Capacity building
The Commission shall support the sharing of best practices and expertise to build capacity within Member States to strengthen digital health systems for primary use and secondary use taking into account the specific circumstances of the different categories of stakeholders involved. To support that capacity building, the Commission shall in close cooperation and consultation with Member States establish indicators for self-assessment for primary use and secondary use.
Training programmes and information for health professionals
1. Member States shall develop and implement or provide access to training programmes and provide access to information for health professionals in order for them to understand and effectively carry out their role in the primary use of and in the accessing of electronic health data, including in relation to Articles 11, 13 and 16. The Commission shall support Member States in that regard.
2. The training programmes and information shall be accessible to and affordable for all health professionals, without prejudice to the organisation of healthcare systems at national level.
Digital health literacy and digital health access
1. Member States shall promote and support digital health literacy and the development of relevant competences and skills for patients. The Commission shall support Member States in this regard. Awareness-raising campaigns or programmes shall aim, in particular, to inform patients and the public at large about primary use and secondary use in the framework of the EHDS, including the rights arising from it, as well as the advantages, risks and potential gains for science and society of primary use and secondary use.
2. The awareness-raising campaigns and programmes referred to in paragraph 1 shall be tailored to the needs of specific groups and shall be developed, reviewed and, where necessary, updated.
3. Member States shall promote access to the infrastructure necessary for the effective management of natural persons’ electronic health data, both for primary use and secondary use.
Additional requirements for public procurement and Union funding
1. Contracting authorities, including digital health authorities and health data access bodies and Union institutions, bodies, offices or agencies, shall make reference to the applicable technical specifications, standards and profiles as referred to in Articles 15, 23, 36, 73, 75 and 78 for public procurement procedures and when formulating their tender documents or calls for proposals, as well as when defining the conditions for Union funding regarding this Regulation, including enabling conditions for the structural and cohesion funds.
2. The criteria for obtaining funding from the Union shall take into account the requirements developed in the framework of Chapters II, III and IV.
Storage of personal electronic health data for primary use
In accordance with the general principles of Union law, which include the fundamental rights enshrined in Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, Member States shall ensure that a particularly high level of protection and security is in place when processing personal electronic health data for primary use, by means of appropriate technical and organisational measures. In this respect, this Regulation shall not preclude a requirement under national law, taking into account the national context, that, in cases where personal electronic health data are processed by healthcare providers for the provision of healthcare or by the national contact points for digital health connected to MyHealth@EU, the storage of personal electronic health data referred to in Article 14 of this Regulation for the purpose of primary use be located within the Union, in compliance with Union law and international commitments.
Storage of personal electronic health data by health data access bodies and secure processing environments
1. Health data access bodies, trusted health data holders and the Union health data access service shall store and process personal electronic health data in the Union when performing pseudonymisation, anonymisation and any other personal data processing operations referred to in Articles 67 to 72, through secure processing environments within the meaning of Article 73 and Article 75(9) or through HealthData@EU. That requirement shall apply to any entity performing those tasks on behalf of such bodies, holders or service.
2. By way of exception from paragraph 1 of this Article, the data referred to in that paragraph may be stored and processed in a third country, or a territory or one or more specified sectors within that third country, where such country, territory or sector is covered by an adequacy decision adopted pursuant to Article 45 of Regulation (EU) 2016/679.
Third-country transfer of non-personal electronic data
1. Non-personal electronic health data made available by health data access bodies to a health data user in a third country under a data permit issued pursuant to Article 68 of this Regulation or a health data request approved pursuant to Article 69 of this Regulation, to authorised participants in a third country or to an international organisation, and based on a natural person’s electronic health data falling within one of the categories referred to in Article 51 of this Regulation, shall be deemed highly sensitive within the meaning of Article 5(13) of Regulation (EU) 2022/868 where the transfer of such non-personal electronic data to third countries presents a risk of re-identification through means going beyond those reasonably likely to be used, in particular in view of the limited number of natural persons to whom those data relate, the fact that they are geographically scattered or the technological developments expected in the near future.
