Skip to content

Text · Comparison of two versions

Changes from adopted text to adopted text

TA-9-2023-0462 → TA-9-2024-0331

From
TA-9-2023-0462 Adopted text of 13 Dec 2023
To
TA-9-2024-0331 Adopted text of 24 Apr 2024
Changes
Not comparable
Paragraphs
+19 added · −542 removed · 1 changed
More facts (2)
Title (from)
European Health Data Space
Title (to)
European Health Data Space

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 2 of 10: Paragraphs 61–120

RemovedRecital 37 a (new): (37a) In the case where the health data user has access to electronic health data for secondary use of data for one of the purposes defined in this Regulation, the health data user should demonstrate the specific legal ground on which it relies as part of the application for access to electronic health data pursuant to this Regulation, namely, on the basis of the applicable law, where the legal basis under Regulation (EU) 2016/679 is Article 6(1), point (e), or Article 6(1), point (f), thereof. If the health data user relies upon the ground provided for in Article 6(1), point (e), it should make reference to another Union or national law, requiring the user to process personal health data for the compliance of its tasks. If the ground for processing by the health data user is Article 6(1), point (f), of Regulation (EU) 2016/679, appropriate and necessary safeguards should be determined in accordance with this Regulation. In this context, the data permits issued by the health data access bodies should be an administrative decision defining the conditions for the access to the data.

RemovedRecital 38: (38) In the context of the EHDS, the electronic health data already exists and is being collected by healthcare providers, professional associations, public institutions, regulators, researchers, insurers etc. in the course of their activities. Some categories of data are collected primarily for the provisions of healthcare (e.g. electronic health records, genetic data, claims data, etc.), others are collected also for other purposes such as research, statistics, patient safety, regulatory activities or policy making (e.g. disease registries, policy making registries, registries concerning the side effects of medicinal products or medical devices, etc.). For instance, European databases that facilitate data (re)use are available in some areas, such as cancer (European Cancer Information System) or rare diseases (European Platform on Rare Disease Registration, ERN registries, etc.). These data should also be made available for secondary use. However, much of the existing health-related data is not made available for purposes other than that for which they were collected. This limits the ability of researchers, innovators, policy-makers, regulators and doctors to use those data for different purposes, including research, innovation, policy-making, regulatory purposes, patient safety or personalised medicine. In order to fully unleash the benefits of the secondary use of electronic health data, all health data holders should contribute to this effort in making different categori…

RemovedRecital 39: (39) The categories of electronic health data that can be processed for secondary use should be broad and flexible enough to accommodate the evolving needs of health data users, while remaining limited to data related to health or known to influence health. It can also include relevant data from the health system (electronic health records, claims data, disease registries, genomic data etc.), as well as data with an impact on health (for example consumption of different substances, socio-economic status, behaviour, including environmental factors (for example, pollution, radiation, use of certain chemical substances). They can also include automatically generated data from medical devices and person-generated data, such as wellness applications. The health data user who benefits from access to datasets provided under this Regulation could enrich the data with various corrections, annotations and other improvements, for instance by supplementing missing or incomplete data, thus improving the accuracy, completeness or quality of data in the dataset. Health data users should be encouraged to report critical errors in datasets to health data access bodies. To support the improvement of the original database and further use of the enriched dataset, the dataset with such improvements and a description of the changes should be made available free of charge to the original data holder. The data holder should make available the new dataset, unless it provides a justified notification …

RemovedRecital 39 a (new): (39a) In order to guarantee trust in the patient-physician relationship, the principle of professional secrecy and the patient's right to confidentiality should be safeguarded when digitalising healthcare services. A relationship of trust between patients and health professionals and healthcare providers and other holders of personal health data is a paramount element of the provision of health or social care or treatment. It is within that context that the patient or the legal representative of the patient should have a say in the processing of their health data for secondary use in the form of a right to opt-out of the processing of all or parts of their health data for secondary use for some or all purposes. An easily understandable and accessible opt-out mechanism in a user-friendly format should be provided for in this regard. However, due to the sensitive nature of human genetic, genomic and proteomic data, data from biobanks and to the nature of the use of data from wellness applications, it is appropriate to provide that the secondary use of such data can only occur following the consent of the natural person concerned in accordance with Article 4(11) of the Regulation (EU) 2016/679. An opt-in mechanism whereby data subjects explicitly consent or give their permission to the processing of part or all of such data for some or all secondary use purposes should be envisaged. Where data subjects explicitly consent to the use of parts or all of this data for some or all se…

RemovedRecital 40: (40) The health data holders in the context of secondary use of electronic health data can be public, non for profit or private health or care providers, public, non for profit and private organisations, associations or other entities, public and private entities that carry out research with regards to the health sector that process the categories of health and health related data mentioned above To the extent that they process personal electronic health data, health data holders are controllers within the meaning of Regulation (EU) 2016/679 in the health or care sector. In order to avoid a disproportionate burden on small entities, micro-enterprises are excluded from the obligation to make their data available for secondary use in the framework of EHDS. Health data access bodies should provide specific support to small enterprises, in particular medical practitioners and pharmacies, in complying with their obligation to make data available for secondary use. The public or private entities often receive public funding, from national or Union funds to collect and process electronic health data for research, statistics (official or not) or other similar purposes, including in area where the collection of such data is fragmented of difficult, such as rare diseases, cancer etc. Such data, collected and processed by health data holders with the support of Union or national public funding, should be made available by health data holders to health data access bodies, in order to max…

