EHDS — Regulation (EU) 2025/327 — in force since March 2025
EHDS Compliance for AI Products and Digital Health Companies
The European Health Data Space Regulation entered into force in March 2025. General obligations apply from March 2027. If your AI product touches electronic health records, clinical data, or health data re-use for research or innovation, EHDS reaches you and the 2027 deadline is moving faster than most digital health teams have planned for.

WHAT IS EUROPEAN HEALTH DATA SPACE
The European Health Data Space — Regulation (EU) 2025/327 — was published in the Official Journal of the European Union on 5 March 2025 and entered into force on 26 March 2025. It is the first sector-specific Data Space adopted by the EU and establishes a comprehensive regulatory, infrastructural, and governance framework for the circulation of healthcare data across the Union.
The EHDS will empower individuals to access, control, and share their electronic health data across borders for healthcare delivery — the primary use of data — and enable the secure and trustworthy reuse of health data for research, innovation, policy-making, and regulatory activities — the secondary use of data — while fostering a single market for electronic health record systems.
For AI and digital health companies, the EHDS is not a distant infrastructure project for hospitals and health ministries. It is a direct compliance obligation if your product touches any of the following:
- AI systems processing electronic health records or patient data
- Digital health platforms providing or integrating with EHR systems
- AI trained on clinical data, medical imaging, genomic data, or patient records
- Research and innovation platforms accessing health data for secondary use
- Medical device software or Software as a Medical Device using health data
- Non-EU digital health companies with EU patients, clients, or health data partnerships
- AI products seeking health data access through the HealthData@EU infrastructure
If any of these apply, the EHDS reaches your product — and the March 2027 general obligation deadline is already running.
European Health Data Space Assessment for Your AI Product
A lawyer-built assessment of your product’s EHDS obligations — health data holder determination, primary use and secondary use obligation mapping, EHR system interoperability requirements, HealthData@EU access obligations, GDPR interaction analysis, EU AI Act overlap mapping, and a documented compliance record your legal team, health data access body, enterprise buyers, and regulatory authorities can rely on.
How European Health Data Space works for AI health products
Two pillars. One regulation. Direct requirements for every AI product touching health data in the EU.

The EHDS regulates two distinct but coordinated areas: primary use — the use of healthcare data to deliver care to the individual patient — and secondary use — the use of healthcare data for scientific research, innovation, official statistics, public health policy, and regulatory activities. Each pillar creates distinct obligations for AI and digital health companies depending on how their product interacts with health data.
Primary use — electronic health records and patient data
The EHDS strengthens patient rights over electronic access to their own health data and harmonises the requirements for EHR systems used by healthcare providers. Companies that develop or distribute electronic health record systems must ensure that their systems support the European EHR exchange format — defined by the European Commission through implementing acts — ensuring machine-readability and cross-border compatibility of data such as patient summaries, laboratory results, and electronic prescriptions. AI products embedded in or integrated with EHR systems must satisfy these interoperability requirements alongside their EU AI Act and MDR obligations. An AI clinical decision support system that cannot exchange data in the European EHR format is non-compliant regardless of how clinically effective it is.
Secondary use — health data for research and innovation
The EHDS establishes a framework for health data holders — hospitals, insurers, pharmaceutical companies, medical device manufacturers, and others — to make health data available for secondary use through Health Data Access Bodies in each member state, connected to the HealthData@EU infrastructure. AI companies seeking to access health data for model training, algorithm development, or research must apply through this framework. AI companies that currently access health data through bilateral agreements, data partnerships, or direct patient consent arrangements must assess whether the EHDS changes the legal basis for that access and what additional obligations apply from 2029.
Health data holder obligations
Organisations that generate, collect, or control electronic health data — including AI platforms processing patient data, digital health applications, and medical device manufacturers — are health data holders under the EHDS. Health data holders must make specified categories of health data available for secondary use through the HealthData@EU infrastructure, subject to defined access conditions. For AI companies, this creates both an obligation — to make data available — and an opportunity — to access data held by other health data holders for AI development purposes through a structured legal framework.
