Feedback on the draft EHDS Implementation Act
The EHDS Implementation Act (GIS Act) conflicts with EU law. The Ministry of Health (VWS) disregards the internal data market, bypasses the Authority for Consumers and Markets, and establishes a non-independent supervisory authority.
Consultation on the EHDS Implementing Act: contrary to European law
Summary:
1. The European Union is a hybrid legal order. The EHDS is primarily based on Article 114 TFEU (harmonisation of the internal market) and not on Article 168 TFEU (public health). This means that the Regulation is supranational law intended to promote the free movement of health data, and not intergovernmental cooperation for the purpose of good care. There is therefore no longer any room for an isolated, national vision of the health information system; the focus must lie exclusively on realising the European vision of the European Health Data Space. A divergent national approach conflicts with the free movement of care and ICT services (Article 56 TFEU) and with the principle of sincere cooperation (Article 4(3) TEU), and is incompatible with settled case law such as the Inter-Environnement Wallonie judgment (CJEU, C-129/96).
2. The EHDS is an integral part of the broader body of European data law (which also includes the Open Data Directive, eIDAS and the Interoperable Europe Regulation). The Regulation moreover addresses persistent market failure in the healthcare ICT market, such as vendor lock-ins, where European competition law has so far offered insufficient relief. Because what is fundamentally at stake here is the regulation of digital data markets, this dovetails seamlessly with the portfolio of the Ministry of Economic Affairs, where virtually all digital policy files are currently placed. The Jetten government would do well to move the EHDS file to that ministry as well. Following on from this, serious consideration should be given to placing supervision of healthcare ICT not with the Health and Youth Care Inspectorate (Inspectie Gezondheidszorg en Jeugd, IGJ) — which supervises care — but with the independent market watchdog that is genuinely equipped for this complex market dynamic: the Netherlands Authority for Consumers and Markets (Autoriteit Consument & Markt, ACM).
3. Finally, the drafting of the EHDS is based in part on Article 16 TFEU (protection of personal data). That article expressly requires that compliance be supervised by "independent authorities". Establishing the Health Data Authority (GezondheidsDataAutoriteit, GDA) as an independent administrative body (zbo) without its own legal personality, hierarchically forming part of the same legal person (the State) as the Ministry of Health, Welfare and Sport (VWS), the RIVM and the IGJ, falls short in terms of institutional independence. Organising supervision in this way amounts to a breach of primary Union law. Any construction in which it is possible for a minister to exert pressure in order to obtain citizens' health data for their own political gain, or conversely to keep confronting data hidden, is untenable and fundamentally contrary to the EHDS itself and to primary European law.
1. The EHDS is European strategy, not an instrument for national strategy
The wrong angle of approach in the Implementing Act
The EHDS Implementing Act bears as its primary title the "Health Information System Act" (Wet op het GezondheidsInformatie-Stelsel). Added in brackets is: "EHDS tranche 1". What's in a name, one might think, but it is genuinely relevant. It is apparent from the Explanatory Memorandum (Memorie van Toelichting, MvT) that the EHDS is not really regarded by VWS as a law with direct effect in the Netherlands. One reads, for example, that the Regulation is "not only aimed at cross-border care, but is also an accelerator for Member States to improve their national health information systems." That is an incorrect reading of the Regulation, which after all bears the name "European Health Data Space". It is not a policy instrument to give impetus to the stalled National Vision and Strategy, but dictates a European vision aimed at bringing about the free movement of health data throughout the Union, in support of the existing free movement of persons (including patients) and services (including the provision of care).
The constitutional basis (Art. 114 TFEU & Art. 5 TEU)
The Explanatory Memorandum wrongly asserts that the primary objective of the Regulation is that "electronic health data become more readily available for the provision of care". Although this is a noble aspiration, it cannot legally be the primary raison d'être of the Regulation. Under the principle of subsidiarity (Article 5 TEU), the EU is after all only competent to enact legislation where an objective cannot be achieved at national level. Laying down patients' rights and improving local care can perfectly well be arranged through national legislation. Removing obstacles to the free movement of data, by contrast, requires European harmonisation. Just as was the case with the General Data Protection Regulation (GDPR), the law is harmonised primarily for the benefit of the internal market, not merely to strengthen patients' rights. The true legal basis of the EHDS is therefore the (supranational) Article 114 TFEU (harmonisation of the internal market) and not Article 168 TFEU (intergovernmental cooperation) concerning care.
