Skip to content
Knowledge base

EHDS and GDPR glossary

This page contains important definitions & terms. Some of these are legal definitions, which have to apply very precisely before a particular legal consequence arises. In the EHDS they are set out in Article 2(2). Article 2(1) also contains definitions for which reference is made to other European legislation; those appear below as well. Because the GDPR remains a very important regulation alongside the EHDS, the definitions from the GDPR are included too. Finally, this list contains widely used terms that are not defined in law, but that follow from or matter for the EHDS. These are terms such as the HDAB and ethics. For each definition or term you will find its source and where it is used in legislation.

Kind
Regulation
Access
data use, in accordance with specific technical, legal or organisational requirements, without necessarily implying the transmission or downloading of data.
Article 2, point (13), Data Governance Act (EU) 2022/868
Accountability principle
The duty not only to comply with the GDPR, but also to be able to demonstrate that compliance.
Not defined in law
Anonymisation / anonymous data
Processing data so that no one can reasonably still determine which person they concern. Recital 26 GDPR describes anonymous information as information that does not relate to an identified or identifiable natural person, or personal data rendered anonymous in such a way that the data subject is not or no longer identifiable; the GDPR does not apply to such data, including for statistical or research purposes. Whether someone is still identifiable depends on all objective factors, such as the cost of and time required for identification and available technology. Note the confusion: sometimes relatively anonymous is meant (anonymous to me) and sometimes absolutely anonymous (anonymous to everyone).
Not defined in law
Binding corporate rules
personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity.
Article 4, point (20), GDPR
Biometric data
personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.
Article 4, point (14), GDPR
Care
a professional service the purpose of which is to address the specific needs of a natural person who, on account of impairment or other physical or mental conditions, requires assistance, including preventive and supportive measures, to carry out essential activities of daily living in order to support his or her personal autonomy.
Article 2(2), point (s), EHDS Regulation
CE marking of conformity
a marking by which the manufacturer indicates that the EHR system is in conformity with the applicable requirements set out in this Regulation and other applicable Union law providing for its affixing pursuant to Regulation (EC) No 765/2008 of the European Parliament and of the Council.
Article 2(2), point (p), EHDS Regulation
Clinical quality registry
A quality registry involves the collection, storage, and further processing of data—including personal data—concerning a client population, carried out for the purpose of measuring and improving the quality of care provided to that population. A client population is a study group of clients defined by shared characteristics regarding their condition, disease, type of care, or complication, or combinations thereof. Examples include registries such as DICA, IKNL, or Perined, which record healthcare outcomes on a large scale; these are significant data holders that could potentially be designated as trusted holders under the EHDS.
Not defined in law
Co-controllers
A number used to identify citizens of the Member States. Under Article 46 of the UAVG (Dutch GDPR Implementation Act), no one may use this number unless authorized by law. Important for the reuse of health data: the *Wet Algemene Bepalingen BSN* (General Provisions Act on the Citizen Service Number) stipulates that all government bodies may use the BSN in the performance of their assigned tasks. The Wabvpz stipulates that the BSN must be used for identification purposes within the healthcare sector. The BSN does not constitute special category personal data within the meaning of Article 9 of the GDPR.
Not defined in law
Common specifications
a set of technical and/or clinical requirements, other than a standard, that provides a means of complying with the legal obligations applicable to a device, process or system.
Article 2, point (71), Regulation (EU) 2017/745
Compatible use
Further use or re-use of data so closely connected to the original purpose that it falls within it; no new Article 6 basis is then required. This is one of the four exceptions to the purpose limitation principle.
Not defined in law
Consent
any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Article 4, point (11), GDPR
Contracting authorities
the State, regional or local authorities, bodies governed by public law or associations formed by one or more such authorities or one or more such bodies governed by public law.
Article 2(1), point (1), Directive 2014/24/EU
Control over health data
The degree of choice or control a citizen has over the use of data about them. We distinguish control during use from control prior to use. Of the latter there are roughly three: no control, an opt-out, or an opt-in.
Not defined in law
Controller
the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Article 4, point (7), GDPR
Corrective action
any action taken by an economic operator to bring any non-compliance to an end where required by a market surveillance authority or on the economic operator's own initiative.