EHR system manufacturer obligations
AI products that qualify as electronic health record systems or components of EHR systems face specific interoperability, labelling, and conformity obligations under the European Health Data Space. Cooperation with national digital health authorities is essential to demonstrate compliance and receive technical support. EHR system manufacturers must register their systems, satisfy the European EHR exchange format requirements, and cooperate with the conformity assessment process — obligations that sit alongside MDR requirements for systems also qualifying as medical devices.
Cross-border data access and MyHealth@EU
The EHDS makes the MyHealth@EU infrastructure mandatory for cross-border clinical document exchange — the infrastructure that allows a patient’s health data to follow them across EU member states. AI products that operate across EU borders, that process patient data from multiple member states, or that provide services to patients receiving cross-border care must assess their obligations under MyHealth@EU and the EHDS’s cross-border access framework alongside their GDPR cross-border transfer obligations.
Who European Health Data Space (EHDS) applies to
The EHDS applies to health data holders, EHR system manufacturers, health data users seeking secondary access, and the AI and digital health companies that interact with health data across the EU. The scope is broader than most digital health teams have mapped.
| Entity type | In scope of EHDS? | Key obligation |
|---|---|---|
| EHR system developer or manufacturer | Yes — directly | European EHR exchange format, interoperability, conformity assessment, national authority cooperation |
| AI clinical decision support system | Yes — directly if integrated with EHR | EHR system obligations where integrated, EU AI Act high-risk obligations simultaneously |
| Digital health application processing patient data | Yes — as health data holder | Secondary use data availability obligations, GDPR interaction, patient rights |
| Medical device manufacturer using health data | Yes — as health data holder and MDR entity | EHDS data holder obligations plus MDR conformity assessment requirements |
| AI company training on clinical or patient data | Yes — as health data user for secondary use | Must access data through HealthData@EU framework from 2029, not bilateral agreements |
| Pharmaceutical or life sciences company | Yes — as health data holder and user | Data availability obligations and secondary use access rights |
| Health insurer processing member health data | Yes — as health data holder | Secondary use availability obligations, patient access rights |
| Non-EU digital health company with EU patients | Yes — extraterritorial | Same obligations as EU-established entities where EU health data is processed |
| Research institution using health data | Yes — as health data user | Must use HealthData@EU framework for secondary access, secure processing environment |
| AI platform with no health data or health function | No | Document this determination — scope depends on whether data processed qualifies as health data |
The European Health Data Space obligation most AI companies miss
The EHDS’s secondary use framework is the provision creating the most significant compliance planning gap for AI companies — and the one whose 2029 application date is creating false comfort about urgency.
AI companies that currently access health data through direct patient consent, bilateral data sharing agreements with hospitals, or informal research partnerships must build the EHDS secondary use framework into their compliance planning now — not in 2028. Three things AI health data teams consistently misunderstand:
The 2029 secondary use application date does not mean secondary use of health data is unregulated until 2029. GDPR continues to govern all health data processing — including AI training on patient data — until EHDS secondary use provisions apply. The EHDS does not create a new lawful basis for health data processing that did not previously exist. It creates a structured framework for secondary use that supplements GDPR. AI companies accessing health data today must satisfy GDPR’s Article 9 special category data requirements now and must plan to transition to EHDS-compliant secondary use access from 2029.
Health data represents over 30% of the world’s data assets, yet less than 3% is utilised for secondary purposes such as research, regulatory, or public health purposes. The EHDS is designed to close that gap — which means it will unlock significantly more health data for AI training and development than is currently accessible. AI companies that establish compliant access frameworks through HealthData@EU early will have a competitive advantage in data access that late movers will not be able to replicate quickly.
The interaction between EHDS and the EU AI Act is almost never mapped for the same product simultaneously. An AI system trained on health data accessed through the EHDS secondary use framework, deployed in a clinical context, is subject to EHDS data access obligations, EU AI Act high-risk classification requirements, MDR obligations where it qualifies as SaMD, and GDPR special category data processing rules — all simultaneously. Each regime has distinct documentation requirements, distinct supervisory authorities, and distinct enforcement timelines. A product assessment that addresses only one of these does not give an accurate picture of the compliance obligations that product actually faces.