RemovedRecital 40 a (new): (40a) Different demographic groups have varying degrees of digital literacy, which can affect natural persons’ ability to exercise their rights to control their electronic health data. In addition to the right for natural persons to authorise another natural person of their choice to access or control their electronic health data on their behalf, Member States should create targeted national digital literacy programmes, including programmes to maximise social inclusion and to ensure all natural persons can effectively exercise their rights under this Regulation. Member States should also provide patient-centric guidance to natural persons in relation to the use of electronic health records and primary use of their personal electronic health data. Guidance should be tailored to the patient’s level of digital health literacy, with specific attention to be given to the needs of vulnerable groups.

RemovedRecital 40 b (new): (40b) Clinical trials and studies are of utmost importance in fostering innovation within the Union for the benefit of Union patients. In order to incentivise continuous Union leadership in this domain, the sharing of the clinical trials data through the EHDS for secondary use should be consistent with the relevant transparency provisions laid down in Union law including Regulation (EU) .../... [proposal for a Regulation on blood, tissue, cells and organs (SoHO) COM(2022)338 final], Regulations (EC) No 726/20041a and (EU) 2019/61b of the European Parliament and of the Council and Directive 2001/83/EC of the European Parliament and of the Council1c regarding veterinary and human medicines and establishing the EMA, Regulation (EC) No 141/2000 of the European Parliament and of the Council1d related to medicinal products for rare diseases (‘orphan medicines’), Regulation (EC) No 1901/2006 of the European Parliament and of the Council1e on medicinal products for children, Regulation (EC) No 1394/2007 of the European Parliament and of the Council1f on advanced therapy medicinal products, Regulation (EU) No 536/2014 of the European Parliament and of the Council1g on clinical trials, Regulation (EU) No 2017/745 and Regulation (EU) No 2017/746. / 1a Regulation (EC) No 726/2004 of the European Parliament and of the Council of 31 March 2004 laying down Community procedures for the authorisation and supervision of medicinal products for human and veterinary use and establishing a Europea…

RemovedRecital 41: (41) The secondary use of health data under EHDS should enable the public, private, not for profit entities, as well as individual researchers, with a demonstrated link to the field of public health, to have access to health data for research, innovation, policy making, educational activities, patient safety, regulatory activities or personalised medicine, in line with the purposes set out in this Regulation. Access to data for secondary use should contribute to the general interest of the society. In particular, the secondary use of health data for research and development purposes should contribute to a benefit to society in the form of new medicines, medical devices, health care products and services at affordable and fair prices for Union citizens, as well as to enhancing access to and the availability of such products and services in all Member States. Activities for which access in the context of this Regulation is lawful may include using the electronic health data for tasks carried out by public bodies, such as exercise of public duty, including public health surveillance, planning and reporting duties, health policy making, ensuring patient safety, quality of care, and the sustainability of health care systems. Public bodies and Union institutions, bodies, offices and agencies may require to have regular access to electronic health data for an extended period of time, including in order to fulfil their mandate, which is provided by this Regulation. Public sector bodi…

RemovedRecital 42: (42) The establishment of one or more health data access bodies, supporting access to electronic health data in Member States, is an essential component for promoting the secondary use of health-related data. Member States should therefore establish one or more health data access body, for instance to reflect their constitutional, organisational and administrative structure. However, one of these health data access bodies should be designated as a coordinator in case there are more than one data access body. Where a Member State establishes several bodies, it should lay down rules at national level to ensure the coordinated participation of those bodies in the EHDS Board. That Member State should in particular designate one health data access body to function as a single contact point for the effective participation of those bodies, and ensure swift and smooth cooperation with other health data access bodies, the EHDS Board and the Commission. Health data access bodies may vary in terms of organisation and size (spanning from a dedicated full-fledged organization to a unit or department in an existing organization) but should have the same functions, responsibilities and capabilities. Health data access bodies should not be influenced in their decisions on access to electronic data for secondary use, Members of the governance and decision-making bodies and staff of each health data access body should therefore refrain from any action that is incompatible with their duties and…

RemovedRecital 43: (43) The health data access bodies should monitor the application of Chapter IV of this Regulation and contribute to its consistent application throughout the Union. For that purpose, the health data access bodies should cooperate with each other and with the Commission, without the need for any agreement between Member States on the provision of mutual assistance or on such cooperation. The health data access bodies should also cooperate with stakeholders, including patient organisations. The selection procedure for health stakeholders should be transparent, public and free of any conflict of interest. Since the secondary use of health data involves the processing of personal data concerning health, the relevant provisions of Regulation (EU) 2016/679 apply and the supervisory authorities under Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 should remain the only authorities competent for enforcing these rules. Moreover, given that health data are sensitive data and in a duty of loyal cooperation, the health data access bodies should inform the data protection authorities of any issues related to the data processing for secondary use, including administrative fines and enforcement measures. In addition to the tasks necessary to ensure effective secondary use of health data, the health data access body should strive to expand the availability of additional health datasets, and promote the development of common standards. They should apply tested state-of-the-art techni…