Free movement of (health) services
In Europe we have free movement of goods, services, capital and persons. Although healthcare is excluded from the material scope of the secondary Services Directive, it is a misconception to conclude e contrario that the EU does not intend there to be free movement of health services. Primary Union law (Article 56 TFEU) unmistakably applies here. As the Court of Justice held in Geraets-Smits and Peerbooms (C-157/99), the free movement of services applies equally to medical care, and may only be restricted where the protection of public health reasonably requires it. In order to enable a hospital in Nieuwegein, for instance, to call in a specialist from Barcelona when it is short of radiologists — without physically relocating the doctor — cross-border free movement of health data is a prerequisite.
Full effect, not exclusively cross-border
To understand the EHDS correctly, it must therefore be read as an integral part of the free movement provisions of Union law and of the remaining body of data law that supports that free movement. When the GDPR was introduced, it was also frequently thought at first that the rules concerned cross-border data traffic only. The Court of Justice put paid to that illusion resolutely in judgments such as Lindqvist (C-101/01) and Österreichischer Rundfunk and Others (C-465/00 and others). In exactly the same way, the EHDS must not be read as a law confined to cross-border data exchange, but as a framework that applies always and everywhere within the Union, unless the Regulation itself expressly formulates an exception.
Correct implementation and the principle of sincere cooperation
In the light of the above, the starting point for the national legislature should not have been fitting the Regulation into the existing national Electronic Data Exchange in Healthcare Act (Wet elektronische gegevensuitwisseling in de zorg, Wegiz). With a directly applicable European regulation, the fundamental questions ought to be: (i) on which points is there maximum harmonisation (where neither less nor more national legal protection is permitted), (ii) where does specific policy discretion remain, and (iii) how is this to be embedded institutionally within the national system? In doing so, the legislature must moreover be seriously on its guard that, with the Health Information System Act, it does not run ahead of — or run counter to — in policy terms, the more than twenty implementing acts that the European Commission will adopt over the coming nine months. Such national frustration of European policy conflicts with the principle of sincere cooperation (Article 4(3) TEU), as pointedly formulated by the Court in the Inter-Environnement Wallonie judgment (C-129/96).
2. The framework of European data law and competition law
Repair of the GDPR to promote the movement of persons
The EHDS must not be read in a vacuum, but as an inseparable part of the broader body of secondary Union law. The Regulation aims, among other things, to give patients direct and immediate access to their medical records. When a European citizen requires acute medical assistance while on holiday in Greece, immediate access to information on allergies or medication use is essential; this directly supports the free movement of persons. The GDPR proved to fall short on this point, since it allows a response period for access requests of "in any event within one month". In an acute care context such a period is utterly useless. On this point the EHDS therefore functions as a specific repair of the GDPR for the health sector.
Market failure, vendor lock-in and European competition law
With regard to healthcare ICT, it is the express intention of the EHDS to make the market fundamentally healthier. In several Member States, including the Netherlands, this sector is characterised by strong market power and persistent vendor lock-ins. (ChipSoft and Epic together serve an estimated 90% of the Dutch market for hospital EHRs, for example.) Ordinary European competition law has proved insufficiently powerful to resolve such problems structurally. The EHDS repairs this market failure by prescribing mandatory, uniform European standards. The aim is that Finnish or Spanish ICT suppliers should be able to enter the Dutch market without difficulty, and vice versa. In the light of this European market objective, it is utterly incomprehensible that the Ministry of Health, Welfare and Sport clings tenaciously to national standards (as in the Wegiz) and national anchors (such as the Chamber of Commerce). This forced national embedding is not only harmful to breaking open the vendor lock-ins, it is quite simply not permitted under Union law.
