Skip to main content
Back to knowledge base
Use case

Use case: Healthcare organisation and GDPR compliance

Healthcare organisations process large volumes of special category data: medical records, treatment plans, medication data and more. The GDPR imposes additional requirements on processing such data. This example shows how a healthcare organisation achieves compliance.

28 March 20268 min read

Why is healthcare particularly vulnerable?

Health data falls under special categories of personal data (Art. 9 GDPR). Processing is prohibited unless a specific exception applies, such as:

  • Explicit consent of the data subject (Art. 9(2)(a))
  • Necessary for healthcare purposes (Art. 9(2)(h)) — the most commonly used basis in healthcare
  • Public interest in public health (Art. 9(2)(i))

Additionally, sector-specific legislation and standards apply, such as information security standards (e.g. NEN 7510 in the Netherlands, ISO 27799 internationally).

The situation

A medium-sized care provider (home care, nursing home care and rehabilitation) with approximately 800 staff works with dozens of vendors with access to patient data:

  • EHR vendor: the electronic health record system containing all medical data
  • Pharmacy/medication system: medication overviews and prescriptions
  • Laboratory: blood test results and diagnostics
  • IT administrator: manages servers, workstations and network
  • Payroll: employee data including sick leave records
  • Video consultation platform: video calls with patients

Healthcare-specific challenges

Security certification

Vendors with access to health data must demonstrate appropriate security through certifications or equivalent measures. Tracking certificate validity is an ongoing task.

Enhanced DPA requirements

DPAs for health data processing must include additional provisions covering access logging, enhanced security measures, incident notification aligned with clinical procedures, and data deletion after the statutory retention period (20 years for medical records in the Netherlands).

DPIAs for new health technology

The healthcare sector innovates rapidly. Many new applications (telehealth, remote monitoring, AI-assisted diagnostics) require a DPIA due to large-scale processing of special category data.

The approach

Step 1: Vendor inventory by risk classification

  • High risk: access to patient data
  • Medium risk: access to employee data
  • Low risk: no access to special category data

Step 2: Tailored DPAs

High-risk vendors receive DPAs with healthcare-specific provisions. Medium and low risk vendors receive standard or basic agreements.

Step 3: Evidence vault

Security certificates and audit reports are stored per vendor with expiry alerts.

Step 4: Processing register linked to the EHR

The processing register is extended to cover all processing via the electronic health record, linking vendors and sub-processors.

The result

  • All vendors classified by risk level
  • Tailored DPAs per risk category
  • Security certificates centrally managed with automatic expiry alerts
  • Processing register linked to vendors and agreements
  • DPIAs for new health technology conducted in a structured way
  • Audit-ready for health inspectorates and external auditors

Tips for healthcare organisations

  • Classify vendors by data type, not just contract value
  • Require security certification from vendors with access to patient data
  • Conduct DPIAs before deploying new health technology
  • Account for the 20-year retention period for medical records in DPAs
  • Use DPAkit to centrally manage DPAs, certificates and the processing register

GDPR compliance in healthcare with DPAkit

DPAkit helps healthcare organisations manage DPAs, the processing register and security certificates.

Start for free