RemovedRecital 44: (44) Health data access bodies should comply with the obligations laid down in Article 14 of Regulation (EU) 2016/679 and inform the natural persons whose data are used in data projects within a secure processing environment. The exceptions provided for in Article 14(5) of Regulation (EU) 2016/679 could apply. Where such exceptions are applied, health data access bodies should provide general information concerning the conditions for the secondary use of their health data containing the information items listed in Article 14(1) and, where necessary to ensure fair and transparent processing, Article 14(2) of Regulation (EU) 2016/679, e.g. information on the purpose and the data categories processed, enabling natural persons to understand whether their data are being made available for secondary use pursuant to data permits. Exceptions from this rule should be made when the results of the research could assist in the treatment of the natural person concerned. In this case, the health data user should inform the health data access body, which should inform the health professional treating the natural person concerned or, in the event that the treating health professional is not traceable, the natural person, with due regard for their stated wish not to be informed, while fully respecting the principles of medical confidentiality and professional secrecy. Natural persons should be able to access the results of different research projects on the website of the health data access b…

RemovedRecital 46: (46) In order to support the secondary use of electronic health data, the data holders should refrain from withholding the data, requesting unjustified fees that are not transparent nor proportionate with the costs for making data available (and, where relevant, with marginal costs for data collection), requesting the data users to co-publish the research or other practices that could dissuade the data users from requesting the data. Where ethical approval is necessary for providing a data permit, its evaluation should be based on its own merits. On the other hand, public sector bodies and Union institutions, bodies, offices and agencies with a legal mandate in the field of public health, have very important and insightful data. Access to data of such institutions, bodies, offices and agencies should be granted through the health data access body where the controller is located.

RemovedRecital 47: (47) Health data access bodies should be allowed to charge fees based on the applicable provisions under this Regulation and the provisions of Regulations (EU) .../... […] [Data Governance Act COM/2020/767 final] and (EU) .../... […] [Data Act COM/2022/68 final] in relation to their tasks. Such fees may take into account the situation and interest of SMEs, individual researchers or public bodies. Health data holders should be allowed to also charge fees for making data available. Such fees should reflect the costs for providing such services. Private health data holders may also charge fees for the collection of data. In order to ensure a harmonised approach concerning fee policies and structure, the Commission should adopt implementing acts. Provisions in Article 10 of the Regulation [Data Act COM/2022/68 final] should apply for fees charged under this Regulation. Public sector bodies and Union institutions, bodies, offices and agencies with a legal mandate in the field of public health should not be charged fees.

RemovedRecital 48: (48) In order to strengthen the enforcement of the rules on the secondary use of electronic health data, appropriate measures should be envisaged that can lead to administrative fines or enforcement measures by health data access bodies or temporary or definitive exclusions from the EHDS framework of the health data users or health data holders that do not comply with their obligations. The health data access body should be empowered to verify compliance and give health data users and holders the opportunity to reply to any findings and to remedy any infringement. When deciding on the amount of the administrative fine or enforcement measure for each individual case, health data access bodies should take into account the margins for costs and criteria set out in this Regulation.

RemovedRecital 49: (49) Given the sensitivity of electronic health data, it is necessary to reduce risks on the privacy of natural persons by applying the data minimisation principle as set out in Article 5 (1), point (c) of Regulation (EU) 2016/679. Therefore, common standards for data anonymisation should be further developed and the use of anonymised electronic health data which is devoid of any personal data should be made available when possible. If the data user needs to use personal electronic health data, it should clearly indicate in its request the justification for the use of this type of data for the planned data processing activity and the health data access body should determine the validity of that justification. The personal electronic health data should only be made available in pseudonymised format and the encryption key can only be held by the health data access body. When providing access to an anonymised or pseudonymised dataset, a health data access body should use state-of-the-art anonymisation or pseudonymisation technology, ensuring to the maximum extent possible that natural persons cannot be re-identified. Health data users should not attempt to re-identify natural persons from the dataset provided under this Regulation, subject to administrative fines and the enforcement measures laid down in this Regulation or possible criminal penalties, where the national laws foresee this. However, this should not prevent, in cases where the results of a project carried out based…

RemovedRecital 50: (50) In order to ensure that all health data access bodies issue permits in a similar way, it is necessary to establish a standard common process for the issuance of data permits, with similar requests in different Member States. The health data applicant should provide health data access bodies with several information elements that would help the body evaluate the application and decide if the applicant may receive a data permit for secondary use of data, also ensuring coherence between different health data access bodies. Such information includes: the legal basis under Regulation (EU) 2016/679 to request access to data (exercise of a task in the public interest assigned by law or legitimate interest), purposes for which the data would be used, the identity of the health data applicant as well as the specific persons who are authorised to have access to the electronic health data in the secure processing environment and how they are qualified vis-à-vis the intended secondary use, description of the needed data and possible data sources, a description of the tools needed to process the data, as well as characteristics of the secure environment that are needed, a description of the safeguards planned to prevent any other use, misuse or possible re-identification, and an explanation of the expected benefits of the secondary use. Where data is requested in pseudonymised format, the health data applicant should explain why this is necessary and why anonymous data would not suff…

RemovedRecital 50 a (new): (50a) A standard ethics assessment should be carried out by ethics bodies within health data access bodies. Such assessment should be an important part of the process. However, where the health data applicant had previously obtained the approval of the competent ethics committee in accordance with national law for research purposes for which they are requesting data through the EHDS, the health data applicant should make that information available to the health data access body as part of the data access application.

