Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0395 → TA-9-2023-0462

From
A-9-2023-0395 Plenary report of 5 Dec 2023
To
TA-9-2023-0462 Adopted text of 13 Dec 2023
Changes
32 changes to the text
Paragraphs
+6 added · −39 removed · 30 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on the European Health Data Space
Title (to)
European Health Data Space

Changes that matter, 32

Changes to the text in document order — the ones the change notes describe. Cover page, renumbering and punctuation-only edits are left out (see “Every difference”); changes to citations and references stay in and are marked as formal in the notes.

Change 1

ChangedRecital 4 a (new): (4 a)(4a) The implementation of the EHDS should take into consideration the European ethical principles for digital health adopted by the eHealth network1a on 26 January 2022. Monitoring the application of those ethical principles should be one of the tasks of the EHDS Board. / 1a Established following Article 14 of Directive 2011/24/EU on the application of patients' rights in cross-border healthcare.

Change 2

ChangedRecital 10: (10) Some Member States allow natural persons to add electronic health data to their EHRs or to store additional information in their separate personal health record that can be accessed by health professionals. However, this is not a common practice in all Member States and therefore should be established by the EHDS across the EU. Information inserted by natural persons may not be as reliable as electronic health data entered and verified by health professionals and does not have the same clinical or legal value as information provided by a health professional, therefore it should be clearly marked to indicate the source of such additional data and should be validated only bvby a health professional. More specifically, relevant fields in the EHR should be clearly marked. Enabling natural persons to more easily and quickly access their electronic health data also further enables them to notice possible errors such as incorrect information or incorrectly attributed patient records and have them rectified using their rights under Regulation (EU) 2016/679. In such cases, natural person should be enabled to request rectification of the incorrect electronic health data online, immediately and free of charge, for example through the personal health data access service. Data rectification requests should be assessed and, where relevant, implemented by the data controllers on case by case basis, if necessary involving health professionals, with a relevant specialisation, responsible f…

Change 3

ChangedRecital 40: (40) The health data holders in the context of secondary use of electronic health data can be public, non for profit or private health or care providers, public, non for profit and private organisations, associations or other entities, public and private entities that carry out research with regards to the health sector that process the categories of health and health related data mentioned above To the extent that they process personal electronic health data, health data holders are controllers within the meaning of Regulation (EU) 2016/679 in the health or care sector. In order to avoid a disproportionate burden on small entities, micro-enterprises are excluded from the obligation to make their data available for secondary use in the framework of EHDS. Health data access bodies should provide specific support to small enterprises, in particular medical practionerspractitioners and pharmacies, in complying with their obligation to make data available for secondary use. The public or private entities often receive public funding, from national or Union funds to collect and process electronic health data for research, statistics (official or not) or other similar purposes, including in area where the collection of such data is fragmented of difficult, such as rare diseases, cancer etc. Such data, collected and processed by health data holders with the support of Union or national public funding, should be made available by health data holders to health data access bodies, in order to maxim…max…

Change 4

ChangedRecital 40 b (new): (40b) Clinical trials and studies are of utmost importance in fostering innovation within the Union for the benefit of Union patients. In order to incentivise continuous Union leadership in this domain, the sharing of the clinical trials data through the EHDS for secondary use should be consistent with the relevant transparency provisions laid down in Union law including Regulation (EU) .../... [proposal for a Regulation on blood, tissue, cells and organs (SoHO) COM(2022)338 final], Regulations (EC) No 726/20041a and (EU) 2019/61b of the European Parliament and of the Council and Directive 2001/83/EC of the European Parliament and of the Council1c regarding veterinary and human medicines and establishing the EMA, Regulation (EC) No 141/2000 of the European Parliament and of the Council1d related to medicinal products for rare diseases (‘orphan medicines’), Regulation (EC) No 1901/2006 of the European Parliament and of the Council1e on medicinal products for children, Regulation (EC) No 1394/2007 of the European Parliament and of the Council1f on advanced therapy medicinal products, Regulation (EU) No 536/2014 of the European Parliament and of the Council1glCouncil1g on clinical trials, Regulation (EU) No 2017/745 and Regulation (EU) No 2017/746. / 1a Regulation (EC) No 726/2004 of the European Parliament and of the Council of 31 March 2004 laying down Community procedures for the authorisation and supervision of medicinal products for human and veterinary use and establishing a Europe…Europea…

Change 5

ChangedRecital 47: (47) Health data access bodies should be allowed to charge fees based on the applicable provisions under this Regulation […] and the provisions of theRegulations (EU) .../... […] [Data Governance Act COM/2020/767 final] and the(EU) .../... […] [Data Act COM/2022/68 final] in relation to their tasks. Such fees may take into account the situation and interest of SMEs, individual researchers or public bodies. Health data holders should be allowed to also charge fees for making data available. Such fees should reflect the costs for providing such services. Private health data holders may also charge fees for the collection of data. In order to ensure a harmonised approach concerning fee policies and structure, the Commission should adopt implementing acts. Provisions in Article 10 of the Regulation [Data Act COM/2022/68 final] should apply for fees charged under this Regulation. Public sector bodies and Union institutions, bodies, offices and agencies with a legal mandate in the field of public health should not be charged fees.