Article 3, point (16), Regulation (EU) 2019/1020
Cross-border processing
either: (a) processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or (b) processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.
Article 4, point (23), GDPR
Data
any digital representation of acts, facts or information and any compilation of such acts, facts or information, including in the form of sound, visual or audiovisual recording.
Article 2, point (1), Data Governance Act (EU) 2022/868
Data Access Application Management System
The Data Access Application Management System: the proposed process or system for applying to the HDAB for a data permit. You criticise coupling this process to the dataset catalogue, because a permit can be requested for all data (including unstructured data), whereas only structured datasets are listed in the catalogue.
Not defined in law
Data altruism
the voluntary sharing of data on the basis of the consent of data subjects to process personal data pertaining to them, or permissions of data holders to allow the use of their non-personal data without seeking or receiving a reward that goes beyond compensation related to the costs that they incur where they make their data available for objectives of general interest as provided for in national law, where applicable, such as healthcare, combating climate change, improving mobility, facilitating the development, production and dissemination of official statistics, improving the provision of public services, public policy making or scientific research purposes in the general interest.
Article 2, point (16), Data Governance Act (EU) 2022/868
Data collector / health data intermediation entity
The EHDS uses the term "health data intermediation entity", which can cause confusion because it resembles the term "data intermediation service" from the Data Governance Act (which is something entirely different). It is an independent legal person that collects health data from many similar data holders (such as GPs or individual municipal health services) and, under or pursuant to a law, takes over their EHDS obligations, so that the HDAB does not have to approach each holder separately.
Not defined in law
Data concerning health
personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.
Article 4, point (15), GDPR
Data hub
A term used in the field that has no legal meaning. What people aim to achieve with a data hub appears to be done by the EHDS role of intermediation entity. Note, however, that under the EHDS an intermediation entity may not simultaneously be a trusted health data holder, whereas current data hubs regularly appear to fulfil precisely such a dual role.
Not defined in law
Data minimisation
The principle that you use only the data you reasonably need for your specific purpose. It is not a general command to process as little data as possible, but a command not to use data that are not actually needed for the specific purpose once that purpose has been set.
Not defined in law
Data permit
an administrative decision issued to a health data user by a health data access body to process certain electronic health data specified in the data permit for specific secondary use purposes, based on conditions laid down in Chapter IV of this Regulation.
Article 2(2), point (v), EHDS Regulation
Data processing agreement
The mandatory contract between controller and processor setting out exactly what the processor may and may not do with the personal data. Under the EHDS it recurs in the allocation of roles (phase 2, when the HDAB becomes the user's processor).
Not defined in law
Data protection impact assessment (DPIA)
A mandatory prior risk assessment for high-risk processing. Note that a DPIA need not be repeated for every similar processing: if the dataset differs but the processing is the same, it need not be redone.
Not defined in law
Data protection officer (DPO)
The internal, independent supervisor and adviser within an organisation who oversees GDPR compliance. Mandatory in certain cases (Article 37 GDPR). The organisation must properly position the DPO (resources, access, independence).
Not defined in law
Data quality
the degree to which the elements of electronic health data are suitable for their intended primary use and secondary use.
Article 2(2), point (z), EHDS Regulation
Data quality and utility label
a graphic diagram, including a scale, describing the data quality and conditions of use of a dataset.
Article 2(2), point (aa), EHDS Regulation
Dataset
a structured collection of electronic health data.
Article 2(2), point (w), EHDS Regulation
Dataset catalogue
a collection of dataset descriptions, arranged in a systematic manner and including a user-oriented public part, in which information concerning individual dataset parameters is accessible by electronic means through an online portal.
Article 2(2), point (y), EHDS Regulation
Dataset of high impact for secondary use
a dataset the re-use of which is associated with significant benefits due to its relevance for health research.
Article 2(2), point (x), EHDS Regulation
Distributor
any natural or legal person in the supply chain, other than the manufacturer or the importer, who makes a product available on the market.
