GDPR Health Data Definition & Classification (Article 4(15))

Definition of Health Data under GDPR

According to GDPR Article 4(15) and Recital 35, personal data concerning health includes all data related to the physical or mental health status of a data subject that reveals information about their health condition.

Health Data Categories & Requirements

Health Data Category GDPR Legal Definition & Scope Technical & Processing Requirements
Direct Clinical Records Personal data related to physical/mental health revealing past, present, or future health status (Art. 4(15) & Recital 35). Requires Article 9 legal basis (e.g., explicit consent), AES-256 encryption at rest, strict access logging, and DPIA execution.
Biometric Data Technical processing of physical, physiological, or behavioral characteristics to uniquely identify a person (Art. 4(14)). Mandatory Data Protection Impact Assessment (DPIA), hardware-level encryption (secure enclaves), and explicit opt-in consent.
Sensor & Wearable Telemetry Real-time device outputs (e.g., continuous heart rate, glucose readings, SPO2) indicating physiological status. Classified as special category data when tied to user identity; requires pseudonymization and isolated data storage pipelines.
Inferred or Derived Health Data Non-medical raw inputs (e.g., step counts, lifestyle logs) processed via algorithms to deduce a health condition. Treated as health data if an inference is drawn; mandates transparent user notice, consent granular controls, and purpose limitation.
Genetic Data Personal data relating to inherited or acquired genetic characteristics providing unique info on physiology or health (Art. 4(13)). Subject to additional member state statutory restrictions, zero-trust cryptographic access controls, and strict multi-factor isolation.

Examples of GDPR Health Data Categories

Under Article 4(15) and Recital 35 of the GDPR, "data concerning health" extends far beyond traditional electronic health records to encompass any personal information that reveals physical or mental health status. Digital health platforms and MedTech applications must classify their data streams accurately to apply appropriate legal processing bases, encryption protocols, and isolation controls across three core categories:

  • Direct Clinical Data: Medical history, diagnoses, lab results, prescriptions, and medical imaging.
  • Biometric & Sensor Data: Heart rate (ECG), blood pressure, disease symptoms, and glucose levels.
  • Derived Health Data: Raw fitness metrics (e.g., step counts, sleep duration) when processed to infer a medical condition or health status.