AsteronAsteron

    GDPR Article 9 governance for European health data

    Asteron turns the legal and operational requirements around special-category health data into defined decisions, accountable workflows and maintainable evidence. We connect processing purposes, controller and processor roles, Article 6 and Article 9 positions, DPIAs, suppliers, product changes, individual rights and incident response. The service is built for healthtech companies operating in the Netherlands, Germany and the wider European market.

    View health-data pricing
    • Article 6 and Article 9 positions mapped
    • Controller and processor roles clarified
    • DPIA and privacy-by-design workflows established
    • Health-data decisions converted into evidence

    Health-data governance from €7,900

    What counts as health data under the GDPR?

    Health data includes personal information that reveals something about a person’s past, present or future physical or mental health. It can originate from a healthcare professional, hospital, medical device, diagnostic test, digital-health product or the individual.

    The category is broader than a medical record. Symptoms, diagnoses, prescriptions, test results and treatment information clearly qualify, but so may device measurements, risk scores, inferred conditions, mental-health information and data generated by remote monitoring.

    Information can become health data through its context or use. A measurement that appears ordinary in isolation may reveal a health condition when combined with identity, behaviour or clinical interpretation.

    Pseudonymised health data generally remains personal data when the information can be linked back to an individual using additional information. Only data that is genuinely anonymous and cannot reasonably be re-identified falls outside the GDPR.

    Health data is defined by what the information reveals, not simply by the database, product label or organisation holding it.

    Common Article 9 routes in healthtech

    Explicit consent

    Explicit consent may support certain voluntary processing, but it must be specific, informed, demonstrable and capable of being withdrawn. It is not automatically appropriate where there is an imbalance of power, where service delivery cannot realistically continue after withdrawal or where another legal route is required.

    Health or social care

    Article 9 may permit processing necessary for medical diagnosis, treatment, preventive or occupational medicine, or management of health and social-care systems. This route depends on EU or Member State law or a qualifying professional relationship and may require professional secrecy.

    Public health

    Processing may be permitted for defined public-health purposes, such as serious cross-border health threats or ensuring the safety and quality of healthcare and medical products. The supporting law and safeguards must be identified.

    Scientific research and statistics

    Research may rely on Article 9 where the relevant EU or national-law conditions and Article 89 safeguards are met. Research purpose, lawful access, minimisation, pseudonymisation, transparency and governance still require explicit decisions.

    Substantial public interest

    Some processing may be based on substantial public interest established in EU or Member State law. A commercial benefit or generally useful product is not, by itself, sufficient.

    The correct route depends on the organisation’s role, purpose, data subjects, care relationship and applicable national law. A single Article 9 label should not be copied across unrelated product functions.

    Where healthtech governance commonly breaks down

    Product and data decisions

    • Product claims do not match the documented processing purpose.
    • Data collected for care is reused for analytics, AI or research without a separate assessment.
    • “Consent” is used as a generic label without a valid withdrawal model.
    • Pseudonymised data is incorrectly treated as anonymous.
    • DPIAs are completed after product decisions have already been made.
    • Retention is inherited from technical defaults rather than defined need.

    Contracts and operations

    • Controller and processor roles conflict across contracts and actual behaviour.
    • Sub-processors receive data beyond the documented scope.
    • Hospital questionnaires, privacy notices and internal records describe different data flows.
    • Cross-border transfers are assessed once and not revisited.
    • Rights requests cannot be traced through suppliers and backups.
    • Security and privacy incident workflows do not share escalation criteria.

    The objective is not to produce more privacy documents. It is to make the product, contracts, technical architecture and operational evidence describe the same processing reality.

    From data flow to operating governance

    1. Processing and role baseline

      Identify products, processing activities, purposes, health-data categories, data subjects, systems, recipients and countries. Confirm controller, joint-controller and processor roles.

    2. Article 6 and Article 9 decision map

      Connect each material purpose to the approved legal position, national-law dependencies, transparency requirements and required safeguards.