RemovedRecital 51: (51) As the resources of health data access bodies are limited, they can apply prioritisation rules, for instance prioritising public institutions before private entities, but they should not make any discrimination between the national or from organisations from other Member States within the same category of priorities. The health data user should be able to extend the duration of the data permit in order, for example, to allow access to the datasets to reviewers of scientific publication or to enable additional analysis of the dataset based on the initial findings. This would require an amendment of the health data permit and may be subject to an additional fee. However, in all the cases, the data permit should reflect theses additional uses of the dataset. Preferably, the health data user should mention them in their initial request for the issuance of the data permit. In order to ensure a harmonised approach between health data access bodies, the Commission should support the harmonisation of data permit.

RemovedRecital 52: (52) As the COVID-19 crisis has shown, the Union institutions, bodies, offices and agencies with a legal mandate in the field of public health, especially the Commission, need access to health data for a longer period and on a recurring basis. This may be the case not only for specific circumstances stipulated by Union or national law in times of crisis but also to provide scientific evidence and technical support for Union policies on a regular basis. Access to such data may be required in specific Member States or throughout the whole territory of the Union.

RemovedRecital 53: deleted

RemovedRecital 54: (54) Given the sensitivity of electronic health data, data users should not have an unrestricted access to such data, in accordance with the data minimisation principle. All secondary use access to the requested electronic health data should be done through a secure processing environment. In order to ensure strong technical and security safeguards for the electronic health data, the health data access body should provide access to such data in a secure processing environment, complying with the high technical and security standards set out pursuant to this Regulation. Some Member States took measures to locate such secure environments in Europe. The processing of personal data in such a secure environment should comply with Regulation (EU) 2016/679, including, where the secure environment is managed by a third party, the requirements of Article 28 and, where applicable, Chapter V. Nevertheless, in order to ensure the proper supervision and security of personal data, such environments need to be located in the Union if they are used to access personal health data. Such secure processing environment should reduce the privacy risks related to such processing activities and prevent the electronic health data from being transmitted directly to the data users. The health data access body or the data holder providing this service should remain at all time in control of the access to the electronic health data with access granted to the data users determined by the conditions of the…

RemovedRecital 55: (55) For the processing of electronic health data in the scope of a granted permit, the health data holders, the health data access bodies and the health data users should each, in turn, be deemed a controller for a specific part of the process and according to their respective roles therein. The health data holder should be deemed controller for the disclosure of the requested personal electronic health data to the health data access body, while the health data access body should in turn be deemed controller for the processing of the personal electronic health data when preparing the data and making them available to the health data user. The health data user should be deemed controller for the processing of personal electronic health data in pseudonymised form in the secure processing environment pursuant to its data permit. The health data access body should be deemed a processor for processing carried out by the health data user pursuant to a data permit in the secure processing environment. HealthData@EU should accelerate the secondary use of electronic health data while increasing legal certainty, respecting the privacy of natural persons and being interoperable. Due to the sensitivity of health data, principles such as “privacy by design”, “privacy by default”, and “bring questions to data instead of moving data” should be respected whenever possible. Authorised participants in HealthData@EU could be health data access bodies, research infrastructures established as an…

RemovedRecital 59: (59) Information on the quality and utility of datasets increases the value of outcomes from data intensive research and innovation significantly, while, at the same time, promoting evidence-based regulatory and policy decision-making. Improving the quality and utility of datasets through informed customer choice and harmonising related requirements at Union level, taking into account existing Union and international standards, guidelines, recommendations for data collection and data exchange (i.e. FAIR principles: Findable, Accessible, Interoperable and Reusable), benefits also data holders, health professionals, natural persons and the Union economy overall. A data quality and utility label for datasets would inform data users about the quality and utility characteristics of a dataset and enable them to choose the datasets that best fit their needs. The data quality and utility label should not prevent datasets from being made available through the EHDS, but provide a transparency mechanism between data holders and data users. For example, a dataset that does not fulfil any requirement of data quality and utility should be labelled with the class representing the poorest quality and utility, but should still be made available. Expectations set in frameworks described in Article 10 of Regulation […] [AI Act COM/2021/206 final] and its relevant documentation specified in Annex IV should be taken into account when developing the data quality and utility framework. The labels s…

RemovedRecital 61: (61) Cooperation and work is ongoing between different professional organisations, the Commission and other institutions to set up minimum data fields and other characteristics of different datasets (registries for instance). This work is more advanced in areas such as cancer, rare diseases, cardiovascular and metabolic diseases, risk factor assessment, and statistics and shall be taken into account when defining new standards and disease-specific harmonised templates for structured data elements. However, many datasets are not harmonised, raising comparability issues and making cross-border research difficult. Therefore, more detailed rules should be set out in implementing acts to ensure a harmonised provision, coding and registration of electronic health data. Member States should work towards delivering sustainable economic and social benefits of European electronic health systems and services and interoperable applications, with a view to achieving a high level of trust and security, enhancing continuity of healthcare and ensuring access to safe and high-quality healthcare. Existing health data infrastructures and registries put in place by institutions and stakeholders can contribute to defining and implementing data standards, to ensuring interoperability and should be leveraged to allow for continuity and build on existing expertise.

