Skip to main content

Article 9 GDPR: Health Data on Websites

Article 9 GDPR explained in plain language: health data on websites for medical practices, therapy, health professionals and pharmacies.

Published: · Updated:

Article 9 GDPR: Health Data on Websites © Velvionix
8 min read DE
Important notice Legal, tax and industry-specific information concerns Germany and expressly identified EU law. It is provided for general orientation and does not replace individual advice. Last review of the cited legal situation: July 2026

Unless stated otherwise, the legal, tax or industry-specific information on this page reflects the law applicable in Germany and German official and professional practice. Directly applicable EU law and references to other jurisdictions are identified separately. The information was researched with due diligence using sources available as of the stated review date. For binding guidance on your specific project, please contact the competent chamber or a qualified specialist, such as a lawyer or tax adviser. The current statutes and official regulations always prevail.

A medical practice offers a contact form and asks visitors to describe symptoms. A psychotherapy practice asks for a short description of the situation. A pharmacy accepts online questions about medication. In cases like these, the website is no longer dealing only with names and email addresses. It may be dealing with health data under Article 9 GDPR.

What the Paragraph Regulates

Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.

Article 9 GDPR starts with a prohibition. Certain data are so sensitive that they cannot be treated like ordinary contact or address data. Health data are part of this category. They can be direct details, such as a diagnosis, medication, treatment, therapy request or medical report. They can also be indirect details if they allow conclusions about someone’s health.

Article 9 GDPR does not replace Article 6 GDPR. The German Data Protection Conference explains that processing special categories of data generally needs both: a legal basis under Article 6 GDPR and an additional exception under Article 9(2) GDPR. For normal readers, this means that a health-related contact form is not just a longer version of a normal contact form.

The GDPR contains exceptions to the prohibition. These include explicit consent, medical diagnosis, health care, social care, public interest in the area of public health and scientific research. Which exception may fit depends strongly on the purpose, the controller and the safeguards in place.

Who Is Affected

Article 9 GDPR becomes relevant whenever a website collects, transmits or structures information that may have a health connection. For our typical customer groups, this mainly affects these areas:

Not every website in these industries automatically processes health data. A static page with a phone number, opening hours and general text is different from a form that asks for symptoms, diagnoses or files. The concrete function is decisive.

Typical Use Cases

For medical and dental practices, the threshold is reached quickly. A field labelled “your message” can be harmless if visitors only ask about opening hours. It can contain health data as soon as people describe symptoms, medication, reports or treatment wishes. A website should therefore avoid encouraging visitors to enter sensitive details into a general form.

Family doctor practices often add prescription and referral requests. The information that a specific person needs a specific medication can already have a health connection. For a simple website, a clear and data-minimising contact path is often better than a broad medical form that collects everything directly on the website.

Psychotherapy practices and naturopathy practices often deal with sensitive life situations. A first-contact form can quickly include information about psychological stress, diagnoses, family circumstances or therapy goals. Restraint matters here. The website can explain how first contact works without collecting every detail in the form.

For physiotherapy and occupational therapy, typical details include complaints, medical prescriptions, accident consequences or everyday limitations. These are not ordinary service details. A form that only asks for a callback is less intrusive than a form that asks for a diagnosis, a prescription photo and a detailed medical history.

Pharmacies have a different focus. They sell and advise, but they still operate in a sensitive environment. A question about product availability may be ordinary. A question about medication, pregnancy, chronic symptoms or interactions can very quickly touch health data.

Exceptions and De Minimis Rules

Article 9 GDPR does not contain a simple de minimis rule such as “a little health connection does not matter”. The practical difference is whether health data are processed at all, whether the processing is necessary and which exception under Article 9(2) GDPR may apply.

Explicit consent is often the first idea. It can matter, but it is not a universal solution. It must be informed, freely given, specific and demonstrable. The first question remains whether the website needs to collect the data at all. Data protection starts with the decision which fields exist, not with the checkbox.

For health care, Article 9(2)(h) GDPR can be relevant. In Germany, § 22 BDSG complements this framework and refers to preventive health care, medical diagnosis, care or treatment in the health or social sector. At the same time, § 22 BDSG requires appropriate and specific safeguards, such as access limitations, encryption, pseudonymisation or procedures for reviewing technical measures.

A data protection impact assessment is not automatically required for every small website. The BfDI explains, however, that Article 35 GDPR requires one when processing is likely to result in a high risk. Large-scale processing of special categories of personal data is expressly named as a typical case. For small practice websites, the practical question is therefore whether the website should really process health data at larger scale itself.

