Secondary use of health data
Secondary use of health data is the processing of health data for a purpose other than the primary purpose for which it was collected, typically the reuse of data from healthcare delivery (electronic health records, claims, registries, laboratory and imaging systems) or from completed clinical trials for scientific research, innovation, real-world evidence generation, health system planning, regulatory activities or training of AI models. Primary use is the care of the patient (or the conduct of the original trial); everything else is secondary.
Under the GDPR, secondary use engages the purpose limitation principle. Further processing is lawful if it is compatible with the original purpose under Art. 6(4), and processing for research or statistical purposes is presumed compatible under Art. 5(1)(b) provided the Art. 89(1) safeguards (minimisation, pseudonymisation, anonymisation where possible) are applied. Because health data is a special category, an Art. 9(2) exception is also required, usually (j) research based on Union or Member State law, or (i) public health. Individuals must be informed under Art. 14 unless doing so is impossible or disproportionate, in which case public information and safeguards are required, and they retain the right to object under Art. 21(6). National law then adds the decisive layer: France requires conformity with MR-004 or a CNIL authorisation and, for hospital health data warehouses, a dedicated framework; Germany, Finland (Findata), Denmark and the Netherlands each have their own access regimes; and in the UK the Health Research Authority and the common-law duty of confidentiality apply alongside the UK GDPR.
The European Health Data Space regulation harmonises secondary use from 2029 by obliging data holders to make defined categories of electronic health data available through national health data access bodies, under data permits, in secure processing environments and for permitted purposes only, with an opt-out for individuals. Until then, and for data outside the EHDS scope, a sponsor or HealthTech company planning secondary use should document the compatibility analysis or the specific legal basis per country, establish who is controller (data holder, sponsor, platform), agree contracts that state whether delivered data is anonymised or pseudonymised, run a DPIA, and plan transparency measures. See iliomad's health data warehouse services and the French HDW guideline.