RemovedRecital 62 a (new): (62a) Improving digital health literacy for both natural persons and their health professionals is key in order to achieve trust, safety and appropriate use of health data and thus to achieve successful implementation of this Regulation. Improving digital health literacy is fundamental in order to empower natural persons to have true control over their health data and actively manage their health and care, and understand the implications of the management of such data for both primary and secondary use. Member States, including regional and local authorities, should therefore support digital health literacy and public awareness, while ensuring that the implementation of this Regulation contributes to reducing inequalities and does not discriminate against people lacking digital skills. Particular attention should be given to persons with disabilities and vulnerable groups including migrants and the elderly. Health professionals and IT operators should have sufficient training in working with new digital infrastructures to ensure cybersecurity and ethical management of health data.

RemovedRecital 63: (63) The use of funds should also contribute to attaining the objectives of the EHDS. Public procurers, national competent authorities in the Member States, including digital health authorities and health data access bodies, as well as the Commission should make references to applicable technical specifications, standards and profiles on interoperability, security and data quality, as well as other requirements developed under this Regulation when defining the conditions for public procurement, calls for proposals and allocation of Union funds, including structural and cohesion funds. To procure or fund services provided by controllers and processors established in the Union that process personal electronic health data, they should be required to demonstrate that they will store the data in the Union and that they are not subject to third country law that conflicts with Union data protection rules. Union funds should be distributed transparently and sufficiently among the Member States, ensuring it is adequate and taking into account different levels of health system digitalisation and the costs involved in making national data infrastructures interoperable and compatible with the requirements of the EHDS. Making data available for secondary use requires additional resources for healthcare systems, in particular public systems. That additional burden for public entities should be addressed and minimised to the greatest possible extent during the implementation phase of the EH…

RemovedRecital 63 a (new): (63a) The economic costs of implementing this Regulation should be borne at both Member State and Union level, and a fair sharing of that burden between national and Union funds should be found. The initial Union funding to achieve a timely application of the EHDS is limited to what can be mobilised under the 2021-2027 Multiannual Financial Framework (MFF) where EUR 220 million can be made available under the EU4Health and Digital Europe programmes. The successful and coherent application of the EHDS across all Member States will however require higher funding. The implementation of the EHDS requires appropriate investments in capacity building and training and a well-funded commitment to public consultation and engagement. The Commission should therefore mobilise further resources for the EHDS as part of the review of the 2021-2027 MFF and for the forthcoming MFF under the principle that new initiatives should be matched with new funding.

RemovedRecital 64 a (new): (64a) The functioning of the EHDS involves processing of a large quantity of personal and non-personal health data of a highly sensitive nature. Article 8(3) of the Charter of Fundamental Rights of the European Union (the ‘Charter’) requires control over the processing of such health data by an independent authority. The control of the compliance with the requirements of protection and security by an independent supervisory authority, carried out on the basis of Union law, is an essential component of the protection of individuals with regard to the processing of personal data and cannot be fully ensured in the absence of a requirement to retain the electronic health data in question within the Union. Therefore, taking into account the need to mitigate the risks of unlawful access and ineffective supervision, in compliance with the principle of proportionality, this Regulation should require Member States to store electronic health data within the Union. Such storage requirements should ensure a uniform high level of protection for data subjects across the Union, preserve the proper functioning of the internal market, in line with Article 114 TFEU, which constitutes the legal basis of this Regulation, and serve to enhance citizens’ trust in the EHDS.

RemovedRecital 64 b (new): (64b) The obligation to store electronic health data in the Union does not preclude transfers of those data to third countries or international organisations by means of granting access to electronic health data. Access to data through the secure processing environment can entail the transfer of personal data, as defined in Chapter V of Regulation (EU) 2016/679. It is possible to reconcile a general requirement to store personal data in the Union with specific transfers being allowed in compliance with Union law on personal data protection, for instance in the context of scientific research, provision of care or international cooperation. In particular, when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organisations, the level of protection of natural persons ensured in the Union under Regulation (EU) 2016/679 should not be undermined, including in cases of onward transfers of personal data from the third country or international organisation to controllers, processors in the same or another third country or international organisation. Transfers of personal health data to third countries and international organisations can only be carried out in full compliance with Chapter V of Regulation (EU) 2016/679. For instance, controllers and processors processing personal electronic health data remain subject to Article 48 of that Regulation on transfers or disclosures not authorised by Union law an…

RemovedRecital 64 c (new): (64c) Access to electronic health data for entities from third countries should take place only on the basis of the reciprocity principle. Making available of health data to a third country can take place only where the Commission has established by means of a delegated act that the third country concerned allows for the use of health data by Union entities under the same conditions and with the same safeguards as within the Union. The Commission should monitor that list and provide for a periodic review thereof. Where the Commission finds that a third country no longer ensures access on the same terms, that third country should be removed from that list.

