Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

GDPR: Health Data (Art. 9)

GDPR Article 9 establishes a general prohibition on processing special categories of personal data, with 'data concerning health' (including mental…

What GDPR: Health Data (Art. 9) requires

GDPR Article 9 establishes a general prohibition on processing special categories of personal data, with 'data concerning health' (including mental health, genetic data, and biometric data used for identification) receiving the highest level of protection. Processing is only permitted under ten exhaustive exemptions including explicit consent, vital interests, medical purposes under professional secrecy, public health, and scientific research under appropriate safeguards. AI systems processing health data - including medical AI, diagnostic tools, health chatbots, and research analytics platforms - must identify a specific Article 9(2) exemption, implement appropriate technical and organizational measures, and in most cases conduct a Data Protection Impact Assessment (DPIA) under Article 35. Violations involving special category health data attract the highest GDPR fines: up to €20 million or 4% of global annual turnover under Article 83(5).

Pillar: Data Protection & Privacy · Authority: GDPR.eu (EU Regulation) · Version: 1.1.0 · Last updated:

Primary source: https://gdpr-info.eu/art-9-gdpr/

SHA-256 integrity: 243e5f3ee616e35c70b8155aa40f9438f5f0f87637b5b63c43172eba9cd1d7cb

Primary Citations — 7 traced to source

  • GDPR Article 9(1) and 9(2): Prohibition of processing of special categories of personal data and exhaustive exemptions.
  • GDPR Article 35(3)(b): Mandatory Data Protection Impact Assessment (DPIA) for processing on a large scale of special categories of data.

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.