What is the EHDS?
The European Health Data Space is the European regulation governing how electronic health data is used and shared within the EU. Find out what it entails, who it applies to, when it comes into effect, and how it relates to the GDPR and open data legislation.
The European Health Data Space (EHDS) is a European Regulation governing how medical data will be used and shared within the European Union. It becomes applicable in stages from March 2025 onwards. The Regulation builds a single European "data space" for health data: a well-secured "free movement of health data" within the EU, somewhat comparable to the free movement of goods and services. To achieve this, equal rights and obligations will apply across the entire EU, along with uniform IT requirements (concerning data, electronic health records, interoperability and secure processing environments) and new authorities tasked with supervising all of this, which will have to cooperate with one another.
A directly applicable European law
The EHDS is a regulation and therefore applies directly in the Member States; unlike a directive, it does not need to be transposed into national law. National implementing legislation will nevertheless be drafted, in order to fit the European rules into national law, such as administrative law, the rules on the citizen service number (BSN) or the Act on Control over Body Material. In addition, the Dutch supervisory authorities must be established or designated: the Health Data Access Body (data police for secondary use), the Health Data Authority (data police for primary use) and the National Contact Point for eHealth. Moreover, choices will have to be made that the Regulation leaves open. Work on that implementing act is currently under way. This page sets out, in broad terms, what the EHDS entails, to whom it applies, what changes when, and how the Regulation relates to the GDPR and to open data law. The theme pages explain individual topics in more detail.
Why is there an EHDS?
There were several reasons for drafting this European law. Health data are indispensable for good care, but also for scientific research, statistics, big data research, policy and the development of medicines and AI applications. Yet it was precisely those data that flowed poorly in Europe. Patients treated in another country could rarely take their records with them. And researchers who needed data ran into a patchwork of national rules, diverging interpretations of the GDPR, and data holders who — out of caution, or out of self-interest — refused to share. The coronavirus pandemic made painfully clear just how badly rapid, international collection and analysis of health data was lacking. The EHDS addresses each of these problems.
Primary use
The Regulation rests on three pillars. Primary use is the use of data for the patient themselves. The EHDS provides that citizens must be able to access their entire electronic health records and take them along to another healthcare provider, in every Member State. Conversely, healthcare providers must therefore also be able to help patients from all Member States without their IT systems getting in the way; you will be able to seek a second opinion in Barcelona if the best specialist happens to be there — and of course the other way round: Greek or Italian patients will be able to request a second opinion at Amsterdam UMC or Erasmus MC. Legally, free movement of data already existed within the EU, but in practice it barely got off the ground. As a result, the free movement of patients and healthcare providers did not get off the ground either. The MyHealth@EU system will now support this. As far as primary use is concerned in particular, the EHDS is a law that will simply apply always and everywhere in the EU: to all healthcare provision, therefore, and not only to cross-border care.
Secondary use
Secondary use is any reuse of existing health data for other purposes, exhaustively listed in the EHDS: scientific research, statistics, policy, education, patient safety, the development of products and services, and more. Certain applications are expressly prohibited, such as use for advertising, for higher insurance premiums, or for decisions to the detriment of the individual concerned. A permit is created, to be applied for at the newly established Health Data Access Body (HDAB), which is supervised by the EHDS Board. Such a permit does not give you the data themselves, but access to them within a secure processing environment. You can also submit a request to the HDAB in order to obtain a statistical answer. The system of cooperating HDABs is HealthData@EU. Because a permit and a request are created, an indirect right of access to data — or to results derived from data — arises (under very strict conditions). That is genuinely revolutionary. Training AI for the development of new (health)care products and services is also explicitly given room, under strict conditions.
Healthcare IT
The third pillar of the EHDS is the introduction of uniform European formats for healthcare IT. Because all manner of highly specific requirements apply in the Netherlands, Finnish or French IT developers cannot bring their products to market here. Nor will they make the effort, because our country is too small. The result is that two IT producers hold 92% of the market. That is unfavourable for the price and quality of healthcare IT. By prescribing the same requirements for electronic health records (EHRs) throughout Europe, it is not only ensured that one can communicate with a specialist in Barcelona, but also that the price and quality of healthcare IT improve. To that end, a uniform format for EHRs (EEHRxF) and a certification system will be introduced.
