What GDPR: Health Data (Art. 9) requires
GDPR Article 9 establishes a general prohibition on processing special categories of personal data, with 'data concerning health' (including mental health, genetic data, and biometric data used for identification) receiving the highest level of protection. Processing is only permitted under ten exhaustive exemptions including explicit consent, vital interests, medical purposes under professional secrecy, public health, and scientific research under appropriate safeguards. AI systems processing health data - including medical AI, diagnostic tools, health chatbots, and research analytics platforms - must identify a specific Article 9(2) exemption, implement appropriate technical and organizational measures, and in most cases conduct a Data Protection Impact Assessment (DPIA) under Article 35. Violations involving special category health data attract the highest GDPR fines: up to €20 million or 4% of global annual turnover under Article 83(5).
Pillar: Data Protection & Privacy · Authority: GDPR.eu (EU Regulation) · Version: 1.1.0 · Last updated:
Primary source: https://gdpr-info.eu/art-9-gdpr/
SHA-256 integrity: 243e5f3ee616e35c70b8155aa40f9438f5f0f87637b5b63c43172eba9cd1d7cb
Primary Citations — 7 traced to source
- GDPR Article 9(1) and 9(2): Prohibition of processing of special categories of personal data and exhaustive exemptions.
- GDPR Article 35(3)(b): Mandatory Data Protection Impact Assessment (DPIA) for processing on a large scale of special categories of data.
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/gdpr-health-data.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/gdpr-health-data.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/gdpr-health-data
- Back to registry: Browse all 10,090 compliance nodes