Article 3, point (10), Regulation (EU) 2019/1020
Economic operator
the manufacturer, the authorised representative, the importer, the distributor, the fulfilment service provider or any other natural or legal person who is subject to obligations in relation to the manufacture of products, making them available on the market or putting them into service in accordance with the relevant Union harmonisation legislation.
Article 3, point (13), Regulation (EU) 2019/1020
EHR
a collection of electronic health data related to a natural person and collected in the health system, processed for the purpose of the provision of healthcare.
Article 2(2), point (j), EHDS Regulation
EHR system
any system whereby the software, or a combination of the hardware and the software of that system, allows personal electronic health data that belong to the priority categories of personal electronic health data established under this Regulation to be stored, intermediated, exported, imported, converted, edited or viewed, and intended by the manufacturer to be used by healthcare providers when providing patient care or by patients when accessing their electronic health data.
Article 2(2), point (k), EHDS Regulation
Electronic health data
personal or non-personal electronic health data.
Article 2(2), point (c), EHDS Regulation
Electronic health data access service
an online service, such as a portal or an application for mobile devices, that enables natural persons not acting in a professional capacity to access their own electronic health data or the electronic health data of those natural persons whose electronic health data they are legally authorised to access.
Article 2(2), point (h), EHDS Regulation
Electronic identification
the process of using person identification data in electronic form uniquely representing either a natural or legal person, or a natural person representing a legal person.
Article 3, point (1), Regulation (EU) No 910/2014
Electronic identification means
a material and/or immaterial unit containing person identification data and which is used for authentication for an online service.
Article 3, point (2), Regulation (EU) No 910/2014
Enterprise
a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
Article 4, point (18), GDPR
Ethics
A reasoned value judgment regarding what is right. It is to be distinguished from law, which constitutes the body of rules enforced—and enforceable—by judges. It serves as an argument for drafting new rules and enables judges to give substance to open legal norms. Under the EHDS, a separate ethical assessment may be mandated in addition to the statutory assessment for secondary use. However, such an assessment must comply with the principles of legality, legal certainty, and equality, given that the permits and decisions issued in response to a request constitute administrative law decisions.
Not defined in law
European interoperability software component for EHR systems
a software component of the EHR system which provides and receives personal electronic health data under a priority category for primary use established under this Regulation in the European electronic health record exchange format provided for in this Regulation and which is independent of the European logging software component for EHR systems.
Article 2(2), point (n), EHDS Regulation
European logging software component for EHR systems
a software component of the EHR system which provides logging information related to access by health professionals or other individuals to priority categories of personal electronic health data established under this Regulation, in the format defined in point 3.2. of Annex II thereto, and which is independent of the European interoperability software component for EHR systems.
Article 2(2), point (o), EHDS Regulation
FAIR
The principle that data should be Findable, Accessible, Interoperable and Reusable.
Not defined in law
Federated learning
A method whereby the data do not travel to the user, but the algorithm or the computational query travels to the data; only results are returned. Fits well with the health data request.
Not defined in law
Filing system
any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
Article 4, point (6), GDPR
Free movement of (health) data
The principle that (health) data must be able to flow freely within the EU internal market, as a condition for the free movement of, among others, persons (including patients) and services (including healthcare providers).
Not defined in law
Genetic data
personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.
Article 4, point (13), GDPR
Group of undertakings
a controlling undertaking and its controlled undertakings.
Article 4, point (19), GDPR
Health Data Access Body
The new, independent public authority that grants permits for the secondary use of health data and supervises it. In the Netherlands it has yet to be decided who this will be.
Not defined in law
Health Data Authority
The name proposed in the draft Dutch EHDS implementing act for the Dutch authority that would be the data authority for both primary and secondary use.
Not defined in law
Health data holder
any natural or legal person, public authority, agency or other body in the healthcare or the care sectors, including reimbursement services where necessary, as well as any natural or legal person developing products or services intended for the health, healthcare or care sectors, developing or manufacturing wellness applications, performing research in relation to the healthcare or care sectors or acting as a mortality registry, as well as any Union institution, body, office or agency, that has either: (i) the right or obligation, in accordance with applicable Union or national law and in its capacity as a controller or joint controller, to process personal electronic health data for the provision of healthcare or care or for the purposes of public health, reimbursement, research, innovation, policymaking, official statistics or patient safety or for regulatory purposes; or (ii) the ability to make available non-personal electronic health data through the control of the technical design of a product and related services, including by registering, providing, restricting access to or exchanging such data.
