Panel: AI × Health Data: Navigating Privacy in the Age of Generative Models
dph
[ mai 4, 2026 by A C 0 Comments ]

Panel: AI × Health Data: Navigating Privacy in the Age of Generative Models

When AI Meets Health Data: Practical Lessons from the Front Line

What does it really mean, in practice, to navigate privacy at the intersection of AI and health data in the age of generative models?

In the age of AI, health data has become the oil of the 21st century. But when AI systems analyze this data to predict, diagnose, or treat, the issue is no longer merely technological. It is also profoundly linked to fundamental rights, governance, and trust. This question was explored during the panel discussion at the Data Privacy for Health Summit, organised by MyData Trust. Rather than focusing on theory or regulation alone, the session examined concrete use cases and lived experience, with insights from experts working directly in healthcare AI, hospital operations, and privacy law: Astou Ndiaye, Founder and CEO at Hale-X; Scott Russell, Founder and CEO at Innatify; Michael Brown, Privacy, AI and Technology Lawyer; and Elisabeth Dehareng, Partner at Baker McKenzie Belgium leading the IP & Tech team.

Moderated by Elisabeth Dehareng, the discussion opened with the observation that legal practice in AI is expanding beyond privacy to include data governance, AI risk management, cybersecurity, and sector-specific compliance frameworks. Healthcare exemplifies this shift, combining highly sensitive data, strict regulatory expectations, and strong pressure to innovate at speed.

From a clinical standpoint, Astou Ndiaye described how AI is enabling truly personalised medicine. Hale-X develops patient-specific digital twins that replicate an individual’s biological state using real-time data. These digital models allow clinicians to simulate disease progression and treatment outcomes for specific patients rather than relying on generalised population data. She highlighted that the biggest hurdle is not data scarcity, but fragmentation. “I really hope that in five to ten years, everyone will have their own digital twins, at hospitals and on themselves. Maybe a smartwatch where all your data are stored… If you travel and have an accident, clinicians can still access your data to treat you. I would love to live in that world…” she said. Beyond technical integration, such a vision raises profound questions around data portability, interoperability, cybersecurity and secondary use of health data, particularly as these solutions move toward consumer-facing applications.

Scott Russell shared a complementary perspective on operational efficiency. His work addresses administrative burdens on hospital staff, aiming to optimise workflows with AI to free time for leadership and patient care. “The AI risks weren’t really the biggest thing; it was the fundamentals—data quality, fragmentation, awareness, literacy, trust. We had to go back to basics and start with trust”, he explained. Security and data protection measures, such as on-premises deployment and strong encryption, were designed as both technical safeguards and confidence-building tools for hospital decision-makers. “They can look at it and go, that’s secure, that’s safe… You can move through that gate” he added.

Turning to the legal perspective, Michael Brown highlighted how healthcare AI projects engage multiple areas of law, with data protection and AI regulation at the forefront. Security remains critical due to the sensitivity of health data and prior enforcement history, while AI introduces new challenges like model leakage, where confidential information can surface unintentionally. Determining whether organisations act as controllers, processors, or joint controllers requires a granular, fact-based assessment of acutal decision-making power and data flows, rather than relying solely on contractual labels. This can pose particular challenges for smaller institutions.

Bias, fairness, and accuracy emerged as persistent AI-specific risks. AI mirrors the data and assumptions it is trained on, and historical healthcare datasets may embed structural biases. Addressing these risks requires continuous investment in data governance, testing, and human oversight. Both Scott and Michael emphasised the importance of explainability and human-in-the-loop mechanisms to preserve clinical accountability and professional judgement. Michael highlighted practical measures such as pseudonymisation, robust authentication, testing for model leakage, and bias/fairness audits to guide organisations toward compliance.

The discussion also explored practical data scenarios. Astou shared concerns about AI platforms like ChatGPT and potential insurer access to health data, illustrating the real-world balancing act between innovation, privacy, and regulation. Audience questions raised cloud versus device-based storage and the management of imperfect legacy datasets. Panelists stressed that data preparation and quality control often require more effort than anticipated, yet failures in these areas carry the highest risk. Treating accuracy and fairness as design principles, rather than afterthoughts, was repeatedly emphasised as essential for sustainable AI deployment and long-term public trust.

