Guides
Your medical data under EU (GDPR) protection
Health information is sensitive personal data. Before sending records, identify who controls them, why they are needed, who receives them, how long they are kept and which rights apply.
Ask for the legal name and contact details of each data controller: clinic, manufacturer, trial sponsor, laboratory or platform. They may have separate purposes and notices.
The GDPR treats health and genetic information as special categories of personal data. Processing needs both a general legal basis and an applicable condition for sensitive data; consent is not the only possible route.
A privacy notice should explain purposes, data categories, recipients, retention, international transfers, rights, complaint authority and any automated decision-making. A generic cookie banner is not a medical-data notice.
Data minimisation means collecting what is necessary for the stated purpose. Ask why passport copies, complete lifetime records, photographs or family data are required before uploading them.
Use a secure clinical portal or another agreed protected channel. Ordinary email, public file links and messaging apps can create avoidable access and retention risks.
For research, consent to participate and the legal basis for processing data are related but distinct. Withdrawal from study procedures may not require deletion of data already needed for scientific integrity or legal duties.
Ask whether identifiable data leave the EEA and what transfer mechanism and safeguards apply. A server location or vendor logo alone does not answer the question.
Pseudonymised data remain personal data when re-identification is possible. Only data that are irreversibly anonymised fall outside GDPR, and that claim should be technically credible.
You can request access to personal data and information about its processing. European Commission guidance says the first copy is generally free; further or excessive requests may be treated differently under the rules.
Rectification can correct inaccurate factual data, but it may not erase a clinician's professional opinion. Ask the provider to record a correction or patient statement where appropriate.
Marketing permission should not be bundled with necessary care or research choices. Refusing optional marketing should not change clinical eligibility.
Photographs, video and testimonials need a clear, separate purpose and permission. Publishing a story can make health information difficult to recover even if consent is later withdrawn.
Ask how long records and traceability data must be retained under healthcare, trial and product law. GDPR does not impose one universal deletion date.
If a breach or misuse occurs, preserve evidence, contact the controller or data protection officer and use the relevant supervisory-authority complaint route. Clinical urgency should be handled separately.
The European Commission's GDPR guide for individuals explains access and sensitive-data rights. Privacy compliance does not establish that an intervention is lawful or effective.
Use the cost worksheet, then verify the exact product, evidence, legal route and written quotation with an independent qualified clinician.
Sources & further reading
- Stem-cell trials registry (ClinicalTrials.gov) ↗
- Peer-reviewed research (PubMed) ↗
- ISSCR — patient resources ↗
- FDA — consumer guidance ↗
- EMA — ATMP framework ↗
Educational guide; most uses are investigational. Verify the exact product, indication and provider with current regulator records and an independent qualified physician.