Why the EU Digital Omnibus
could Make GDPR
Unworkable and Harm People
Why the EU Digital Omnibus
could Make GDPR
Unworkable and Harm People
AI Training
In its latest revision, the EU Digital Omnibus states that anybody could use any personal data to train AI based on its legitimate interest.
So, of course, a lot of digital health organisations will scroll the web in search for patient data, train their AI algorithms with such data, without all the IT and organisational security measures mandated by the GDPR. In other words, patient data could leak.
Our opinion at PharMarketing GDPR Life Sciences is that it could have important impacts on the private life of patients and lead to important psychological problems, which in turn is against the 'spirit' of the GDPR.
Clinical research data are NOT personal data anymore
Also, the EU Digital Omnibus states that de-identified personal data could be considered as not being personal data in some situations, creating a Big precedent, in particular for clinical trial data and for retrospective studies patient data.
As you might be aware, clinical study reports can contain de-identified patient data. And pharma companies must make them public according to EU 070 Regulation ('open data act'), otherwise the clinical study will not be approved.
This is why the GDPR has always considered that de-identified personal data ('pseudonymised' personal data as the GDPR calls it) are still personal data and fall under GDPR.
So what does the EU Digital Omnibus say?
The new article 25a of the EU Digital Omnibus states that “pseudonymised data shall not be considered personal data for a third party
if that person is unable to identify the natural person to whom the data relates.” This creates a
subjective assessment of what is and is not personal data, effectively allowing companies to decide whether or
not they choose to comply with the GDPR.
And you can be sure that many organizations will claim they can not reidentify the patients. This is in opposition to many research which have demonstrated that it is always possible to reidentify a patient if you have access to another source of information:
Remember 2 years ago when several researchers from Norway managed to reidentify European patients in a server made public by the FDA: subsequently the EMA sent a letter to all PV and Quality representatives in the EU, asking them to redact more infos in the Eudravigilance Database.
To learn more contact Bertrand at b.p.lebourgeois@pharmarketing.net
Examples of Non-Compliance
with Health Data Privacy
Data Protection Authorities ('DPAs') published several decisions related to the processing of health data in the past months.
Such decisions shed light on the key measures to implement to stay compliant with privacy (and healthcare) laws and avoid a critical finding.
For each decision, we propose key takeaways: use them as ideas and guidelines for your own organisations: check that such measures are implemented at your organisation, and if not, talk to your management (or talk to us!).
Many thanks to GDPR hub NOYB and to IAPP for all this valuable information!
Australia:
Fact:
The Australian government has initiated a review into a hacking incident in which tech giant OpenAI’s artificial intelligence (AI) model secured unintended access to private health files, marking one of the first publicly reported examples of an AI-led hack impacting a government website.
As per the BBC, which first reported the breach, OpenAI’s model gained access to files from several government websites and services in June after it was tasked with health statistics research. This includes data from Australia’s public health scheme, Medicare, which is not available to the public.
While the hacking incident occurred in June, OpenAI claims it was not aware of the event until August! After discovering the breach, OpenAI informed Australian authorities of the incident on 10 September via an email to the Services Australia general email inbox.
OpenAI noted an “extensive review of misaligned model activity” found no evidence of patient records being accessed: it looks only statistics were accessed and as you know statistics are NOT personal data. OpenAI holds partnerships with a broad range of life sciences companies, including pharma giants like Novo and Eli Lilly, as well as Thermo Fisher Scientific’s clinical trials business. Read full article from GlobalData here: https://www.globaldata.com/new... Read BBC article here: https://www.bbc.com/news/live/...
Takeaway:
All organizations storing patient data, whether in clear or de-identified, should protect access with the best IT and organizational security measures. One of such measure is post-quantum encryption, which is the ONLY robust security measures to fight AI cyberattacks: refer to our July/August 2026 Newsletter for details on this new technology.
Austria:
Fact:
The Austrian DPA held that health data that is required for an expert opinion in a court proceeding can be processed under Article 9(2)(f) GDPR and Article 9(2)(g) GDPR in conjunction with Austrian national law and the selection of relevant data is at the discretion of the expert. Read more or edit on https://gdprhub.eu/index.php?t...
Takeaway:
Court proceedings take precedence on 'classic' privacy rules.
