Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2023-0395 → TA-9-2023-0462
- From
- A-9-2023-0395 Plenary report of 5 Dec 2023
- To
- TA-9-2023-0462 Adopted text of 13 Dec 2023
- Changes
- 32 changes to the text
- Paragraphs
- +6 added · −39 removed · 30 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on the European Health Data Space
- Title (to)
- European Health Data Space
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 9 of 11: Paragraphs 481–540
Article 48 – paragraph 1: By derogation from Article 46 of this Regulation, a health data permit shall not be required to access the electronic health data under this Article. When carrying out those tasks under Article 37 (1), points (b) and (c), the health data access body shall inform public sector bodies and Union institutions, offices, agencies and bodies with a legal mandate in the field of public health, about the availability of data within 2 months of the data access application, in accordance with Article 9 of Regulation […] [Data Governance Act COM/2020/767 final]. By way of derogation from that Regulation […] [Data Governance Act COM/2020/767 final ], the health data access body may extend the period by 2 additional months where necessary, taking into account the complexity of the request. The health data access body shall make available the electronic health data to the health data user within 2 months after receiving them from the health data holders, unless it specifies that it will provide the data within a longer specified timeframe. Articles 43 and 43a shall be applicable to the situations covered under this Article.
Article 49: deleted / (deleted) / (deleted) / (deleted) / (deleted) / (deleted)
Article 50 – paragraph 1 – introductory part: 1. The health data access bodies shall provide access to electronic health data pursuant to a data permit only through a secure processing environment, with technical and organisational measures and security and interoperability requirements. In particular, they shall take the following security measures:
Change 22
ChangedArticle 50 – paragraph 1 – point b: (b) minimise the risk of the unauthorised reading, copying, modification or removal of electronic health data hosted in the secure processing environment through state-of-the-art technical and organisational mesures;measures;
7 unchanged paragraphs
Article 50 – paragraph 1 – point d: (d) ensure that health data users have access only to the electronic health data covered by their data permit, by means of individual and unique user identities and confidential access modes only;
Article 50 – paragraph 1 – point e: (e) keep identifiable logs of access to the secure processing environment for the period of time necessary to verify and audit all processing operations in that environment, and in any event for not shorter than one year;
Article 50 – paragraph 1 – point f a (new): (fa) ensure that the secure processing environment is located within the Union.
Article 50 – paragraph 2: 2. The health data access bodies shall ensure that electronic health data from health data holders in the format determined by the data permit can be uploaded by health data holders and can be accessed by the health data user in a secure processing environment. The health data users shall only be able to download or copy non-personal electronic health data from the secure processing environment, in accordance with Article 37.
Article 50 – paragraph 3: 3. The health data access bodies shall ensure regular audits, including by third parties, of the secure processing environments and take immediate corrective action for any shortcomings, risks or vulnerabilities identified in the secure processing environments.
Article 50 – paragraph 4: 4. The Commission shall, by means of implementing acts, provide for the technical, organisational, information security, confidentiality, data protection and interoperability requirements for the secure processing environments, after having consulted with ENISA. Those implementing acts shall be adopted in accordance with the advisory procedure referred to in Article 68(2).
Article 51 – title: Controllership
Change 23
ChangedArticle 51 – paragraph 1: 1. The health data holder shall be deemed controller for e the requested personal electronicdata healthmade dataavailable to the health data access body pursuant to Article 41(1) and (1a) of this Regulation. The health data access body shall be deemed controller for the processing of the personal electronic health data when fulfilling its tasks pursuant to Article 37(1), point (d), of this Regulation. The health data user shall be deemed controller for the processing of personal electronic health data in pseudonymised form in the secure processing environment pursuant to its data permit. The health data access body shall act as a processor for the processing by the health data user pursuant to a data permit in the secure processing environment.
28 unchanged paragraphs
Article 52 – paragraph 3: 3. Union institutions, bodies, offices and agencies involved in health research, health policy or analysis, shall be authorised participants of HealthData@EU.