Market regulation
This makes the EHDS, at its core, a market regulation law: it orders the European market for health data, as has previously been done for goods, services and capital. That does not, of course, mean that large sums may be earned from those data. Data cannot be owned in any event. What is meant is that the free movement of data, the efficient but also heavily secured exchange of medical data, and the requirements as to transparency and non-discrimination, should together contribute indirectly to better care and medical innovation. At its core, then, the EHDS is not about healthcare, but forms part of data law. Is all of this ethical? Ethics is a different discipline from law. As a lawyer, I simply observe that the democratically elected European Parliament considered that it was, and personally I take the view that failing to carry out medical research can itself be unethical.
What does the EHDS mean for citizens?
Almost everyone will be affected by the Regulation. Under the GDPR, patients already had a right of access to their own medical records. But the GDPR allows fairly long time limits, whereas matters are frequently urgent. Patients gain the right to consult their entire file themselves, free of charge, for a second opinion. It is also required that their healthcare providers be able to consult it, should they be admitted to a southern European hospital in a coma while on holiday. And, as under the GDPR, they can correct data in that file or add data to it. Patients do retain control: they can object (though having done so, they cannot subsequently hold the physician liable for treatment based on incomplete data). Instead of arranging this per healthcare provider, this will now be organised nationally. A similar central system will also be introduced for medical research, allowing people to object where they wish. An entirely new right is also created: the right to be informed if significant findings about you are made in the course of research.
What does the EHDS offer researchers and innovators?
The EHDS is most revolutionary where the useful reuse of health data is concerned. At present, a researcher usually has to beg hospitals in order to assemble the necessary data. But if research that could save lives fifteen years from now is not carried out for fear of fines, then that costs lives fifteen years from now. We will never know whose, but there are still considerable ethical objections to not conducting medical scientific research. That is why the EHDS will create more possibilities. A Health Data Access Body will be established, where a permit can be applied for. If it is granted because the use of health data is genuinely beneficial, the holder of those data is obliged to cooperate with that (heavily secured) research. Companies developing medical products — enabling, for instance, a particular treatment to be carried out at home from now on rather than in hospital — can also apply for a permit.
What does the EHDS say about healthcare providers?
Healthcare providers will be affected by the EHDS in two ways. First, a great deal will have to change in their healthcare IT. This should ensure that all necessary data about a patient can be consulted; scans or blood tests therefore need not be repeated. It also reduces the risk of overlooking the fact that a patient is already taking other medication or has an allergy. Second, healthcare providers will be under a duty to supply data when the Health Data Access Body asks for them. Healthcare providers such as hospitals can of course be data users at the same time. University medical centres in particular may be designated as trusted data holders. They can then largely continue their data work independently, with the HDAB conducting only a marginal review of whether this is going well. An organisation such as IPCI (set up by Erasmus MC) could become a data hub, referred to in the EHDS as a data intermediation entity. By making extensive use of these two roles, we can set up a safe and efficient health data infrastructure.
When does the EHDS take effect?
The Regulation has been in force since 26 March 2025, but becomes applicable in phases. Preparations run until 2027: the Member States are working on implementing legislation and the European Commission is elaborating dozens of elements in secondary legislation, including the strict requirements for secure processing environments. From 26 March 2027 the frameworks are in place: the HDAB must have been designated and the European templates and requirements must have been adopted. From 26 March 2029 secondary use genuinely begins: users can submit permit applications and statistical questions, and data holders must supply most categories of data. From 26 March 2031 the more sensitive categories follow, such as genetic and other molecular data and data from clinical trials. Finally, from 2035 non-EU countries with an adequate level of privacy protection, or international organisations, will also be able to join.
How does the EHDS relate to the GDPR?
The GDPR continues to apply almost in full alongside the EHDS. The EHDS does not replace data protection law, but supplements it for health data and — more importantly — makes it workable. The requirement therefore remains that data be anonymised wherever reasonably possible. Where that is not possible, pseudonymisation must be applied. The principles of Article 5 also continue to apply, such as the principle of data minimisation. Under the EHDS, as now, there must be a valid legal basis under Article 6 for processing the data. And because medical and care data are special categories of personal data, one must be able to rely on one of the exceptions in Article 9 to the prohibition on processing them. Medical data must of course be properly secured, although highly specific requirements prescribed by the European Commission will now apply to the secure processing environment and to healthcare IT. The only thing that changes is that, under the EHDS, Member States have less room to arrange their privacy law differently from their neighbours. There is therefore greater harmonisation. The effect of this is that the Netherlands may no longer prescribe an opt-in (consent). Most European countries were content with an opt-out, so that is what the European Parliament chose.
