GDPR, EHDS, nLPD: what actually protects your health data in Europe?
Three legal regimes matter for health data in Europe, and they do different jobs.
GDPR: the baseline prohibition
The General Data Protection Regulation places health data among its “special categories” of personal data: processing is prohibited unless a narrow, explicitly justified condition applies. GDPR also defines the accountability structure. The Data Controller determines why and how data is processed and carries full legal responsibility; a Data Processor acts on the controller’s instructions (GDPR Art. 28 governs that relationship).
EHDS: the new European framework
The European Health Data Space, Regulation (EU) 2025/327, entered into force on 26 March 2025. It is more ambitious than anything before it: a common framework for both primary use (your own care, across borders) and secondary use (research, policy, regulatory decisions) of health data across all EU Member States, with mandatory interoperability standards, secure processing environments, and a “data altruism” pathway for patients who want to contribute their data to research.
Two caveats matter. Its obligations apply only gradually, most of them four years after entry into force. And the early evidence from national secondary-use systems urges caution: Finland, the first country to fully implement secondary-use rules, saw approved research permits fall an estimated 47% below projected levels in 2023. Moving decisions away from individual consent toward administrative authorisation does not automatically produce more research.
Switzerland: the nLPD
Switzerland is not in the EU, and its revised Federal Act on Data Protection (nLPD/FADP) governs health data with the same core logic: health data is specially protected, and the Data Controller carries the accountability for how it is stored, accessed and used.
The gaps the laws leave open
Strong law has not prevented weak outcomes. Healthcare has been the most expensive sector for data breaches for fourteen consecutive years; in 2025 the average healthcare data breach cost $7.42 million and took 279 days to identify and contain. Consumer health apps largely escape medical-privacy regimes, and institutional caution over-restricts the legitimate research the laws were meant to enable.
Where Health Data Safe sits
HDS is built to operate under all three regimes at once: a Swiss non-profit foundation acting as Data Controller, so that clinics, researchers and app developers who partner with it inherit the consent, audit and compliance machinery instead of building it alone. Its Compliance Matrix, published in June 2026, provides a publicly browsable record of how patient rights under HIPAA, GDPR and the Swiss nLPD map onto platform capabilities.
See How it works for the model, or Join as a partner if you are building on health data.