The session concluded with a clear takeaway: AI in healthcare is neither merely a compliance challenge nor a technological breakthrough in isolation. Its success depends on careful alignment of innovation, governance, legal responsibility, and professional judgment. When these elements coexist rather than compete, AI can improve efficiency, enhance clinical outcomes, and strengthen trust across the healthcare ecosystem provided that privacy and ethics remain embedded from design to deployment.

[Co-Authors: Myrto-Amaryllis Lappa, Giuseppe Chiapparo]

Patient wallet 4
dph
[ avril 10, 2026 by A C 0 Comments ]

Patient-controlled Health Data: The Rise of the Patient Wallet

Insights from Panel 5 — MyData-TRUST Data Privacy for Health Summit, Brussels, 29 January 2026

At the MyData-TRUST Summit in Brussels, the concept of the Patient Wallet discussed during this panel session emerged as one of the most interesting shifts in health data governance. The opening metaphor sets the tone for the discussion: the sector is driving fast, and the question is whether the brakes are good enough. For data controllers and processors, patient wallets represent both the accelerated innovation and a potential safety mechanism.

What Is a Patient Wallet?

A patient wallet is a secure, user-controlled digital repository that allows patients to store, manage, and possibly share their health data and credentials. The concept built on the EU Digital Identity Wallet (EUDI) under the electronic IDentification, Authentication and trust Services(eIDAS Regulation (EU) No 910/2014)  . The concept extends digital identity into healthcare — allowing patients to hold verifiable credentials directly on their personal device.

Through two projects presented at the panel, it became clear that the wallet concept is closely connected to the broader objectives of the European Health Data Space (EHDS). It holds critical data categories, not the entire health record. Six categories have been identified for cross-border sharing, but the reality remains challenging: health data across the EU is scattered, heterogeneous in quality, and often error-prone. EHDS maturity varies considerably across Member States.

The MyHealth@MyHands EU project aims to put the EHDS vision into practice. Similarly, the Digital COVID Certificate served as an early proof of concept for the verifiable credential process that patient wallets may require at scale. The AIDAVA project, an AI-powered virtual assistant using a Personal Health Knowledge Graph (a from of digital twin), seeks to help patients curate, structure, and validate their own data.

Then panel also presented  Andaman7, an AI-powered smartphone application thatalready enables  patients to access and manage their health data in clinical trial and pharmaceutical contexts. Wallet-like initiatives are also emerging in the United States and Australia, while Belgium’s national eID app ItsMe illustrates how existing digital identity infrastructure may support future  health wallet functionality.

Identity, Privacy, and Compliance

From a legal perspective, patient wallet raise signifance compliance challenges, because they sit at the intersection of eIDAS, GDPR, and EU cybersecurity legislation,and compliance with all three frameworks is required simultaneously.

In practice, when identifiers are reused across systems, identity itself becomes a trace: even metadata alone may reveal a patient’s journey through healthcare systems without accessing the underlying health data. Risks of function creep and data correlation are therefore real, and there are vulnerabilities in the EHDS identifier model that could potentially allow identity spoofing or misuse if sagefuards are insufficient.

Data minimization by design, unlinkability, strict purpose limitation, accountability, and genuine user control therefore be built in from the outset rather than retrofitted. Under eIDAS, wallet use is voluntary and intended to be accessible to all citizens, with qualified electronic signatures providing a high level of assurance.

Key Safety Challenges

  • On children’s data — a topic that remains relatively underexplored int his context — guardians typically control data on behalf of minors, but the legal and technical frameworks will need to balance parental consent with the progressive inclusion of children’s assent.
  • Data quality and safety issues also emerge as a central concern  : individuals may wish to correct or modify their records in order to obtain what they believe to be  the most efficacy treatment. This may reframe data quality as a patient safety issue rather than solely a data governance issue. The guiding principle for what to share with patients need base it on the patient’s concerns and the potential for harm, rather than a blanket approach.
  • Data stewardship to build – ensuring the patient wallet movement does not become another round of data harvesting by large technology companies. It shall truly serve patients’ medical needs.
  • It is acknowledged that some populations and countries may benefit from these technologies earlier than others,  but inclusive design must remain a priority.

