Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0395 → TA-9-2023-0462

From
A-9-2023-0395 Plenary report of 5 Dec 2023
To
TA-9-2023-0462 Adopted text of 13 Dec 2023
Changes
32 changes to the text
Paragraphs
+6 added · −39 removed · 30 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on the European Health Data Space
Title (to)
European Health Data Space

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 7 of 11: Paragraphs 361–420

9 unchanged paragraphs

Article 36 – paragraph 3 a (new): 3a. Each health data access body shall act with complete independence in performing its tasks and exercising its powers in accordance with this Regulation. The members of the governance and decision-making bodies and staff of each health data access body shall, in the performance of their tasks and exercise of their powers in accordance with this Regulation, remain free from external influence, whether direct or indirect and shall neither seek nor take instructions from any natural or legal person. Members of the governance and decision-making bodies and staff of each health data access body shall refrain from any action incompatible with their duties and shall not, during their term of office, engage in any incompatible occupation, whether gainful or not.

Article 37 – paragraph 1 – point a: (a) decide on data access applications pursuant to Article 45, including deciding on whether the data shall be made accessible in anonymised or pseudonymised form, based on its own thorough assessment of any reasons provided by the health data applicant pursuant to Article 45(2), point (d);

Article 37 – paragraph 1 – point a a (new): (aa) assess and issue data permits pursuant to Article 46 of this Regulation and assess data request pursuant to Article 47 of this Regulation to access electronic health data falling within their national remit for secondary use and decide on data requests in accordance with Chapter II of Regulation (EU) .../... […] [Data Governance Act COM/2020/767 final] and this Chapter;

Article 37 – paragraph 1 – point a b (new): (ab) request electronic health data referred to in Article 33 from relevant health data holders pursuant to a data permit or a data request granted;

Article 37 – paragraph 1 – point d: (d) process electronic health data for the purposes set out in Article 34, including the combination, preparation, anonymisation and pseudonymisation and disclosure of those data for secondary use on the basis of a data permit, while also ensuring proper security of that data;

Article 37 – paragraph 1 – point e: deleted

Article 37 – paragraph 1 – point f: (f) take all measures necessary to preserve the confidentiality of IP rights and regulatory data protection, and the confidentiality of trade secrets as provided for in Article 33a;

Article 37 – paragraph 1 – point g: (g) based on a data permit, put the relevant electronic health data at the disposal of data users in a secure processing environment in accordance with the requirements laid down in Article 50 and store the data for the period of the duration of the data permit;

Article 37 – paragraph 1 – point i: deleted

Change 18

ChangedArticle 37 – paragraph 1 – point j a (new): (j a)(ja) support data holders that are small enterprises in accordance with Commission Recommendation 2003/361/EC, in particular medical practionerspractitioners and pharmacies, to comply with their obligations under Article 41;

38 unchanged paragraphs

Article 37 – paragraph 1 – point k: (k) maintain a management system to record and process data access applications, data requests, the decisions on those applications and the data permits issued and data requests answered, providing at least information on the name of the data applicant, the purpose of access the date of issuance, duration of the data permit and a description of the data application or the data request;

Article 37 – paragraph 1 – point m: (m) cooperate at Union and national level to lay down common standards, technical requirements and appropriate measures for accessing electronic health data in a secure processing environment;

Article 37 – paragraph 1 – point n: (n) cooperate at Union and national level and provide advice to the Commission on techniques and best practices for the secondary use and management of electronic health data;

Article 37 – paragraph 1 – point q – point i: (i) a national dataset catalogue that shall include details about the source and nature of electronic health data, in accordance with Articles 55, 56 and 58, and the conditions for making electronic health data available. The national dataset catalogue shall also be made available to single information points under Article 8 of Regulation […] [Data Governance Act COM/2020/767 final];

Article 37 – paragraph 1 – point q – point ii: (ii) all health data applications and requests without undue delay after their reception;

Article 37 – paragraph 1 – point q – point ii a (new): (iia) all health data permits or requests granted as well as denied, together with a justification, within 30 working days of their issuance;

