Skip to content

Text · Comparison of two versions

Changes from adopted text to adopted text

TA-9-2023-0462 → TA-9-2024-0331

From
TA-9-2023-0462 Adopted text of 13 Dec 2023
To
TA-9-2024-0331 Adopted text of 24 Apr 2024
Changes
Not comparable
Paragraphs
+19 added · −542 removed · 1 changed
More facts (2)
Title (from)
European Health Data Space
Title (to)
European Health Data Space

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 7 of 10: Paragraphs 361–420

RemovedArticle 36 – paragraph 1: 1. Member States shall designate one or more health data access bodies responsible for the tasks and obligations referred to in Articles 37, 38 and 39 of this Regulation. Member States may either establish one or more new public sector bodies or rely on existing public sector bodies or on internal services of public sector bodies that fulfil the conditions set out in this Article. / Where a Member State designates several health data access bodies, it shall designate one health data access body to act as coordinator, with responsibility for coordinating data access applications and requests with the other health data access bodies. / Each health data access body shall contribute to the consistent application of this Regulation throughout the Union. For that purpose, the health data access bodies shall cooperate with each other and with the Commission, and, for concerns regarding data protection, with the supervisory authorities under Regulation (EU) 2016/679 as well as with the EDPB and the EDPS.

RemovedArticle 36 – paragraph 2: 2. Member States shall ensure that each health data access body is provided with the human and financial resources, including necessary expertise, and ethics bodies, to support their tasks as provided for in Article 37(1), points (a) and (aa), and shall guarantee that all rights of natural persons under this Chapter are respected. / Member States shall also ensure technical resources, premises and infrastructure necessary for the effective performance of its tasks and the exercise of its powers, in a timely manner.

RemovedArticle 36 – paragraph 2 a (new): 2a. Member States shall ensure that designated separate structures are set up within health data access bodies for the authorisation of the data permit, on the one hand, and for the reception and preparation of the data set, including anonymisation, pseudonymisation of the electronic health data and possible re-identification of natural persons for the purposes of Article 33(5) and 38(3), on the other hand.

RemovedArticle 36 – paragraph 3: 3. In the performance of their tasks, health data access bodies shall actively cooperate with relevant stakeholders’ representatives, especially with representatives of patients, consumers, data holders and data users.

RemovedArticle 36 – paragraph 3 a (new): 3a. Each health data access body shall act with complete independence in performing its tasks and exercising its powers in accordance with this Regulation. The members of the governance and decision-making bodies and staff of each health data access body shall, in the performance of their tasks and exercise of their powers in accordance with this Regulation, remain free from external influence, whether direct or indirect and shall neither seek nor take instructions from any natural or legal person. Members of the governance and decision-making bodies and staff of each health data access body shall refrain from any action incompatible with their duties and shall not, during their term of office, engage in any incompatible occupation, whether gainful or not.

RemovedArticle 37 – paragraph 1 – point a: (a) decide on data access applications pursuant to Article 45, including deciding on whether the data shall be made accessible in anonymised or pseudonymised form, based on its own thorough assessment of any reasons provided by the health data applicant pursuant to Article 45(2), point (d);

RemovedArticle 37 – paragraph 1 – point a a (new): (aa) assess and issue data permits pursuant to Article 46 of this Regulation and assess data request pursuant to Article 47 of this Regulation to access electronic health data falling within their national remit for secondary use and decide on data requests in accordance with Chapter II of Regulation (EU) .../... […] [Data Governance Act COM/2020/767 final] and this Chapter;

RemovedArticle 37 – paragraph 1 – point a b (new): (ab) request electronic health data referred to in Article 33 from relevant health data holders pursuant to a data permit or a data request granted;

RemovedArticle 37 – paragraph 1 – point d: (d) process electronic health data for the purposes set out in Article 34, including the combination, preparation, anonymisation and pseudonymisation and disclosure of those data for secondary use on the basis of a data permit, while also ensuring proper security of that data;

RemovedArticle 37 – paragraph 1 – point e: deleted

RemovedArticle 37 – paragraph 1 – point f: (f) take all measures necessary to preserve the confidentiality of IP rights and regulatory data protection, and the confidentiality of trade secrets as provided for in Article 33a;