Opportunities/Looking Ahead

The patient wallet changes the situation in which patients have traditionally been passive recipients of a system that their most sensitive information behind institutional walls. With such tools, they may gain the ability to verify whether  their records are accurate, complete, and up to date, helping to support  better treatment decisions.

More importantly, it may provide patients with greater agency and control on their own care, potentially contributing to improvements in the quality of care.

The patient wallet  is emerging as a potential component of Europe’s future digital health architecture, enabled by the EHDS, the EUDI wallet, and a broader policy shift toward data sovereignty and patient empowerment.

However, success will depend on more than technology alone: interoperability, verifiable credentials, transparent consent mechanisms, genuine patient choice, and implementations that serve patients’ interests rather than only digital platforms will ultimately determine whether the promise of the patient walelt becomes a sustainable reality.

Privacy-Enhancing Technologies:  Enabling Data Innovation Without Compromise
dph
[ mars 22, 2026 by A C 0 Comments ]

Privacy-Enhancing Technologies: Enabling Data Innovation Without Compromise

Gregory Collet – Introduction

In many organizations, data innovation and privacy are still managed as mutually exhaustive. On one side, product and innovation teams push for AI, new digital services: partnership and data spaces. On the other, legal, compliance, and security functions are mandated to prevent harm and control risk. The dominant narrative follows: to innovate, organization must accept more privacy risk; to protect privacy, they must slow down innovation. The perception persists largely because of how data environments are structured. Data remains in silo by department, country and partner. Each new use case triggers new negotiations, new Data Protection Impact Assessment, … The result is friction at every step: friction to access data, to share data and to combine data across entities or jurisdictions. Privacy-Enhancing (Confidentiality) Technologies, or PETs, Federated Learning, secure multiparty computation, synthetic data and related technologies aim precisely at shifting this equation by allowing useful computation without exposing data directly. This is not science fiction. PETs are grounded in cryptography, privacy engineering and statistics. Regulators increasingly reference them to reduce risk and enable responsible reuse. “Without compromise” is an aspiration, not a guarantee. PETs do not eliminate trade-offs, they reshape them (privacy versus performance; cost versus scalability). The real question is whether PETs can provide a better option with measurable properties so innovation, legal, engineering team can make informed decisions together.

To evaluate the audience’s initial mindset, we invited them to complete a poll following the introduction with the questions: “”Do you believe Privacy-Enhancing Technologies can be a core enabler of innovation in your organization or it is just a compliance/technological add-on?”. The results are shown below:

 

 

 

Aymeric Pontvianne: From an innovation perspective: can privacy/compliance be considered an enabler?

Regulation imposes strict limits on how data can be used, which creates a need to innovate to meet both compliance requirements and computational needs. PETs arise precisely from this tension: they enable new methods that respect legal constraints while still allowing meaningful data processing. In this way, regulatory pressure becomes a driver for innovation.

Sophie Stalla-Bourdillon: Do PETs change the legal qualification of the data itself, or only the way we consider the data in a specific context?

To determine whether PETs change the legal status of data, we need to examine the specific method used and its effect on identifiability. The answer also depends on the release context: has the data been pseudonymized or transformed into synthetic/aggregated outputs? What technical and organisational controls exist (key separation, access control, audit logs, contractual limits, onward-transfer restrictions) that could prevent re-identification? This brings us back to examples such as the SRB case, where the analysis turns on “in whose hands” the data sits and what means are realistically available. For the moment, we navigate case by case there are no harmonised European operational guidelines on PETs and identifiability thresholds. The UK ICO frames PETs as data minimization techniques, but EU policy shifts (e.g., Omnibus package) could recalibrate expectations and enforcement practice.

Maarten Everts: What is the biggest misconception about PETs?