Brazil and Latin America:
Fact:
Healthcare appointment site Doctoralia, which serves millions of people in Latin America and Europe, sent sensitive information about their medical appointments, including the specialties and names of doctors, to social media companies including TikTok, Google, and LinkedIn, according to a review of its websites. Doctoralia’s parent company, Docplanner Group, founded in Poland in 2012, says it operates a sprawling platform across 13 countries, from Turkey to Chile, letting 100 million people book 25 million appointments per month across countries, cultures, and languages.
Doctoralia said it would review its practices. Read artcile from The Markup: https://themarkup.org/pixel-hu...
Takeaway:
Privacy laws in South America, in Europe and in most other countries require to inform users on what personal are collected, how they are used and shared etc. A company like Doctoralia might share patient data with social media, but it needs: 1) to identify the legal basis for collecting such patient data and for sharing them with social media companies 2) to inform its users of such transfer of personal data 3) have a data transfer agreement in place with social media companies 4) check that the social media companies comply with privacy laws and have security measures in place 5) Conduct a Data Privacy Impact Assessment as we are talking here of sensitive personal data (heal date) and of vulnerable data subjects (patients) 6) and document everything in its Register of Processing Activities ('ROPA')
China:
Fact:
The Cyberspace Administration of China ('CAC'), China's Data Protection Authority asked 30 mobile apps to provide information on data collection and consent agreements and implement changes that allow consumers to delete their accounts within 15 business days. This includes healthcare monitoring apps like iNAP Care. Read CAC's press release: https://www.cac.gov.cn/2026-09...
Takeaway:
It's mandatory in China and many other countries to inform people BEFORE you collect their personal data, and in some situations you must obtain their consent. Also, data subjects should be able to exercise their rights on their personal data in a simple manner; this includes the request to delete their personal data.
Fact:
The Cyberspace Administration of China ('CAC') found a weak password vulnerability in the hospital's physical examination system, which allowed access to medical case data and other data. After ordering the hospital to make comprehensive rectifications, the local cyberspace administration found that the hospital's network firewall, intrusion prevention system, vulnerability scanning tools, log audit system, database audit system, fortress computer, and other security devices had failed due to expired authorization. The network system terminals still had 700 security vulnerabilities, including 73 high-risk vulnerabilities that could be exploited, and the risk of data leakage had not been eliminated. The hospital failed to fulfill its obligations for network and data security protection according to law, violating the Cybersecurity Law, Data Security Law, Network Data Security Management Regulations, and other legal provisions. The local Cyberspace Administration has lawfully ordered corrections, issued warnings, and imposed fines, and fined the directly responsible supervisors, while reporting the relevant situation to the local health department.
Takeaway:
In China as in rest of the world, organisations processing patient data should apply the best level of IT and organisational security measures, in accordance to the recommendations of their country's IT security agency.
France:
Fact:
The French DPA, the CNIL, issued a 500 000 euros fine against the Loire Private Hospital ('HÔPITAL PRIVÉ DE LA LOIRE', a French private hospital based in Saint-Etienne and owned by the RAMSAY Group: after a cyberattack exposed personal data of thousands patients, the CNIL conducted an audit of the hospital, which showed that the hospital had not implemented the required Technical and Organizations ('TOMs') security measures.
Comment from PharMarketing: Most French hospitals, whether public or private, have experienced cyberattacks with patient data being exposed, but to our knowledge it's the first time that the CNIL communicates officially on a fine given to a hospital. Read more here (in French): https://www.cnil.fr/fr/sanctio...
Takeaway:
All organizations collecting or processing personal data should implement the TOMs recommended that their country's National IT Security Agency. Especially if organisation processes healthcare personal data.
Guernsey:
Fact:
Guernsey's Office of the Data Protection Authority claimed
a health care provider breached a patient's sensitive personal information by taking a phone call during an examination, BBC News reports. ODPA Commissioner Brent Homan said the organization is providing additional training to doctors to ensure patient privacy remains protected, noting data breaches "are not just about records, but include overheard conversations."
Read more: https://www.bbc.com/news/artic...
Takeaway:
Mobile apps should comply with local privacy laws. In particular,
users should be informed on which of their personal data are processed and how, and should be able to
exercise their rights on their personal data in a simple way.
