European Health Data Space (“EHDS”) – what are the ramifications for user data and intellectual property rights?

Background
The EHDS is envisaged to become the European Union’s ecosystem for health data, aiming to create efficient cross-border healthcare across the Member States. By creating a shared, centralised framework for health data to be shared across the EU, this allows patients to access prescriptions, or hospitals to access a patient’s medical records, no matter where they are across the EU. In essence, the EHDS establishes rules for the access of electronic health data for healthcare purposes and the sharing and access of specific health data for ‘secondary’ purposes. However, there are potential issues with the use of confidential information and potential intellectual property implications that are outlined below.
Timeline
- March 2022: The EHDS was first proposed by the European Commission.
- 21 January 2025: The EHDS was adopted by the Council of the European Union.
- 26 March 2025: The EHDS came into force.
- March 2027: This is the approximate deadline for the European Commission to adopt key implementing acts and to provide detailed rules.
- March 2029: This is the envisaged date that the key parts of the EHDS will enter into application. This will include primary use (including patient summaries and prescriptions) in all EU Member States.
- March 2031: This is the envisaged date where all primary use should be operational in all EU Member States.
- March 2035: Third countries and international organisations will be able to apply to join HealthData@EU for secondary use.
Primary use
The primary purpose of the EHDS is the ability to use health data for diagnostic purposes, continuation of care and issuance of prescriptions across the EU. This, in theory, allows for seamless medical treatment across the Member States (for example, by sharing a patient’s health data who is being treated in hospital in a different Member State). This primary purpose is generally considered to be a positive step in harmonisation. However, as this data is not anonymised, it poses potential risks from a GDPR perspective and the potential for data leaks. Furthermore, there is also a risk that individuals’ data may be misused. However, the use of electronic health data from a primary use perspective poses less significant data and IP problems than those from a secondary use perspective.
Secondary use
Secondary use of electronic health data is for purposes other than the direct provision of healthcare. The EHDS permits many purposes as ‘secondary use’ such as scientific research, public health and policy making decisions, statistics and training of AI systems to name a few. Contrary to the primary use, this electronic health data should be anonymised where possible. However, this poses a variety of IP and data implications for individuals and companies alike.
IP implications for secondary use
The EHDS requires health data holders (hospitals, pharmacists etc) to make data available for secondary use. Smartwatches, by way of example, generate continuous data, combining data such as heart rate along with behaviours, such as sleep patterns and activity levels. These all qualify as electronic health data for the purpose of EHDS. This data will be collected for both the primary and secondary purpose.
Manufacturers of devices that collect health data (for example, providers of smartwatches and other health monitoring tech) are legally obliged to make certain categories of health data available for secondary purposes.
Due to the continuous data such wearables collect (24/7 heart rate, sleep patterns etc), these companies possess an enormous amount of data and are expected to share this data through Health Data Access Bodies. A major concern is the exclusivity of this data, as competitors will be able to gain access to the same data they collect. This has the potential to affect competitiveness and even expose trade secrets. This will also place higher compliance costs on associated companies who will be under increased scrutiny to share this data.
Furthermore, data is incredibly valuable. Companies who collect health data usually have exclusive access to this data, being able to utilise this to their competitive advantage and assisting in their innovation. However, under the EHDS and the requirement for secondary use, companies will now lose their exclusive access, and as already mentioned, must share this with an array of bodies (including but not limited to researchers and policy makers). This will not only impact competitiveness within the EU, but could have wider implications globally. For instance, companies operating within the EU already have stringent requirements under the GDPR, particularly when compared with their competitors in the US and China. The EHDS, despite its benefits, places an additional burden on those companies in the EU, potentially reducing their competitive edge against innovators in the US and China (insofar as these companies are not domiciled in and operating within the EU).
The first drawback is that all companies, irrespective of their size, must comply with the requirements to share their health data. This inherently impacts smaller companies, such as startups and SMEs, who may not have the requisite infrastructure to meet these requirements. As a result, there will be a greater burden on these companies, who in turn may have to reallocate resources away from innovation to compliance. Although this will hamper SMEs significantly, there is also a greater burden on established corporations, who will likely possess a greater amount of health data and will be subject to a larger number of health data requests. This requires greater resources and has the potential to detract from innovation.
Anonymising sensitive health information
The EHDS will rely on sharing anonymised health information. This is extremely difficult for rare diseases or small populations, which can allow for a breach of confidentiality and re-identification, potentially being at odds with GDPR provisions.
There is also an inherent risk with sharing data. The EU’s Member States each have different approaches to enforcement policies, cybersecurity infrastructure and operational oversight.
How does the EHDS deal with IP?
The EHDS requires the disclosure of data where it is considered to be necessary and proportionate, and data processing can only take place in secure processing environments. Companies, such as pharma companies, and tech and AI developers, will be required to share data including clinical trials and product performance. This is likely to pose issues to such companies by potentially exposing trade secrets and eroding their competitive advantage. This is exacerbated by the EHDS’s wording in Article 52, which provides that IP rights and trade secrets should not be an obstacle to the re-use of data. Furthermore, there is no implementing act attached to Article 52 and as a result, the risk of fragmentation across Member States is high.
Article 52 of the EHDS outlines the cross-border infrastructure for secondary use of electronic health data. In essence, Article 52 gives each Member State discretion regarding the implementation of secondary use, for example, how Health Data Access Bodies are organised as well as the differing national procedures for data access requests and potential enforcement. The risk of fragmentation stems from the differing approaches of each Member State and as a result, it could result in a lack of harmonisation across the EU’s implementation of the EHDS. As a result, there is unlikely to be a uniform policy across the EU and this could result in 27 different regimes operating under one umbrella.
Issues for individuals
Citizens of Member States may be under the impression that the EHDS works to the extent that it allows free movement and a unified health-sharing regime. However, the inclusion of secondary use poses greater issues. Although this data should be anonymised, individuals with certain characteristics such as rare genetic conditions, will be easily identifiable, which as a result poses a risk to the protection of their data. Furthermore, as the opt-out provisions outlined in the EHDS (see below) are likely to be fragmented and unclear, it may be difficult for individuals to protect their data.
Opt-out?
Individuals who are unwilling to share their data may decide to opt out of the EHDS. However, this is only applicable for secondary use. They are unable to opt out of primary use. However, such opt-out is only prospective, and so the data already shared cannot be retrieved and/or unpublished. Furthermore, as different mechanisms operate across various Member States, there is no unified method of opting out. As opt-outs are usually done via an online portal or using health applications, this disadvantages individuals who may not be as digitally literate as others.
Conclusion
The EHDS is an ambitious project by the EU to allow individuals to access, control and share their electronic health data across Member States. However, as it is currently drafted, it poses clear risks to both individuals and companies alike. Even though the EHDS will not be operational until 2029, it is important for data holders to understand their legal obligations in making health data available and ensuring they have adequate safeguards in place.