There are two extremes. Some people believe PETs are a kind of magic that allows us to escape the GDPR, which is wrong. Others think PETs are an illusion and simply do not work, which is equally false. PETs that combine homomorphic encryption, which allows calculations to be performed on encrypted data, with Secure Multi Party Computation, which decentralises computation among several actors without revealing their inputs, exist and function in practice. The real point is that PETs do not remove obligations; they change the technical conditions under which processing occurs and can reduce exposure when designed properly. A major limitation of many PETs is that they split data into several locations. Once this happens, it becomes very difficult to naively explore the data, because no one can see the entire dataset at once. To some extent, this forces a shift from exploratory to “query-by-design”: you must define the objective and features upfront. In such situations, the data can only be used to answer specific predefined questions. That is why governance, orchestration and outputs controls are as critical as cryptography.

Aymeric Pontvianne: How do PETs enable new market models?

We can have three different dimensions. First, PETs do not fit traditional business approaches built on exclusive data ownership and bilateral sharing. They encourage data contribution in a model closer to open-source logic, where value is created through trusted participation and shared outcomes rather than raw dataset transfers. Second, by allowing safer collaboration around sensitive data, PETs can stimulate competition and lower barriers, making it easier for new actors to enter to the market. Third, PETs support interoperability within the ecosystem: they can connect data sources, but true interoperability requires common standards and governance, as foreseen in the European Health Data Space. Adoption therefore depends on aligned technical interfaces, assurance mechanisms (auditability, measurable privacy) and clear accountability rules. Today, PETs development remains below its potential and demand remains limited. But uptake is likely to grow as regulatory pressure and ecosystem initiatives increase.

Emmanuel Pham: When do synthetic data enable innovation, and when do they distort reality?

Synthetic data should not be framed as “never distort reality”, (what is reality?) but as producing a model-based approximation of reality: they reflex the assumptions, constraints and sampling properties of the source data and generator. They offer an alternative perspective on real data. The question becomes how accurately do they represent the world? Enable innovation when they provide safe, scalable access for exploration, testing and sharing (e.g. simulating cohorts that are not yet available, adapt synthetic datasets to specific needs, increasing sample size for rare diseases). Synthetic data must therefore be validated against real dataset using utility metrics (distributional similarity, predictive performance, coverage of edge cases) and privacy metrics (attribute inference, linkage risk). When used correctly, synthetic data can even help identify biases or missing values in real dataset acting as a diagnostic tool rather than a substitute for ground truth.

Sophie Stalla-Bourdillon: Where do PETs reduce or remove risk?

Zero risk is an illusion. PETs do not eliminate risk but reallocate and attenuate it across the data life cycle. They reduce risk most effectively when the dominant threat is unauthorised disclosure of sensitive attributes (e.g. during data sharing, cross-border collaboration). Hard PETs, such as differential privacy or homomorphic encryption can provide formal, mathematically specified guarantees under explicit threat models: differential privacy bound the incremental disclosure attributable to any individual, while homomorphic encryption enables computation over ciphertexts without revealing plaintext to the compute operator. However, guarantees are conditional on correct parameters, implementation and governance.

Rafa Gálvez Vizcaíno: What is the state of research on PETs?

Applied research increasingly evaluates PETs in concrete deployments, but results are often context-dependant and non-transferable: assumption about data distributions, operational constrains vary across domain, so conclusions from one setting do not necessarily generalise to another. A key scientific challenge is composition: we cannot reliably predict how PETs interact when combined, nor how the parameterisation of one PET propagates to overall utility, privacy and robustness. This creates a need for standardised benchmarks, interoperable threat models, and reproducible evaluation protocols that jointly measure privacy leakage, utility degradation and attack resilience. A second difficulty is on the regulatory side: authorities want guarantee about PETs efficacy while PETs are conditional on explicit models and correct implementation and so subject to uncertainty. Bridging this gap requires evidence and formal proof.

 

QA

What is the common definition of PETs?

The term “Privacy Enhancing Technologies” is used very broad, and in practice this can be misleading: a single definition is rarely operationally useful. A more functional approach is to define PETs as techniques that measurably reduce privacy risk or exposure for a specific use case and threat model, while preserving a target level of utility. This highlights the context dependence of PET claims: different PETs protection against different risks (disclosure, linkage, inference, misuse) and their effectiveness depends on architecture and governance. Federated learning illustrates this ambiguity. It is often classified as a PET, yet its primary purpose is collaborative model training, not privacy per se. Depending on the design, Federated learning can introduce risks such as interception during transfer between the different parties. Without secure aggregation, encryption in transit and outputs controls, “federated” can still be leaky.