Article 37 – paragraph 1 – point q – point iii: (iii) enforcement measures applied pursuant to Article 43 and administrative fines applied pursuant to Article 43a;

Article 37 – paragraph 1 – point r a (new): (ra) monitor and supervise compliance by data users and data holders with the requirements laid down in this Chapter; monitoring and supervision shall include regular audits on health data users regarding their processing of electronic health data in the secure processing environment;

Article 37 – paragraph 2 – point a: (a) cooperate with supervisory authorities under Regulation (EU) 2016/679 in relation to personal electronic health data and the EHDS Board;

Article 37 – paragraph 2 – point a a (new): (aa) immediately notify the relevant supervisory authorities under Regulation (EU) 2016/679 of any potential issue related to the processing of personal electronic health data for secondary use, and exchange any relevant information at their disposal to ensure application and enforcement of this Regulation and relevant provisions of Regulation (EU) 2016/679 and this Regulation, including penalties;

Article 37 – paragraph 2 – point b: (b) inform the relevant supervisory authorities under Regulation (EU) 2016/679 where a health data access body has imposed enforcement measures pursuant to Article 43 or administrative fines pursuant to Article 43a in relation to processing personal electronic health data and where such processing refers to an attempt to re-identify an individual or unlawful processing of personal electronic health data;

Article 37 – paragraph 2 – point c: (c) cooperate with all relevant stakeholders, including patient organisations, representatives from natural persons, health professionals, researchers, and ethics committees, where applicable in accordance with Union and national law;

Article 37 – paragraph 4: deleted

Article 38 – paragraph 1 – introductory part: 1. Health data access bodies shall make publicly available and easily searchable and accessible for natural persons the conditions under which electronic health data is made available for secondary use, with information concerning:

Article 38 – paragraph 1 – point a: (a) the legal basis under which access is granted to the health data user;

Article 38 – paragraph 1 – point c: (c) the applicable rights of natural persons in relation to secondary use of electronic health data, including the right to opt-out pursuant to Article 33(5) and the right to opt-in pursuant to Article 33(5a), and detailed information on how to exercise them;

Article 38 – paragraph 1 – point d: (d) the modalities for natural persons to exercise their rights in accordance with Chapter III of Regulation (EU) 2016/679;

Article 38 – paragraph 1 – point d a (new): (da) the identity and the contact details of the health data access body;

Article 38 – paragraph 1 – point d b (new): (db) the record on who has been granted access to which sets of electronic health data and a justification regarding the purposes for processing them as referred to in Article 34(1);

Article 38 – paragraph 2: deleted

Article 38 – paragraph 3: 3. Where a health data access body is informed by a health data user of a significant finding related to the health of a natural person, as referred to in Article 41a(5) of this Regulation, the health data access body shall inform the treating health professional with the relevant competence of the natural person and if that health professional cannot be found, and shall inform the natural person about that finding. Natural persons shall have the right to request not to be informed of such findings. In accordance with Article 23(1), point (i), of Regulation (EU) 2016/679, Member States may restrict the scope of the obligation to inform the natural persons whenever necessary for the protection of the natural persons based on patient safety and ethics, by delaying the communication of their information until a health professional can communicate and explain to the natural persons information that potentially can have an impact on them .

Article 38 a (new): Article 38a / Right to lodge a complaint with a health data access body / 1. Without prejudice to any other administrative or judicial remedy, natural and legal persons shall have the right to lodge a complaint, individually or, where relevant, collectively, with the health data access body, where their rights laid down in this Chapter are affected. Where the complaint concerns the rights of natural persons pursuant to Article 38(1), point (d), of this Regulation, the health data access body shall inform and send a copy of the complaint to the competent supervisory authorities under Regulation (EU) 2016/679. / 2. The health data access body with which the complaint has been lodged shall inform the complainant of the progress of the proceedings and of the decision taken. / 3. Health data access bodies shall cooperate to handle and resolve complaints, including by exchanging all relevant information by electronic means, without undue delay. / 4. Each health data access body shall facilitate submitting complaints, in particular by providing a complaint submission form which can also be completed electronically, without excluding the possibility of using other means of communication.

