Assuming pseudonymised data is out of scope
Pseudonymised data is still personal data. Only genuinely anonymous data — irreversibly so, judged against reasonably available means — falls outside the regulation.
The GDPR — Regulation (EU) 2016/679 — governs how personal data about people in the EU and EEA is collected, processed, stored and shared. Health data is a special category under Article 9: processing it is prohibited by default and permitted only under a specific listed condition, which for most digital health products means explicit consent or a healthcare-provision basis.
The determination that decides most of the architecture is controller versus processor. Selling a platform to a hospital usually makes the hospital the controller and you the processor, which constrains what you may do with the data — including, critically, whether you may use it to train models. A direct-to-consumer app is generally its own controller, and carries the full weight of consent, rights handling and transparency. Get this wrong and the contracts, the privacy notice and the retention design are all wrong together.
Two further points bite in practice. Consent must be freely given, which is difficult when the service cannot be delivered without the data — so consent is often the wrong basis to reach for first. And secondary use for research or product improvement needs its own analysis, not a clause buried in the terms.
Pseudonymised data is still personal data. Only genuinely anonymous data — irreversibly so, judged against reasonably available means — falls outside the regulation.
It is revocable, it must be freely given, and it collapses awkwardly when the product cannot function without the processing it supposedly authorises.
Where you are a processor, using the data for your own purposes without documented instruction is a role breach before it is anything else.
Whoever determines the purposes and means of processing is the controller. Selling a platform to a hospital usually makes the hospital the controller and you the processor, which constrains what you may do with the data. A direct-to-consumer app is generally its own controller, carrying the full weight of consent, transparency and rights handling.
As a processor, only on the controller’s documented instruction — using it for your own purposes is a role breach before it is anything else. As a controller, you need a lawful basis and an Article 9 condition for that specific secondary purpose. A clause buried in the terms of service is not sufficient for either.
Yes. Pseudonymisation is a security measure, not an exit from the regulation. Only genuinely anonymous data falls outside GDPR, and the test is whether re-identification is possible using means reasonably likely to be used — which is a higher bar than removing direct identifiers.
Working out how GDPR applies to what you are building is usually the first conversation.
Get in touch →