Article 52 – paragraph 5: 5. Third countries or international organisations may become authorised participants where they comply with the rules of Chapter IV of this Regulation, where the transfer stemming from such connection complies with the rules in Chapter V of Regulation (EU) 2016/679 and Article 63a of this Regulation and where provide access to data users located in the Union, on equivalent terms and conditions, to the electronic health data available to their health data access bodies. The Commission may adopt implementing acts establishing that a national contact point of a third country or a system established at an international level is compliant with requirements of HealthData@EU for the purposes of secondary use of health data, is compliant with the Chapter IV of this Regulation and Chapter V of Regulation (EU) 2016/679 and provides access to data users located in the Union to the electronic health data it has access to on equivalent terms and conditions. The compliance with these legal, organisational, technical and security requirements, including with the standards for secure processing environments pursuant to Article 50 shall be checked under the control of the Commission. These implementing acts shall be adopted in accordance with the advisory procedure referred to in Article 68(2). The Commission shall make the list of implementing acts adopted pursuant to this paragraph publicly available.
Article 52 – paragraph 12: 12. Member States and the Commission shall seek to ensure interoperability of HealthData@EU with other relevant common European data spaces as referred to in Regulations (EU) 2022/868 and […] [Data Act COM/2022/68 final].
Article 52 – paragraph 13 – subparagraph 1 – introductory part: The Commission shall, by means of delegated acts, set out:
Article 52 – paragraph 13 – subparagraph 1 – point a: (a) requirements, technical specifications, the IT architecture of HealthData@EU, which shall ensure state-of-the-art data security, confidentiality, and protection of electronic health data in the cross border infrastructure;
Article 52 – paragraph 13 – subparagraph 1 – point a a (new): (aa) conditions and compliance checks for authorised participants to join and remain connected to HealthData@EU and conditions for temporary or definitive exclusion from HealthData@EU, including specific provisions for cases of serious misconduct or repeated violation;
Article 52 – paragraph 13 – subparagraph 2: The Commission shall consult with the ENISA in the drawing up of the delegated act.
Article 53 – title: Access to cross-border registries and databases for secondary use
Article 54 – title: Cross-border access to and mutual recognition of data permits
Article 54 – paragraph 1: 1. When handling an access application for cross-border access to electronic health data for secondary use, health data access bodies and relevant authorised participants shall remain responsible for taking decisions to grant or refuse access to electronic health data within their remit in accordance with the requirements for access laid down in this Chapter. After a decision has been made regarding the granting or refusal of the health data permit, the health data access body shall inform the other health data bodies concerned by the same application about the decision.
Article 55 – title: Dataset description and dataset catalogue
Article 56 – paragraph 2 a (new): 2a. The health data access body shall assess whether the data meets the requirements in paragraph 3 and shall revoke the label in the event the data does not meet the required quality.
Article 56 – paragraph 3 – introductory part: 3. The data quality and utility label shall cover the following elements:
Article 57 – paragraph 1: 1. The Commission shall establish an EU Datasets Catalogue connecting the national catalogues of datasets established by the health data access bodies and other authorised participants in HealthData@EU taking into consideration the health interoperability resources already developed across the Union.
Article 59 – paragraph 1: The Commission shall support sharing of best practices and expertise, aimed to build the capacity of Member States to strengthen digital health systems for primary and secondary use of electronic health data. To support capacity building, the Commission shall draw up benchmarking guidelines for the primary and secondary use of electronic health data. The Commission shall issue guidance with regard to compliance of data holders with the provisions of Chapter IV, taking into account the specific conditions of data holders that are civil society, researchers, medical societies and SMEs.