In cases where synthetic data are misused, who is responsible?

Responsibility depends on the role of each actor. The person who generates the synthetic dataset is responsible for the quality of the dataset (including documented fit-for-purpose, validation metrics, limitations), just as a car manufacturer is responsible for the quality of the cars it sells. However, if someone misuses the dataset, the responsibility shifts to the user, especially where use exceeds the stated scope or ignores safeguards, just as a reckless driver is responsible for their own accident.

How can one verify that a PET is effective? Can PETs be certified by authorities?

When an authority certifies a PET, it validates the specific claims made by the developer. For example, if the developer claims that the residual risk is five percent and this is demonstrated empirically, the authority certifies the technology at that five percent level. However, a certified method does not imply that every implementation is safe: configuration, key handling and deployment context can undermine guarantees. Authorities cannot verify each implementation in every system. The context evolves: new attack methods appear and sharing environments change. As a result, PET behaviour and strength can shift over time, requiring continuous monitoring, making certification difficult to achieve.

Currently, PETs are not mandatory in healthcare. How can organisations be encouraged to adopt them?

One approach is to emphasise their financial advantages or their value for research, notably reduced transaction costs, faster data access approvals and easier collaboration. Whether or not a method is formally labelled as a PET is not what matters. What matters is its effectiveness and evidence supporting it. If a technique can reduce risk, save money, or accelerate scientific discovery while providing measurable assurance and auditability, it becomes attractive for adoption.

Implementing these techniques adds complexity because it combines technical knowledge with regulatory knowledge. How can this be handled?

In many cases PETs increase complexity, but not always. In specific architectures, they can even simplify legal considerations. For instance, federated analytics or secure enclaves keep personal data in situ, reducing exposure and often materially limiting cross-border transfers cross organisational exchanges.

Re-identification risks 1
dph
[ mars 3, 2026 by A C 0 Comments ]

Re-identification Risks and the Mosaic Effect : Are Health Data Ever Truly Anonymous ?

Moderator : Winnie Dongbou Wamba

Speakers : Timmothy Dangeon, Pierre-Antoine Gourraud, Donovan Sheppard.

The SRB case has reshaped the debate on anonymization under the GDPR. For the life sciences sector, the question is no longer whether pseudonymized data is personal, but how contextual risk, governance responsibilities and emerging technologies redefine compliance and innovation.

When Pseudonymization Is Not Enough

Timmothy Dangeon opened the discussion with a technically grounded and deliberately provocative message: pseudonymization should never be assumed; it must be demonstrated and challenged. His presentation focused on MRI data and the risk of facial reconstruction, illustrating how data thought to be de-identified can still carry re-identification potential when analyzed with advanced techniques.

Imaging data is often perceived as neutral once names and direct identifiers are removed. Yet MRI scans contain structural information that, under certain conditions, may allow reconstruction of facial features. The issue is not that such re-identification is routine or trivial, but that the possibility exists, and evolves with technological progress. What was once considered “remote” may become “reasonable” as tools become more accessible.

This intervention set the tone for the day: anonymization is not a static label but a moving target. Risk must be assessed dynamically, and claims of anonymity must be supported by evidence rather than assumptions. In this context, the SRB case does not eliminate responsibility; it increases the need for methodological rigor. If identifiability is contextual, then contextual analysis must be robust.

The implications for research are immediate. Clinical imaging datasets, especially in rare diseases, cannot rely solely on the removal of direct identifiers. Risk assessment must consider reconstruction techniques, data linkage possibilities and future technological developments. The message was clear: legal comfort without technical validation is fragile.

Synthetic Data as a Structural Response

Where Dangeon highlighted the limits of pseudonymization, Professor Pierre-Antoine Gourraud proposed a forward-looking alternative: augmented ( fit-for use) anonymous synthetic data as a structural solution to the identifiability dilemma.

