The General Data Protection Regulation (GDPR) applies to all sectors, including healthcare. Even so, the healthcare sector has a special position within the GDPR. That is because health data is classified as a special category of personal data (Article 9 GDPR). As a result, stricter rules and additional safeguards apply to the processing of this data. At the same time, the GDPR remains a uniform framework: the core principles, data subject rights and security obligations are the same throughout the EU, regardless of the sector.
Stricter requirements through Article 9 GDPR
Article 9 GDPR provides that processing health data is prohibited in principle, unless a specific exception applies. For healthcare, the most important exception is that processing is necessary for providing medical care, diagnosis or treatment, provided it takes place under the responsibility of a professional bound by confidentiality. This article ensures that health data may only be processed when it is truly necessary, and always under strict safeguards.
The GDPR applies uniformly
Although health data enjoys extra protection, the GDPR as a whole is uniform. Healthcare providers are subject to the same obligations as other organisations: they have to comply with the general principles such as lawfulness, purpose limitation, data minimisation and transparency. This uniform application ensures that the protection of personal data in healthcare is in line with that in other sectors.
Added value compared with existing healthcare laws
In the Netherlands we already have sector-specific laws such as the WGBO, the Wkkgz and the Wabvpz, which contain specific rules on handling medical data. These laws provide a legal basis for many processing activities, such as keeping patient records or reporting incidents. Still, the GDPR adds important elements:
- Security requirements (Art. 32 GDPR): these apply to all processing, including the primary processing of data within the treatment relationship. Without the GDPR, such uniform security standards would be missing and healthcare institutions would have to fall back on fragmented provisions.
- Data subject rights: the GDPR strengthens existing patient rights, for example through the right to erasure, data portability and restriction of processing – rights that are not fully covered by sector-specific healthcare laws.
- Supervision and sanctions: the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) supervises compliance with the GDPR and can enforce it with fines, including for breaches in healthcare.
- Harmonisation within the EU: the GDPR ensures that the same standards apply in all member states, which matters for cross-border care and digital data exchange.
The added value of open standards
The GDPR works with open standards – such as “appropriate technical and organisational measures” or “processing in proportion to the risk”. This leaves room to give these standards a specific meaning in healthcare. Sector-specific laws, guidance from supervisory authorities and professional codes give concrete substance to these open standards, which makes the GDPR in healthcare practice not only strict but also workable.
Conclusion
The GDPR treats health data separately through Article 9, with stricter requirements and extra protection. At the same time, the GDPR remains a uniform legal framework that applies in full in healthcare too. What the GDPR adds to existing healthcare laws includes a risk-based security obligation for all data processing, stronger patient rights, effective supervision and EU-wide harmonisation. Thanks to its open standards, the GDPR can be applied flexibly in healthcare, while it considerably strengthens the protection of patient data.
In short: healthcare operates within the uniform framework of the GDPR, but benefits from the stricter requirements and the additional safeguards this law brings.