RemovedArticle 37 – paragraph 1 – point g: (g) based on a data permit, put the relevant electronic health data at the disposal of data users in a secure processing environment in accordance with the requirements laid down in Article 50 and store the data for the period of the duration of the data permit;

RemovedArticle 37 – paragraph 1 – point i: deleted

RemovedArticle 37 – paragraph 1 – point j a (new): (ja) support data holders that are small enterprises in accordance with Commission Recommendation 2003/361/EC, in particular medical practitioners and pharmacies, to comply with their obligations under Article 41;

RemovedArticle 37 – paragraph 1 – point k: (k) maintain a management system to record and process data access applications, data requests, the decisions on those applications and the data permits issued and data requests answered, providing at least information on the name of the data applicant, the purpose of access the date of issuance, duration of the data permit and a description of the data application or the data request;

RemovedArticle 37 – paragraph 1 – point m: (m) cooperate at Union and national level to lay down common standards, technical requirements and appropriate measures for accessing electronic health data in a secure processing environment;

RemovedArticle 37 – paragraph 1 – point n: (n) cooperate at Union and national level and provide advice to the Commission on techniques and best practices for the secondary use and management of electronic health data;

RemovedArticle 37 – paragraph 1 – point q – point i: (i) a national dataset catalogue that shall include details about the source and nature of electronic health data, in accordance with Articles 55, 56 and 58, and the conditions for making electronic health data available. The national dataset catalogue shall also be made available to single information points under Article 8 of Regulation […] [Data Governance Act COM/2020/767 final];

RemovedArticle 37 – paragraph 1 – point q – point ii: (ii) all health data applications and requests without undue delay after their reception;

RemovedArticle 37 – paragraph 1 – point q – point ii a (new): (iia) all health data permits or requests granted as well as denied, together with a justification, within 30 working days of their issuance;

RemovedArticle 37 – paragraph 1 – point q – point iii: (iii) enforcement measures applied pursuant to Article 43 and administrative fines applied pursuant to Article 43a;

RemovedArticle 37 – paragraph 1 – point r a (new): (ra) monitor and supervise compliance by data users and data holders with the requirements laid down in this Chapter; monitoring and supervision shall include regular audits on health data users regarding their processing of electronic health data in the secure processing environment;

RemovedArticle 37 – paragraph 2 – point a: (a) cooperate with supervisory authorities under Regulation (EU) 2016/679 in relation to personal electronic health data and the EHDS Board;

RemovedArticle 37 – paragraph 2 – point a a (new): (aa) immediately notify the relevant supervisory authorities under Regulation (EU) 2016/679 of any potential issue related to the processing of personal electronic health data for secondary use, and exchange any relevant information at their disposal to ensure application and enforcement of this Regulation and relevant provisions of Regulation (EU) 2016/679 and this Regulation, including penalties;

RemovedArticle 37 – paragraph 2 – point b: (b) inform the relevant supervisory authorities under Regulation (EU) 2016/679 where a health data access body has imposed enforcement measures pursuant to Article 43 or administrative fines pursuant to Article 43a in relation to processing personal electronic health data and where such processing refers to an attempt to re-identify an individual or unlawful processing of personal electronic health data;

RemovedArticle 37 – paragraph 2 – point c: (c) cooperate with all relevant stakeholders, including patient organisations, representatives from natural persons, health professionals, researchers, and ethics committees, where applicable in accordance with Union and national law;

RemovedArticle 37 – paragraph 4: deleted

RemovedArticle 38 – paragraph 1 – introductory part: 1. Health data access bodies shall make publicly available and easily searchable and accessible for natural persons the conditions under which electronic health data is made available for secondary use, with information concerning:

RemovedArticle 38 – paragraph 1 – point a: (a) the legal basis under which access is granted to the health data user;

RemovedArticle 38 – paragraph 1 – point c: (c) the applicable rights of natural persons in relation to secondary use of electronic health data, including the right to opt-out pursuant to Article 33(5) and the right to opt-in pursuant to Article 33(5a), and detailed information on how to exercise them;

RemovedArticle 38 – paragraph 1 – point d: (d) the modalities for natural persons to exercise their rights in accordance with Chapter III of Regulation (EU) 2016/679;

