Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2023-0395 → TA-9-2023-0462
- From
- A-9-2023-0395 Plenary report of 5 Dec 2023
- To
- TA-9-2023-0462 Adopted text of 13 Dec 2023
- Changes
- 32 changes to the text
- Paragraphs
- +6 added · −39 removed · 30 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on the European Health Data Space
- Title (to)
- European Health Data Space
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 8 of 11: Paragraphs 421–480
15 unchanged paragraphs
Article 42 – paragraph 6: 6. The Commission shall, by means of implementing acts, lay down principles and rules for the fee policies and fee structures, including deductions for the entities listed in paragraph 4, second sub-paragraph. Those implementing acts shall be adopted in accordance with the advisory procedure referred to in Article 68(2).
Article 43 – title: Enforcement by health data access bodies
Article 43 – paragraph 1: deleted
Article 43 – paragraph 2: 2. When carrying out its monitoring and supervisory tasks to verify compliance with this Chapter, as referred to in Article 37(1), point (ra), the health data access bodies shall request information from health data holders and users that is proportionate for the performance of the task.
Article 43 – paragraph 3: 3. Where health data access bodies find that a health data user or health data holder does not comply with the requirements of this Chapter, they shall immediately notify the health data user or health data holder of those findings and shall give it the opportunity to state its views within 4 weeks. / Where the finding of non-compliance concerns a possible breach of Regulation (EU) 2016/679, the health data access body shall immediately inform the supervisory authorities under Regulation (EU) 2016/679 and provide them with all relevant information at their disposal concerning this finding to ensure application and enforcement of the relevant provisions of that Regulation, including penalties.
Article 43 – paragraph 4: 4. Health data access bodies shall have the power to revoke the data permit issued pursuant to Article 46 and stop the affected electronic health data processing operation carried out by the health data user in order to ensure the cessation of the non-compliance referred to in paragraph 3, immediately or without undue delay, and shall take appropriate and proportionate measures aimed at ensuring compliant processing by the health data users. In this regard, the health data access bodies shall be able, where appropriate, to revoke the data permit and to exclude the health data user from any access to electronic health data for a period of up to 5 years.
Article 43 – paragraph 5: 5. Where health data holders withhold the electronic health data from health data access bodies with the manifest intention of obstructing the use of electronic health data, or do not respect the deadlines set out in Article 41, the health data access body shall have the power to fine the health data holder with fines for each day of delay, which shall be transparent and proportionate. The amount of the fines shall be established by the health data access body. In case of repeated breaches by the health data holder of the obligation of loyal cooperation with the health data access body, that body can exclude the health data holder from submitting data access applications pursuant to Chapter IV for a period of up to 5 years, while still being obliged to make data accessible pursuant to Chapter IV, where applicable.
Article 43 – paragraph 6: 6. The health data access body shall communicate the measures imposed pursuant to paragraphs 4 and 5 and the reasons on which they are based to the health data user or holder concerned, without delay, and shall lay down a reasonable period for the health data user or holder to comply with those measures.
Article 43 – paragraph 7: 7. Any enforcement measures imposed pursuant to paragraph 4 shall be notified to other health data access bodies and made publicly available on the website of the EHDS Board.
Article 43 – paragraph 7 a (new): 7a. The health data access body shall ensure coherent enforcement based on the provisions of this Regulation and Regulation (EU) 2016/679 by taking into account any decision or investigation ongoing in supervisory authorities.
Article 43 – paragraph 9: deleted
Article 43 – paragraph 10: 10. The Commission shall issue guidelines on enforcement measures to be applied by the health data access bodies, in accordance with the principles set out in Article 68a.
Article 43 a (new): Article43a / General conditions for the imposition of administrative fines by health data access bodies / 1. Each health data access body shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements referred to in paragraphs 4 and 5 shall in each individual case be effective, proportionate and dissuasive. / 2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in Article 43(4) and (5). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following: / (a) the nature, gravity and duration of the infringement; / (b) whether any penalties or administrative fines have already been applied by other competent authorities to the same infringing party for the same infringement; / (c) the intentional or negligent character of the infringement; / (d) any action taken by the health data holder or health data user to mitigate the damage suffered by natural persons; / (e) the degree of responsibility of the health data user, taking into account technical and organisational measures implemented by them pursuant to Article 45(2), points (e) and (f),and Article 45(4); / (f) any relevant previous infringements by the health data holder or health data user; / (g) the degree of cooperation with the health data access body, in order to remedy …
Article 44 – paragraph 1: 1. The health data access body shall ensure that access is only provided to requested electronic health data that are adequate, relevant and limited to what is necessary in relation to the purpose of processing indicated in the data access application by the data user and in line with the data permit granted.
Article 44 – paragraph 2: 2. The health data access bodies shall provide the electronic health data in an anonymised format, in any event where the purpose of processing by the health data user can be achieved with such data, taking into account the information provided by the health data user.
