GDPR Article 9 governance for European health data
Asteron turns the legal and operational requirements around special-category health data into defined decisions, accountable workflows and maintainable evidence. We connect processing purposes, controller and processor roles, Article 6 and Article 9 positions, DPIAs, suppliers, product changes, individual rights and incident response. The service is built for healthtech companies operating in the Netherlands, Germany and the wider European market.
- Article 6 and Article 9 positions mapped
- Controller and processor roles clarified
- DPIA and privacy-by-design workflows established
- Health-data decisions converted into evidence
Health-data governance from €7,900
What counts as health data under the GDPR?
Health data includes personal information that reveals something about a person’s past, present or future physical or mental health. It can originate from a healthcare professional, hospital, medical device, diagnostic test, digital-health product or the individual.
The category is broader than a medical record. Symptoms, diagnoses, prescriptions, test results and treatment information clearly qualify, but so may device measurements, risk scores, inferred conditions, mental-health information and data generated by remote monitoring.
Information can become health data through its context or use. A measurement that appears ordinary in isolation may reveal a health condition when combined with identity, behaviour or clinical interpretation.
Pseudonymised health data generally remains personal data when the information can be linked back to an individual using additional information. Only data that is genuinely anonymous and cannot reasonably be re-identified falls outside the GDPR.
Health data is defined by what the information reveals, not simply by the database, product label or organisation holding it.
Article 9 is only one part of the legal test
Article 9 begins with a general prohibition on processing special-category data, including health, genetic and certain biometric data. Processing is permitted only when an applicable Article 9 condition can be demonstrated.
For controllers, that condition normally works alongside a lawful basis under Article 6. An Article 9 condition does not replace Article 6, and an Article 6 basis does not remove the additional protection required for health data.
Processors usually do not independently select the controller’s legal basis. They must nevertheless understand the permitted purpose, follow documented instructions, apply appropriate safeguards and support the controller’s compliance obligations.
Asteron structures these decisions and turns the approved position into operating controls. Formal legal conclusions remain with the organisation’s DPO or qualified legal counsel.
Common Article 9 routes in healthtech
Explicit consent
Explicit consent may support certain voluntary processing, but it must be specific, informed, demonstrable and capable of being withdrawn. It is not automatically appropriate where there is an imbalance of power, where service delivery cannot realistically continue after withdrawal or where another legal route is required.
Health or social care
Article 9 may permit processing necessary for medical diagnosis, treatment, preventive or occupational medicine, or management of health and social-care systems. This route depends on EU or Member State law or a qualifying professional relationship and may require professional secrecy.
Public health
Processing may be permitted for defined public-health purposes, such as serious cross-border health threats or ensuring the safety and quality of healthcare and medical products. The supporting law and safeguards must be identified.
Scientific research and statistics
Research may rely on Article 9 where the relevant EU or national-law conditions and Article 89 safeguards are met. Research purpose, lawful access, minimisation, pseudonymisation, transparency and governance still require explicit decisions.
Substantial public interest
Some processing may be based on substantial public interest established in EU or Member State law. A commercial benefit or generally useful product is not, by itself, sufficient.
The correct route depends on the organisation’s role, purpose, data subjects, care relationship and applicable national law. A single Article 9 label should not be copied across unrelated product functions.
Where healthtech governance commonly breaks down
Product and data decisions
- – Product claims do not match the documented processing purpose.
- – Data collected for care is reused for analytics, AI or research without a separate assessment.
- – “Consent” is used as a generic label without a valid withdrawal model.
- – Pseudonymised data is incorrectly treated as anonymous.
- – DPIAs are completed after product decisions have already been made.
- – Retention is inherited from technical defaults rather than defined need.
Contracts and operations
- – Controller and processor roles conflict across contracts and actual behaviour.
- – Sub-processors receive data beyond the documented scope.
- – Hospital questionnaires, privacy notices and internal records describe different data flows.
- – Cross-border transfers are assessed once and not revisited.
- – Rights requests cannot be traced through suppliers and backups.
- – Security and privacy incident workflows do not share escalation criteria.
The objective is not to produce more privacy documents. It is to make the product, contracts, technical architecture and operational evidence describe the same processing reality.
From data flow to operating governance
Processing and role baseline
Identify products, processing activities, purposes, health-data categories, data subjects, systems, recipients and countries. Confirm controller, joint-controller and processor roles.
Article 6 and Article 9 decision map
Connect each material purpose to the approved legal position, national-law dependencies, transparency requirements and required safeguards.
Risk and DPIA assessment
Identify processing likely to create high risk, including large-scale health data, vulnerable individuals, innovative technology, profiling, automated decisions and combined datasets. Establish the DPIA and prior-consultation route.
Product and supplier controls
Translate approved decisions into privacy by design, data minimisation, access, retention, deletion, supplier, transfer and change-management controls.
Rights and incident operations
Establish workflows for access, correction, deletion, restriction, objection, portability and automated-decision questions. Connect privacy breaches with security incident response and regulatory escalation.
Review and evidence
Assign owners, retain decision evidence, review changes and report unresolved risks to management. Health-data governance must remain current as products, suppliers and markets change.
What Asteron delivers
The exact scope depends on the number of products, roles, processing purposes and target jurisdictions. Individual legal opinions, large portfolios of DPIAs and technical implementation work are included only when expressly stated in the proposal.