Grounding his analysis in the well-established anonymization criteria of the former Article 29 Working Party (“WP 29”), singling out, linkability and inference, he reminded the audience that anonymization must prevent all three. The challenge is that traditional anonymization techniques often degrade utility, making datasets less valuable for research while still failing to eliminate residual risk. It is also strict application of GDPR minimization principle – if possible why risking re-identification ?

Synthetic data generation offers a different approach. Rather than masking or suppressing original data, it creates new datasets that replicate statistical structure and analytical behavior without corresponding to real individuals. Properly designed synthetic datasets exhibit structural similarity, informational relevance and indistinguishability from the original dataset in analytical terms.

For research, the potential is considerable. Synthetic datasets can facilitate open science, allow data sharing for peer review, support training environments for AI models, and enable sandbox experimentation without exposing personal data. In clinical research contexts where data reuse is essential for validation and replication, this could represent a paradigm shift.

However, Gourraud’s intervention was not a call for deregulation. The compliance of Synthetic data generation with the anonymization criteria of WP 29 must be documented. It must be auditable. It must ensure that rare patterns do not inadvertently allow inference. Moreover, synthetic representations may still carry ethical implications if misused or misinterpreted.

The underlying proposition is strategic rather than tactical: instead of continuously debating whether pseudonymized data crosses the anonymity threshold, research ecosystems might redesign their data architecture to reduce reliance on personal data in the first place whenever possible. No need to use personal data for non-personal application.

Anonymization in Rare and Ultra-Rare Diseases

Donovan Sheppard brought the discussion back to fundamentals but applied to one of the most sensitive domains: rare and ultra-rare diseases. His central question, “What if you are alone?”, captured the structural vulnerability of anonymization in small populations.

In rare disease research, even heavily pseudonymized datasets may allow singling out simply because of uniqueness. When only a handful of patients worldwide share a specific condition, combinations of non-direct identifiers can quickly narrow down possibilities. In such contexts, the argument that “we do not hold the key” may provide limited reassurance.

Sheppard emphasized that anonymization evaluation through the WP 29 criteria must heavily rely on the real-world context of the dataset. Legal disclaimers and formal distancing from identification capabilities do not substitute for substantive risk evaluation.

His intervention also underscored the governance dimension. In multinational pharmaceutical environments, anonymization assessments influence secondary use strategies, data sharing agreements, AI development pipelines and regulatory positioning. Divergent interpretations between partners can create operational friction and ethical tension.

The rare disease perspective therefore reinforces a broader lesson: identifiability is relational. It depends not only on data structure but on context, ecosystem, and the evolving landscape of available knowledge.

The Practitioner’s Reality: What the Audience Revealed

The interactive exchanges throughout the summit revealed that professionals are navigating these debates in real time. When asked about the difficulties encountered in practice, participants mentioned divergent role interpretations (controller versus processor), challenges in conducting joint re-identification assessments, prolonged contracting discussions, ethics committee disagreements and reputational risks.

When asked what arguments organizations rely on to claim anonymity, many cited the absence of access to identification keys, the lack of direct identifiers, or the inability to re-identify from their specific perspective. These arguments mirror the SRB reasoning, yet their operationalization remains complex.

Most participants saw potential in the evolving interpretation but expressed uncertainty regarding consequences and responsibilities. This ambivalence reflects maturity rather than confusion. The sector recognizes the opportunity to reduce unnecessary regulatory burden but also understands that premature conclusions may create longer-term instability.

Conclusion: From Relative Anonymity to Structured Responsibility

The discussions at the summit converge toward a central insight: the SRB case does not simplify the anonymization debate, it reframes it.

If anonymity is contextual, then contextual analysis must be rigorous. If identifiability depends on reasonable means, then those means must be documented and periodically reassessed. If synthetic data offers a pathway beyond personal data constraints, it must be validated and governed responsibly.

For the life sciences sector, the challenge is architectural. It concerns how data ecosystems are designed, how responsibilities are allocated, and how trust is preserved. Innovation and data protection are not opposing forces; they are interdependent. Scientific progress depends on public trust that personal data will not be mishandled or prematurely declared anonymous.