Article 59 a (new): Article 59a / Digital health literacy and digital health access / 1. In order to ensure successful implementation of the EHDS, Member States shall support digital health literacy, promote public awareness, including through educational programmes for natural persons, health professionals and stakeholders, to inform the public of the rights and obligations in the EHDS and inform natural persons of the advantages, risks and potential gains to science and society of the primary and secondary use of electronic health data, and offer free of charge accessible training to health professionals in this regard. Those programmes shall be tailored to the needs of specific groups and shall be developed and reviewed, and where necessary updated, on a regular basis in consultation and cooperation with relevant experts and stakeholders. / The Commission shall support Member States in this regard. / 2. Member States shall monitor and evaluate, on a regular basis, the digital health literacy of health professionals and natural persons, in particular about the primary and secondary use of health data, functionalities and conditions as well as rights of natural persons within the EHDS. / 3. Member States shall promote the access to the infrastructure necessary for the effective management of natural persons’ electronic health data, both within primary and secondary use. / 4. Member States shall regularly inform the public at large about the role and benefits of the secondary use of health data …
Article 60 – paragraph 2 a (new): 2a. Public procurers, national competent authorities, including digital health authorities and health data access bodies, and the Commission shall require, as a condition to procure or fund services provided by controllers and processors established in the Union processing personal electronic health data, that such controllers and processors: / (a) store those data in the Union, in accordance with Article 60a of this Chapter: and / (b) have duly demonstrated that they are not subject to third country law conflicting with Union data protection rules.
Article 60 a (new): Article 60a / Storage of personal electronic health data / For the purposes of primary and secondary use of personal electronic health data, the storage of personal electronic health data shall exclusively take place within the territory of the Union, without prejudice to the provisions of Article 63.
Article 61 – title: Sensitive nature of non-personal electronic health data
Article 61 – paragraph 1: 1. Non-personal electronic health data made available by health data access bodies, that are based on a natural person’s electronic data falling within one of the categories of Article 33 shall be deemed highly sensitive within the meaning of Article 5(13) of Regulation […] [Data Governance Act COM/2020/767 final].
Article 61 – paragraph 2: 2. The protective measures for the categories of data mentioned in paragraph 1 shall be detailed in the Delegated Act under the empowerment set out in Article 5(13) of Regulation (EU) 2022/868.
Article 63 – paragraph 1: International access and transfer of personal electronic health data shall be granted in accordance with Chapter V of Regulation (EU) 2016/679. Member States may maintain or introduce further conditions on international access to, and transfer of, personal electronic health data, including limitations, in accordance with and under the conditions of article 9(4) of the Regulation (EU) 2016/679.
Article 63 a (new): Article 63a / Reciprocity of access to electronic health data for secondary use / 1. Notwithstanding Articles 62 and 63, only entities and bodies that are established in third countries included in the list referred to in paragraph 2 shall be allowed access to electronic health data in the secure processing environment and have the possibility of downloading non-personal electronic health data held in the Union for the purposes of secondary use. / 2. The Commission is empowered to adopt delegated acts in accordance with Article 67 supplementing this Regulation by setting up a list of third countries which are considered to provide for equivalent access to, and transfer of, electronic health data of its data holders for the purposes of secondary use of electronic health data by entities and bodies within the Union. / 3. The Commission shall monitor the list of third countries benefiting from such access, and shall provide for a periodic review of the functioning of this Article. / 4. Where the Commission considers that a third country no longer meets the requirement to be included on the list referred to in paragraph 2, it shall adopt a delegated act to remove such third country that benefits from access.
Article 64 – paragraph 1: 1. A European Health Data Space Board (EHDS Board) is hereby established to facilitate cooperation and the exchange of information among Member States. The EHDS Board shall be composed of, one high level representative of digital health authorities and one high level representative of health data access bodies per Member State appointed by the Member State concerned. Where a Member State has designated several health data access bodies, the representative of the coordinating health data access body shall be a member of the EHDS Board; / Other national authorities, including market surveillance authorities referred to in Article 28, European Data Protection Board and European Data Protection Supervisor and Union agencies within the field of public health and cybersecurity shall also be invited to the meetings, where the issues discussed are of relevance for them. The Board may invite stakeholders, experts and observers to attend its meetings, and may cooperate with other external experts as appropriate. Other Union institutions, bodies, offices and agencies, research infrastructures and other similar structures may have an observer role. The EHDS Board shall invite a representative of the European Parliament to attend its meetings as an observer.