RemovedRecital 65: (65) In order to promote the consistent application of this Regulation, including cross-border interoperability of health data, and potential mechanisms of funding support to ensure equal development of data systems across the Union in respect of the primary and secondary use of electronic health data, a European Health Data Space Board (EHDS Board) should be set up. The Commission should participate in its activities and chair it. The EHDS Board should contribute to the consistent application of this Regulation throughout the Union, including by helping Member State to coordinate the use of electronic health data for healthcare, certification, but also concerning the secondary use of electronic health data. Given that, at national level, digital health authorities dealing with the primary use of electronic health data may be different to the health data access bodies dealing with the secondary use of electronic health data, the functions are different and there is a need for distinct cooperation in each of these areas, the EHDS Board should be able to set up subgroups dealing with these two functions, as well as other subgroups, as needed. For an efficient working method, the digital health authorities and health data access bodies should create networks and links at national level with different other bodies and authorities, but also at Union level. Such bodies could comprise data protection authorities, cybersecurity, eID and standardisation bodies, as well as bodies and e…

RemovedRecital 65 a (new): (65a) An advisory forum should be set up to advise the EHDS Board in the fulfilment of its tasks by providing stakeholder input on matters pertaining to this Regulation. The advisory forum should be composed of representatives of patients, consumers, health professionals, industry, scientific researchers and academia. It should have a balanced composition and represent the views of different relevant stakeholders. Both commercial and non-commercial interests should be represented.

RemovedRecital 66 a (new): (66a) Any natural person should have the right to lodge a complaint with a digital health authority or with a health data access body, in particular in the Member State of his or her habitual residence, and the right to an effective judicial remedy in accordance with Article 47 of the Charter if the natural person considers that his or her rights under this Regulation have been infringed or where the digital health authority or health data access body does not act on a complaint, partially or wholly rejects or dismisses a complaint or does not act where such action is necessary to protect the rights of the natural person. The investigation following a complaint should be carried out, subject to judicial review, to the extent that is appropriate in the specific case. The digital health authority or health data access body should inform the natural person of the progress and the outcome of the complaint within a reasonable period. If the case requires further investigation or coordination with another digital health authority or health data access body, intermediate information should be given to the natural person. In order to facilitate the submission of complaints, each digital health authority and health data access body should take measures such as providing a complaint submission form which can also be completed electronically, without excluding the possibility of using other means of communication. Where the complaint concerns the rights of natural persons, the health da…

RemovedRecital 66 b (new): (66b) Where a natural person considers that his or her rights under this Regulation have been infringed, he or she should have the right to mandate a not-for-profit body, organisation or association which is constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest and is active in the field of the protection of personal data, to lodge a complaint on his or her behalf.

RemovedRecital 66 c (new): (66c) Any natural or legal person has the right to bring an action for annulment of decisions of the EHDS Board before the Court of Justice under the conditions provided for in Article 263 TFEU. As addressees of such decisions, the digital health authorities or health data access bodies concerned which wish to challenge them have to bring an action within two months of being notified of them, in accordance with Article 263 TFEU. In accordance with Article 263 TFEU, a health data holder, a health data applicant, a health data user or a complainant can bring an action for annulment against the decisions of the EHDS Board which concern them within two months of their publication on the website of the EHDS Board. Without prejudice to this right under Article 263 TFEU, each natural or legal person should have an effective judicial remedy before the competent national court against a decision of a digital health authority or health data access body which produces legal effects concerning that person. Such a decision concerns in particular the exercise of investigative, corrective and authorisation powers by the health data access body or the dismissal or rejection of complaints. However, the right to an effective judicial remedy does not encompass measures taken by digital health authorities and health data access bodies which are not legally binding, such as opinions issued or advice provided. Proceedings against a digital health authority or health data access body should be brou…

RemovedRecital 66 d (new): (66d) Where a court seised of proceedings against a decision by a digital health authority or health data access body has reason to believe that proceedings concerning the same access to electronic health data by the same health data user, such as for the same purpose for processing for secondary use, are brought before a competent court in another Member State, it should contact that court in order to confirm the existence of such related proceedings. If related proceedings are pending before a court in another Member State, any court other than the court first seised should be able to stay its proceedings or be able to, on request of one of the parties, decline jurisdiction in favour of the court first seised if that court has jurisdiction over the proceedings in question and its law permits the consolidation of such related proceedings. Proceedings should be deemed to be related where they are so closely connected that it is expedient to hear and determine them together in order to avoid the risk of irreconcilable judgments resulting from separate proceedings.

RemovedRecital 66 e (new): (66e) For proceedings against a health data holder or health data user, the plaintiff should have the choice of bringing the action before the courts of the Member States where the health data holder or health data user has an establishment or where the natural person resides, unless the health data holder is a public authority of a Member State acting in the exercise of its public powers.

