Reliance on Healthcare and Health Management Exception for Processing Special Categories of Personal Data, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 9(2)(h).
Assessment Step
1
Reliance on Healthcare and Health Management Exception for Processing Special Categories of Personal Data (RelianceonHealthcareandHealthManagementExceptionforProcessingSpecialCategoriesofPersonalData)
If and when the entity relies on the healthcare exception as the lawful basis for processing special categories of personal data, is the processing necessary for medical or health-related purposes, based on law or contract with a health professional, and subject to appropriate conditions and safeguards?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Reliance on Healthcare and Health Management Exception for Processing Special Categories of Personal Data
If the data controller relies on the healthcare exception as the lawful basis for processing special categories of personal data, then the processing must be necessary for specified medical or health-related purposes, be based on Union or Member State law or a contract with a health professional, and be subject to appropriate conditions and safeguards.
Citation
GDPR
Art. 9(2)(h), Recital 53
|