Article 38 b (new): Article 38b / Right to an effective judicial remedy against a health data access body / 1. Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of a health data access body concerning them. / 2. Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy where the health data access body which is competent pursuant to Article 37 does not handle a complaint or does not inform the natural or legal person within three months about the progress or outcome of the complaint lodged pursuant to Article 38a. / 3. Proceedings against a health data access body shall be brought before the courts of the Member States where the health data access body is established.

Article 39 – paragraph 1 – introductory part: 1. Each health data access body shall publish an annual activity report and make it publicly available on its website, which shall contain at least the following categories of information:

Article 39 – paragraph 1 – point a: (a) information relating to the data access applications and data requests for electronic health data access submitted, such as the types of applicants, number of data permits granted or refused, purposes of access and categories of electronic health data accessed, and a summary of the results of the electronic health data uses, where applicable;

Article 39 – paragraph 1 – point c: (c) information on the fulfilment of regulatory and contractual commitments by data users and data holders, as well as the number and amount of administrative fines imposed by health data access bodies;

Article 39 – paragraph 1 – point d: (d) information on audits carried out on data users to ensure compliance of the processing within the secure processing environment as referred to in Article 50 of this Regulation;

Article 39 – paragraph 1 – point e: (e) information on internal and third party audits on compliance of secure processing environments with the defined standards, specifications and requirements, as referred to in Article 50(3) of this Regulation;

Article 39 – paragraph 1 – point j: deleted

Article 39 – paragraph 1 – point l: (l) number of data quality labels issued by data holders, disaggregated per quality category;

Article 39 – paragraph 2: 2. The report shall be transmitted to the Commission, which shall make it publicly available on its website.

Article 39 – paragraph 3: 3. The Commission is empowered to adopt delegated acts in accordance with Article 67 to amend paragraph 1 of this Article by adding categories to those listed in that paragraph.

Article 40 – paragraph 1: 1. In addition to rules regarding data altruism established by Regulation (EU) 2022/868, where data altruism organisations recognised under Chapter IV of that Regulation process personal electronic health data using a secure processing environment, such environments shall also comply with the requirements set out in Article 50 of this Regulation.

Article 40 – paragraph 2: 2. Health data access bodies shall support the competent authorities designated in accordance with Article 23 of Regulation (EU) 2022/868 in the monitoring of entities carrying out data altruism activities, where electronic health data are concerned.

Article 41 – title: Duties of health data holders

Article 41 – paragraph 1: 1. Health data holders shall make relevant electronic health data under Article 33 available upon request to the health data access body pursuant to a data permit issued or data request granted by such a body. Health data holders shall cooperate in good faith with the health data access bodies, where relevant.

Article 41 – paragraph 1 a (new): 1a. The requirement laid down in the first paragraph shall not apply to data holders that qualify as micro enterprises as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC.

Article 41 – paragraph 1 b (new): 1b. The health data holder shall put the electronic health data at the disposal of the health data access body within three months of receiving the request from the health data access body. In justified cases, after consultation with the health data holder concerned, that period may be extended by the health data access body for a maximum of two months. The health data access body may decide that the extension is to be shorter than two months.

Change 19

ChangedArticle 41 – paragraph 1 c (new): 1c. Paragraphs 1 and 1a of this Article constitute a legal obligation pursuant to Article 6(1), point (c), of this Regulation in combination with Article 9(2), points (g) (toto (j), of Regulation 2016/679 for the health data holder to disclose personal electronic health data to the health data access body.

11 unchanged paragraphs

Article 41 – paragraph 2: 2. The health data holder shall communicate to the health data access body a general description of the dataset it holds in accordance with Article 55.

Article 41 – paragraph 3: 3. Where a data quality and utility label accompanies the dataset pursuant to Article 56, the health data holder shall provide sufficient documentation to the health data access body for that body to confirm the accuracy of the label.

Article 41 – paragraph 4: deleted

Article 41 – paragraph 5: 5. Where a health data holder has received enriched datasets following a processing based on a data permit, it shall make available the new dataset, unless it considers it unsuitable and notifies the health data access body in this respect.

