Skip to main content
Category: Special Category Data

Health Data

Also known as: Data Concerning Health, Healthcare Data
Simply put

Health data is personal information about a person's physical or mental health. It can include things like your medical history, diagnoses, test results, and treatment plans, and in some contexts information collected from health-related devices or apps. Because it is sensitive, it generally receives extra protection under data protection law.

Formal definition

Under the GDPR, 'data concerning health' is defined as personal data related to the physical or mental health of a natural person, and it constitutes a special category of personal data attracting heightened protection. Processing generally requires both an Article 6 lawful basis and a separate condition under Article 9, because the general prohibition on processing special category data applies unless a specific exception is met. The precise scope of what qualifies as health data can turn on context and interpretation, and member state derogations and national implementing law (including under the UK GDPR) may vary the position; readers should verify the applicable article text and current regulatory guidance, and note this definition does not extend to anonymous data falling outside the concept of personal data.

Why it matters

Health data is treated as a special category of personal data under the GDPR because it reveals intimate details about a person's physical or mental condition. Unlike ordinary personal data, its processing is subject to a general prohibition that lifts only where a specific condition applies, reflecting the heightened risk of harm, discrimination, or distress if such information is exposed or misused. For organisations, this means that handling diagnoses, test results, treatment plans, or information derived from health-related devices and apps carries additional compliance obligations that must be built into systems and governance from the outset.

The practical stakes are significant across the healthcare ecosystem and beyond. As the digitisation of healthcare data expands, with information collected from patients including diagnoses, medications, treatment plans, and test results stored digitally, and with health-related information increasingly gathered from consumer devices such as step counters, more actors touch health data than the traditional clinical setting. The scope of what qualifies as health data can turn on context and interpretation, so an organisation may find itself processing special category data without having recognised it as such, which creates compliance exposure.

Because the precise boundary of health data is context-dependent and may be shaped by member state derogations and national implementing law (including under the UK GDPR), organisations should not assume a single fixed interpretation applies. Where uncertainty exists about whether particular information constitutes data concerning health, the safer course is generally to assess against current regulatory guidance and the applicable article text rather than to rely on a narrow reading.

Who it's relevant to

Healthcare providers and clinical organisations
Hospitals, clinics, and other providers routinely process diagnoses, medications, treatment plans, and test results stored digitally. As handlers of special category data, they generally need both an Article 6 lawful basis and an Article 9 condition, and should confirm how national implementing law affects their obligations.
Data protection officers and compliance leads
Because the scope of what qualifies as health data can turn on context and interpretation, DPOs and compliance teams should assess borderline cases carefully, document the legal bases and Article 9 conditions relied upon, and monitor current regulatory guidance for developments.
Developers of health-related devices and apps
Information collected from health-related devices or apps, from daily steps to other health metrics, may in some contexts constitute data concerning health. Product and engineering teams should assess whether their processing engages special category obligations rather than assuming consumer-facing data falls outside the concept.
Organisations operating across the EU and UK
Member state derogations and national implementing law, including under the UK GDPR, may vary the position on health data processing. Multi-jurisdictional organisations should verify the applicable article text and guidance for each relevant jurisdiction rather than applying a single interpretation uniformly.

Inside Health Data

Special category data classification
Health data is treated as a special category of personal data under Article 9 of the GDPR, meaning its processing is generally prohibited unless one of the specific Article 9(2) conditions applies in addition to an Article 6 legal basis.
Data concerning health
The GDPR defines health data as personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about that person's health status.
Dual-basis requirement
Lawful processing typically requires both an Article 6 legal basis and a separate Article 9(2) condition, so identifying only one is insufficient. The applicable Article 9(2) condition should be assessed against the specific processing context.
Scope limited to identifiable individuals
Health data protections apply to personal data of identifiable living individuals. Anonymous data generally falls outside the GDPR, and the position on deceased persons' data is typically governed by member state law rather than the GDPR itself, so it can vary.
Risk-elevated processing
Because of its sensitivity, processing health data can trigger heightened obligations, and processing at scale may require a Data Protection Impact Assessment under Article 35, subject to assessment of the specific circumstances.

Common questions

Answers to the questions practitioners most commonly ask about Health Data.