A systemic flaw in supervision: the IGJ instead of the ACM
Although the EHDS in substance amounts to a repair of competition law, this is entirely ignored in the Explanatory Memorandum (MvT). The MvT does refer to the Data Act and the Data Governance Act (DGA), regulations that in the Netherlands are supervised by the Netherlands Authority for Consumers and Markets (ACM). In the draft Health Information System Act, however, the ACM is given no new or formal role whatsoever in enforcing the EHDS; it merely retains its existing powers under the Dutch Competition Act (Mededingingswet). Instead, the Health Information System Act places the enforcement duties for the EHR market with the Health and Youth Care Inspectorate (IGJ). The IGJ has traditionally been set up to safeguard the quality of medical care and patient safety. It is therefore the logical authority to enforce the MDR concerning medical devices for diagnosis and treatment: that, after all, concerns care. Its AI powers likewise concern patient safety. But the IGJ lacks the specific economic and legal expertise to fathom ICT market dynamics and API interfaces. The Ministry of Economic Affairs (EZ), under which the ACM falls, is pre-eminently equipped to prise open such closed markets and to dissect the business models of tech giants. By nevertheless placing the power with the IGJ, VWS prevents EZ from putting its stamp on the Dutch care infrastructure. The result is an inefficient fragmentation of supervision: the IGJ will shortly have to enforce the European rules of the game for the EHR market, while the ACM has to keep exactly the same market players in check through competition law.
The blind spot for adjacent European data law
VWS's tunnel vision is further apparent from the fact that all manner of adjacent European data law goes unmentioned in the MvT:
- The eIDAS 2.0 Regulation: this legislation will shortly make the use of the European Digital Identity Wallet mandatory, with which citizens must be able to log in to their EHRs always and everywhere. Where one ministry arranges for EHRs to come into being, another ministry must therefore ensure that we also gain access to them.
- The Open Data Directive (which is to be incorporated into the Data Act): this regulation relates specifically to research data and requires the use of APIs and bulk downloads. This is essential for secondary data use (for example when the RIVM urgently needs data during a pandemic). Incidentally, the Netherlands has implemented this directive incorrectly by stating that it does not apply to personal data, whereas the directive only excludes data that may not be processed under the GDPR.
- The Interoperable Europe Regulation (2024/903): this regulation applies to trans-European digital services such as MyHealth@EU and HealthData@EU, and also affects direct cooperation between, for example, the RIVM and the ECDC.
Within the sitting government it has been agreed that virtually all digital files are to be brought together under the Ministry of Economic Affairs. Given that the EHDS is primarily about the free movement of data, digital markets and interoperability — and is not about the provision of care — it is incomprehensible that EZ is nowhere mentioned in the MvT. The government would do well to transfer the entire EHDS file to Economic Affairs as well, including the allocation of the market supervision tasks to the ACM.
3. The illusory independence of the Health Data Authority
The constitutional requirement of independence (Art. 16 TFEU)
The EHDS is also anchored in Article 16 TFEU, which confers on the Union the power to lay down rules relating to the processing of personal data, "and the rules relating to the free movement of such data". This principle of free movement of data has for years been laid down in mandatory terms in Article 1 of the GDPR and in Regulation 2018/1807 on the free flow of non-personal data (something on which the Dutch Data Protection Authority unfortunately rarely enforces in practice). Crucially, however, Article 16 TFEU also expressly provides: "Compliance with these rules shall be subject to the control of independent authorities." In the Dutch GDPR Implementation Act (Uitvoeringswet AVG, UAVG), this has been correctly transposed: "There shall be a Dutch Data Protection Authority. The Dutch Data Protection Authority shall have legal personality." The proposal for the Health Information System Act, by contrast, merely states: "There shall be a Health Data Authority." According to the proposal, the GDA therefore does not obtain its own legal personality, but is set up as an independent administrative body (zelfstandig bestuursorgaan, zbo) within the legal person The State. Although such a construction is possible under Dutch administrative law, it is extremely problematic in the light of European law. On this point the Explanatory Memorandum states only that what already existed under the Wegiz and the Wabvpz is being maintained, but that, like our administrative law, is national legislation, which may not conflict with the TFEU.