Governance foundation
- – Health-data processing and role map
- – Article 6 and Article 9 decision structure
- – National-requirement register
- – Health-data governance policy
- – Privacy responsibility and escalation model
- – DPIA screening and assessment workflow
- – Privacy-by-design checkpoints
- – Management reporting and review cadence
Operational evidence
- – Processing-record structure
- – Purpose and minimisation decisions
- – Supplier and sub-processor controls
- – International-transfer workflow
- – Rights-request operating process
- – Retention and deletion decisions
- – Privacy-incident assessment workflow
- – Prioritised remediation plan
Netherlands, Germany and cross-border health data
GDPR provides a European baseline, but Article 9 expressly allows Member States to introduce additional conditions for genetic, biometric and health data.
For the Netherlands, healthtech companies may also need to account for the Dutch GDPR Implementation Act, medical-treatment and confidentiality rules, Autoriteit Persoonsgegevens guidance and care-sector requirements such as NEN 7510 where applicable.
For Germany, the Federal Data Protection Act, state legislation, professional secrecy, healthcare and social-data rules may create additional requirements. The relevant supervisory authority may also depend on the organisation’s establishment and processing context.
A company serving both markets should maintain one controlled European processing model with traceable national extensions. Separate country documents should not contradict the product architecture, contracts or central processing record.
Related regulatory frameworks
Health-data governance from €7,900
The starting scope covers the operational governance of special-category health data. It typically includes the role and processing baseline, Article 6 and Article 9 decision structure, priority risk assessment, core workflows and an implementation roadmap.
- – number of products and processing purposes;
- – controller, processor and joint-controller complexity;
- – number of countries and legal entities;
- – existing records, DPIAs and privacy controls;
- – supplier and transfer complexity;
- – research, AI or secondary-use requirements.
This is a readiness and governance project, not a certification.
For fixed-scope engagements, commercial milestones are confirmed in the proposal. The standard structure is:
- – 40% at signing
- – 40% at the agreed implementation-ready milestone
- – 20% after the contracted governance outcome is delivered
Prices exclude VAT where applicable.
External legal work and implementation boundaries
Asteron builds the operational governance model, connects approved decisions to controls and prepares the supporting evidence. Asteron does not issue a GDPR certificate and does not present operational readiness as a formal legal opinion.
Where a binding interpretation of Article 9, Dutch or German law, research rules, professional secrecy or another jurisdiction-specific requirement is needed, the client appoints qualified legal counsel or a specialist adviser. Their fees are quoted and paid separately unless expressly included in the proposal.
Changes requiring production access—such as consent implementation, access-control changes, deletion logic, logging, data segregation or infrastructure migration—remain with the client’s product and engineering teams unless separately scoped.
Responsibilities
Asteron
- – Maps processing, privacy roles and governance gaps
- – Structures Article 6 and Article 9 decision evidence
- – Builds the agreed operational workflows
- – Connects privacy with security and product governance
- – Assigns actions and prepares management evidence
- – Coordinates external specialists where required
Your organisation
- – Determines purposes and means where acting as controller
- – Provides accurate information about products, data and suppliers
- – Approves legal bases and Article 9 conditions with DPO or legal input
- – Assigns accountable business and product owners
- – Implements required technical and contractual changes
- – Operates and reviews the governance model after delivery
Frequently asked questions
What is GDPR Article 9?
Article 9 regulates processing of special categories of personal data, including health, genetic and certain biometric data. Processing is generally prohibited unless a defined condition applies.
Do we need both Article 6 and Article 9?
Controllers processing health data generally need an Article 6 lawful basis and a separate Article 9 condition. These answer different legal questions.
Is consent always required for health data?
No. Explicit consent is one possible Article 9 condition, but healthcare, public health, research and other processing may depend on different legal routes and safeguards.
Are wellness and wearable data health data?
They may be. The assessment depends on what the information reveals, how it is used and whether it is linked or linkable to an individual.
Is pseudonymised health data still covered by GDPR?
Usually yes. Pseudonymisation reduces risk but the information remains personal data when re-identification is possible using additional information.
Does a processor need its own Article 9 condition?
The controller normally determines the purpose and legal basis. A processor must operate within documented instructions, meet its own GDPR obligations and understand the permitted scope.
When is a DPIA required?
A DPIA is required when processing is likely to create high risk for individuals. Large-scale health data, vulnerable people, profiling, automated decisions, monitoring and innovative technology are common indicators.
Can health data be reused for research or AI development?
Possibly, but reuse requires a separate assessment of purpose, role, legal basis, Article 9 condition, transparency, safeguards and applicable national law. The original collection does not create unlimited reuse rights.
Does ISO 27701 solve Article 9 compliance?
No. ISO 27701 provides a management system for operating privacy responsibilities. It does not select or validate the legal basis for an individual processing activity.
Is this a GDPR certification?
No. The service creates operational governance and readiness evidence. It does not issue a GDPR certificate or guarantee a regulator’s legal interpretation.
How much does the project cost?
GDPR Article 9 Health-Data Governance starts from €7,900. Final scope depends on the number of products, roles, jurisdictions, suppliers and high-risk processing activities.
Official references
- – Regulation (EU) 2016/679, particularly Articles 4, 5, 6, 9, 25, 28, 30, 32, 35 and 44–49
- – European Data Protection Board guidance for controllers and processors
- – European Data Protection Board guidance on data protection by design and DPIAs
- – Autoriteit Persoonsgegevens health-data guidance
- – German federal and state data-protection authorities
- – European Commission information on the European Health Data Space
Last reviewed: July 2026
Asteron is not endorsed by or partnered with the European Commission, the European Data Protection Board, any supervisory authority or certification body.
Related services and frameworks
Turn health-data decisions into controls your team can operate
We will assess your processing purposes, privacy roles, Article 9 positions, suppliers and target markets, then define a practical health-data governance plan.