Article 64 – paragraph 2: Members of the EHDS Board shall not have financial or other interests in industries or economic activities which could affect their impartiality. They shall undertake to act in the public interest and in an independent manner, and shall make an annual declaration of their financial interests. All indirect interests which could relate to such industries or economic activities shall be entered in a register held by the Commission which is accessible to the public, upon request, at the Commission’s offices. / The EHDS Board’s code of conduct shall make reference to the application of this Article, in particular in relation to the acceptance of gifts.
Article 64 – paragraph 3: 3. The EHDS Board shall adopt rules of procedure and a code of conduct, following a proposal from the Commission. Those rules of procedure shall provide for the composition, organisation, functioning and cooperation of the Board and its cooperation with the Advisory Board.
Article 64 – paragraph 4: deleted
Article 64 – paragraph 5: 5. The EHDS Board shall cooperate with other relevant bodies, entities and experts, such as the European Data Innovation Board referred to in Article 26 of Regulation […] [Data Governance Act COM/2020/767 final], competent bodies set up under Article 7 of Regulation […] [Data Act COM/2022/68 final], supervisory bodies set up under Article 17 of Regulation […] [eID Regulation], European Data Protection Board referred to in Article 68 of Regulation (EU) 2016/679 and cybersecurity bodies, in particular the ENISA.
Change 24
ChangedArticle 64 – paragraph 7 a (new): 7 a.7a. The EHDS Board shall publish meeting dates and minutes of the discussions and publish an annual report on its activities.
4 unchanged paragraphs
Article 64 – paragraph 8: 8. The Commission shall, by means of implementing acts, adopt the necessary measures for the establishment and operations of the EHDS Board. Those implementing acts shall be adopted in accordance with the advisory procedure referred to in Article 68(2).
Article 64 a (new): Article 64a / Advisory forum / 1. An advisory forum to advise the EHDS Board in the fulfilment of its tasks by providing stakeholder input in matters covered by this Regulation is hereby established. / 2. The advisory forum shall be composed of relevant stakeholders, including representatives of patients’ organisations, health professionals, industry, consumer organisations, scientific researchers and academia. The advisory forum shall have a balanced composition and represent the views of different relevant stakeholders. / Where commercial interests are represented in the advisory forum, they shall be balanced between large companies, SMEs and start-ups. Focus on primary and secondary use of electronic health data shall also be balanced. / 3. Members of the advisory forum shall be appointed by the Commission following a public call for interest and a transparent selection procedure, in consultation with the European Parliament. Members of the advisory forum shall make an annual declaration of their interests, which shall be updated whenever relevant and shall be made publicly available. / 4. The term of office of the members of the advisory forum shall be two years and it shall be renewable only once consecutively. / 5. The advisory forum may establish standing or temporary subgroups as appropriate for the purpose of examining specific questions related to the objectives of this Regulation. / 6. The advisory forum shall draw up its rules of procedure and elect one co-chair f…
Article 65 – paragraph -1 (new): -1. The EHDS Board shall promote the consistent application of this Regulation.
Article 65 – paragraph 1 – point b – introductory part: (b) to issue written contributions and to exchange best practices on matters related to the coordination of the implementation at Member State level of this Regulation and of the delegated and implementing acts adopted pursuant to it, taking into account the regional and local level, in particular as regards:
Change 25
ChangedArticle 65 – paragraph 1 – point b – point iii: (iii) other aspects of the primary use of electronic health data without prejudice to the powers of the supervisory authorities pursuant to Regulation (EU) 2016/679; the written contributions of the EHDS board shall not concern the interpretation or application of rights and obligations under Regulation (EU) 2016/679 or Regulation 2018/175.(EU) 2018/1725.
