals a health condition, and the source of the data does not determine whether it qualifies. The boundary lies in whether the data reveals something about health status; the exact classification of borderline data can be subject to assessment and may vary with regulatory guidance.
Is data concerning health always subject to a strict consent requirement before it can be processed?
Not necessarily. Consent is one condition, but data concerning health falls within the special categories under Article 9, which generally prohibits processing unless one of the Article 9 conditions applies. Consent is only one of those conditions; others may include, for example, purposes relating to health or social care, or reasons of public interest in the area of public health, subject to conditions and member state law. In addition, a separate Article 6 lawful basis is typically also required. Treating consent as the universal requirement is a common misconception, and the availability of specific conditions can depend on national implementing law.
How should an organisation identify data concerning health within its existing datasets?
Organisations generally map their processing activities and review data fields to identify anything that reveals an individual's physical or mental health status, including data that reveals health indirectly through inference. This exercise typically forms part of a broader data mapping or record of processing exercise. Because some data reveals health only in context or by inference, classification often requires case-by-case assessment rather than a fixed field list, and organisations should document their reasoning.
What additional safeguards typically apply when processing data concerning health?
Because health data is a special category under Article 9, processing generally attracts heightened scrutiny. Organisations typically need to identify both an Article 6 lawful basis and an Article 9 condition, and may need to consider whether a Data Protection Impact Assessment under Article 35 is required, particularly for large-scale processing of special category data. Appropriate technical and organisational measures, and any specific safeguards required by member state law, should be assessed in context, as requirements can vary by jurisdiction.
Does processing health data trigger a requirement to carry out a Data Protection Impact Assessment?
Not automatically in every case, but processing of special category data such as health data on a large scale is among the situations that commonly indicate a DPIA under Article 35 may be required. Whether a DPIA is needed depends on an assessment of whether the processing is likely to result in a high risk to the rights and freedoms of individuals. Supervisory authorities may publish lists of processing operations that require a DPIA, and these can vary between member states, so organisations should check the applicable guidance.
How should health data be handled when transferred to a processor or across borders?
Where a processor handles health data on behalf of a controller, a Data Processing Agreement under Article 28 is generally required, setting out the processor's obligations. For transfers outside the EEA, an appropriate transfer mechanism is typically needed, such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules, and supplementary measures may need to be considered depending on the circumstances. Because transfer tools, adequacy decisions, and expectations around supplementary measures evolve, organisations should verify the current position against official sources rather than rely on a snapshot.

Common misconceptions

Health data can only be processed with the individual's consent.
Consent (explicit consent for special category data) is one of several Article 9 conditions. Other conditions, such as those relating to the provision of health or social care, may apply. The appropriate condition depends on the context, and a lawful basis under Article 6 is also generally required.
Only records created by doctors or health care providers count as health data.
Health data is defined by what the information reveals about a person's health status, not solely by its source. Data from other contexts, including inferences drawn from non-medical information, may qualify as health data depending on the circumstances.
Health data, genetic data, and biometric data are interchangeable terms.
These are distinct special categories with separate definitions under the GDPR. A data set may fall into more than one category, but each should be identified and handled according to its own definition and applicable conditions.

Best practices

Assess on a case-by-case basis whether a given data point reveals health status, including through inference or combination, rather than relying solely on whether the source is a medical provider.
Identify and document both an Article 6 lawful basis and a separate Article 9 condition before processing health data, and do not assume consent is the only or default condition.
Where more than one special category may be engaged, distinguish health data from genetic and biometric data and apply the correct definition and conditions to each.
Record the reasoning for classification and condition selection so the position can be demonstrated and revisited if the processing context changes.
Verify the current statutory text and applicable national or UK GDPR implementing provisions, as member state derogations can vary the position for health data.
Treat borderline or inferred cases as requiring documented assessment, and revisit classifications where regulatory guidance or context evolves.