Consequences of Violations

Health data are not just a matter of adding the right notice text. They are particularly sensitive information. For small practices and health-related providers, the most practical step is to avoid unnecessary data collection and explain the contact path clearly. That reduces misunderstandings, protects trust and keeps later coordination manageable.

For small practices, the trust issue is often especially important. Patients expect restraint when health matters are involved. If a website asks too openly for sensitive details, transmits them insecurely or explains the process unclearly, it does not feel professional.

Practical Implementation on the Website

Data minimisation is the starting point for the website structure. A contact form does not need to collect medical details if a callback is enough. An appointment request does not automatically need a diagnosis. A prescription or report request should not be mixed into a general contact form if a specialist system or a more controlled process is more appropriate.

For website creation for practices and health-related providers, we structure contact paths with restraint: clear separation between general contact and sensitive requests, minimal form fields, clear instructions for using the form, TLS-secured SMTP forwarding without promising end-to-end encryption and no permanent storage of sensitive content on our systems. For real booking, video consultation or patient portal workflows, we refer to suitable specialist systems or embed existing providers only as widgets or links.

The boundary matters, but it should not feel complicated: Velvionix builds the website so sensitive information is not requested unnecessarily and suitable specialist systems can be embedded cleanly. Which internal legal basis or practice rule applies in a specific case remains with the business; the website itself supports a data-minimising and traceable setup.

Frequently Asked Questions

Are health data only diagnoses?

No. Information about symptoms, medication, treatment, limitations or therapy requests can also be health data if it allows conclusions about someone’s health.

Is a normal contact form on a practice website prohibited?

Not automatically. It depends on what the form asks for, what it encourages visitors to submit and how the input is processed. A callback form with a few fields is different from a form with diagnosis, report upload and medical history.

Is a consent checkbox enough?

A checkbox alone does not solve the issue. First, the practice needs to know whether the data are necessary, which legal basis fits and which safeguards are required.

Should health data be stored in a website database?

For small practice websites, restraint is sensible. Often it is better not to store sensitive content permanently on the website infrastructure and to use specialist systems or direct practice processes instead.

When does a data protection impact assessment become important?

It becomes important when the planned processing is likely to create a high risk. Large-scale processing of special categories of personal data is a typical trigger.

What does Velvionix handle for these forms?

Velvionix plans the technical website structure: minimal fields, clear instructions, no permanent storage of sensitive content on our systems and, where useful, a clean connection to a specialist system. The central notice above explains the legal boundary.

Sources

Notice: The respective providers or operators are solely responsible for the content of external links.

  1. [1]
    EUR-Lex : "Regulation (EU) 2016/679 - Article 9"
    https://eur-lex.europa.eu/eli/reg/2016/679/art_9/oj
  2. [2]
    EUR-Lex : "Regulation (EU) 2016/679 - Article 4 definitions"
    https://eur-lex.europa.eu/eli/reg/2016/679/art_4/oj
  3. [3]
    European Data Protection Board : "Article 9 (Processing of special categories of personal data)"
    https://www.edpb.europa.eu/gdpr-articles/article-9-processing-special-categories-personal-data_en
  4. [4]
    Gesetze im Internet / BMJ : "§ 22 BDSG - Verarbeitung besonderer Kategorien personenbezogener Daten"
    https://www.gesetze-im-internet.de/bdsg_2018/__22.html
  5. [5]
    Datenschutzkonferenz / ULD : "Kurzpapier Nr. 17: Besondere Kategorien personenbezogener Daten"
    https://www.datenschutzkonferenz-online.de/media/kp/dsk_kpnr_17.pdf
  6. [6]
    BfDI : "Datenschutz-Folgenabschätzungen und Listen von Verarbeitungsvorgängen"
    https://www.bfdi.bund.de/DE/Fachthemen/Inhalte/Technik/Datenschutz-Folgenabschaetzungen.html
  7. [7]
    EUR-Lex : "CJEU judgment C-184/20 - OT v Vyriausioji tarnybinės etikos komisija"
    https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62020CJ0184
  8. [8]
  9. [9]
    Kassenärztliche Bundesvereinigung : "Datenschutz - Datenschutz-Grundverordnung in der Praxis"
    https://www.kbv.de/praxis/praxisfuehrung/datenschutz
  10. [10]
  11. [11]
    European Data Protection Board : "Guidelines 03/2020 on the processing of data concerning health for scientific research"
    https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-032020-processing-data-concerning-health-purpose_en
  12. [12]

Related Articles

Comments

No comments yet.

Comments disabled

Comments are disabled for this article because the topic may involve sensitive legal, professional or personal information.