Change 6

ChangedRecital 64 c (new): (64c) Access to electronic health data for entities from third countries should take place only on the basis of the reciprocity principle. Making available of health data to a third country can take place only where the Commission has established by means of a delegated act that the third country concerned allows for the use of health data by Union entities under the same conditions and with the same safeguards as within the Union. The Commission should monitor that list and provide for a periodic review thereof. Where the Commission finds that a third country no longer ensures access on the same terms ,terms, that third country should be removed from that list.

Change 7

ChangedRecital 66 c (new): (66c) Any natural or legal person has the right to bring an action for annulment of decisions of the EHDS Board before the Court of Justice under the conditions provided for in Article 263 TFEU. As addressees of such decisions, the digital health authorities or health data access bodies concerned which wish to challenge them have to bring an action within two months of being notified of them, in accordance with Article 263 TFEU. In accordance with Article 263 TFEU, a health data holder, a health data applicant, a health data user or a complainant can bring an action for annulment against the decisions of the EHDS Board which concern them within two months of their publication on the website of the EHDS Board..Board. Without prejudice to this right under Article 263 TFEU, each natural or legal person should have an effective judicial remedy before the competent national court against a decision of a digital health authority or health data access body which produces legal effects concerning that person. Such a decision concerns in particular the exercise of investigative, corrective and authorisation powers by the health data access body or the dismissal or rejection of complaints. However, the right to an effective judicial remedy does not encompass measures taken by digital health authorities and health data access bodies which are not legally binding, such as opinions issued or advice provided. Proceedings against a digital health authority or health data access body should be bro…brou…

Change 8

ChangedRecital 66 f (new): (66f) The digital health authority, health data access body, health data holder or health data user should compensate any damage which a person could suffer as a result of processing that infringes this Regulation. The digital health authority, health data access body, health data holder or health data user should be exempt from liability if it proves that it was not in any way responsible for the damage. The concept of damage should be broadly interpreted in the light of the case-lawcase law of the Court of Justice in a manner which fully reflects the objectives of this Regulation. This is without prejudice to any claims for damage deriving from the violation of other rules in Union or national law. Processing that infringes this Regulation should also include processing that infringes delegated and implementing acts adopted in accordance with this Regulation and national law specifying rules related to this Regulation. Natural persons should receive full and effective compensation for the damage they have suffered. Where digital health authorities, health data access bodies, health data holders or health data users are involved in the same processing, each actor should be held liable for the entire extent of the damage. However, where they are joined to the same judicial proceedings, in accordance with Member State law, it should be possible to apportion compensation according to the responsibility of each digital health authority, health data access body, health data holder or hea…

Show 24 more changes

Change 9

ChangedRecital 74: (74) The European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42 of Regulation (EU) 2018/1725 and delivered Joint opinion n. 03/2022 on 12 July 2022.

Change 10

AddedArticle 7 – paragraph 1 a (new): 1a. Member States may provide for natural persons to have the right to object to the registration of their personal health data in an EHR system. / If a Member State provides for such a right, it shall establish the rules and specific safeguards regarding such objection mechanisms.

Change 11

ChangedArticle 23 – paragraph 4 a (new): 4 a.4a. Where common specifications have an impact on data protection requirements for EHR systems, they shall be subject to consultation with the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) before their adoption, pursuant to Article 42(2) of Regulation (EU) 2018/1725.

Change 12

ChangedArticle 25 – paragraph 2 – subparagraph 1a (new): If the EHR system is not accompanied by the information sheet referred to in this Article and by clear and complete instructions for use in accessible formats for persons with disabilities, the manufacturer of the EHR system concerned, its authorised representative and all other relevant economic operators shall be required to add to the EHR system that information sheet and those instructions for use .use.

