All articles
Sovereignty

Health data: GDPR gives you rights, not guarantees

A right is exercised against someone, which assumes someone is still there. What that changes before you hand your sleep and your blood work to an app.

Share
G

In short

GDPR places health data in the special categories of its article 9: processing is prohibited by default, and the prohibition is lifted notably by your explicit consent, the one you give at signup. Protection is therefore procedural: it opens rights of access, portability, rectification and erasure, exercised against an identified company, and assuming that company still exists and can still be reached by a regulator. Three situations show the limit: the 23andMe bankruptcy, fined £2.31 million by the UK regulator in June 2025 before its assets were bought in July; the US CLOUD Act, which reaches a provider subject to US law wherever the servers sit; and anonymisation, where a Nature Communications study estimates 99.98% of Americans would remain re-identifiable from 15 demographic attributes. The only protection that depends on nobody is architectural: data that stays on your device has no controller to send a request to.

Key takeaways

  • GDPR article 9 prohibits processing health data by default. Your explicit consent lifts that prohibition: it is the intended door, not a loophole.
  • A right is exercised against an identified controller. It assumes the company still exists, still answers, and can be reached by a regulator.
  • Your weight combined with your step count and your calorie intake becomes health data in the French regulator's reading, with no doctor involved at any point.
  • «Anonymised» does not mean anonymous: 99.98% of Americans would be re-identifiable in any dataset from 15 demographic attributes.
  • Where the servers sit and which law the operating company answers to are two separate facts. Only the second decides who can compel disclosure.

In March 2025, 23andMe filed for Chapter 11 protection under US bankruptcy law. Its genetic database did not evaporate with the company: it became an asset to sell, acquired in July by a nonprofit foundation founded and led by the company's co-founder.

The right to erasure applied throughout. It did not stop the database from changing hands: to have any effect, it had to have been exercised, one person at a time, beforehand.

GDPR is a procedure: it opens remedies against someone. An architecture decides what exists at all. A remedy needs a counterparty; a lock does not.

What article 9 prohibits, and the door people walk through anyway

GDPR article 9 places data concerning health in the special categories. The principle is stronger than most people assume: processing is prohibited. Not regulated, not subject to authorisation. Prohibited by default.

The same article then lists ten situations that lift the prohibition. The first is your explicit consent, the one you give at signup, and it is sufficient on its own. Nothing abnormal about that: it is the intended mechanism, and it is what allows an app to be useful to you at all.

But it moves the subject. The law does not guard the door, it sets the conditions under which you hand over the key.

Your sleep and your stack are health data

The French regulator lists three families: data that is health data by nature, data that becomes health data by combination with other data, and data that becomes health data through the medical use made of it. The second is the underestimated one: the example given is a weight measurement combined with a step count and calorie intake. Nothing medical line by line, and the sensitive data regime applies to the result all the same.

G
Sleep, stack and blood work combined say more about you than any advertising profile.

A sleep log, a supplement list with doses and timings, and three months of blood panels clear that bar comfortably. It is a medical file rebuilt by accumulation, with no doctor involved at any point.

Three places where the right runs out

Access, portability, rectification and erasure are real rights. They share one dependency: someone has to be there, able to answer, and reachable by a regulator.

When the company changes hands

In June 2025 the UK data protection authority issued a £2.31 million fine against 23andMe, following a joint investigation with its Canadian counterpart: no mandatory multi-factor authentication, and no proper access controls over raw genetic data.

The attack dated back to 2023. Credential stuffing, meaning mass attempts using passwords stolen in earlier unrelated breaches. The result: access to the information of 155,592 UK residents, including ethnicity, family trees and health reports. The company only opened a full investigation in October, when an employee found the stolen data advertised for sale on Reddit.

« Unlike usernames, passwords and e-mail addresses, you can't change your genetic makeup when a data breach occurs. »

A person affected by the breach, quoted by the ICO, June 2025

The penalty was heavy. It did not restore the confidentiality of what had left, and it did not stop the database from being sold the following month. A fine punishes. It does not repair.

When the host is European and the law is not

«Hosted in Europe» has become a sales argument. It answers a question about location, not a question about jurisdiction.

The US CLOUD Act, passed in 2018, lets American authorities compel a provider subject to US law to disclose the data it holds, wherever the servers sit. The European Data Protection Board and the European Data Protection Supervisor took a position in July 2019: such an order alone is not a valid basis for transfer under GDPR, whose article 48 points to an international agreement.

The two texts say different things, and the provider sits in between. Where the servers sit and which law the operating company answers to are two separate facts, and only the second decides who can compel disclosure.

When «anonymised» does not mean anonymous

Genuinely anonymous data falls outside GDPR. That explains why the word appears in almost every privacy policy.

Removing the name is not enough. A 2019 study in Nature Communications estimates that 99.98% of Americans would be correctly re-identified in any dataset from 15 demographic attributes. Even heavily sampled, the authors conclude, such datasets are unlikely to meet GDPR's anonymisation standard.