Is all data collected in a health or medical context automatically 'health data'?
Not necessarily. Under the GDPR, health data is personal data relating to the physical or mental health of a natural person that reveals information about their health status. The determining factor is whether the data reveals something about a person's health, not merely the context in which it was collected. Some data gathered in a healthcare setting (for example, purely administrative or billing identifiers) may not, on its own, reveal health status. However, assessment can be fact-specific, and data may become health data when combined with other information or when inferences about health can be drawn. You should assess each data element in context rather than applying a blanket label.
Does processing health data always require the individual's explicit consent?
No. Consent is not a universal requirement. Health data is a special category of personal data, so processing requires both a legal basis under Article 6 and a separate condition under Article 9. Explicit consent is one Article 9 condition, but others exist, such as those relating to health or social care, public health, or the establishment, exercise, or defence of legal claims, among others. The availability of specific conditions can depend on member state implementing law and applicable derogations. You should identify the appropriate Article 9 condition alongside your Article 6 basis rather than defaulting to consent, and verify the position against the current text and any national requirements.
How should we document the legal basis for processing health data?
Generally, you should record both the Article 6 legal basis and the applicable Article 9 condition, and keep this within your records of processing and related documentation. Because some Article 9 conditions depend on member state law, it is prudent to note the specific national provision relied upon where relevant. This documentation typically supports your accountability obligations and should be reviewed if the processing purpose changes. Confirm the precise requirements against the current official text and any applicable national implementing law.
When might processing health data trigger a Data Protection Impact Assessment?
Processing special category data such as health data on a large scale is among the factors that typically indicate a DPIA (Article 35) may be required, particularly where processing is likely to result in a high risk to individuals. Supervisory authorities also publish lists of processing operations for which a DPIA is mandatory, and these can vary between member states. You should assess whether your processing meets the high-risk threshold and consult applicable regulator guidance, as the position is context-dependent and subject to ongoing guidance.
What should we consider before sharing health data with a third-party service provider?
First, determine whether the provider acts as a processor or as a separate or joint controller, as this affects the appropriate instrument and responsibilities. Where the provider processes on your behalf as a processor, a Data Processing Agreement under Article 28 is generally required. You should also confirm the Article 6 basis and Article 9 condition covering the disclosure, apply appropriate security measures, and, where the arrangement involves a transfer outside the relevant jurisdiction, assess whether an adequacy decision or a transfer tool with any necessary supplementary measures applies. These transfer mechanisms evolve, so verify the current position.
How do security expectations differ for health data compared with ordinary personal data?
As a special category of data, health data typically warrants heightened technical and organisational measures reflecting its sensitivity and the potential severity of harm from a breach. The GDPR requires security appropriate to the risk, and the higher risk associated with health data generally means measures such as access controls, encryption where appropriate, and strict need-to-know limitations are expected. The specific measures should follow a risk assessment rather than a fixed checklist, and expectations may be informed by regulator guidance and applicable national requirements.

Common misconceptions

Health data can always be processed with the individual's consent alone.
Consent under Article 9(2)(a) is one possible condition, but it must be explicit and it does not remove the need for an Article 6 basis. Other Article 9(2) conditions may apply instead, and consent is not a universal requirement. The appropriate condition depends on the context and should be assessed case by case.
Any data held by a healthcare provider is automatically health data.
Health data is data that reveals information about a person's health status. Administrative or contact details held by a provider are not necessarily health data, though they remain personal data. Whether a given data element qualifies as health data is context dependent.
Aggregated or de-identified health information is always outside the GDPR.
Only genuinely anonymous data generally falls outside the GDPR. Data that remains re-identifiable is typically still personal data and, where it reveals health status, may still be health data. The threshold for effective anonymisation is subject to assessment and regulator guidance.

Best practices

Before processing, identify and document both a valid Article 6 legal basis and a separate Article 9(2) condition, and record why each applies to the specific processing activity.
Assess whether the intended processing meets the threshold for a Data Protection Impact Assessment under Article 35, particularly where health data is processed at scale, and document the outcome.
Distinguish carefully between data that genuinely reveals health status and other personal data held in the same context, applying the special category safeguards only where warranted but not overlooking borderline cases.
Where relying on consent as the Article 9(2) condition, ensure it is explicit, freely given, specific, and separately obtained, and confirm an appropriate Article 6 basis is also in place.
Check for relevant member state derogations and national implementing rules, since the position on matters such as deceased persons' data and specific health processing conditions can vary.
Verify claims of anonymisation against a robust re-identification risk assessment and current regulator guidance, rather than assuming de-identified data is automatically out of scope.