BlackTree Security · Infrastructure · Automation · AI

The European Health Data Space Is Not Just Another GDPR Article

The European Health Data Space creates infrastructure and governance for exchanging and reusing health data. It entered into force in March 2025, but most operational duties arrive through a long, staged implementation.

Regulation (EU) 2025/327 entered into force on 26 March 2025. The European Health Data Space has three connected goals: improve access to electronic health data for care, enable secure secondary use for research and policy, and create a single market for interoperable electronic health-record systems.

It sits alongside the GDPR rather than replacing it. GDPR establishes the general data-protection framework. EHDS adds sector-specific rights, infrastructure, governance and technical requirements.

Primary use follows the patient

Primary use means using electronic health data to provide healthcare. The framework is intended to make priority data categories available across providers and borders through common formats and infrastructure.

Patients gain greater access and control, including visibility into access, correction mechanisms and the ability to restrict access in specified circumstances. Health professionals gain a route to relevant records beyond the boundaries of one hospital or national system.

This requires more than connecting databases. Identity, professional authorisation, emergency access, semantic interoperability, logging and record correction all need common rules.

Secondary use occurs in controlled environments

Secondary use includes research, innovation, public health, policymaking and regulatory activities. Access is governed through national Health Data Access Bodies rather than informal copies of datasets.

Permitted users apply for access and receive a permit. Personal data should be minimised and, depending on the purpose, anonymised or pseudonymised. Processing occurs in secure environments, and attempts to re-identify individuals are prohibited.

The architecture resembles a controlled analysis platform more than a conventional data export. Researchers bring approved computation to governed data; they should not simply download identifiable records to a local workstation.

EHR software becomes a regulated product category

EHDS creates common requirements for electronic health-record systems, including mandatory interoperability and logging components. Manufacturers will need to demonstrate that systems meet applicable requirements before placing them on the market and support post-market compliance.

For health providers, procurement criteria will need to examine export formats, access logs, security, update support and conformity, not only clinical features and licence cost.

Entry into force is not immediate application

The implementation is deliberately staged. The Commission has identified major milestones including implementing acts by March 2027, application of key primary-use and most secondary-use provisions from March 2029, further data categories from March 2031, and possible third-country participation later.

That distinction matters. Saying “EHDS applies now” can be as misleading as saying “nothing happens until 2029”. The transition period is when standards, access bodies, platforms and procurement decisions are being built.

What organisations should do during the transition

Healthcare providers, EHR vendors and data holders should:

  1. Inventory electronic health-data categories and systems.
  2. Map identity, access, logging and correction workflows.
  3. Test export and import using European exchange formats as they mature.
  4. Separate primary-care use from secondary-use pipelines.
  5. Design secure processing environments that prevent unauthorised extraction.
  6. Add EHDS conformity and interoperability to procurement roadmaps.
  7. Track national implementation and the implementing acts scheduled through 2027.
  8. Coordinate EHDS work with GDPR, NIS2, the Cyber Resilience Act and medical-product rules.

Health data cannot be made interoperable later

The difficult part of EHDS is not writing the legal basis for sharing. It is turning decades of incompatible identifiers, formats, clinical vocabularies and access models into trustworthy exchange.

Organisations that wait for the final application date may discover that their largest problem is not policy. It is technical debt that cannot be removed on a regulatory timetable.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *