Data Concerning Health (Article 4(15) GDPR)
Data concerning health is personal data about a person's physical or mental health from which information about their state of health can be derived. As a special category, it is subject to a general prohibition of processing.
Data concerning health is personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status (Article 4(15) GDPR). The term is defined broadly: it covers information on a person's past, current or future state of health (Recital 35 GDPR).
Key takeaways
- Data concerning health is personal data related to physical or mental health, from which the data subject's state of health can be derived.
- The term is to be interpreted broadly and covers information from medical practices and hospitals as well as data from fitness apps, wearables, or orders of pharmacy-only medicinal products.
- Data concerning health is one of the special categories of personal data under Article 9 GDPR: its processing is generally prohibited and permitted only under the narrowly defined conditions of Article 9(2) GDPR.
- Member States may introduce further requirements for the processing of data concerning health (Article 9(4) GDPR).
1. Overview
Data concerning health forms a subcategory of personal data and is at the same time among the information especially worthy of protection that Article 9 GDPR subjects to a stricter regime. The Union legislature has given the term an autonomous definition in Article 4(15) GDPR, which is substantially specified by Recital 35 GDPR.
The essential feature is the twofold connection: the datum must relate to the health of a natural person and it must reveal information about their state of health. This covers not only classic medical records but all data from which something about a person's physical or psychological condition can be derived, whether directly or indirectly.
2. Scope of the Definition
2.1 Material Scope
Recital 35 GDPR lists, by way of example, which information falls under the term:
| Data category | Examples |
|---|---|
| Information from health care services | Registration data, treatment records, billing information |
| Numbers and symbols | Insurance number, patient identifier, health insurance card |
| Examination and test results | Laboratory findings, imaging data, biopsy results |
| Genetic and biological samples | Health information derived from samples (see also genetic data) |
| Disease-related information | Diagnoses, disabilities, risk profiles, pre-existing conditions, clinical treatments |
| Physiological and biomedical parameters | Blood pressure, pulse, blood sugar, values recorded by medical devices or in-vitro diagnostics |
The origin of the data is irrelevant: whether it comes from a physician, a hospital, a medical device, or a fitness app makes no difference to its classification as data concerning health.
2.2 Temporal Dimension
The term is not limited to present health information. It equally covers data about a past state of health (e.g. earlier illnesses, completed treatments) and information about future health risks (e.g. genetically determined probabilities of disease, predictive findings).
2.3 Broad Interpretation in Practice
The CJEU has consistently interpreted the term broadly. According to this case law, even ordering pharmacy-only, non-prescription medicinal products in an online shop generates data concerning health, because the products ordered allow inferences to be drawn about the buyer's state of health (CJEU, judgment of 4 October 2024, C-21/23, Lindenapotheke). Not every mere possibility of a connection to health suffices; there must be a sufficiently concrete informational content regarding the state of health.
Data collected about users on social media platforms can also constitute data concerning health where health-related inferences can be drawn from it. In this context, the CJEU has clarified that the operator of a social network may not process such data merely because the data subject has expressed corresponding information in a public context (CJEU, judgment of 4 October 2024, C-446/21, Schrems/Meta).
Measurements recorded by wearables and fitness apps, such as pulse, blood pressure, or sleep patterns, are also data concerning health as soon as they can be attributed to an identifiable person. Applications that process such data are therefore subject to the prohibition of processing under Article 9(1) GDPR and require a legal basis under Article 9(2) GDPR.
3. Classification Within the GDPR Framework
Data concerning health is one of the special categories of personal data exhaustively enumerated in Article 9(1) GDPR. A general prohibition of processing applies to it; processing is permitted only where one of the exceptions in Article 9(2) GDPR applies. Of particular relevance in the health context are:
- the explicit consent of the data subject (Article 9(2)(a) GDPR),
- processing to protect vital interests (Article 9(2)(c) GDPR),
- processing by health professionals (Article 9(2)(h) GDPR), and
- reasons of public interest in the area of public health (Article 9(2)(i) GDPR).
In addition, Article 9(4) GDPR gives Member States the option to lay down further conditions for data concerning health, which in Germany is done above all through sector-specific rules in the German Social Code (Sozialgesetzbuch) and other specialized statutes.
Further details on the grounds for permissibility can be found in the overview of the special categories of personal data.
Personal Data
Article 4(1) GDPR: the basic concept to which data concerning health belongs as a subcategory.
Genetic Data
Article 4(13) GDPR: overlap with information derived from biological samples.
Biometric Data
Article 4(14) GDPR: further special data category with a connection to the body.
Special Categories (Article 9)
Overview of the prohibition of processing and the grounds for permissibility under Article 9 GDPR.
CJEU Lindenapotheke (C-21/23)
Orders of pharmacy-only medicinal products as data concerning health.
CJEU Schrems/Meta (C-446/21)
Scope of sensitive data in personalized advertising on social networks.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Biometric Data (Article 4(14) GDPR)
Biometric data are characteristics of a person resulting from specific technical processing (fingerprint, facial image, voice and others) that allow their unique identification and that, as a special category under Article 9 GDPR, are subject to a general prohibition of processing.
Individual Topics
Individual topics of the GDPR, organized by regulatory area.