Does GDPR apply to my medical device data?
In short: Almost certainly yes: health data is special-category data under GDPR Article 9, so processing needs an explicit legal basis, strong security, and usually a data protection impact assessment. GDPR runs alongside MDR and the AI Act as a third parallel obligation — same evidence, three regulators.
Why health data gets stricter treatment
GDPR (Regulation (EU) 2016/679) Article 9 designates data concerning health as a "special category" alongside a small number of other especially sensitive types, subject to a general prohibition on processing unless a specific exception applies. For medical device makers, that usually means relying on explicit consent, or on processing necessary for healthcare provision or public health under professional secrecy obligations — but which exception fits depends on your specific product and data flows, and getting the legal basis wrong at the design stage is expensive to unwind later. Note also that Member States can add their own conditions for health data under Article 9(4), so the rules can vary across a multi-country EU rollout. Beyond the legal basis question, special-category data also triggers heightened security expectations and, under Article 35, a Data Protection Impact Assessment wherever processing is likely to result in a high risk — large-scale processing of special-category data is a strong trigger, which most medical device processing will meet.
Three regulators, one underlying evidence base
GDPR sits alongside MDR and the AI Act as a third framework your device likely has to satisfy simultaneously — and the practical reality is that the underlying work substantially overlaps. One question to settle early: whether you're the controller or a processor for a given data flow — when a hospital deploys your device, the hospital is typically the controller for its patients' data and you may be a processor, which changes who carries which GDPR obligation. Your data governance documentation for the AI Act's Article 10, your risk management file for MDR, and your GDPR data protection impact assessment are all describing largely the same data pipeline from different regulatory angles. Building these as three disconnected compliance exercises, each starting from scratch, wastes effort a single well-designed data governance programme would avoid.
Where teams underinvest
GDPR compliance is sometimes treated as a website cookie-banner problem rather than a core product design question, which badly underestimates its relevance to a device processing genuine patient health data. A DPIA done properly, early, and revisited as the product evolves is a stronger foundation than a generic privacy policy retrofitted once a Notified Body or a customer's procurement team asks a pointed question.
Where next: When Medical Device AI Becomes High-Risk · What does AI Act Article 10 (data governance) require?
Talk to us about your data protection strategy. Book an expert conversation →
The full guide to GDPR and AI Act governance for medical devices covers this question in context.