    3. Risk and DPIA assessment

      Identify processing likely to create high risk, including large-scale health data, vulnerable individuals, innovative technology, profiling, automated decisions and combined datasets. Establish the DPIA and prior-consultation route.

    4. Product and supplier controls

      Translate approved decisions into privacy by design, data minimisation, access, retention, deletion, supplier, transfer and change-management controls.

    5. Rights and incident operations

      Establish workflows for access, correction, deletion, restriction, objection, portability and automated-decision questions. Connect privacy breaches with security incident response and regulatory escalation.

    6. Review and evidence

      Assign owners, retain decision evidence, review changes and report unresolved risks to management. Health-data governance must remain current as products, suppliers and markets change.

    What Asteron delivers

    The exact scope depends on the number of products, roles, processing purposes and target jurisdictions. Individual legal opinions, large portfolios of DPIAs and technical implementation work are included only when expressly stated in the proposal.

    Governance foundation

    • Health-data processing and role map
    • Article 6 and Article 9 decision structure
    • National-requirement register
    • Health-data governance policy
    • Privacy responsibility and escalation model
    • DPIA screening and assessment workflow
    • Privacy-by-design checkpoints
    • Management reporting and review cadence

    Operational evidence

    • Processing-record structure
    • Purpose and minimisation decisions
    • Supplier and sub-processor controls
    • International-transfer workflow
    • Rights-request operating process
    • Retention and deletion decisions
    • Privacy-incident assessment workflow
    • Prioritised remediation plan

    Netherlands, Germany and cross-border health data

    GDPR provides a European baseline, but Article 9 expressly allows Member States to introduce additional conditions for genetic, biometric and health data.

    For the Netherlands, healthtech companies may also need to account for the Dutch GDPR Implementation Act, medical-treatment and confidentiality rules, Autoriteit Persoonsgegevens guidance and care-sector requirements such as NEN 7510 where applicable.

    For Germany, the Federal Data Protection Act, state legislation, professional secrecy, healthcare and social-data rules may create additional requirements. The relevant supervisory authority may also depend on the organisation’s establishment and processing context.

    A company serving both markets should maintain one controlled European processing model with traceable national extensions. Separate country documents should not contradict the product architecture, contracts or central processing record.

    Related regulatory frameworks

    ISO/IEC 27701
    Provides a certifiable privacy management system for operating controller and processor responsibilities.
    ISO/IEC 27001
    Manages information-security risk but does not establish the lawfulness of health-data processing.
    NEN 7510
    Supports health-information security in the Dutch healthcare context.
    EHDS
    Introduces additional European rules for primary and secondary use of electronic health data through a phased implementation.
    MDR and IVDR
    Regulate medical-device safety and performance; they do not replace GDPR legal-basis and privacy requirements.
    EU AI Act
    May add governance requirements for AI systems; health-data processing still needs a separate GDPR position.

    Health-data governance from €7,900

    The starting scope covers the operational governance of special-category health data. It typically includes the role and processing baseline, Article 6 and Article 9 decision structure, priority risk assessment, core workflows and an implementation roadmap.

    Final price depends on
    • number of products and processing purposes;
    • controller, processor and joint-controller complexity;
    • number of countries and legal entities;
    • existing records, DPIAs and privacy controls;
    • supplier and transfer complexity;
    • research, AI or secondary-use requirements.

    This is a readiness and governance project, not a certification.

    Payment terms (fixed-scope)

    For fixed-scope engagements, commercial milestones are confirmed in the proposal. The standard structure is:

    • 40% at signing
    • 40% at the agreed implementation-ready milestone
    • 20% after the contracted governance outcome is delivered

    Prices exclude VAT where applicable.

    View all pricing

    External legal work and implementation boundaries

    Asteron builds the operational governance model, connects approved decisions to controls and prepares the supporting evidence. Asteron does not issue a GDPR certificate and does not present operational readiness as a formal legal opinion.