The SRB reasoning invites organizations to move beyond binary thinking. Pseudonymization is not anonymity. Absence of a key is not absence of risk. Synthetic data is not a magic solution. What is required is structured governance, transparent documentation and interdisciplinary collaboration between legal, technical and ethical experts.

In the end, anonymization is not merely a legal status, it is a commitment to protecting individuals while enabling collective benefit. The future of health research will depend less on semantic debates and more on our capacity to build data frameworks that are robust, auditable and worthy of trust.

EHDS
dph
[ février 20, 2026 by A C 0 Comments ]

European Health Data Space in Action: From Regulation to Real-World Implementation

Introduction

The European Health Data Space (EHDS) is the European Union’s  most ambitious initiative in the field of digital health policy. Aimed to unlock the value of health data , at its core, the EHDS has been designed to enable the secure and interoperable use of health data across Member States, to strengthen healthcare systems, support innovation, and improve public health and policymaking while maintaining high standards of data protection and data quality.

To accomplish those objectives, the EHDS establishes a structured and interoperable framework for the exchange of personal and non-personal electronic health data across Europe. It is built around two complementary objectives:

Primary use of health data, aimed at improving healthcare delivery by ensuring that patients’ health information is accessible when and where it is needed, including across borders.

Secondary use of health data, enabling research, innovation, public health initiatives, and policymaking through secure and controlled access to de-identified or pseudonymised data.

As the regulation moves from years of policy development into its implementation phase, attention is increasingly focused on how the EHDS will function in practice. At My Data-TRUST’s Summit organized in January, one of the panels discussion moderated by Michelle Ayora, brought together experts from industry, academia, and public health to explore the key challenges, risks, and solutions associated with making the EHDS operational. Claire François, Anouk Berger, Mikel Recuero and Wannes Van Hoof hared their expertise across a range of topics, offering insights that resonate with the diverse industries affected by the EHDS.

What are the main challenges related to awareness, understanding, and trust in EHDS?

1. Complexity of framework and Trust

A central theme of the discussion was the complexity of the EHDS framework. Panelists noted that the regulation introduces broad concepts, such as health data holders, health data access bodies, and secondary use, that remain high-level and depend heavily on forthcoming implementing and delegated acts.

Further, this complexity is compounded by the potential for divergent national interpretation in areas left to Member States’ competence. The EHDS adds a new layer of regulation on top of the GDPR, the Clinical Trials Regulation, and other legal instruments, making compliance obligations less straightforward. While the EHDS seeks harmonisation, Member States retain discretion in areas such as governance structures, opt-out mechanisms, and certain technical standards, thereby increasing the likelihood of inconsistent national implementation. The resulting risk is the continuation of the current regulatory fragmentation, particularly in cross-border contexts.

Trust emerged as a parallel concern. Panelists, Claire F. and Anouk B. both emphasized that trust depends on striking the right balance between enabling data access for research and innovation, and protecting confidential information, intellectual property, and trade secrets. Industry stakeholder worries about whether the pseudonymisation and standard will be applied consistently, the Health Data Access Bodies (HDABs) will operate in transparency and efficiency. Any perception of weak governance could undermine confidence in the system. Without clear and consistent guidance, stakeholders may hesitate to engage fully with the EHDS.

2. Patient Awareness and Opt-Out Mechanisms

Anouk B., legal lead at a pharmaceutical company, emphasized another major challenge related to patient awareness and consent choices, particularly opt-out mechanisms for secondary use of health data. Effective communication is essential: patients must understand how their data will be used, what safeguards will apply, and how they can exercise their rights.

Fragmented implementation of opt-out systems across Member States risks confusion and mistrust. From an industry perspective, high opt-out rates could significantly affect data representativeness and, consequently, the quality of research outcomes. Transparency and consistent information were seen as critical to maintaining public confidence in the system.

3. Legal and Technical Interoperability

The panel stressed that the EHDS does not replace existing legal frameworks. Instead, it operates alongside the GDPR, Clinical Trials Legislation, and other sectoral rules, adding another regulatory layer. This creates legal complexity, particularly for organisations conducting cross-border research or operating in multiple Member States.

