Bidda Sovereign Intelligence · 10,099 Verified Nodes · 39 Sovereign Pillars

GDPR: Health Data (Art. 9)

GDPR Article 9 establishes a general prohibition on processing special categories of personal data, with 'data concerning health' (including mental…

What GDPR: Health Data (Art. 9) requires

GDPR Article 9 establishes a general prohibition on processing special categories of personal data, with 'data concerning health' (including mental health, genetic data, and biometric data used for identification) receiving the highest level of protection. Processing is only permitted under ten exhaustive exemptions including explicit consent, vital interests, medical purposes under professional secrecy, public health, and scientific research under appropriate safeguards. AI systems processing health data - including medical AI, diagnostic tools, health chatbots, and research analytics platforms - must identify a specific Article 9(2) exemption, implement appropriate technical and organizational measures, and in most cases conduct a Data Protection Impact Assessment (DPIA) under Article 35. Violations involving special category health data attract the highest GDPR fines: up to €20 million or 4% of global annual turnover under Article 83(5).

Pillar: Data Protection & Privacy · Authority: GDPR.eu (EU Regulation) · Version: 1.1.0 · Last updated:

Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679

SHA-256 integrity: bd282dd1addac28797a296e1c35f0687fbea32724d03fd48aea29792d6ee961a

Primary Citations — 7 traced to source

  • GDPR Article 9(1) and 9(2): Prohibition of processing of special categories of personal data and exhaustive exemptions.
  • GDPR Article 35(3)(b): Mandatory Data Protection Impact Assessment (DPIA) for processing on a large scale of special categories of data.

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.