Ireland:
Fact:
Ireland's Data Protection Commission issued a
645,000 euro fine against
Health Service Executive, Ireland's healthcare public service. The first breach was notified to the DPC in October 2023, when individuals gained
unauthorised access to paper records stored and retained in St. Loman’s Hospital (Mullingar, County Westmeath). St Loman’s Hospital is a former
disused psychiatric hospital
which is contaminated with asbestos. Another issued psychiatric hospital was also used for storing patient health paper records. The
accesses to both disused hospitals were not secured, nor were the access to the patients' documents. The paper documents were
damaged by mould, water, animals droppings, rubble and detritus and some paper documents
were not readable anymore. This is an important breach of privacy, but also of health laws, as patient information were lost. Read the article from the DPC:
https://www.dataprotection.ie/...
Takeaway:
All organisations must implement not only IT security measures, but also security measures for the facilities, the buildings and paper documents. It is of the utmost importance that the facilities manager be associated with the privacy compliance exercise.
Italy:
Fact:
An employee of the University Health Agency of Friuli Centrale (the controller) complained related to the access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs.
After enquiring, the Italian DPA, the Garante, fined the University Health Agency of Friuli Centrale €24,000 for having an inadequate configuration of access to electronic health records, which resulted in unlawful processing of the data subject’s personal data. Read more: https://gdprhub.eu/index.php?t...
Takeaway:
Same as for the cyberattack at the French Loire Private Hospital above.
Netherlands:
Fact:
A court held that Article 16 GDPR
does not require rectification of a medical report where the alleged inaccuracies
are not objectively verifiable and concern the physician’s account of a past conversation. Read more or edit on GDPRhub…
https://gdprhub.eu/index.php?t...
Takeaway:
This is a good example of the interplay between the GDPR and local healthcare laws. The medical opinion of a healthcare professional cannot be discussed and modified after the visit.
Poland:
Fact:
MyDr healthcare software breach potentially affected 19 million people. MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said in August that it had identified and removed the cause of the incident and introduced additional security measures. It did not provide details about the vulnerability or how the attackers gained access. Poland's Personal Data Protection Office plans to inspect MyDr, while security agencies are working to identify those responsible for the attack. Read article from The Record: https://therecord.media/poland...
Takeaway:
We cannot comment as the cause of the cyberattack has not been disclosed.
Spain:
Fact:
Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of accesses to his medical history, including the date, time, identity of the professional and purpose of each access.
The Spanish DPA, the AEPD, held that automatically refusing to disclose the identity of persons who accessed medical records was incompatible with the enhanced transparency required in the healthcare context, in violation of Article 15 GDPR. It ordered the controller to grant access or provide a properly reasoned refusal. Read more or edit on GDPRhub… https://gdprhub.eu/index.php?t...
Takeaway:
We have seen similar situations where the local Data Protection Authority decided the opposite. So we guess it is a case by case interpretation. Also, there might be a history of facts which happened to the employee that are not disclosed in this article, but explain the decision of the AEPD.
Sweden:
Fact:
Sweden's data protection authority, the Integritetsskyddsmyndigheten ('IMY'), issued a SEK1.8 million (159 480 euros) fine to medical IT solutions provider Miljödata i Karlskrona following an investigation into a 2025 data breach. The investigation reportedly found a hacker accessed an internal system and stole sensitive personally identifiable information of 2.2 million people. The IMY said the company did not implement commensurate data protection safeguards for the types of sensitive data it stored. Read more (in Swedish): https://www.imy.se/nyheter/san...
Takeaway:
Same as for the cyberattack at a French hospital abobe
United Kingdom:
Fact:
Grindr , the global LGBTQ networking app, agreed to pay
26 million GBP
to settle a class-action lawsuit over claims the company violated the U.K. General Data Protection Regulation after allegedly sharing users' sensitive personal information, including whether they were HIV positive, with advertising companies, the Guardian reports. Grindr stated the alleged incident occurred during its 2020 merger with San Vicente Acquisition, noting it has worked to bolster its privacy standards and "remains a safe space for users, committed to transparency, user control and responsible data practices."
Full story
Takeaway:
Organisations cannot share personal data of people without informing them. And in the case of sensitive personal information like HIV test results, you need to obtain the consent of the persons.
Privacy News
from around the Globe:
Privacy News from around the Globe:
Australia:
Australia released the Exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 in August; it was open for public comment between 31 August and 18 September.
This Bill contains significant updates to Australia Privacy Laws which will make it closer to the EU/EEA/UK/CH GDPR; the main items are the following:
1) The Definition of Personal Information is the same as in the GDPR, see clause 6FD page 6: 'Personal information means information or an opinion that relates to an identified individual, or an individual who is reasonably identifiable' In other words, redacted personal data fall under the Australian Privacy Act.
