Health data is the most sensitive category most organisations will ever handle, and the EU has just built a whole legal framework around it. The European Health Data Space Regulation, Regulation (EU) 2025/327, entered into force on 26 March 2025 and rolls out in phases over the following years. If you work anywhere near clinical AI, it is worth understanding, because it says a lot about where the EU thinks sensitive data should be processed.

Two uses, two sets of rules

The EHDS splits health data use into two categories, and the distinction matters.

Primary use is what you would expect: using someone's health data to care for them. Electronic health records, cross-border access when a patient travels, that sort of thing. Secondary use is everything else, research, innovation, policymaking, training a model, and it runs through national health data access bodies that issue permits. The Commission's EHDS pages lay out the phased timeline, with the main secondary-use machinery arriving toward the end of the decade.

The rule that should make AI vendors pay attention

For secondary use, the EHDS does not just wave data out the door. Processing has to happen inside a secure processing environment that meets high privacy and cybersecurity standards. Data is pseudonymised or anonymised. And here is the striking part: you cannot download the personal data out of that environment. You bring your analysis to the data, run it inside the walls, and take only the results away.

Sit with that for a second, because it is a profound statement of principle. The most sensitive data in Europe, the EU has decided, should be processed in a controlled environment that the data does not leave. Researchers come to it. It does not go to them.

If that architecture sounds familiar, it should. "Bring the computation to the data, do not move the data to the computation" is exactly how on-premise AI works. The model runs where the records already live. Nothing is exported. The EHDS did not invent this pattern, but by writing it into law for health data it has blessed the idea that for truly sensitive information, local and sealed is the responsible default.

Health data was always special, and now it has scaffolding

Under GDPR Article 9, health data is a special category with extra protection, and Swedish rules like the patient data act (patientdatalagen) add their own layer. The EHDS does not replace any of that. It builds infrastructure on top of it, and where AI is a medical device, the Medical Device Regulation comes into play as well. It is a dense stack.

The practical takeaway for anyone building or buying clinical AI is not that the EHDS forces you on-premise today. The phased dates stretch out for years, and much of the detail lives in implementing acts still to come. The takeaway is about direction. When European regulators design their flagship health data framework around secure, no-download environments, they are telling you what "good" looks like for sensitive data. Running the AI where the data already sits is not a fringe position. It is increasingly the one the law is describing.

This is general information, not legal or clinical advice. Health data rules are among the most complex in the book, and the EHDS interacts with the GDPR, the MDR and national law in ways your compliance and clinical governance teams need to work through for your setting.