My bookmarksSign up free

Regulation (EU) 2025/327 SECTION 2 — Governance for primary use

Article 19–Article 22 · 4 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Digital health authorities

Article 19

1.   Each Member State shall designate one or more digital health authorities responsible for the implementation and enforcement of this Chapter at national level. The Member States shall inform the Commission of the identity of the digital health authorities by 26 March 2027. Where a Member State designates more than one digital health authority or where the digital health authority consists of multiple organisations, the Member State concerned shall communicate to the Commission a description of the distribution of tasks between those various authorities or organisations. Where a Member State designates several digital health authorities, it shall designate one digital health authority to act as coordinator. The Commission shall make that information publicly available. 2.   Each digital health authority shall be entrusted with the following tasks and powers: (a) ensuring the implementation of the rights and obligations provided for in this Chapter and Chapter III by adopting necessary national, regional or local technical solutions and by establishing relevant rules and mechanisms; (b) ensuring that complete and up-to-date information about the implementation of rights and obligations provided for in this Chapter and Chapter III is made readily available to natural persons, health professionals and healthcare providers; (c) in the implementation of technical solutions referred to in point (a) of this paragraph, ensuring that such technical solutions comply with this Chapter, Chapter III and Annex II; (d) contributing at Union level to the development of technical solutions enabling natural persons and health professionals to exercise their rights and comply with their obligations set out in this Chapter; (e) facilitating persons with disabilities to exercise their rights under this Chapter in accordance with Directive (EU) 2019/882 of the European Parliament and of the Council  ( 31 ) ; (f) supervising the national contact points for digital health and cooperating with other digital health authorities and the Commission on further development of MyHealth@EU; (g) ensuring the implementation at national level of the European electronic health record exchange format, in cooperation with national authorities and stakeholders; (h) contributing at Union level to the development of the European electronic health record exchange format, to the elaboration of common specifications, in accordance with Article 36, which address quality, interoperability, security, safety, ease of use, accessibility, non-discrimination or fundamental right concerns, and to the elaboration of the specifications of the EU database for registration of EHR systems and wellness applications referred to in Article 49; (i) where applicable, performing market surveillance activities in accordance with Article 43, while ensuring that any conflicts of interest are avoided; (j) building national capacity for implementing requirements concerning interoperability and security of electronic health data for primary use and participating in information exchanges and capacity building activities at Union level; (k) cooperating with market surveillance authorities, participating in the activities related to handling of risks posed by EHR systems and of serious incidents and supervising the implementation of corrective action in accordance with Article 44; (l) cooperating with other relevant entities and bodies at local, regional, national or Union level, to ensure interoperability, portability and security of electronic health data; (m) cooperating with supervisory authorities in accordance with Regulations (EU) No 910/2014 and (EU) 2016/679 and Directive (EU) 2022/2555 of the European Parliament and of the Council  ( 32 ) and with other relevant authorities, including those competent for cybersecurity and electronic identification. 3.   Each Member State shall ensure that each digital health authority is provided with the human, technical and financial resources, premises and infrastructure necessary for the effective performance of its tasks and exercise of its powers. 4.   In the performance of its tasks, each digital health authority shall avoid any conflicts of interest. Each member of staff of the digital health authority shall act in the public interest and in an independent manner. 5.   In the performance of their tasks, the relevant digital health authorities shall actively cooperate and consult with relevant stakeholders’ representatives, including patients’ representatives, healthcare providers and health professionals’ representatives, including health professional associations, as well as consumer organisations and industry associations.

Reporting by digital health authorities

Article 20

Digital health authorities designated pursuant to Article 19 shall publish an activity report every two years, which shall contain a comprehensive overview of their activities. If a Member State designates more than one digital health authority, one of them shall be responsible for the drawing up of the report and, in doing so, it shall request the necessary information from the other digital health authorities. That activity report shall follow a structure agreed at Union level within the European Health Data Space Board (the ‘EHDS Board’) referred to in Article 92. That activity report shall contain at least information concerning: (a) the measures taken to implement this Regulation; (b) the percentage of natural persons having access to the various data categories of their electronic health records; (c) the handling of requests from natural persons regarding the exercise of their rights pursuant to this Regulation; (d) the number of healthcare providers of different types, including pharmacies, hospitals and other points of care, connected to MyHealth@EU calculated: (i) in absolute terms; (ii) as a share of all healthcare providers of the same type; and (iii) as a share of natural persons that are able to use the services; (e) the volumes of electronic health data of different categories shared across borders through MyHealth@EU; (f) the number of cases of non-compliance with mandatory requirements.

Right to lodge a complaint with a digital health authority

Article 21

1.   Without prejudice to any other administrative or judicial remedy, natural and legal persons shall have the right to lodge a complaint in relation to the provisions laid down in this Chapter, individually or, where relevant, collectively, with the competent digital health authority, provided that their rights or interests are negatively affected. 2.   Where the complaint concerns the rights of natural persons pursuant to Articles 3 and 5 to 10 of this Regulation, the digital health authority shall transmit the complaint to the competent supervisory authorities under Regulation (EU) 2016/679. The digital health authority shall provide the necessary information at its disposal to the competent supervisory authority under Regulation (EU) 2016/679 in order to facilitate the assessment and investigation of the complaint. 3.   The competent digital health authority with which the complaint has been lodged shall inform, in accordance with national law, the complainant of the progress made in dealing with the complaint, of the decision taken on the complaint, of any referral of the complaint to the competent supervisory authority under Regulation (EU) 2016/679 and, in cases of such a referral, that that supervisory authority is, from that moment on, to be the sole point of contact for the complainant in that matter. 4.   Digital health authorities in the Member States concerned shall cooperate to handle and resolve complaints related to cross-border exchange of and access to personal electronic health data, including by exchanging all relevant information by electronic means, without undue delay. 5.   Digital health authorities shall facilitate the submission of complaints and provide easily accessible tools for the submission of complaints.

Relationship with supervisory authorities under Regulation (EU) 2016/679

Article 22

The supervisory authority or supervisory authorities responsible for monitoring and enforcing the application of Regulation (EU) 2016/679 shall also be competent for monitoring and enforcing the application of Articles 3 and 5 to 10 of this Regulation. The relevant provisions of Regulation (EU) 2016/679 shall apply mutatis mutandis . Supervisory authorities shall be empowered to impose administrative fines up to the amount referred to in Article 83(5) of Regulation (EU) 2016/679. The supervisory authorities referred to in the first paragraph of this Article and digital health authorities referred to in Article 19 shall, where relevant, cooperate in the enforcement of this Regulation, within the remit of their respective competences.

Back to Regulation (EU) 2025/327 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next