Fifteen attributes is not many on a health profile. Age, sex, postcode, height, weight, and the list is already half done.

SituationWhat GDPR providesWhat execution depends on
Data breachNotification to the authority within 72 hoursThe breach being detected, and dated
Acquisition or bankruptcyRights follow the database to the buyerThe buyer honouring them and staying reachable
Foreign disclosure orderArticle 48: an international agreement is requiredWhich law the company answers to
«Anonymised» reuseAnonymous data falls outside the regulationThe anonymisation actually being one
ErasureReply within one month, no justification neededThe reference copy sitting with them
What the regulation provides for, and what its execution actually depends on.

The protection that needs no exercising

There is one category of data on which no right needs to be exercised: the data that never left.

The French regulator notes it about mobile health apps: the rules do not apply the same way when data is collected exclusively on the device, with no outside connection and for strictly personal purposes. No controller, no transfer, no processor, because there is nothing to process elsewhere.

That is what local-first means, stripped of the engineering vocabulary: your data is written on your phone first and stays there by default. No central database to breach, and erasure is immediate because the reference copy is already yours.

Questions to ask before handing over your blood work

  1. 1

    Which law does the company answer to?

    Not where the servers are: who owns the company, and under which jurisdiction.

  2. 2

    What happens to the database if it is sold?

    If the words «merger» or «asset sale» appear nowhere in the privacy policy, nobody thought about it.

  3. 3

    Which processors have access?

    The list must be public and current. An analytics vendor has no business inside a biomarker database.

  4. 4

    How long after the account is closed?

    A stated duration is expected, per category. «As long as necessary» is not a duration.

  5. 5

    Is the data used for advertising?

    If the answer is not a plain no, it is a yes with intermediate steps.

  6. 6

    Is there a reachable DPO and a public register?

    A dedicated address and an online register are worth more than any trust badge, and take thirty seconds to check.

What this article does not say

  • That GDPR is useless. Without it the UK fine would not exist and no processor list would be public anywhere.
  • That European hosting is pointless. It removes an entire class of transfer problems, not the jurisdiction question.
  • That local-first is free. Losing your phone without a backup means losing the history. Sharing with a doctor takes an explicit step instead of a link.
  • That this is legal advice. It is the reading of someone who has to make these architecture decisions, texts in hand, and would rather show his work.

« Data sovereignty is not a legal checkbox, it is an architecture decision. »

Where Helix stands

Helix is built in Europe, with European hosting and a public processing register: processors, purposes and retention periods are readable without creating an account. Granular consent for anything not required by the service. No advertising, no resale.

Sensitive data stays local-first on your device. That choice is expensive and makes sync harder. It has one advantage, and it is enough: there is no central database whose sale could one day appear in a bankruptcy filing.

Check what is collected, by whom and for how long, before creating an account.

Read the processing register

Sources

Frequently asked questions

What happens to my health data if the company goes bankrupt?

It becomes an asset. A database is not destroyed by insolvency proceedings, it is valued and sold with everything else. GDPR still applies and your rights follow the database to the buyer, but exercising them assumes the buyer honours them and stays reachable. 23andMe showed this at full scale in 2025: Chapter 11 in March, assets acquired in July by a nonprofit foundation. The only genuinely effective move was to request erasure before proceedings opened.

Is European hosting enough to protect my health data?

It settles location, not jurisdiction. The US CLOUD Act lets American authorities compel a provider subject to US law to disclose data it holds, wherever the servers sit. The European Data Protection Board and the European Data Protection Supervisor took a position in July 2019: such an order alone is not a valid transfer basis under GDPR, whose article 48 points to an international agreement. The two legal orders say different things, and the provider sits in between.

Is my sleep data health data?

Usually yes. The French regulator lists three families: data that is health data by nature, data that becomes health data when combined with other data, and data that becomes health data through its medical use. The second is the widest: the example given is a weight measurement combined with a step count and calorie intake. A sleep log alongside a supplement list and blood panels clears that bar without difficulty.

Can a health app resell my data?

Not without explicit, separate and revocable consent covering that exact purpose. Consent buried in terms accepted in bulk does not meet the bar. Two checks are enough: do resale or ad sharing appear in the privacy policy, and can you refuse without losing access to the service?

How do I exercise my right to erasure?

A written request to the controller or the data protection officer is enough, without justification in most cases. The response deadline is one month, extendable to three for complex requests. If nothing comes back, the supervisory authority can be contacted. Keep a dated record of your request: it is what counts if the company's situation changes in the meantime.

Educational content. Helix is not a medical device and does not replace professional medical advice. How these articles are written and checked · Corrections

Comments

Moderated before publication

Loading comments…

    Leave a comment

    Your health connected, your tribe with you. The beta opens soon.

    Join the beta