RemovedRecital 66 f (new): (66f) The digital health authority, health data access body, health data holder or health data user should compensate any damage which a person could suffer as a result of processing that infringes this Regulation. The digital health authority, health data access body, health data holder or health data user should be exempt from liability if it proves that it was not in any way responsible for the damage. The concept of damage should be broadly interpreted in the light of the case law of the Court of Justice in a manner which fully reflects the objectives of this Regulation. This is without prejudice to any claims for damage deriving from the violation of other rules in Union or national law. Processing that infringes this Regulation should also include processing that infringes delegated and implementing acts adopted in accordance with this Regulation and national law specifying rules related to this Regulation. Natural persons should receive full and effective compensation for the damage they have suffered. Where digital health authorities, health data access bodies, health data holders or health data users are involved in the same processing, each actor should be held liable for the entire extent of the damage. However, where they are joined to the same judicial proceedings, in accordance with Member State law, it should be possible to apportion compensation according to the responsibility of each digital health authority, health data access body, health data holder or hea…

RemovedRecital 66 g (new): (66g) Where specific rules on jurisdiction are contained in this Regulation, in particular as regards proceedings seeking a judicial remedy including compensation, against a digital health authority, health data access body, health data holder or health data user, general jurisdiction rules such as those of Regulation (EU) No 1215/2012 of the European Parliament and of the Council1a should not prejudice the application of such specific rules. / 1a Regulation (EU) No 1215/2012 of the European Parliament and of the Council of 12 December 2012 on jurisdiction and the recognition and enforcement of judgments in civil and commercial matters (OJ L 351, 20.12.2012, p. 1).

RemovedRecital 66 h (new): (66h) In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of, appropriate measures imposed by the digital health authority or health data access body pursuant to this Regulation. In the case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden for a natural person, it should be possible to issue a reprimand instead of a fine. Due regard should however be given to the nature, gravity and duration of the infringement, the intentional character of the infringement, actions taken to mitigate the damage suffered, the degree of responsibility or any relevant previous infringements, the manner in which the infringement became known to the digital health authority or health data access body, compliance with measures ordered against the health data holder or health data user, adherence to a code of conduct and any other aggravating or mitigating factor. The imposition of penalties, including administrative fines, should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including effective judicial protection and due process.

RemovedRecital 66 i (new): (66i) Member States should be able to lay down the rules on criminal penalties for infringements of this Regulation, including for infringements of national rules adopted pursuant to and within the limits of this Regulation. Such criminal penalties could also involve the deprivation of profits obtained through infringements of this Regulation. However, the imposition of criminal penalties for infringements of such national rules and of administrative penalties should not lead to a breach of the principle of ne bis in idem, as interpreted by the Court of Justice.

RemovedRecital 66 j (new): (66j) It is appropriate to lay down provisions enabling health data access bodies to apply administrative fines for certain infringements of this Regulation whereby certain infringements are to be regarded as serious infringements, such as the re-identification of natural persons, downloading personal health data outside of the secure processing environment and processing of data for prohibited uses or outside a data permit. This Regulation should indicate infringements and the upper limit and criteria for setting the related administrative fines, which should be determined by the competent health data access body in each individual case, taking into account all the relevant circumstances of the specific situation, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences and the measures taken to ensure compliance with the obligations under this Regulation and to prevent or mitigate the consequences of the infringement. Where administrative fines are imposed on an undertaking, an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU for those purposes. Where administrative fines are imposed on persons that are not an undertaking, the health data access body should take account of the general level of income in the Member State as well as the economic situation of the person in considering the appropriate amount of the fine. The consistency mechanism could also be used to promote …

RemovedRecital 66 k (new): (66k) The legal systems of Denmark and Estonia do not provide for administrative fines as set out in this Regulation. It should be possible to apply the rules on administrative fines in a manner such that in Denmark the fine is imposed by competent national courts as a criminal penalty, and that in Estonia the fine is imposed by the supervisory authority in the framework of a misdemeanour procedure, provided that such an application of the rules in those Member States has an equivalent effect to administrative fines imposed by supervisory authorities. Therefore the competent national courts should take into account the recommendation by the health data access body initiating the fine. In any event, the fines imposed should be effective, proportionate and dissuasive.

RemovedRecital 66 l (new): (66 l) Where this Regulation does not harmonise administrative penalties or where necessary in other cases, for example in cases of serious infringements of this Regulation, Member States should implement a system which provides for effective, proportionate and dissuasive penalties. The nature of such penalties, criminal or administrative, should be determined by national law.

RemovedRecital 69 a (new): (69a) In accordance with Article 42 of Regulation (EU) 2018/1725, the Commission should, when preparing delegated acts or implementing acts, consult the European Data Protection Supervisor where there is an impact on the protection of individuals’ rights and freedoms with regard to the processing of personal data, and where such an act is of particular importance for the protection of individuals’ rights and freedoms with regard to the processing of personal data, the Commission can also consult the European Data Protection Board. The Commission should moreover consult the European Data Protection Board in the cases specified in Regulation (EU) 2016/679 and when relevant in the context of this Regulation.