    Where a binding interpretation of Article 9, Dutch or German law, research rules, professional secrecy or another jurisdiction-specific requirement is needed, the client appoints qualified legal counsel or a specialist adviser. Their fees are quoted and paid separately unless expressly included in the proposal.

    Changes requiring production access—such as consent implementation, access-control changes, deletion logic, logging, data segregation or infrastructure migration—remain with the client’s product and engineering teams unless separately scoped.

    If an agreed outcome is not reached because an Asteron deliverable is incomplete or deficient, Asteron corrects that work at no additional professional fee within the contracted scope. This does not cover changed processing, new jurisdictions, missing client decisions or external legal conclusions.

    Responsibilities

    Asteron

    • Maps processing, privacy roles and governance gaps
    • Structures Article 6 and Article 9 decision evidence
    • Builds the agreed operational workflows
    • Connects privacy with security and product governance
    • Assigns actions and prepares management evidence
    • Coordinates external specialists where required

    Your organisation

    • Determines purposes and means where acting as controller
    • Provides accurate information about products, data and suppliers
    • Approves legal bases and Article 9 conditions with DPO or legal input
    • Assigns accountable business and product owners
    • Implements required technical and contractual changes
    • Operates and reviews the governance model after delivery

    Frequently asked questions

    What is GDPR Article 9?

    Article 9 regulates processing of special categories of personal data, including health, genetic and certain biometric data. Processing is generally prohibited unless a defined condition applies.

    Do we need both Article 6 and Article 9?

    Controllers processing health data generally need an Article 6 lawful basis and a separate Article 9 condition. These answer different legal questions.

    Is consent always required for health data?

    No. Explicit consent is one possible Article 9 condition, but healthcare, public health, research and other processing may depend on different legal routes and safeguards.

    Are wellness and wearable data health data?

    They may be. The assessment depends on what the information reveals, how it is used and whether it is linked or linkable to an individual.

    Is pseudonymised health data still covered by GDPR?

    Usually yes. Pseudonymisation reduces risk but the information remains personal data when re-identification is possible using additional information.

    Does a processor need its own Article 9 condition?

    The controller normally determines the purpose and legal basis. A processor must operate within documented instructions, meet its own GDPR obligations and understand the permitted scope.

    When is a DPIA required?

    A DPIA is required when processing is likely to create high risk for individuals. Large-scale health data, vulnerable people, profiling, automated decisions, monitoring and innovative technology are common indicators.

    Can health data be reused for research or AI development?

    Possibly, but reuse requires a separate assessment of purpose, role, legal basis, Article 9 condition, transparency, safeguards and applicable national law. The original collection does not create unlimited reuse rights.

    Does ISO 27701 solve Article 9 compliance?

    No. ISO 27701 provides a management system for operating privacy responsibilities. It does not select or validate the legal basis for an individual processing activity.

    Is this a GDPR certification?

    No. The service creates operational governance and readiness evidence. It does not issue a GDPR certificate or guarantee a regulator’s legal interpretation.

    How much does the project cost?

    GDPR Article 9 Health-Data Governance starts from €7,900. Final scope depends on the number of products, roles, jurisdictions, suppliers and high-risk processing activities.

    Official references

    • – Regulation (EU) 2016/679, particularly Articles 4, 5, 6, 9, 25, 28, 30, 32, 35 and 44–49
    • – European Data Protection Board guidance for controllers and processors
    • – European Data Protection Board guidance on data protection by design and DPIAs
    • – Autoriteit Persoonsgegevens health-data guidance
    • – German federal and state data-protection authorities
    • – European Commission information on the European Health Data Space

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with the European Commission, the European Data Protection Board, any supervisory authority or certification body.

    Turn health-data decisions into controls your team can operate

    We will assess your processing purposes, privacy roles, Article 9 positions, suppliers and target markets, then define a practical health-data governance plan.

    View health-data pricing