Article 2(2), point (t), EHDS Regulation
Health data request
The lighter route alongside the permit: one does not request access to data, but receives only a specific, anonymised statistical answer. One never sees the underlying data. Note: the EHDS does not mention federated learning, but this appears possible within the health data request.
Not defined in law
Health data user
a natural or legal person, including Union institutions, bodies, offices or agencies, which has been granted lawful access to electronic health data for secondary use pursuant to a data permit, a health data request approval or an access approval by an authorised participant in HealthData@EU.
Article 2(2), point (u), EHDS Regulation
Health institution
an organisation the primary purpose of which is the care or treatment of patients or the promotion of public health.
Article 2, point (36), Regulation (EU) 2017/745
Health professional
a doctor of medicine, a nurse responsible for general care, a dental practitioner, a midwife or a pharmacist within the meaning of Directive 2005/36/EC, or another professional exercising activities in the healthcare sector which are restricted to a regulated profession as defined in Article 3(1)(a) of Directive 2005/36/EC, or a person considered to be a health professional according to the legislation of the Member State of treatment.
Article 3, point (f), Directive 2011/24/EU
Health professional access service
a service, supported by an EHR system, that enables health professionals to access data of natural persons under their treatment.
Article 2(2), point (i), EHDS Regulation
Healthcare
health services provided by health professionals to patients to assess, maintain or restore their state of health, including the prescription, dispensation and provision of medicinal products and medical devices.
Article 3, point (a), Directive 2011/24/EU
Healthcare provider
any natural or legal person or any other entity legally providing healthcare on the territory of a Member State.
Article 3, point (g), Directive 2011/24/EU
HealthData@EU
The European infrastructure for cross-border secondary use: through one's own HDAB one can apply for a permit to work with data from several Member States. The HDABs share such applications (among other things) via HealthData@EU.
Not defined in law
Implementing legislation
Detailed rules implementing a piece of European legislation. At the EU level, these take the form of implementing acts adopted by the Commission. At the national level, regulations are elaborated upon in an implementing act. A regulation has direct effect and therefore does not require transposition into national law (unlike a directive), though it often requires implementation and integration into the national legal framework. This is accomplished through an implementing act, such as the GDPR Implementation Act.
Not defined in law
Importer
any natural or legal person established within the Union who places a product from a third country on the Union market.
Article 3, point (9), Regulation (EU) 2019/1020
Information society service
a service as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535.
Article 4, point (25), GDPR
Instructions for use
the information provided by the manufacturer to inform the user of a device's intended purpose and proper use and of any precautions to be taken.
Article 2, point (14), Regulation (EU) 2017/745
Intended purpose
the use for which a device is intended according to the data supplied by the manufacturer on the label, in the instructions for use or in promotional or sales materials or statements and as specified by the manufacturer in the clinical evaluation.
Article 2, point (12), Regulation (EU) 2017/745
International organisation
an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.
Article 4, point (26), GDPR
Interoperability
the ability of organisations, as well as of software applications or devices from the same manufacturer or different manufacturers, to interact through the processes they support, involving the exchange of information and knowledge, without changing the content of the data, between those organisations, software applications or devices.
Article 2(2), point (f), EHDS Regulation
Joint controllers
Two or more controllers that jointly determine the purposes and means of a processing operation. They must make an arrangement between them setting out who is responsible for what.
Not defined in law
Legal basis / element
A widely used but confusing term that usually refers to a valid reason for processing under Article 6 GDPR, but can also refer to various other parts of the GDPR. The word "basis" barely appears in the GDPR itself. The better Translation into Dutch is "element" that lawyers use for the various parts of a legal rule that must be fulfilled (alternatively or cumulatively) for the legal effect to arise. In the same way, several elements of the GDPR must be met before the legal effect "permitted processing" arises.