Uncertainties in the EHDS
There are all sorts of reasons why a law — particularly one concerning a new phenomenon — is not immediately entirely clear. The EHDS is no different. It is not entirely clear, for instance, whether a DPIA will still have to be carried out for secondary use of health data via the HDAB, and if so by whom. Nor is it yet entirely clear how the principle of purpose limitation is to be applied under the EHDS. And anyone who thinks the EDPB can provide clarity is mistaken. As part of the executive branch, the EDPB can restrict its own powers, but not extend them. The courts will have to provide clarity, so it would be a good thing if various parties actively brought test cases before the judiciary in order to obtain more clarity about the EHDS.
The EHDS and the rest of European data law
The EHDS does not stand alone; it forms part of a broad European web of data rules. That body of data law can be read as a matrix with three axes. The first axis consists of the rules that restrict data sharing. These include the GDPR on privacy, trade secrets law, database law and all cyber legislation. The second axis consists of the rules that actively promote fair data sharing. These include the Data Governance Act, the Data Act, open data law and the High-Value Datasets Regulation. The third axis concerns the rules for specific types of data, such as the EHDS, which covers health data.
The Open Data Directive
The current, third Open Data Directive (2019/1024) has been implemented in the Netherlands in the Reuse of Government Information Act (Wet hergebruik van overheidsinformatie, Who), the operation of which is tied to the Open Government Act (Wet open overheid, Woo). That link seems logical, but rests on a misunderstanding: open data is not the same as public data. The Woo serves openness of government and makes information public for everyone; the Directive serves the economy and governs the sharing of data with specific reusers — if need be under protective licence conditions. By making reuse dependent on public disclosure, the Dutch implementation has turned out too narrow on two counts. Because the rules of the Open Data Directive will probably be incorporated into the Data Act under the Omnibus, they will become directly applicable law. That could well have considerable effect. The High-Value Datasets Regulation likewise applies directly as law in the Netherlands. Anyone looking for data to innovate with can benefit greatly from this open data law, under which data can also be requested from all manner of semi-public bodies and (grant-funded) foundations.
As open as possible, as closed as necessary
The European Union sums up the whole of data law as: "as open as possible, as closed as necessary." What is meant is that data are seen as "the new raw material" for economic growth and innovation. Those data should therefore be widely shared and reused. On the other hand, there are all sorts of reasons to protect those data and keep them confidential, such as privacy legislation and trade secrets law. The very short summary of data law is therefore: "if data can and may be shared, then they must be." The EU also seeks to encourage useful reuse of data in other ways. Researchers today often cannot see the wood for the trees, given the enormous number of agreements that have to be concluded when data come from different countries, where different laws and divergent soft law apply. From now on, a permit is applied for at a single HDAB, even where the data come from several countries. Moreover, all kinds of model agreements will be introduced. Privacy is not compromised in the process, since the GDPR continues to apply, while all manner of additional — but uniform — requirements are introduced. I therefore see no added value in any additional ethical review, which would only undermine the objectives of the EHDS.
What should you do now?
For citizens: you need do nothing at present, but you may wish to follow the process of the legislation that is to embed the EHDS in Dutch law. For IT suppliers: you will have your work cut out once the European Commission has adopted all the requirements — your products will all have to comply with them and you will have to obtain the necessary certification. Bear in mind that the idea is for a single European market to emerge. So seize this opportunity to design your product in such a way that you can also sell it in Germany or Spain. Healthcare providers should take stock as soon as possible of the healthcare IT they currently have in house, and the extent to which it will still suffice. Seek timely advice from specialists in procurement law: is there a material modification? Data holders will have to take stock of which datasets they hold that must be registered in the national catalogue. In doing so, they will have to determine which sets are subject to intellectual property rights. And all data users will have to take stock of the improbable possibilities that are about to arise. Whoever is first to benefit from the new opportunities offered by the EHDS will probably be far ahead of their competitors.
Want to know more?
If you would like to know more about the EHDS, the GDPR or open data law, please contact Mr. Dr. Vlieger. She has published in various journals and is working on a book about the EHDS and the GDPR. She can give you legal advice on how best to prepare for the EHDS, or how to benefit from the future law to the fullest. She can carry out additional research, for instance on what might be included in the implementing act to improve data availability for your particular sector. She can also provide education in all areas of law relating to health data, privacy law and open data law.