Change 20
ChangedArticle 44 – paragraph 3: 3. Where the health data user has sufficiently demonstrated that the purpose of processing cannot be achieved with anonymised data in line with Article 46(1c), taking into account the information provided by the health data usertheuser the health data access bodies shall provide access to electronic health data in pseudonymised format. The information necessary to reverse the pseudonymisation shall be available only to the health data access body. Health Data users shall not re-identify the electronic health data provided to them in anonymised or pseudonymised format.
24 unchanged paragraphs
Article 44 – paragraph 3 a (new): 3a. The health data user’s failure to respect the health data access body’s measures ensuring anonymisation and pseudonymisation shall be considered a particularly serious breach of this Regulation and shall be subject to effective, proportionate and dissuasive penalties.
Article 44 – paragraph 3 b (new): 3b. The Commission shall, by means of implementing acts, set out the procedures and requirements, and provide technical tools, for a unified procedure for anonymising and pseudonymising the electronic health data. Those implementing acts shall be adopted in accordance with the advisory procedure referred to in Article 68(2).
Article 45 – paragraph 1: 1. Health data applicants may submit a data access application for the purposes referred to in Article 34.
Article 45 – paragraph 2 – point -a (new): (-a) the health data applicant´s identity, description of professional functions and operations, including the identity of the natural persons who will have access to electronic health data, if a data permit is granted; the list of natural persons can be updated and in that case it shall be notified to the health data access body;
Article 45 – paragraph 2 – point a: (a) a detailed explanation of the intended use of the electronic health data including for which of the purposes referred to in Article 34(1), access is necessary;
Article 45 – paragraph 2 – point a a (new): (aa) a description of how the health data applicant is qualified vis-à-vis the intended purposes of data use, including professional qualifications to demonstrate appropriate expertise, consistent with ethical practice and applicable laws and regulations;
Article 45 – paragraph 2 – point a b (new): (ab) an explanation of the expected benefits and how these benefits contribute to the purposes referred to in Article 34(1);
Article 45 – paragraph 2 – point b: (b) a description of the requested electronic health data, their timeframe, format and data sources, where possible, including geographical coverage where data is requested from several Member States;
Article 45 – paragraph 2 – point c: (c) an explanation whether electronic health data needs to be made available in a pseudonymised format and why the envisaged purpose for processing cannot be pursued using anonymised data;
Article 45 – paragraph 2 – point d: (d) a description of the safeguards planned to prevent any other use or any misuse of the electronic health data;
Article 45 – paragraph 2 – point e: (e) a description of the safeguards proportionate to the risks, planned to protect the rights and interests of the health data holder;
Article 45 – paragraph 2 – point f: (f) for personal electronic health data, a description of the necessary technical and organisational measures pursuant to Article 32 of Regulation (EU) 2016/679; to protect the rights and interests of the natural persons concerned, including to prevent any re-identification of natural persons in the dataset;
Article 45 – paragraph 2 – point g: (g) a justified estimation of the period during which the electronic health data is needed for processing;
Article 45 – paragraph 2 – point h a (new): (ha) where applicable, information on the assessment of ethical aspects of the processing and details of any necessary ethics approval obtained by the competent ethics committee in line with national law, which may serve to replace their own ethics assessment;
Article 45 – paragraph 2 – point h b (new): (hb) a plan defining audiences and tools to provide information publicly on the results or outcomes of the access to the data in accordance with Article 46(11);
Article 45 – paragraph 2 – point h c (new): (hc) a declaration that the intended uses of the data requested do not pose a risk of stigmatisation of or causing harm to the dignity of individuals or the groups to which the dataset requested relates.
Article 45 – paragraph 3: 3. Health data applicants seeking access to electronic health data from more than one Member State shall submit a single application to one of the concerned health data access bodies of their choice which shall be responsible for sharing the application with the other health data access bodies and authorised participants in HealthData@EU referred to in Article 52, which have been identified in the data access application. In such a case, the health data access body shall notify the other relevant health data access bodies of the receipt of an application relevant to them within 15 days from the date of receipt of the data access application.
Article 45 – paragraph 4 – introductory part: 4. Where the health data applicants intend to access the personal electronic health data in a pseudonymised format, the following additional information shall be provided together with the data access application:
Article 45 – paragraph 4 – point a: (a) a description of how the processing would comply with applicable Union and national law on data protection and privacy, notably Regulation (EU) 2016/679;
Article 45 – paragraph 4 – point b: deleted
Article 45 – paragraph 5 – subparagraph 2: deleted
Article 45 – paragraph 6: 6. The Commission shall, by means of implementing acts, set out the templates for the data access application referred to in this Article, the data permit referred to in Article 46 and the data request referred to in Article 47. Those implementing acts shall be adopted in accordance with the procedure referred to in Article 68(2).
Article 46 – paragraph 1: 1. Health data access bodies shall issue a data permit only when, after an assessment of the data access application, they find that it fulfils all of the following criteria: / (a) the purpose described in the health data access application is one of the purposes listed in Article 34(1); / (b) the requested data is necessary, adequate and proportionate for the purpose or purposes listed in the health data access application; / (c) in the case of pseudonomised data, there is sufficient justification that the purpose cannot be achieved with anonymised data; / (d) the processing complies with Article 6(1) and Article 9(2) of Regulation (EU) 2016/679 in the case of access to pseudonymised electronic health data; / (e) the health data applicant demonstrates sufficient technical and organisational measures to prevent any other use or misuse of the electronic health data and to protect the rights and interests of the data holder and of the natural persons concerned; / (f) the information on the assessment of ethical aspects of the processing, where applicable, is in line with national law; / (g) all other requirements in this Chapter are fulfilled by the health data applicant.