The Framework Act on Independent Administrative Bodies illusion
VWS writes in the MvT: "The Framework Act on independent administrative bodies (Kaderwet zbo's) applies to the Health Data Authority. The Health Data Authority is (...) established as a zbo because there is a need for independent judgement on the basis of specific expertise." VWS also states that although the Minister makes staff available, the staff are accountable to the GDA and not to the Minister. This is a classic Hague-style, formal-legal defence. VWS brandishes the formal zbo status in order to claim independence. That the independence in the Health Information System Act is an illusion emerges painfully clearly from Article 2.2.3 (paragraphs 3 to 5). That article provides that the Minister must approve the mandate scheme (the internal division of work of the GDA's staff), may withhold that approval, and may even instruct the GDA in binding terms to amend the scheme. In the MvT, VWS frankly acknowledges this, but paradoxically argues that it is a 'safeguard' to guarantee the proper performance of tasks. Strikingly, the fact that the Netherlands also has the Instructions concerning the national inspectorates (Aanwijzingen inzake de rijksinspecties) — which are specifically intended to give inspectorates more de facto autonomy — is passed over entirely in silence in the MvT.
Conflicts of interest and incompatibility with Article 55 EHDS
The construction in the Health Information System Act is also contrary to the EHDS itself, now that the GDA will also perform the tasks arising under Chapter IV of the EHDS (secondary use). Article 55(3) EHDS mandatorily requires Member States to prevent conflicts of interest between the organisational components of the HDAB. Paragraph 5 adds: "The staff of health data access bodies shall act in the public interest and in an independent manner." Contrary to what the Explanatory Memorandum argues, this makes it legally and factually impossible for the HDAB to remain an inseparable part of the Ministry of Health, Welfare and Sport. After all, through institutions such as the RIVM, VWS is itself one of the largest data holders. When, during a pandemic, a researcher applies to the HDAB for a data permit in order to independently recalculate the RIVM's calculations, a direct conflict of interest arises for the ministry's staff. In such a scenario it is tempting for a sitting minister to frustrate such painful research on political grounds, whereas the EHDS mandatorily guarantees precisely such access to data. It would be worse still if, in the future, a Minister were to exert pressure, for their own political gain, to demonstrate with health data that there is something wrong with specific population groups.
A systemic flaw in enforcement: the Minister as supervisory authority (Art. 43 EHDS)
A comparable fundamental design flaw is to be found in the enforcement construction for market surveillance. Article 7.1.1 of the Health Information System Act formally designates the IGJ for market surveillance of EHR systems. If, however, we look at the actual administrative enforcement powers — such as imposing an order subject to a penalty payment or a written instruction (Article 7.4.1) — these lie not with the IGJ, but exclusively with Our Minister. This is presumably connected with the dogmatic question of whether the IGJ is in fact an independent administrative body that can take enforcement decisions in its own name, as a result of which the power is placed with the Minister (who will in practice mandate it back to the IGJ). Be that as it may, this construction is contrary to Article 43(2) of the EHDS. That article requires: "Member States shall confer on their market surveillance authorities the necessary powers (...) The market surveillance authorities shall have the power to take the market surveillance measures referred to in Article 16 of Regulation (EU) 2019/1020". Under the current arrangement, the IGJ simply cannot exercise these powers in independence. The authority that does indeed possess these powers, and in full independence, is the Netherlands Authority for Consumers and Markets (ACM).
Conclusion: the need to move to an independent domain
The proposal in fact leads to a situation in which the Ministry of Health, Welfare and Sport designates itself as the supervisory authority. Given the strong political colouring of the minister, this is utterly untenable. This institutional straddle is of course nothing new and currently also underlies the ongoing discussions surrounding the draft Framework Act on National Inspectorates (Concept-Kaderwet Rijksinspecties). It would do the legislature credit to take the lessons from that file to heart in the context of the design of the GDA. There is a noticeable tendency in the Netherlands to set up supervisory authorities less often as legal persons in their own right, and to opt more often for a zbo within the State. However, in order to secure independence as required by European law within such a construction, such a zbo must be placed under a ministry without conflicting interests (whether substantive care interests or interests as a data holder). If one insists on setting up the GDA and the supervisory authority as a zbo without its own legal personality, that body must not be made subordinate to precisely that minister who is themselves a very large holder of health data. By their very nature (European competition and data law), the supervisory and enforcement tasks relating to the EHDS belong with the Ministry of Economic Affairs and the ACM. That this transition calls for the transfer of specialised civil servants from VWS to EZ or the ACM is not an obstacle, but rather a necessary organisational consequence.
