Skip to main content
Category: Special Category Data

Health Data Definition

Also known as: Data Concerning Health, Healthcare Data, Health Data
Simply put

Health data is information about a person's physical or mental health. It can include things like your medical history, diagnoses, test results, treatments, and even data from everyday sources such as fitness trackers. Because it is sensitive, this kind of information generally receives stronger protection than ordinary personal data.

Formal definition

Under the GDPR framework, data concerning health is defined as personal data related to the physical or mental health of a natural person. In practice it encompasses information collected from patients (such as diagnoses, medications, treatment plans, and test results) as well as broader health-related information, and it is treated as a special category of data under Article 9, which generally requires an additional Article 9 condition beyond a lawful basis under Article 6. The precise scope of what constitutes health data can be subject to assessment, particularly where information indirectly reveals health status, and readers should verify the current official GDPR text and applicable regulatory guidance, noting that national implementing law and member state derogations may vary the position.

Why it matters

Health data sits within the special category of data under Article 9 of the GDPR, meaning it generally attracts stronger protection than ordinary personal data. Processing it typically requires not only a lawful basis under Article 6 but also a separate condition under Article 9. For organisations in healthcare, insurance, employment, wellness, and consumer technology, correctly identifying when information qualifies as health data is a threshold question that determines which obligations apply and how much protection must be built around the data.

The stakes are heightened by the breadth of what can count as health data. It is not limited to clinical records such as diagnoses, medications, treatment plans, and test results; it can extend to health-related information drawn from everyday sources such as fitness trackers and step counters. Information that only indirectly reveals a person's health status may also fall within scope, and this boundary is subject to assessment rather than being fixed. Misclassifying such data risks applying the wrong safeguards and legal basis.

Because national implementing law and member state derogations can vary the position, and because regulatory guidance in this area continues to evolve, organisations should treat health data classification as a context-dependent exercise rather than a one-off determination. Readers should verify the current official GDPR text and applicable regulatory guidance before relying on any particular classification.

Who it's relevant to

Healthcare providers and clinical organisations
Providers that collect diagnoses, medications, treatment plans, and test results are handling data concerning health at the core of their operations. They generally need to identify both an Article 6 lawful basis and an Article 9 condition, and should assess how national implementing law affects their obligations.
Consumer technology and wellness companies
Businesses building fitness trackers, wearables, and health apps may process data that reveals physical or mental health, including everyday metrics such as step counts. Because such data can qualify as special category data, they should assess whether their processing crosses the threshold into health data and apply the appropriate safeguards.
Data protection officers and compliance leads
DPOs and compliance teams are responsible for correctly classifying information and confirming that the right legal basis and Article 9 condition are in place. Given that the scope of health data is subject to assessment, particularly for indirectly revealing data, they should document their classification reasoning and monitor evolving regulatory guidance.
Privacy lawyers advising on cross-jurisdictional processing
Because national implementing law and member state derogations can vary the position, lawyers advising organisations operating across EU member states should verify how health data is treated in each relevant jurisdiction rather than assuming a uniform standard, and check the current official text and guidance.

Inside Health Data Definition

Data concerning health
Under the GDPR, personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about that person's health status. This is a defined category of special category data under Article 9.
Special category status
Health data is treated as a special category of personal data under Article 9, meaning that in addition to identifying an Article 6 lawful basis, a controller must generally satisfy a separate Article 9(2) condition before processing.
Information revealing health status
The concept extends beyond diagnoses to information from which a health status can be derived or inferred. Where data reveals something about an individual's health, it may fall within scope even if it was not originally collected in a clinical context, subject to assessment of the specific facts.
Relationship to identifiability
The definition applies to personal data, meaning data relating to an identified or identifiable natural person. Data that has been effectively anonymised so that no individual can be identified generally falls outside the GDPR, though the threshold for anonymisation is context dependent and subject to assessment.
Overlap with related special categories
Health data can overlap with, but is distinct from, genetic data and biometric data processed for the purpose of uniquely identifying a person, which are separately enumerated within Article 9. A single dataset may implicate more than one special category.

Common questions

Answers to the questions practitioners most commonly ask about Health Data Definition.