Article 46 – paragraph 2: 2. Health data access bodies shall refuse all applications where requirements in this Chapter are not met.
Change 21
ChangedArticle 46 – paragraph 3: 3. After the health data applicant has demonstrated the effective implementation of their security measures referred to in Article 45(2), points (e) and (f), the health data access body shall issue or refuse a data permit within 2 months of receiving a complete data access application. If the health data access body finds that the data access application is incomplete, it shall notify the health data applicant, who shall be given the possibility of completing their application. If the health data applicant does not fulfillfulfil this request within four weeks, a permit shall not be granted. By way of derogation from that Regulation (EU) 2022/868 the health data access body may extend the period for responding to a data access application by 2 additional months where necessary, taking into account the complexity of the request. In such cases, the health data access body shall notify the applicant as soon as possible that more time is needed for examining the application, together with the reasons for the delay.
19 unchanged paragraphs
Article 46 – paragraph 4: 4. Following the issuance of the data permit, the health data access body shall immediately request the electronic health data from the data holder and inform them whether the data will be made accessible in anonymised or pseudonymised form. The health data access body shall make available the electronic health data to the health data user within 2 months after receiving them from the data holders.
Article 46 – paragraph 5: 5. When the health data access body refuses to issue a data permit, it shall provide a justification for the refusal to the health data applicant.
Article 46 – paragraph 6 – introductory part: 6. The data permit shall set out the general conditions applicable to the health data user, in particular:
Article 46 – paragraph 6 – point a: (a) categories and format of electronic health data accessed, covered by the data permit, including their sources;
Article 46 – paragraph 6 – point b: (b) a detailed description of the purpose for which data are made available;
Article 46 – paragraph 6 – point b a (new): (ba) the identity of the user as well as the concrete persons who are authorised to have access to the electronic health data in the secure processing environment;
Article 46 – paragraph 6 – point d: (d) information about the technical characteristics and tools available to the health data user within the secure processing environment;
Article 46 – paragraph 6 – point e: (e) fees to be paid by the health data user;
Article 46 – paragraph 7: 7. Data users shall have the right to access and process the electronic health data in a secure processing environment in accordance with the data permit delivered to them on the basis of this Regulation.
Article 46 – paragraph 8: 8. The Commission is empowered to adopt delegated acts to amend the list of aspects to be covered by a data permit in paragraph 6 of this Article, in accordance with the procedure set out in Article 67.
Article 46 – paragraph 9: 9. A data permit shall be issued for the duration necessary to fulfil the requested purposes which shall not exceed 5 years. This duration may be extended once, at the request of the data user, based on arguments and documents to justify this extension provided, 1 month before the expiry of the data permit, for a period which cannot exceed 5 years. By way of derogation from Article 42, the health data access body may charge increasing fees to reflect the costs and risks of storing electronic health data for a longer period of time exceeding the initial 5 years. In order to reduce such costs and fees, the health data access body may also propose to the data user to store the dataset in storage system with reduced capabilities. The data within the secure processing environment shall be deleted without undue delay following the expiry of the data permit. Upon request of the data user, the formula on the creation of the requested dataset shall be stored by the health data access body.
Article 46 – paragraph 11: deleted
Article 46 – paragraph 12: deleted
Article 46 – paragraph 14: 14. The liability of health data access bodies as controller is limited to the scope of the issued data permit until the completion of the processing activity and in accordance with Article 51.
Article 47 – title: Health data request
Article 47 – paragraph 1: 1. The health data applicant may submit a health data request for the purposes referred to in Article 34 with the aim of obtaining an answer only in anonymised or aggregated statistical format. A health data access body shall not provide an answer to a health data request in any other format and the health data user shall have no access to the electronic health data used to provide this answer.
Article 47 – paragraph 2 – introductory part: 2. A health data request shall include the elements mentioned in paragraphs 2 (a) and (b) of Article 45 and if needed may also include:
Article 47 – paragraph 3: 3. The health data access body shall assess the health data request, within 2 months and, where possible, provide the result to the health data user within 2 months.
Article 48 – title: Making data available, without a data permit, for public sector bodies and Union institutions, bodies, offices and agencies with a legal mandate in the field of public health
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=8
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 29 September 2026
Cite as
European Parliament (2023). “Changes between A-9-2023-0395 and TA-9-2023-0462”. Text, 13 December 2023. from A-9-2023-0395, to TA-9-2023-0462. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=8 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-13,
author = {{European Parliament}},
title = {{Changes between A-9-2023-0395 and TA-9-2023-0462}},
year = {2023},
date = {2023-12-13},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=8}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=8},
urldate = {2026-09-29},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2023-0395, to TA-9-2023-0462. Data: European Parliament Open Data (CC BY 4.0)}
}