The panelists share the similar uncertainties including:

  • How intellectual property and trade secrets will be protected when data are shared under EHDS access rules
  • How to avoid unintentionally creating competitive disadvantages when proprietary data are made available
  • How international data transfers will be handled, given that GDPR Chapter V continues to apply and EHDS does not fully resolve global data-sharing challenges

From a technical perspective, interoperability remains uneven. While the EHDS envisions a federated infrastructure, differences in data standards, electronic health record systems, and digital maturity across Member States continue to hinder seamless data exchange.

4. Fragmentation, Inequities, and Member State Diversity

Several panelists highlighted the risk that the EHDS could exacerbate existing disparities between Member States. Countries with advanced digital health infrastructures, eg. Finland are better positioned to benefit quickly, while others may struggle with data quality, registration, and system readiness.

At the same time, Member State autonomy was recognised as both a strength and a limitation. Wannes V. highligthed tha full unification is unrealistic in Europe, but harmonisation and interoperability are achievable. By ensuring systems can communicate efficiently and adopting standards that support cross-border compatibility, EHDS can function without forcing identical national solutions. He encouraged viewing fragmentation as an opportunity for creativity and innovation, pointing to the evolution of GDPR implementation as a precedent for systems maturing over time.

What are the potential solutions and good practices?

Despite these challenges, the panel identified a range of practical solutions to support effective implementation.

1. Clear Guidance and Sector-Specific Training

There was broad agreement on the need for clear, harmonised guidance tailored to specific sectors, including pharmaceuticals, medical devices, research institutions, and public authorities. New EHDS concepts, such as HDAs, opt-out models, and interoperability standards, require practical interpretation rather than abstract legal explanation.

Training and explanatory materials were seen as essential to building consistent understanding and compliance.

2. Collaborative Platforms and Early Engagement

Anouk B. emphasised the value of early and continuous stakeholder engagement. Collaborative platforms where regulators, industry, researchers, and public bodies can share interpretations, challenges, and best practices would help reduce divergent approaches and build trust.

Mikel Recuero highlighted that such cooperation could also limit “forum shopping” and encourage convergence in procedural approaches.

3. Mutual Recognition and Cross-Border Cooperation

Mikel R. also suggested solutions to address procedural barriers in cross-border projects, the panel proposed:

  • Mutual recognition of data permits issued by health data access bodies
  • Mutual recognition of research ethics committee approvals
  • Inter-state cooperation agreements on jurisdiction and applicable law

These mechanisms could significantly reduce delays and administrative burden while respecting national competencies.

4. Incentives and Funding Mechanisms

Wannes V. also mentioned that rather than relying solely on top-down obligations, he advocated for positive incentives. Linking funding to data quality, registration practices, and interoperability readiness could encourage organic harmonisation. Showcasing successful national or sectoral examples may also accelerate adoption of best practices.

A Necessary Cultural Shift?

Beyond legal and technical fixes, the panel repeatedly returned to the need for a cultural shift. The GDPR has reshaped how people think about data, often framing it as something inherently risky and in need of strict protection. While this awareness is important, it can also reinforce defensive attitudes that limit responsible data use.

The EHDS seeks to demonstrate that health data can be used safely, ethically, and transparently for both individual care and collective benefit. A clear definition of purpose, with a precise explanation of why data are used and which societal objectives they aim to advance, was identified as the strongest driver of public trust. When individuals understand that their data contribute to well-defined goals in the common interest, many subsequent technical and operational challenges become more manageable.

Conclusion

The European Health Data Space is more than a regulatory framework—it is the foundation for a new European health data ecosystem. Its success will depend on trust, legal and technical coherence, and genuine cross-border collaboration.

Clear guidance, strong governance, effective communication, and practical solutions for interoperability and intellectual property protection are all essential. Equally important is sustained collaboration across borders and sectors, and a shared commitment to building public trust.

While implementation will undoubtedly be complex, the discussion reflected cautious optimism. With thoughtful execution and an emphasis on alignment rather than uniformity, the EHDS has the potential to deliver significant benefits for patients, researchers, public authorities, and industry, while helping to shape the future of healthcare innovation in Europe.

Author: Chim Kei Chan