2. The protective measures for the categories of data mentioned in paragraph 1 of this Article shall be detailed in a delegated act referred to in Article 5(13) of Regulation (EU) 2022/868.
International governmental access to non-personal electronic health data
1. Digital health authorities, health data access bodies, authorised participants in the cross-border infrastructures provided for in Articles 23 and 75 and health data users shall take all reasonable technical, legal and organisational measures, including contractual arrangements, in order to prevent the transfer of non-personal electronic health data held in the Union to a third country or an international organisation, including for governmental access in a third country, where such transfer would create a conflict with Union law or the national law of the relevant Member State.
2. Any judgment of a third-country court or tribunal and any decision of a third-country administrative authority requiring a digital health authority, health data access body or health data users to transfer or give access to non-personal electronic health data within the scope of this Regulation held in the Union shall be recognised or enforceable in any manner only if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union, or any such agreement between the requesting third country and a Member State.
3. In the absence of an international agreement as referred to in paragraph 2, where a digital health authority, a health data access body or a health data user is the addressee of a decision or judgment of a third-country court or tribunal or of a decision of a third-country administrative authority requiring them to transfer or to give access to non-personal data within the scope of this Regulation held in the Union, and compliance with such a decision or judgment would risk putting the addressee in conflict with Union law or with the national law of the relevant Member State, the transfer to, or accessing of such data by, that third-country court, tribunal or administrative authority shall only take place or be provided where:
(a)
the third-country legal system requires the reasons and proportionality of such a decision or judgment to be set out and requires such a decision or judgment to be specific in character, for instance by establishing a sufficient link to certain suspected persons or infringements;
(b)
the reasoned objection of the addressee is subject to a review by a competent third-country court or tribunal; and
(c)
the competent third-country court or tribunal issuing the decision or judgment or reviewing the decision of an administrative authority is empowered by the national law of the third country to take duly into account the relevant legal interests of the provider of the data protected under Union law or the national law of the relevant Member State.
4. If the conditions laid down in paragraph 2 or 3 are met, a digital health authority, a health data access body or a data altruism organisation shall provide the minimum amount of data permissible in response to a request, based on a reasonable interpretation of the request.
5. The digital health authorities, health data access bodies and health data users shall inform the health data holder about the existence of a request of a third-country administrative authority to access its data before complying with that request, except where the request serves law enforcement purposes and for as long as compliance is necessary to preserve the effectiveness of the law enforcement activity.
Additional conditions for transfer of personal electronic health data to a third country or an international organisation
Transfer of personal electronic health data to a third country or an international organisation shall be granted in accordance with Chapter V of Regulation (EU) 2016/679. Member States may maintain or introduce further conditions on international access to, and transfer of, personal electronic health data, including limitations, in accordance with Article 9(4) of Regulation (EU) 2016/679, in addition to the requirements laid down in Article 24(3) and Article 75(5) of this Regulation and in Chapter V of Regulation (EU) 2016/679.
Health data access applications and health data requests from third countries
1. Without prejudice to Articles 67, 68 and 69, health data access applications and health data requests submitted by a health data applicant established in a third country shall be considered eligible by health data access bodies and the Union health data access service if the third country concerned:
(a)
is an authorised participant on the basis of having a national contact point for secondary use covered by an implementing act referred to in Article 75(5); or
(b)
allows Union health data applicants access to electronic health data in that third country under conditions that are not more restrictive than those provided for in this Regulation, and therefore such access is covered by an implementing act referred to in paragraph 2 of this Article.
2. By means of implementing acts, the Commission may determine that a third country meets the requirement set out in paragraph 1, point (b), of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2). The Commission shall make the list of implementing acts adopted pursuant to this paragraph publicly available.
3. The Commission shall monitor developments in third countries and international organisations that could affect the application of the implementing acts adopted pursuant to paragraph 2, and shall provide for a periodic review of the application of this Article.
Where the Commission considers that a third country no longer meets the requirement laid down in paragraph 1, point (b), of this Article, it shall adopt an implementing act repealing the implementing act referred to in paragraph 2 of this Article relating to that third country that benefits from access. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.