Not defined in law
Legitimate interest
A valid reason for processing (Article 6(1)(f) GDPR) that may also be a purely commercial interest, such as approaching potential new customers. Public authorities may not rely on legitimate interest. If one relies on this ground, a three-step test must be applied: (1) is there a real, legitimate interest, (2) is the processing necessary for it, and (3) do the interests, fundamental rights and reasonable expectations of the data subject not outweigh it. Recital 47 GDPR gives as examples a client or employment relationship, fraud prevention and direct marketing.
Not defined in law
Lex specialis
A conflict rule: where two laws of the same rank apply to the same case and give different outcomes, the more specific rule prevails over the more general one. Note some misconceptions: (i) it applies only to rules of the same rank (otherwise higher law prevails over lower); (ii) only to concrete rules, not entire statutes; and (iii) only where there are genuinely two conflicting outcomes. If one law prescribes something and the other is silent, there is no conflict and the rule does not apply.
Not defined in law
Main establishment
a) as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment; (b) as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor take place to the extent that the processor is subject to specific obligations under this Regulation.
Article 4, point (16), GDPR
Making available on the market
any supply of a product for distribution, consumption or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge.
Article 3, point (1), Regulation (EU) 2019/1020
Manufacturer
any natural or legal person who manufactures a product or has a product designed or manufactured, and markets that product under its name or trademark.
Article 3, point (8), Regulation (EU) 2019/1020
Marginal cost
The costs of making data available. This refers to the costs of making the data available, not the total organizational costs or the costs of generating the data. In principle, data must not be offered at a price exceeding these marginal costs, so as not to unnecessarily hinder reuse.
Not defined in law
Market surveillance
the activities carried out and measures taken by market surveillance authorities to ensure that products comply with the requirements set out in the applicable Union harmonisation legislation and to ensure protection of the public interest covered by that legislation.
Article 3, point (3), Regulation (EU) 2019/1020
Market surveillance authority
an authority designated by a Member State under Article 10 as responsible for carrying out market surveillance in the territory of that Member State.
Article 3, point (4), Regulation (EU) 2019/1020
Medical device
any instrument, apparatus, appliance, software, implant, reagent, material or other article intended by the manufacturer to be used, alone or in combination, for human beings for one or more of the following specific medical purposes: — diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease, — diagnosis, monitoring, treatment, alleviation of, or compensation for, an injury or disability, — investigation, replacement or modification of the anatomy or of a physiological or pathological process or state, — providing information by means of in vitro examination of specimens derived from the human body, including organ, blood and tissue donations, and which does not achieve its principal intended action by pharmacological, immunological or metabolic means, in or on the human body, but which may be assisted in its function by such means. The following products shall also be deemed to be medical devices: — devices for the control or support of conception; — products specifically intended for the cleaning, disinfection or sterilisation of devices as referred to in Article 1(4) and of those referred to in the first paragraph of this point.
Article 2, point (1), Regulation (EU) 2017/745
Medical secrecy resting on everyone
Medical professional secrecy is the duty of confidentiality tied to certain professions; its purpose is that one can tell those professionals everything, as with lawyers. The medical secret of Article 9 GDPR, by contrast, is the duty resting on everyone in principle not to process (and thus to keep secret) medical data.
Not defined in law
Medicinal product
a medicinal product as defined by Directive 2001/83/EC.
Article 3, point (i), Directive 2011/24/EU
Member State of affiliation
(i) for persons referred to in point (b)(i), the Member State that is competent to grant to the insured person a prior authorisation to receive appropriate treatment outside the Member State of residence according to Regulations (EC) No 883/2004 and (EC) No 987/2009; (ii) for persons referred to in point (b)(ii), the Member State that is competent to grant to the insured person a prior authorisation to receive appropriate treatment in another Member State according to Regulation (EC) No 859/2003 or Regulation (EU) No 1231/2010. If no Member State is competent according to those Regulations, the Member State of affiliation shall be the Member State where the person is insured or has the rights to sickness benefits according to the legislation of that Member State.
Article 3, point (c), Directive 2011/24/EU
Member State of treatment
the Member State on whose territory healthcare is actually provided to the patient. In the case of telemedicine, healthcare is considered to be provided in the Member State where the healthcare provider is established.