Change 13

ChangedArticle 27 a (new): Article 27a / Conformity assessment for EHR systems / 1. In order to certify the conformity of an EHR system with this Regulation, prior to placing an EHR system on the market, the manufacturer, its authorised representative, or any economic operator referred to in Article 21 shall apply for a conformity assessment procedure. / 2. The conformity assessment procedure shall require the notified body to assess: / (a) whether the EHR system is in conformity with the requirements laid down in Annex II; / (b) whether the EHR system is in conformity with the requirements laid down in Regulation (EU) .../... [.. (Cyber Resilience Act COM/2022/457];COM(2022)454]; / (c) whether the technical documentation is available and complete; / (d) whether the technical design of an EHR system meets the applicable requirements of this Regulation as provided for in an EU type examination procedure laid down in Annex IVa; / The EU type-examination is the part of a conformity assessment procedure in which a notified body examines the technical design of an EHR system and verifies and attests that the technical design of the EHR system meets the applicable requirements of this Regulation. / Only after an Union wide approval has been issued, may the CE marking be affixed, together with an identification number. / 3. Notified bodies shall take into account the specific interests and needs of SMEs when setting the fees for conformity assessment and reduce those fees proportionately to their specific interests and nee…

Change 14

ChangedArticle 27 h (new): Article 27h / Use of subcontractors and subsidiaries by notified bodies / 1. Where a notified body subcontracts specific tasks connected with conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements set out in Article 27fand27f and shall inform the notifying authority accordingly. / 2. A notified body shall take full responsibility for the tasks performed by subcontractors or subsidiaries wherever those are established. / 3. Activities may be subcontracted or carried out by a subsidiary only with the agreement of the client. / 4. A notified body shall keep at the disposal of the notifying authority the relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under Annex IVa.

Change 15

ChangedArticle 27 m (new): Article 27m / Challenge of the competence of notified bodies / 1. The Commission shall investigate all cases where it has doubts, or a doubt is brought to its attention, regarding the competence of a notified body or the continued fulfilment by a notified body of the requirements and responsibilities to which it is subject. / 2. The notifying authority shall provide the Commission, on request, with all information relating to the basis for the notification or the maintenance of the competence of the notified body concerned. / 3. The Commission shall ensure that all sensitive information obtained in the course of its investigations is treated confidentially. / 4. Where the Commission ascertains that a notified body does not meet or no longer meetsthemeets the requirements for its notification, it shall adopt an implementing act requesting the notifying authority to take the necessary corrective measures, including the withdrawal of the notification if necessary. / That implementing act shall be adopted in accordance with the advisory procedure referred to in Article 68(2).

Change 16

ChangedArticle 27 n (new): Article 27n / Operational obligations of notified bodies / 1. A notified body shall carry out conformity assessments in accordance with the conformity assessment procedures set out in Article 27a. / 2. A notified body shall perform its activities in a proportionate manner, avoiding an unnecessary burden for economic operators, and taking due account of the size of an undertaking, the structure of the undertaking, the degree of complexity of the EHR system in question. In so doing, the notified body shall nevertheless respect the degree of rigour and the level of protection required for the compliance of the EHR system with the requirements of this Regulation. / 3. Where a notified body finds that the harmonised standards or common specifications referred in this Regulation have not been met by a manufacturer, it shall require the manufacturer to take appropriate corrective actions and shall not issue an EU type-examination certificate. / 4. Where, in the course of the monitoring of conformity following the issuance of a certificate of conformity or the adoption of an approval decision, a notified body finds that aan EHR system no longer complies, it shall require the manufacturer to take appropriate corrective measures and shall suspend or withdraw the certificate of conformity or the approval decision, if necessary. / Where corrective measures are not taken or do not have the required effect, the notified body shall restrict, suspend or withdraw any certificates of conformity …conformity…

Change 17

ChangedArticle 33 – paragraph 1 – introductory part: 1. This chapterChapter shall apply to the following categories of electronic health data available for secondary use:

Change 18

ChangedArticle 37 – paragraph 1 – point j a (new): (j a)(ja) support data holders that are small enterprises in accordance with Commission Recommendation 2003/361/EC, in particular medical practionerspractitioners and pharmacies, to comply with their obligations under Article 41;

Change 19

ChangedArticle 41 – paragraph 1 c (new): 1c. Paragraphs 1 and 1a of this Article constitute a legal obligation pursuant to Article 6(1), point (c), of this Regulation in combination with Article 9(2), points (g) (toto (j), of Regulation 2016/679 for the health data holder to disclose personal electronic health data to the health data access body.

Change 20

ChangedArticle 44 – paragraph 3: 3. Where the health data user has sufficiently demonstrated that the purpose of processing cannot be achieved with anonymised data in line with Article 46(1c), taking into account the information provided by the health data usertheuser the health data access bodies shall provide access to electronic health data in pseudonymised format. The information necessary to reverse the pseudonymisation shall be available only to the health data access body. Health Data users shall not re-identify the electronic health data provided to them in anonymised or pseudonymised format.