2) Notion of information or an opinion which is de-identified at a particular time, meaning fully anonymized in the sense of GDPR (clause 6FG page 7).
3)
Introduction of a new fair and reasonable test for the collection, use and disclosure of personal information
Health research:page 11: 'Subsection 16B(2A) requires an organisation to take reasonable steps to de-identify health information before disclosing it, if the organisation collected the health information in the permitted health situation described in subsection 16B(2) (research etc.). ' Comment from PharMarketing: this is in line with what Good Clinical Practices demand.
4) Introduction of the trade of information (clause 6FC page 10)
5) Fair and reasonable in the circumstances (section 3.2 page 12) introduces an
obligation to conduct a risk analysis for the private life of data subjects in some circumstances; such circumstances are not indicated clearly, but we can guess it applies for the processing of high volumes of personal information and/or of sensitive personal data; there is an exemption for healthcare if 'a permitted health situation exists in relation to the collection, use or disclosure. ' (section 3.3 page 13)
6) Data subject consent is mandatory in all cases, except if 'a permitted health situation exists in relation to the collection' (sections 4.1 and 4.3 page14)collection of their
7) Data subjects must be informed of the collection of their personal data (section 5 page 16)
8) Mandatory to notify eligible data breaches to the commissioner within 72 hours: a data breach that is likely to result in serious harm to any of the individuals to whom the information involved in the data breach relates must be notified to the Authority; such breaches are called 'eligible data breaches' (Clauses 26WA page 26, 26WE page 29 and 26WK page 30).
It is interesting to note that the impossibility for a data subject to access its personal data (for example because its bank has been the target of a cyberattack) is not considered a a personal data breach by the Australian law: this is a difference with the GDPR.
9) Right to access and the Technically impossible or infeasible clause
(schedule 4 part 1 page 41): if giving access 14
proves to be 'unreasonable or impracticable', an entity is not required to give access to the personal information.
Schedule 5—Exception for research (page 48): human research that meets the requirements (if any) in the human research guidelines does not breach that Australian Privacy Principle.
Download the Exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 here:
https://consultations.ag.gov.a...
Canada:
10 September 2026: The Privacy Commissioner of Canada released a guidance for businesses working with third-party service providers. The guide is open for public comment through 4 Dec. https://www.priv.gc.ca/en/opc-...
China:
The Cyberspace Administration of China ('CAC') issues guidelines for device data deletion requirements, read here: https://www.cac.gov.cn/2026-09...
European Union:
Organ Data: Alongside the proposed European Biotech Act, a new draft directive makes targeted updates to Directive 2010/53/EU on the quality and safety of human organs intended for transplantation
In Opinion 11/2026, adopted on 27 May 2026, the EDPS writes that the organ provisions introduce a new duty for competent authorities to exchange “clinical outcome data”, a term the proposal leaves undefined.
Given the sensitivity involved, the EDPS recommends:
Read the EDPS press release: https://www.edps.europa.eu/pre...
Read EDPS opinion: https://www.edps.europa.eu/dat...
Read proposed amendments to directive the quality and safety of human organs intended for transplantation on organ transplantation: https://eur-lex.europa.eu/lega...
EMA and the U.S. Food and Drug Administration (FDA) have jointly identified ten principles for good artificial intelligence (AI) practice in the medicines lifecycle. Read here: https://www.ema.europa.eu/en/d...
General principles on the
use of Artificial Intelligence in the preparation of dossiers for Joint Clinical Assessments:
https://health.ec.europa.eu/do...
The EU Agency for Cybersecurity, the ENISA, launched the
Single Reporting Platform
to help software developers and open-source stewards meet their new Cyber Resilience Act reporting requirements. Read press release:
https://www.enisa.europa.eu/ne...
France:
Indonesia:
Indonesia released Personal Data Protection Law implementing regulations will take effect on 16 January 2027. The regulations clarify PDPL provisions covering lawful bases for data processing, consent requirements, international data transfers, data protection impact assessments, data protection officer, data transfers and more. Read article from Hogan Lovells here: https://www.hlc.com/en/publica...
Kenya:
Kenya's DPA released Guidance Notes for Cross-border Data Transfers, see here: https://www.odpc.go.ke/wp-cont...