RemovedArticle 38 – paragraph 1 – point d a (new): (da) the identity and the contact details of the health data access body;

RemovedArticle 38 – paragraph 1 – point d b (new): (db) the record on who has been granted access to which sets of electronic health data and a justification regarding the purposes for processing them as referred to in Article 34(1);

RemovedArticle 38 – paragraph 2: deleted

RemovedArticle 38 – paragraph 3: 3. Where a health data access body is informed by a health data user of a significant finding related to the health of a natural person, as referred to in Article 41a(5) of this Regulation, the health data access body shall inform the treating health professional with the relevant competence of the natural person and if that health professional cannot be found, and shall inform the natural person about that finding. Natural persons shall have the right to request not to be informed of such findings. In accordance with Article 23(1), point (i), of Regulation (EU) 2016/679, Member States may restrict the scope of the obligation to inform the natural persons whenever necessary for the protection of the natural persons based on patient safety and ethics, by delaying the communication of their information until a health professional can communicate and explain to the natural persons information that potentially can have an impact on them .

RemovedArticle 38 a (new): Article 38a / Right to lodge a complaint with a health data access body / 1. Without prejudice to any other administrative or judicial remedy, natural and legal persons shall have the right to lodge a complaint, individually or, where relevant, collectively, with the health data access body, where their rights laid down in this Chapter are affected. Where the complaint concerns the rights of natural persons pursuant to Article 38(1), point (d), of this Regulation, the health data access body shall inform and send a copy of the complaint to the competent supervisory authorities under Regulation (EU) 2016/679. / 2. The health data access body with which the complaint has been lodged shall inform the complainant of the progress of the proceedings and of the decision taken. / 3. Health data access bodies shall cooperate to handle and resolve complaints, including by exchanging all relevant information by electronic means, without undue delay. / 4. Each health data access body shall facilitate submitting complaints, in particular by providing a complaint submission form which can also be completed electronically, without excluding the possibility of using other means of communication.

RemovedArticle 38 b (new): Article 38b / Right to an effective judicial remedy against a health data access body / 1. Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of a health data access body concerning them. / 2. Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy where the health data access body which is competent pursuant to Article 37 does not handle a complaint or does not inform the natural or legal person within three months about the progress or outcome of the complaint lodged pursuant to Article 38a. / 3. Proceedings against a health data access body shall be brought before the courts of the Member States where the health data access body is established.

RemovedArticle 39 – paragraph 1 – introductory part: 1. Each health data access body shall publish an annual activity report and make it publicly available on its website, which shall contain at least the following categories of information:

RemovedArticle 39 – paragraph 1 – point a: (a) information relating to the data access applications and data requests for electronic health data access submitted, such as the types of applicants, number of data permits granted or refused, purposes of access and categories of electronic health data accessed, and a summary of the results of the electronic health data uses, where applicable;

RemovedArticle 39 – paragraph 1 – point c: (c) information on the fulfilment of regulatory and contractual commitments by data users and data holders, as well as the number and amount of administrative fines imposed by health data access bodies;

RemovedArticle 39 – paragraph 1 – point d: (d) information on audits carried out on data users to ensure compliance of the processing within the secure processing environment as referred to in Article 50 of this Regulation;

RemovedArticle 39 – paragraph 1 – point e: (e) information on internal and third party audits on compliance of secure processing environments with the defined standards, specifications and requirements, as referred to in Article 50(3) of this Regulation;

RemovedArticle 39 – paragraph 1 – point j: deleted

RemovedArticle 39 – paragraph 1 – point l: (l) number of data quality labels issued by data holders, disaggregated per quality category;

RemovedArticle 39 – paragraph 2: 2. The report shall be transmitted to the Commission, which shall make it publicly available on its website.

RemovedArticle 39 – paragraph 3: 3. The Commission is empowered to adopt delegated acts in accordance with Article 67 to amend paragraph 1 of this Article by adding categories to those listed in that paragraph.

RemovedArticle 40 – paragraph 1: 1. In addition to rules regarding data altruism established by Regulation (EU) 2022/868, where data altruism organisations recognised under Chapter IV of that Regulation process personal electronic health data using a secure processing environment, such environments shall also comply with the requirements set out in Article 50 of this Regulation.

