GDPR, EHDS, nLPD: what actually protects your health data in Europe?
Three legal regimes matter for health data in Europe, and they do different jobs.
GDPR: the baseline prohibition
The General Data Protection Regulation places health data among its “special categories” of personal data: processing is prohibited unless a narrow, explicitly justified condition applies. GDPR also defines the accountability structure. The Data Controller determines why and how data is processed and carries full legal responsibility; a Data Processor acts on the controller’s instructions (GDPR Art. 28 governs that relationship).
EHDS: the new European framework
The European Health Data Space, Regulation (EU) 2025/327, entered into force on 26 March 2025. It is more ambitious than anything before it: a common framework for both primary use (your own care, across borders) and secondary use (research, policy, regulatory decisions) of health data across all EU Member States, with mandatory interoperability standards, secure processing environments, and a link to the EU Data Governance Act’s “data altruism” mechanism for patients who want to contribute their data to research.
Two caveats matter. Its obligations apply only gradually: the general application date is 26 March 2027, the core primary-use exchange and the whole secondary-use chapter apply from 26 March 2029, and further stages follow in 2031 and 2035. And the early evidence from national secondary-use systems urges caution: Finland, where a dedicated Secondary Use Act has applied since 2020, saw approved research permits fall an estimated 47% below projected levels in 2023. Moving decisions away from individual consent toward administrative authorisation does not automatically produce more research.
Switzerland: the nLPD
Switzerland is not in the EU, and its revised Federal Act on Data Protection (nLPD/FADP), in force since 1 September 2023, governs health data with the same core logic: health data is specially protected, and the Data Controller carries the accountability for how it is stored, accessed and used.
The gaps the laws leave open
Strong law has not prevented weak outcomes. Healthcare has been the most expensive sector for data breaches for thirteen consecutive years, and in 2026 the average healthcare data breach cost $6.64 million, the highest of any industry, according to IBM’s 2026 Cost of a Data Breach report. Consumer health apps largely fall outside hospital-grade privacy regimes such as HIPAA (see our explainer on period-tracking apps), and institutional caution over-restricts the legitimate research the laws were meant to enable.
Where Health Data Safe sits
HDS is built to operate under all three regimes at once: a Swiss non-profit foundation acting as Data Controller, so that clinics, researchers and app developers who partner with it inherit the consent, audit and compliance machinery instead of building it alone. HDS is compliant by design, and it goes further than any of these frameworks requires: on HDS, data can be seen by or shared with anyone else only if the patient, who is the HDS user, has explicitly consented to it. Its Compliance Matrix, published in June 2026, adds no protection of its own. It records in plain language how exactly each obligation under HIPAA, GDPR, the Swiss nLPD and SOC 2 is met, and whether the platform, HDS, or the implementer building on it carries that obligation.
The matrix covers two frameworks this article has not described. HIPAA is the United States’ federal health privacy law of 1996. It does not apply to every piece of health data but to specific actors, the care providers, health plans and the companies that handle data for them, and it imposes rules on confidentiality, security and the notification of breaches. When a US clinic uses HDS, HDS becomes its business associate in HIPAA’s sense, and those rules bind HDS. SOC 2 is not a law. The American Institute of Certified Public Accountants publishes it as a standard. An independent auditor examines an organisation’s controls for security, availability, processing integrity, confidentiality and privacy, and issues a report that US hospitals and health companies routinely ask their suppliers for. HDS has not yet been through such an audit. The matrix maps its controls to the criteria so that anyone can see where it stands.
See How it works for the model, or Join as a partner if you are building on health data.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4, 9 and 28. EUR-Lex, English and French.
- Regulation (EU) 2025/327 on the European Health Data Space, OJ L 2025/327 of 5 March 2025, Articles 1, 73 and 105. EUR-Lex, English and French.
- Regulation (EU) 2022/868 (Data Governance Act), Chapter IV on data altruism. EUR-Lex, English and French.
- Brück O, Sanmark E, Ponkilainen V, et al. (2024). European health regulations reduce registry-based research. Health Research Policy and Systems 22: 135. doi:10.1186/s12961-024-01228-1
- Federal Act on Data Protection (FADP) of 25 September 2020, SR 235.1, in force since 1 September 2023, Articles 5 and 8. Fedlex, English and French.
- Health Insurance Portability and Accountability Act of 1996, implementing regulations at 45 C.F.R. Parts 160 and 164 (Privacy, Security and Breach Notification Rules). eCFR, Part 164.
- American Institute of Certified Public Accountants (2017, points of focus revised 2022). Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. aicpa-cima.com.
- IBM and Ponemon Institute (2026). Cost of a Data Breach Report 2026. IBM Corporation. ibm.com/reports/data-breach