Change 21

ChangedArticle 46 – paragraph 3: 3. After the health data applicant has demonstrated the effective implementation of their security measures referred to in Article 45(2), points (e) and (f), the health data access body shall issue or refuse a data permit within 2 months of receiving a complete data access application. If the health data access body finds that the data access application is incomplete, it shall notify the health data applicant, who shall be given the possibility of completing their application. If the health data applicant does not fulfillfulfil this request within four weeks, a permit shall not be granted. By way of derogation from that Regulation (EU) 2022/868 the health data access body may extend the period for responding to a data access application by 2 additional months where necessary, taking into account the complexity of the request. In such cases, the health data access body shall notify the applicant as soon as possible that more time is needed for examining the application, together with the reasons for the delay.

Change 22

ChangedArticle 50 – paragraph 1 – point b: (b) minimise the risk of the unauthorised reading, copying, modification or removal of electronic health data hosted in the secure processing environment through state-of-the-art technical and organisational mesures;measures;

Change 23

ChangedArticle 51 – paragraph 1: 1. The health data holder shall be deemed controller for e the requested personal electronicdata healthmade dataavailable to the health data access body pursuant to Article 41(1) and (1a) of this Regulation. The health data access body shall be deemed controller for the processing of the personal electronic health data when fulfilling its tasks pursuant to Article 37(1), point (d), of this Regulation. The health data user shall be deemed controller for the processing of personal electronic health data in pseudonymised form in the secure processing environment pursuant to its data permit. The health data access body shall act as a processor for the processing by the health data user pursuant to a data permit in the secure processing environment.

Change 24

ChangedArticle 64 – paragraph 7 a (new): 7 a.7a. The EHDS Board shall publish meeting dates and minutes of the discussions and publish an annual report on its activities.

Change 25

ChangedArticle 65 – paragraph 1 – point b – point iii: (iii) other aspects of the primary use of electronic health data without prejudice to the powers of the supervisory authorities pursuant to Regulation (EU) 2016/679; the written contributions of the EHDS board shall not concern the interpretation or application of rights and obligations under Regulation (EU) 2016/679 or Regulation 2018/175.(EU) 2018/1725.

Change 26

ChangedArticle 69 b (new): Article 69b / Representation of a natural person / Where a natural person considers that their rights under this Regulation have been infringed, they shall have the right to mandate a not-for-profit body, organisation or association which is constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest and is active in the field of the protection of personal data, to lodge a complaint on their behalf or to exercise the rights referred to in Article 11a.

Change 27

ChangedArticle 70 – paragraph 1 a (new): 1a. By...By ... [please insert the date two years from the entry into force of this Regulation], the Commission shall carry out an evaluation of the Union funding attributed to the setting up and functioning of the EHDS, in particular concerning the ability of the bodies established under this Regulation to carry out their tasks and obligations under this Regulation and of Member States in relation to applying the Regulation in a uniform and coherent manner. The Commission shall submit a report on its main findings to the European Parliament and to the Council, the European Economic and Social Committee and the Committee of the Regions, accompanied, where appropriate, by the necessary measures.

Change 28

ChangedArticle 71 a (new): Article 71a / Amendments to Directive (EU) 2020/1828 / In the Annex ofto Directive (EU) 2020/1828, the following point is added: / (XX) Regulation (EU) XXX of the European Parliament and of the Council on the European Health Data Space.

Change 29

ChangedArticle 72 – paragraph 3 – point b: (b) from 3 years after date of entry into application to categories of personal electronic health data referred to in Article 5(1), points (d), (e) (f), and f(a)(fa) and to EHR systems intended by the manufacturer to process such categories of data;

Change 30

RemovedThis amendment aims to promote patients' understanding and control of their personal health data. The blood type is a relevant type of data that should be added to the priority categories of health data.

Change 31

ChangedAnnex II – point 3 – point 3.1: 3.1. An EHR system shall be designed and developed in such a way that it ensures safe and secure processing of electronic health data, and that it prevents unauthorised access to such data, and that it duly takes into consideration the principles of data minimizationminimisation and data protection by design.

Change 32

RemovedAmendment in line with EDPB/EDPS joint opinion recommendation.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
25 September 2026

Cite as

European Parliament (2023). “Changes between A-9-2023-0395 and TA-9-2023-0462”. Text, 13 December 2023. from A-9-2023-0395, to TA-9-2023-0462. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462 (retrieved 25 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-13,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0395 and TA-9-2023-0462}},
  year = {2023},
  date = {2023-12-13},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462},
  urldate = {2026-09-25},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0395, to TA-9-2023-0462. Data: European Parliament Open Data (CC BY 4.0)}
}