Article 41 – paragraph 6: 6. Health data holders of non-personal electronic health data shall ensure access to data through trusted open databases to ensure unrestricted access for all users and data storage and preservation. Trusted open public databases shall have in place a robust, transparent and sustainable governance and a transparent model of user access.

Article 41 – paragraph 7: deleted

Article 41 a (new): Article 41a / Duties of health data users / 1. Health data users may access and process the electronic health data for secondary use referred to in Article 33 only in accordance with the data permit issued by the health data access body in accordance with Article 46 of this Regulation. / 2. Health data users shall not re-identify or seek to re-identify the natural persons to whom the electronic health data which they obtained based on the data permit or data request belong. Such conduct shall be considered a serious breach of this Regulation. / 3. Health data users shall make public the results or output of the secondary use of electronic health data, including information relevant for the provision of healthcare, no later than 18 months after the completion of the electronic health data processing or after having received the answer to the data request referred to in Article 47. Those results or output shall not contain personal data. In justified cases, especially cases referred to in Article 34(1), point (e), that period may be extended by the relevant health data access body, after consultation with the health data user. The health data users shall inform the health data access bodies from which a data permit was obtained about the results or output and provide them with necessary support in order to make them public also on health data access bodies’ websites. The result shall also be made publicly available in lay summaries. Whenever the health data users have used elec…

Article 42 – paragraph 1: 1. Health data access bodies may charge fees to health data users for making electronic health data available for secondary use. Any fees shall include and be derived from the costs related to the set up, combination, preparation, anonymisation, pseudonymisation, maintenance, tasks under Article 33a, making available or updating of the dataset and conducting the procedure for requests, including for assessing a data application or a data request, granting, refusing or amending a data permit pursuant to Articles 45 and 46 or providing an answer to a data request pursuant to Article 47, in accordance with Article 6 of Regulation […] [Data Governance Act COM/2020/767 final]. No fees shall be charged to public sector bodies and Union institutions, offices, agencies and bodies when making data available for the purposes referred to in Article 34(1), points (a), (b) and(c). No fees shall be charged to public sector bodies or Union institutions, offices, agencies and bodies with a legal mandate in the field of public health.

Article 42 – paragraph 2: 2. In the case of health data holders, where the data in question are not held by the health data access body or a public sector body or a Union institution, office, agency and body, the fees may be derived from the costs for gathering, enriching, and preparing the electronic health data specifically under this Regulation in addition to the fees that may be charged pursuant to paragraph 1. The part of the fees linked to the health data holder’s costs shall be paid to the health data holder.

Article 42 – paragraph 4: 4. Any fees charged to health data users pursuant to this Article by the health data access bodies or health data holders shall be transparent, non-discriminatory, and proportionate to the cost of making electronic health data available for secondary use, objectively justified and shall not restrict competition. The support received by the health data holder from donations, public national or Union funds, to set up, develop or update that dataset shall be excluded from this calculation. The specific interests and needs of SMEs, public bodies, Union institutions, bodies, offices and agencies involved in research, health policy or analysis, academic and educational institutions, non-commercial entities and healthcare providers shall be taken into account when setting the fees, by reducing those fees proportionately to their size or budget.

Article 42 – paragraph 5: 5. Where health data holders and health data users do not agree on the level of the fees within 1 month of the data permit being granted, the health data access body may set the fees in proportion to the cost of making available electronic health data for secondary use. Where the health data holder or the health data user disagree with the fee set out by the health data access body, they shall have access to dispute settlement bodies set out in accordance with Article 10 of the Regulation […] [Data Act COM/2022/68 final].

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2023). “Changes between A-9-2023-0395 and TA-9-2023-0462”. Text, 13 December 2023. from A-9-2023-0395, to TA-9-2023-0462. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=7 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-13,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0395 and TA-9-2023-0462}},
  year = {2023},
  date = {2023-12-13},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=7}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=7},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0395, to TA-9-2023-0462. Data: European Parliament Open Data (CC BY 4.0)}
}