Health Data
Health data is personal information about a person's physical or mental health. It can include things like your medical history, diagnoses, test results, and treatment plans, and in some contexts information collected from health-related devices or apps. Because it is sensitive, it generally receives extra protection under data protection law.
Under the GDPR, 'data concerning health' is defined as personal data related to the physical or mental health of a natural person, and it constitutes a special category of personal data attracting heightened protection. Processing generally requires both an Article 6 lawful basis and a separate condition under Article 9, because the general prohibition on processing special category data applies unless a specific exception is met. The precise scope of what qualifies as health data can turn on context and interpretation, and member state derogations and national implementing law (including under the UK GDPR) may vary the position; readers should verify the applicable article text and current regulatory guidance, and note this definition does not extend to anonymous data falling outside the concept of personal data.
Why it matters
Health data is treated as a special category of personal data under the GDPR because it reveals intimate details about a person's physical or mental condition. Unlike ordinary personal data, its processing is subject to a general prohibition that lifts only where a specific condition applies, reflecting the heightened risk of harm, discrimination, or distress if such information is exposed or misused. For organisations, this means that handling diagnoses, test results, treatment plans, or information derived from health-related devices and apps carries additional compliance obligations that must be built into systems and governance from the outset.
The practical stakes are significant across the healthcare ecosystem and beyond. As the digitisation of healthcare data expands, with information collected from patients including diagnoses, medications, treatment plans, and test results stored digitally, and with health-related information increasingly gathered from consumer devices such as step counters, more actors touch health data than the traditional clinical setting. The scope of what qualifies as health data can turn on context and interpretation, so an organisation may find itself processing special category data without having recognised it as such, which creates compliance exposure.
Because the precise boundary of health data is context-dependent and may be shaped by member state derogations and national implementing law (including under the UK GDPR), organisations should not assume a single fixed interpretation applies. Where uncertainty exists about whether particular information constitutes data concerning health, the safer course is generally to assess against current regulatory guidance and the applicable article text rather than to rely on a narrow reading.
Who it's relevant to
Inside Health Data
Common questions
Answers to the questions practitioners most commonly ask about Health Data.