What EDHS readiness assessment requires
These are the EHDS requirements that apply most directly to AI products and digital health companies — and to organisations accessing or processing health data for AI development and deployment purposes.
Cross-framework mapping — identification of where EHDS obligations interact with GDPR special category data processing rules under Article 9, EU AI Act high-risk classification for AI in healthcare decision support, MDR conformity assessment requirements for AI qualifying as SaMD, and NIS2 cybersecurity obligations for health sector entities — showing where one compliance programme satisfies multiple frameworks simultaneously.
Health data holder determination — confirmation of whether your organisation qualifies as a health data holder under the EHDS, which categories of health data you hold, and what secondary use availability obligations that triggers from 2029 — the starting point for every subsequent EHDS compliance obligation.
Primary use obligation assessment — determination of whether your AI product qualifies as an EHR system or EHR system component, what European EHR exchange format requirements apply, and what the interoperability and conformity obligations require before the March 2027 general application deadline.
Secondary use access framework assessment — assessment of how your organisation currently accesses health data for AI training, research, or innovation purposes, whether existing access arrangements satisfy GDPR and will transition to EHDS-compliant secondary use access from 2029, and what the HealthData@EU application process requires.
GDPR interaction mapping — assessment of the interaction between your current GDPR lawful basis for health data processing and the EHDS framework — identifying where the EHDS supplements GDPR, where it creates new obligations, and where your current GDPR compliance programme needs to be updated to reflect EHDS requirements.
MyHealth@EU cross-border assessment — determination of whether your product’s cross-border data processing obligations require engagement with the MyHealth@EU infrastructure and what technical and governance measures that requires.
EHR system conformity assessment — where your product qualifies as an EHR system or component, assessment of the conformity obligations, national authority registration requirements, and labelling obligations under the EHDS alongside any MDR conformity assessment already in progress.
AI model training data compliance — assessment of the lawful basis and conditions under which your AI model training data is accessed and processed, mapped against both GDPR Article 9 requirements and the EHDS secondary use framework obligations that will apply from 2029.
Living Compliance File™ — audit-ready compliance record structured by EHDS obligation area and product function, formatted so a Health Data Access Body, supervisory authority, notified body, enterprise buyer, or investor’s due diligence team can open it and find what they need.
One engagement. Every EHDS gap identified and documented.
A lawyer-built EHDS assessment covering health data holder determination, primary use EHR system obligations, secondary use access framework assessment, GDPR interaction mapping, MyHealth@EU cross-border assessment, AI model training data compliance, and cross-framework mapping against your EU AI Act, MDR, GDPR, and NIS2 position where all apply.
Frequently Asked Questions About European Health Data Space
What is the European Health Data Space (EHDS) and when does it apply?
Regulation (EU) 2025/327 on the European Health Data Space establishes a common EU framework for the sharing and use of health data for primary purposes — healthcare delivery — and secondary purposes — research, policy-making, and innovation. The Regulation entered into force on 26 March 2025. General provisions will be applicable from 26 March 2027, while some specific obligations will not become applicable until March 2029 and March 2031.
What is the difference between primary use and secondary use under the European Health Data Space?
Primary use covers the use of health data to deliver care to individual patients — including patient access to their own electronic health records, cross-border clinical data exchange through MyHealth@EU, and EHR system interoperability obligations. Secondary use covers the use of health data for research, innovation, policy-making, official statistics, and regulatory activities — accessed through Health Data Access Bodies and the HealthData@EU infrastructure. The two pillars have different obligation structures, different timelines, and different supervisory authorities, but apply to many of the same organisations simultaneously.
Does the European Health Data Space apply to non-EU digital health companies?