RemovedArticle 40 – paragraph 2: 2. Health data access bodies shall support the competent authorities designated in accordance with Article 23 of Regulation (EU) 2022/868 in the monitoring of entities carrying out data altruism activities, where electronic health data are concerned.

RemovedArticle 41 – title: Duties of health data holders

RemovedArticle 41 – paragraph 1: 1. Health data holders shall make relevant electronic health data under Article 33 available upon request to the health data access body pursuant to a data permit issued or data request granted by such a body. Health data holders shall cooperate in good faith with the health data access bodies, where relevant.

RemovedArticle 41 – paragraph 1 a (new): 1a. The requirement laid down in the first paragraph shall not apply to data holders that qualify as micro enterprises as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC.

RemovedArticle 41 – paragraph 1 b (new): 1b. The health data holder shall put the electronic health data at the disposal of the health data access body within three months of receiving the request from the health data access body. In justified cases, after consultation with the health data holder concerned, that period may be extended by the health data access body for a maximum of two months. The health data access body may decide that the extension is to be shorter than two months.

RemovedArticle 41 – paragraph 1 c (new): 1c. Paragraphs 1 and 1a of this Article constitute a legal obligation pursuant to Article 6(1), point (c), of this Regulation in combination with Article 9(2), points (g) to (j), of Regulation 2016/679 for the health data holder to disclose personal electronic health data to the health data access body.

RemovedArticle 41 – paragraph 2: 2. The health data holder shall communicate to the health data access body a general description of the dataset it holds in accordance with Article 55.

RemovedArticle 41 – paragraph 3: 3. Where a data quality and utility label accompanies the dataset pursuant to Article 56, the health data holder shall provide sufficient documentation to the health data access body for that body to confirm the accuracy of the label.

RemovedArticle 41 – paragraph 4: deleted

RemovedArticle 41 – paragraph 5: 5. Where a health data holder has received enriched datasets following a processing based on a data permit, it shall make available the new dataset, unless it considers it unsuitable and notifies the health data access body in this respect.

RemovedArticle 41 – paragraph 6: 6. Health data holders of non-personal electronic health data shall ensure access to data through trusted open databases to ensure unrestricted access for all users and data storage and preservation. Trusted open public databases shall have in place a robust, transparent and sustainable governance and a transparent model of user access.

RemovedArticle 41 – paragraph 7: deleted

RemovedArticle 41 a (new): Article 41a / Duties of health data users / 1. Health data users may access and process the electronic health data for secondary use referred to in Article 33 only in accordance with the data permit issued by the health data access body in accordance with Article 46 of this Regulation. / 2. Health data users shall not re-identify or seek to re-identify the natural persons to whom the electronic health data which they obtained based on the data permit or data request belong. Such conduct shall be considered a serious breach of this Regulation. / 3. Health data users shall make public the results or output of the secondary use of electronic health data, including information relevant for the provision of healthcare, no later than 18 months after the completion of the electronic health data processing or after having received the answer to the data request referred to in Article 47. Those results or output shall not contain personal data. In justified cases, especially cases referred to in Article 34(1), point (e), that period may be extended by the relevant health data access body, after consultation with the health data user. The health data users shall inform the health data access bodies from which a data permit was obtained about the results or output and provide them with necessary support in order to make them public also on health data access bodies’ websites. The result shall also be made publicly available in lay summaries. Whenever the health data users have used elec…

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between TA-9-2023-0462 and TA-9-2024-0331”. Text, 24 April 2024. from TA-9-2023-0462, to TA-9-2024-0331. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/TA-9-2023-0462/compare/TA-9-2024-0331?all=1&part=7 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-24,
  author = {{European Parliament}},
  title = {{Changes between TA-9-2023-0462 and TA-9-2024-0331}},
  year = {2024},
  date = {2024-04-24},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/TA-9-2023-0462/compare/TA-9-2024-0331?all=1&part=7}},
  url = {https://news.eu-parl.st-solutions.dev/texts/TA-9-2023-0462/compare/TA-9-2024-0331?all=1&part=7},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from TA-9-2023-0462, to TA-9-2024-0331. Data: European Parliament Open Data (CC BY 4.0)}
}