Article 3, point (d), Directive 2011/24/EU
Monists versus dualists
Two camps in the debate on the scope of Chapter IV of the EHDS: monists read the EHDS as an exhaustive, mandatory route for secondary use (a permit must almost always be applied for and the EHDS almost always applies); dualists hold that data users may freely choose whether to apply for a permit with the HDAB (falling under the EHDS) or to approach the data holder directly (falling under national law).
Not defined in law
MyHealth@EU
The European infrastructure for cross-border primary use of health data, allowing healthcare providers in another EU country to access relevant patient data.
Not defined in law
National contact point for eHealth
The national point of contact for digital health that facilitates cross-border exchange of data for primary use (care). It is the primary-use counterpart of the contact point for secondary use.
Not defined in law
National contact point for secondary use / National Gateway
The link between the national HDAB and HealthData@EU for cross-border applications. The Netherlands designates the HDAB itself for this.
Not defined in law
National control register
A national register in which a citizen can exercise their control over the secondary use of health data: an opt-out (objection) or a broad opt-in (consent).
Not defined in law
National health data catalogue
The public overview where data holders register their datasets (via metadata—i.e., a description) so that users can discover what data is available. Note: only structured datasets are registered, whereas a permit can be requested for all data (see DAAMS). Consequently, it is possible to request data that is not listed in the catalog.
Not defined in law
Necessity / necessity test
The legal "necessary" as used in the GDPR is not absolute indispensability, but a test of proportionality and subsidiarity: is the aim proportionate to the disadvantages, and could the aim be achieved in a less intrusive way. Note what is actually tested: not whether a public-interest task, a contract or a legitimate interest is necessary, but whether the processing is necessary for it.
Not defined in law
Non-compliance
any failure to comply with any requirement under the Union harmonisation legislation or under this Regulation.
Article 3, point (7), Regulation (EU) 2019/1020
Non-personal electronic health data
electronic health data other than personal electronic health data, including both data that have been anonymised so that they no longer relate to an identified or identifiable natural person (the ‘data subject’) and data that have never related to a data subject.
Article 2(2), point (b), EHDS Regulation
Not-incompatible use
Use for archiving in the public interest, scientific or historical research, or statistics, which the GDPR treats in advance as lawful and not incompatible with the original purpose. This is one of the four exceptions to purpose limitation. There is debate whether not-incompatible use also "rides along" on the original basis (like compatible use) or is simply permitted. That difference matters where there was no valid Article 6 ground for the original use: compatible use is then impossible, but not-incompatible use may still be allowed. The European Commission has proposed replacing "not incompatible" with "compatible".
Not defined in law
Opt-in
A form of control whereby data may only be used once the data subject has actively given prior consent. Note that the GDPR sets high requirements for consent, but lower requirements apply for scientific research purposes (see consent (legal definition) and broad consent, recital 33 GDPR).
Not defined in law
Opt-out
A form of control whereby use of personal data is permitted unless the data subject has objected beforehand. Also called the "no-objection system". Under the EHDS, secondary use is subject to an opt-out that can be exercised at any time. The opt-out has no retroactive effect, however, and therefore does not affect a permit already granted or a request already approved.
Not defined in law
Performance
the ability of a device to achieve its intended purpose as stated by the manufacturer.
Article 2, point (22), Regulation (EU) 2017/745
Personal data
any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Article 4, point (1), GDPR
Personal data breach
a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Article 4, point (12), GDPR
Personal electronic health data
data concerning health and genetic data, processed in an electronic form.
Article 2(2), point (a), EHDS Regulation
Placing on the market
the first making available of a product on the Union market.
Article 3, point (2), Regulation (EU) 2019/1020
Prescription
a prescription for a medicinal product or for a medical device issued by a member of a regulated health profession within the meaning of Article 3(1)(a) of Directive 2005/36/EC who is legally entitled to do so in the Member State in which the prescription is issued.