14 unchanged paragraphs
Article 65 – paragraph 1 – point b a (new): (ba) to provide guidance and recommendations to digital health authorities;
Article 65 – paragraph 1 – point d: (d) to share among the Members of the Board information concerning risks posed by EHR systems and serious incidents as well as their handling, without prejudice to the obligation to inform competent supervisory authorities pursuant to Regulation (EU) 2016/679;
Article 65 – paragraph 1 – point e: (e) to facilitate the exchange of views on the primary use of electronic health data with the Advisory Forum referred to in Article 64(a), regulators and policy makers in the health sector to support the design of aligned implementation strategies, guidance and standards and to assess the needs for further improvement. In addition, the co-chairs of the advisory forum shall be invited at least once annually to a meeting of the EHDS Board to present its activities.
Article 65 – paragraph 2 – point b – point v: deleted
Article 65 – paragraph 2 – point b – point vi: (vi) other aspects of the secondary use of electronic health data without prejudice to the powers of the supervisory authorities pursuant to Regulation (EU) 2016/679.
Article 65 – paragraph 2 – point c: (c) to facilitate cooperation and exchange of best practices between health data access bodies through capacity-building, establishing the structure for annual activity reporting, peer-review of annual activity reports and exchange of information pursuant to the obligations laid down in Article 37(1), point (q);
Article 65 – paragraph 2 – point d: (d) to share information concerning risks and data protection incidents related to secondary use of electronic health data, as well as their handling; without prejudice to the obligation to inform competent supervisory authorities pursuant to Regulation (EU) 2016/679;
Article 65 – paragraph 2 – point f: (f) to exchange views on the secondary use of electronic health data with the Advisory Forum referred to in Article 64(a) regulators and policy makers in the health sector, to support the design of aligned implementation strategies, guidance and standards and to assess the needs for further improvement;
Article 65 – paragraph 2 – point f a (new): (fa) adopt recommendations to facilitate consistent provision of the secure processing environment compliant with the technical, information security and interoperability requirements.
Article 65 – paragraph 2 a (new): 2a. The EHDS board shall provide recommendations to the Commission and the Member States on the implementation and enforcement of this Regulation, including cross-border interoperability of health data, and potential mechanisms of funding support to ensure equal development of health data systems across Europe in respect of the secondary use of electronic health data, without prejudice to the competences of the EDPB, where personal electronic health data are concerned;
Article 65 – paragraph 2 b (new): 2b. The EHDS board may commission studies and other initiatives in order to support the implementation and development of the EHDS.
Article 65 – paragraph 2 c (new): 2c. The EHDS Board shall publish an annual report to include the implementation status of the EHDS and other relevant points of development, including with respect to cross-border health data interoperability, and related implementation challenges.
Article 66 – paragraph 3: 3. Stakeholders and relevant third parties, including patients’, health professionals’, consumers’ and industry representatives, may be invited to attend meetings of the groups and to participate in their work.
Article 66 – paragraph 6 a (new): 6a. The groups shall consult relevant experts when carrying out their tasks, as well as on technical implementing measures related to cybersecurity, confidentiality and data protection, in particular experts from ENISA, EDPB and EDPS.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=9
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 29 September 2026
Cite as
European Parliament (2023). “Changes between A-9-2023-0395 and TA-9-2023-0462”. Text, 13 December 2023. from A-9-2023-0395, to TA-9-2023-0462. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=9 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-13,
author = {{European Parliament}},
title = {{Changes between A-9-2023-0395 and TA-9-2023-0462}},
year = {2023},
date = {2023-12-13},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=9}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0395/compare/TA-9-2023-0462?all=1&part=9},
urldate = {2026-09-29},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2023-0395, to TA-9-2023-0462. Data: European Parliament Open Data (CC BY 4.0)}
}