Sarita Lindstad
When is the processing of data from medical implants lawful? The legal grounds for processing health-related personal data from ICT implantable medical devices for treatment purposes under EU data protection law
Lindstad, Sarita; Ludvigsen, Kaspar Rosager
Abstract
Medicine is one of the biggest use cases for emerging information technologies. Data processing brings huge advantages but forces lawmakers and practitioners to balance between privacy, autonomy, accessibility, and functionality. ICT-connected Implantable Medical Devices plant themselves firmly between traditional medical equipment and software that processes health-related personal data, and these implants face many data management challenges. It is essential that healthcare providers and others can identify and understand the legal grounds they rely on to process data. The European Union is currently updating its framework, and the special provisions in the GDPR, the current ePrivacy Directive, and the coming ePrivacy Regulation all provide enhanced thresholds for processing data. This article provides an overview and explanation of the applicability of the rules and the legal grounds for processing data. We find that only a cumulative application of the GDPR and the ePrivacy rules ensure adequate protection of this data and present the legal grounds for processing in these cases. We discuss the challenges in obtaining and maintaining valid consent and necessity as a legal ground for processing and offer use case-specific discussions of the role of consent long-term and the lack of an adequate ‘vital interest’ exception in the ePrivacy rules.
Citation
Lindstad, S., & Ludvigsen, K. R. (2023). When is the processing of data from medical implants lawful? The legal grounds for processing health-related personal data from ICT implantable medical devices for treatment purposes under EU data protection law. Medical Law Review, 31(3), 317-339. https://doi.org/10.1093/medlaw/fwac038
Journal Article Type | Article |
---|---|
Acceptance Date | Oct 13, 2022 |
Online Publication Date | Oct 25, 2022 |
Publication Date | Aug 25, 2023 |
Deposit Date | Jul 22, 2024 |
Journal | Medical Law Review |
Print ISSN | 0967-0742 |
Electronic ISSN | 1464-3790 |
Publisher | Oxford University Press |
Peer Reviewed | Peer Reviewed |
Volume | 31 |
Issue | 3 |
Pages | 317-339 |
DOI | https://doi.org/10.1093/medlaw/fwac038 |
Public URL | https://durham-repository.worktribe.com/output/2609777 |
You might also like
Cybersecurity of AI medical devices: risks, legislation, and challenges
(2024)
Book Chapter
Medical diagnostic artificial intelligence; medical, safety, security, and legal considerations
(2024)
Presentation / Conference Contribution
The Role of Cybersecurity in Medical Devices Regulation: Future Considerations and Solutions
(2023)
Journal Article
Downloadable Citations
About Durham Research Online (DRO)
Administrator e-mail: dro.admin@durham.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search