Is health data only the information generated by doctors or medical professionals?
No. Health data is not limited to information created in a clinical setting or by healthcare professionals. It generally covers any personal data relating to the physical or mental health of a person that reveals information about their health status, regardless of source. This can include data generated outside a medical context, such as by an individual or by a device, provided it reveals something about health status. The key test is whether the data reveals information about a person's health, not who produced it. You should assess each data point against this substance-over-source approach.
Does data have to be an explicit medical diagnosis to count as health data?
Not necessarily. Data can qualify as health data even where it is not a formal diagnosis, because information that permits conclusions to be drawn about a person's health status can fall within the concept. Whether a particular data element crosses the threshold typically depends on context and on what inferences can be drawn from it, so this is subject to assessment rather than a fixed rule. Where the position is uncertain, treat the more cautious interpretation as a starting point and document your reasoning.
How should we determine whether a specific dataset we hold qualifies as health data?
Assess whether the data, in context, reveals or permits conclusions about an individual's physical or mental health status. Consider not only the raw data but the inferences that can reasonably be drawn from it, alone or in combination with other data you hold. Because this is context-dependent and can vary with the surrounding information, document the assessment for each processing activity and revisit it if the data or its use changes. Where classification is genuinely borderline, note the uncertainty and consider whether cautious handling is warranted.
If our processing involves health data, what additional legal steps apply compared with ordinary personal data?
Health data is a special category of data, so in addition to identifying a lawful basis under Article 6, you generally need to satisfy a separate condition under Article 9 before processing. These are distinct requirements and one does not substitute for the other. The available Article 9 conditions and any applicable member state derogations should be checked against the current official text, because national implementing law can vary the position. Document both the Article 6 basis and the Article 9 condition relied upon.
Does processing health data mean we automatically need a Data Protection Impact Assessment?
Processing special category data such as health data, particularly on a large scale, is one of the factors that typically points toward a higher likelihood of high risk and therefore toward carrying out a DPIA under Article 35. A DPIA is a risk assessment instrument and is separate from the Article 9 condition and the Article 6 basis, which address lawfulness. Whether a DPIA is required in a given case depends on the specifics of the processing and on applicable regulator guidance, which can differ between authorities, so assess this on a case-by-case basis.
Can we avoid the health data rules by removing identifiers from the dataset?
It depends on whether the result is genuinely anonymous or merely pseudonymised. Data protection rules, including those for health data as a special category, generally continue to apply to pseudonymised data because individuals can still be re-identified. Only where data is anonymous, such that individuals can no longer be identified, does it generally fall outside the scope of the GDPR. Whether a particular technique achieves anonymisation is a technical and context-dependent question that should be assessed and, where relevant, checked against current regulator guidance.

Common misconceptions

Only data generated by a doctor or hospital counts as health data.
The definition is not limited to clinical settings. Information from other sources, such as certain lifestyle or app-generated data, may qualify where it reveals information about an individual's health status. Whether a given dataset qualifies depends on assessment of the specific facts.
Consent is always required to process health data.
Consent is one possible condition, but Article 9 sets out several distinct conditions for processing special category data. Processing health data requires both an Article 6 lawful basis and a separate Article 9 condition, which need not be consent, and member state law may add further requirements or derogations.
Health data of a deceased person is always protected by the GDPR.
The GDPR generally applies to personal data of living individuals and does not, as a rule, govern data of deceased persons. However, national implementing law in some member states may extend protection, so the position can vary and should be verified against the applicable jurisdiction.

Best practices

Assess at the outset whether the data you process reveals anything about an individual's health status, since data collected outside a clinical context may still fall within the definition subject to assessment.
Identify and document both an Article 6 lawful basis and a distinct Article 9 condition before processing health data, and do not assume consent is the only or default option.
Check whether applicable national implementing law adds conditions, safeguards, or derogations for health data, as member state positions can diverge from the baseline GDPR text.
Evaluate whether the same dataset also engages genetic or biometric data provisions under Article 9, and treat each special category on its own terms.
Where you rely on anonymisation to take data outside scope, test the robustness of that anonymisation against re-identification risk in context rather than assuming it is permanent or absolute.
Verify article references, conditions, and jurisdictional scope against the current official GDPR text and relevant regulator guidance before relying on them in a compliance program.