Article 3, point (k), Directive 2011/24/EU
Primary use
the processing of electronic health data for the provision of healthcare, in order to assess, maintain or restore the state of health of the natural person to whom those data relate, including the prescription, dispensation and provision of medicinal products and medical devices, as well as for relevant social, administrative or reimbursement services.
Article 2(2), point (d), EHDS Regulation
Processing
any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Article 4, point (2), GDPR
Processor
a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Article 4, point (8), GDPR
Profiling
any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
Article 4, point (4), GDPR
Prohibited (secondary) use
Uses prohibited under the EHDS (Article 54). Prohibited are, among others: (a) decisions detrimental to a person or group based on their health data; (b) decisions on job offers, less favourable terms or exclusion in insurance or credit (premiums, conditions) or otherwise discriminatory decisions; (c) advertising and marketing; (d) developing harmful products or services (such as drugs, alcohol, tobacco, weapons or addictive products); and (e) activities conflicting with national ethical provisions.
Not defined in law
Pseudonymisation
the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
Article 4, point (5), GDPR
Public health
all elements related to health, namely health status, including morbidity and disability, the determinants having an effect on that health status, health care needs, resources allocated to health care, the provision of, and universal access to, health care as well as health care expenditure and financing, and the causes of mortality.
Article 3, point (c), Regulation (EC) No 1338/2008
Public sector body
the State, regional or local authorities, bodies governed by public law or associations formed by one or more such authorities, or one or more such bodies governed by public law.
Article 2, point (17), Data Governance Act (EU) 2022/868
Purpose limitation
The principle that data collected for a particular purpose may not simply be used for a different purpose. There are four exceptions: (i) compatible use (which resembles, and still falls within, the original purpose), (ii) consent for other use, (iii) a law that permits that other use, or (iv) research, statistics and archiving.
Not defined in law
Putting into service
the first use, for its intended purpose, in the Union of an EHR system covered by this Regulation.
Article 2(2), point (l), EHDS Regulation
Recall
any measure aimed at achieving the return of a product that has already been made available to the end user.
Article 3, point (22), Regulation (EU) 2019/1020
Recipient
a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
Article 4, point (9), GDPR
Registration of electronic health data
the recording of health data in an electronic format, through the manual entry of such data, through the collection of such data by a device, or through the conversion of non-electronic health data into an electronic format, to be processed in an EHR system or a wellness application.
Article 2(2), point (g), EHDS Regulation
Relevant and reasoned objection
an objection to a draft decision as to whether there is an infringement of this Regulation, or whether envisaged action in relation to the controller or processor complies with this Regulation, which clearly demonstrates the significance of the risks posed by the draft decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union.
Article 4, point (24), GDPR
Representative
a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation.
Article 4, point (17), GDPR
Restriction of processing
the marking of stored personal data with the aim of limiting their processing in the future.
Article 4, point (3), GDPR
Risk
the combination of the probability of an occurrence of a hazard causing harm to health, safety or information security and the degree of severity of such harm.
Article 2(2), point (q), EHDS Regulation
Scientific research
The GDPR and the EHDS do not define scientific research in the definitions article, but recital 159 GDPR gives a broad description: the processing of personal data for scientific research purposes should be interpreted in a broad manner, including for example technological development and demonstration, fundamental research, applied research and privately funded research. Scientific research purposes also include studies conducted in the public interest in the area of public health.
Not defined in law
Secondary use
the processing of electronic health data for the purposes set out in Chapter IV of this Regulation, other than the initial purposes for which they were collected or produced.
Article 2(2), point (e), EHDS Regulation
Secure processing environment
the physical or virtual environment and organisational means to ensure compliance with Union law, such as Regulation (EU) 2016/679, in particular with regard to data subjects’ rights, intellectual property rights, and commercial and statistical confidentiality, integrity and accessibility, as well as with applicable national law, and to allow the entity providing the secure processing environment to determine and supervise all data processing actions, including the display, storage, download and export of data and the calculation of derivative data through computational algorithms.
Article 2, point (20), Data Governance Act (EU) 2022/868
Sensitive data (categories)
Four especially sensitive types of data for which Member States may prescribe stricter rules or an opt-in under the EHDS: genetic data, other molecular (omics) data, data from wellness applications, and data from biobanks.