Yes, where those companies process health data about EU patients or operate digital health products in the EU market. The European Health Data Space follows the same extraterritorial logic as GDPR — it applies based on where the data subject is located and where the service is offered, not where the company is established. A US AI company training on EU patient data, a Canadian digital health platform serving EU healthcare providers, or an Indian EHR system manufacturer selling to EU hospitals faces European Health Data Space obligations on the same terms as an EU-established entity.
What is a health data holder under the European Health Data Space?
A health data holder is any natural or legal person — including AI companies, digital health platforms, medical device manufacturers, health insurers, and pharmaceutical companies — that has the right or obligation to process specific categories of electronic health data. Health data holders must make specified health data categories available for secondary use through the HealthData@EU infrastructure from 2029, subject to defined access conditions and subject to GDPR compliance. The definition is broader than most digital health companies have applied to themselves.
How does the EHDS interact with GDPR for AI systems processing health data?
The EHDS supplements rather than replaces GDPR for health data processing. GDPR continues to govern all health data processing — including AI training on patient data — and the EHDS does not create a new lawful basis that overrides GDPR’s Article 9 special category data requirements. The European Health Data Space secondary use framework establishes structured conditions for health data access that, where satisfied, provide the public interest or scientific research lawful basis that GDPR Article 9(2)(j) already permits. AI companies must satisfy both frameworks simultaneously — GDPR for data protection and the European Health Data Space for structured access and availability obligations.
How does the EHDS interact with the EU AI Act for clinical AI products?
Clinical AI products frequently sit under both frameworks simultaneously. An AI system making or supporting clinical decisions is likely high-risk under EU AI Act Annex III, requiring technical documentation, conformity assessment, and human oversight measures. The same system processes health data subject to EHDS primary use obligations if it integrates with EHR systems, and may access health data through the European Health Data Space secondary use framework for model training. A cross-framework assessment maps where EU AI Act technical documentation satisfies European Health Data Space data governance requirements and where the two frameworks impose distinct and non-overlapping obligations.
What is HealthData@EU and how does it affect AI development?
HealthData@EU is the EU infrastructure connecting national Health Data Access Bodies — enabling health data from multiple member states to be accessed for secondary use purposes through a single application process. From 2029, AI companies seeking to access health data for model training, algorithm development, or research must do so through the HealthData@EU framework rather than through bilateral agreements or informal partnerships. Companies that build compliant HealthData@EU access processes early will have structured access to significantly more health data than is currently available through informal channels.
Does the EHDS apply to AI products that qualify as medical devices under MDR?
Yes — and both frameworks apply simultaneously. An AI system qualifying as Software as a Medical Device must satisfy MDR conformity assessment requirements alongside European Health Data Space EHR system obligations where it integrates with electronic health records, European Health Data Space health data holder obligations where it processes patient data, and EU AI Act high-risk obligations. The three frameworks have overlapping but distinct documentation requirements — a product assessment maps where one document satisfies multiple frameworks and where distinct evidence is required.
What are the penalties for EHDS non-compliance?
Penalties are set at member state level within the European Health Data Space framework, and specific penalty provisions vary by obligation type. Member state supervisory authorities — Health Data Access Bodies and national digital health authorities — have enforcement powers covering EHR system conformity, data holder availability obligations, and secondary use access conditions.
GDPR supervisory authorities retain enforcement powers over health data processing that violates GDPR’s Article 9 requirements regardless of European Health Data Space status. Non-compliant EHR systems may be required to be withdrawn from the market.
How do I start EHDS compliance for my AI product?
First, determine whether your organisation is a health data holder, an EHR system manufacturer, or a health data user seeking secondary access — or a combination — as the role determines your specific obligations and timelines. Second, assess your primary use obligations — whether your AI product qualifies as an EHR system or component and what the European EHR exchange format requires before March 2027. Third, map your current health data access arrangements against both GDPR Article 9 requirements and the European Health Data Space secondary use framework that applies from 2029. Fourth, identify where your EU AI Act and MDR compliance programmes overlap with European Health Data Space obligations and where distinct additional work is required. A lawyer-built assessment covers all four steps and delivers a documented compliance position specific to your product — mapped against your EU AI Act, MDR, GDPR, and NIS2 position where all apply.