Netherlands:
The Dutch Data Protection Authority (DPA) has published 2 templates targeted at SMB organisations: one template for the Register Of Processing Activities ('ROPA') and one for a privacy statement. Read here: https://www.autoriteitpersoons...
South Korea:
South Korea released an Enforcement Decree, and Notice to Strengthen Prevention and Remedy for Personal Information Leaks Effective September 11. It includes the following measures:
▴punitive fines (up to 10% of total sales) for repetitive, intentional, or gross negligence of personal information leaks,
▴ A reduction system for mandatory fines linked to proactive investment in personal data protection has been introduced.
▴ The ultimate responsibility of business owners and representatives (hereinafter referred to as 'CEOs') is clearly defined,
▴ The authority of the Personal Information Protection Officer (hereinafter 'CPO') has been strengthened (management of professional personnel, securing budget, and obligation to report to the board of directors).
▴ When a personal information processor designates, changes, or cancels a CPO, board resolution and notification are now mandatory.
▴Forgery, alteration, or damage of personal information (such as ransomware) is also included in the scope of leak reporting and notification.
The amendment also includes provisions to require ISMS-P certification for important personal information processors in both the public and private sectors. However, the revised regulations require companies and institutions to obtain ISMS-P certification. Considering the time required to secure the budget, this item is scheduled to take effect from July 1, 2027.
Read the full text of the decree here: https://pipc.go.kr/np/cop/bbs/...
Spain:
Spain's AEPD releases guidance on cyber risks connected to AI tools. Read the article here: https://www.aepd.es/prensa-y-c...
United Kingdom:
The Information Commissioner’s Office will transition to the Information Commission on 30 September 2026. Read ICO's press release: https://ico.org.uk/about-the-i...
The UK HRA has updated the following model agreements for use from 7 September 2026:
• model Non-Commercial Agreement (mNCA)
• model Commercial Chief Investigator Agreement (mCCIA) and CRO-mCCIA
• model Clinical Trial Agreement (mCTA) and CRO-mCTA
• model Primary Care mCTAs (PC-mCTAs)
• Advanced Therapy Medicinal Product Agreement model Clinical Trial Agreement (ATMP-mCTA) and CRO-ATMP-mCTA
• model Clinical Investigation Agreement (mCIA) and CRO-mCIA
• model Non-Interventional Study Agreement (mNISA) and CRO-mNISA
• commercial hub and spoke agreement
Read more:
https://www.myresearchproject....
The MHRA has updated its clinical trials transitional guidance to clarify timelines and labelling requirements under the new UK clinical trial regime. https://therqa.us12.list-manag...EDPB adopts new GDPR fine methodology, DSA-GDPR interplay guidelines https://www.edpb.europa.eu/new...
Dr Alison Knight, Data and Privacy Specialist and Research Data Policy Lead at HRA, has written a blog reflecting on the
guidance and the practical things that researchers should be considering around recruitment.
Read more:
https://www.hra.nhs.uk/plannin...
New Site Selected Email Template for NHS and HSC site
https://www.myresearchproject....
United States:
The U.S. House of Representatives passed the proposed Non-Disclosure Order Fairness Act, which allows technology companies to inform consumers when law enforcement agencies have accessed personal data stored within the cloud. The bill now moves to Senate consideration Read more here: https://www.govtrack.us/congre...
The State of California issued 2 AI Audit bills in September 2026:
Let's recall that California is at the forefront of Frontier AI with the Transparency in Frontier Artificial Intelligence Act (SB‑53), signed on 29 September 2025 and effective from 1 January 2026: https://www.cdt.ca.gov/initiat...
On 2 Sept., Delaware enacted HB 380 which updates the Delaware Personal Data Privacy Act; the updates relate only to consumers personal data; so, as with most US privacy laws, it doesn't apply to organizations collecting or processing patient data during care or medical research. HB 380 will apply as of 1st January 2027.
On 9 September 2026: CISA Released Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats. Read here: https://www.cisa.gov/news-even...

Dear Sir/Madam,
Thank you for contacting us.
We will get back to you as soon as possible.
Best regards,
PharMarketing
PharMarketing, a business unit of Silicon Marketing SASU
8 rue Roublot - 94120 Fontenay-sous-Bois - France
VAT Number FR38799016977
Subscribe to our free GDPR Life Sciences Newsletter
NB: we reserve the right to accept or deny requests to receive our Newsletter
Copyright PharMarketing 2013-2026 © All rights reserved.