RemovedRecital 70: (70) Member States should take all necessary measures to ensure that the provisions of this Regulation are implemented, including by laying down effective, proportionate and dissuasive penalties for their infringement. When deciding on the amount of the penalty for each individual case Member States should take into account the margins and criteria set out in this Regulation. Re-identification of natural persons should be considered a particularly serious breach of this Regulation. Member States should be able to consider criminalising re-identification by health data users so that it serves as a deterrent measure.

RemovedRecital 71: (71) In order to assess whether this Regulation reaches its objectives effectively and efficiently, is coherent and still relevant and provides added value at Union level the Commission should carry out an evaluation of this Regulation. The Commission should carry out a partial evaluation of this Regulation 5 years after its entry into force, and an overall evaluation 7 years after the entry into force of this Regulation. The Commission should submit reports on its main findings following each evaluation to the European Parliament and to the Council, the European Economic and Social Committee and the Committee of the Regions.

RemovedRecital 74: (74) The European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42 of Regulation (EU) 2018/1725 and delivered Joint opinion 03/2022 on 12 July 2022.

RemovedRecital 76: (76) Given the need for technical preparation, this Regulation should apply from [24 months after entry into force],

RemovedArticle 1 – paragraph 2 – point a: (a) specifies the rights of natural persons in relation to the availability, sharing and control of their electronic health data;

RemovedArticle 1 – paragraph 3 – point a: (a) manufacturers and suppliers of EHR systems and wellness applications, and of products claiming interoperability with EHR systems, placed on the market and put into service in the Union and the users of such products;

RemovedArticle 1 – paragraph 4: 4. This Regulation shall be without prejudice to other Union legal acts regarding access to, sharing of or secondary use of electronic health data, or requirements related to the processing of data in relation to electronic health data, in particular Regulations (EU) 2016/679, (EU) 2018/1725, (EU) 2022/868 and […] [Data Act COM/2022/68 final] and Directive 2002/58/EC of the European Parliament and of the Council1a. / 1a Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37).

RemovedArticle 1 – paragraph 4 a (new): 4a. References to the provisions of Regulation (EU) 2016/679 shall be understood also as references to the corresponding provisions of Regulation (EU) 2018/1725 for Union institutions and bodies, where relevant.

RemovedArticle 1 – paragraph 5 a (new): 5a. This Regulation shall be without prejudice to Regulation (EU) No 536/2014 and Directive (EU) 2016/9431a. / 1a Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure (OJ L 157, 15.6.2016, p. 1).

RemovedArticle 2 – paragraph 1 – point c: (c) the definitions of ‘data’, ‘access’, ‘data altruism’, ‘public sector body’ and ‘secure processing environment’, pursuant to Article 2, points (1), (8), (10), (11) and (14) of Regulation (EU) 2022/868;

RemovedArticle 2 – paragraph 2 – point a: (a) ‘personal electronic health data’ means data concerning health and genetic data as defined in Regulation (EU) 2016/679, that are processed in an electronic form;

RemovedArticle 2 – paragraph 2 – point b: (b) ‘non-personal electronic health data’ means data concerning health and aggregated genetic data in electronic format that falls outside the definition of personal data provided in Article 4, point (1), of Regulation (EU) 2016/679; where personal and non-personal data in a data set are inextricably linked, the entire dataset shall be processed as personal electronic health data;

RemovedArticle 2 – paragraph 2 – point d: (d) ‘primary use of electronic health data’ means the processing of electronic health data for the provision of health services to assess, maintain or restore the state of health of the natural person to whom that data relates, including the prescription, dispensation and provision of medicinal products and medical devices, as well as for relevant social security, administrative or reimbursement services;

RemovedArticle 2 – paragraph 2 – point e: (e) ‘secondary use of electronic health data’ means the processing of electronic health data for purposes set out in Chapter IV of this Regulation. The data used may include personal electronic health data initially collected in the context of primary use, but also electronic health data collected for the purpose of Chapter IV of this Regulation;

RemovedArticle 2 – paragraph 2 – point j: (j) ‘health professional access service’ means a service, supported by an EHR system, that enables health professionals to access data of natural persons under their care;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
28 September 2026

Cite as

European Parliament (2024). “Changes between TA-9-2023-0462 and TA-9-2024-0331”. Text, 24 April 2024. from TA-9-2023-0462, to TA-9-2024-0331. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/TA-9-2023-0462/compare/TA-9-2024-0331?all=1&part=2 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-24,
  author = {{European Parliament}},
  title = {{Changes between TA-9-2023-0462 and TA-9-2024-0331}},
  year = {2024},
  date = {2024-04-24},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/TA-9-2023-0462/compare/TA-9-2024-0331?all=1&part=2}},
  url = {https://news.eu-parl.st-solutions.dev/texts/TA-9-2023-0462/compare/TA-9-2024-0331?all=1&part=2},
  urldate = {2026-09-28},
  publisher = {EU Parl Watch Research},
  note = {Text. from TA-9-2023-0462, to TA-9-2024-0331. Data: European Parliament Open Data (CC BY 4.0)}
}