Not defined in law
Separation of powers
The separation between legislative, executive and judicial power. Relevant because ultimately only the courts authoritatively determine what the law means, and not a regulator such as the Dutch DPA or the EDPB.
Not defined in law
Serious incident
any malfunction or deterioration in the characteristics or performance of an EHR system made available on the market that directly or indirectly leads, might have led or might lead to any of the following: (i) the death of a natural person or serious harm to a natural person’s health; (ii) serious prejudice to a natural person’s rights; (iii) serious disruption of the management and operation of critical infrastructure in the health sector.
Article 2(2), point (r), EHDS Regulation
Soft law
Non-binding rules or guidelines—such as codes of conduct and supervisory guidelines—that do not constitute law but nonetheless shape practice. They are binding only insofar as a statute contains open norms and the courts have chosen to give substance to those norms by reference to the relevant soft law. The situation differs in Anglo-American law, where there is less strict adherence to the principle of legality and soft law is more likely to have binding force.
Not defined in law
Software component
a discrete part of software which provides a specific functionality or performs specific functions or procedures and which can operate independently or in conjunction with other components.
Article 2(2), point (m), EHDS Regulation
Special categories of personal data
Sensitive data subject to a processing prohibition (Article 9 GDPR), unless one can rely on one of the exceptions of Article 9(2). Article 9(1) lists: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health, or data concerning a person's sex life or sexual orientation. Note that the European Commission has proposed narrowing the categories of data covered.
Not defined in law
Statistics
The GDPR describes statistics in recital 162: statistical purposes mean any operation of collection and the processing of personal data necessary for statistical surveys or for the production of statistical results. Characteristically, the result is not personal data but aggregate data, and that result and the personal data are not used in support of measures or decisions regarding any particular natural person.
Not defined in law
Supervisory authority
an independent public authority which is established by a Member State pursuant to Article 51.
Article 4, point (21), GDPR
Supervisory authority concerned
a supervisory authority which is concerned by the processing of personal data because: (a) the controller or processor is established on the territory of the Member State of that supervisory authority; (b) data subjects residing in the Member State of that supervisory authority are substantially affected or likely to be substantially affected by the processing; or (c) a complaint has been lodged with that supervisory authority.
Article 4, point (22), GDPR
Tehdas (Towards the European Health Data Space)
Tehdas, "Towards the European Health Data Space", is a joint action of EU Member States that prepared draft policy, recommendations and guidelines for the HDABs and for implementing secondary use under the EHDS. These outputs are not legally binding and are not always considered correct: you criticise, for example, Tehdas coupling the application process (DAAMS) to the dataset catalogue, which does not appear to be in line with the EHDS.
Not defined in law
Third party
a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
Article 4, point (10), GDPR
Transposition legislation
National legislation transposing a European directive into national law. Distinction from implementing legislation: a directive must be implemented (transposed), whereas a regulation has direct effect. Note regarding translations: ‘uitvoeringswetten’ are implementation acts, while ‘implementatiewetten’ are transposition acts..
Not defined in law
Trusted health data holder
A data holder designated as trusted by a public authority (probably the HDAB), which may therefore handle certain access applications itself through a simplified procedure, instead of everything going through the HDAB. That simplified procedure means the trusted holder drafts a proposal for the decision to be taken on the data access application or request. The HDAB reviews these proposals only marginally. The trusted holder may then make the data available in its own secure processing environment.
Not defined in law
Wellness application
any software, or any combination of hardware and software, intended by the manufacturer to be used by a natural person, for the processing of electronic health data, specifically for providing information on the health of natural persons, or the delivery of care for purposes other than the provision of healthcare.
Article 2(2), point (ab), EHDS Regulation
Withdrawal
any measure aimed at preventing a product in the supply chain from being made available on the market.
Article 3, point (23), Regulation (EU) 2019/1020

All definitions are taken verbatim from the official texts: from Article 2 of Regulation (EU) 2025/327, from Article 4 of the GDPR, and from the regulations and directives referred to in Article 2(1) of the EHDS Regulation. The full text of the EHDS Regulation is available on this site, in Dutch and English.