The introduction of the General Data Protection Regulation (GDPR) has significantly impacted the management of patient data in healthcare providers. A key interpretative tool in Poland is the Code of Conduct for the Healthcare Sector, which supports the application of the accountability principle. However, it should be emphasized that this Code is voluntary and supportive, and the primary source of obligations remains legal provisions.

1. Data protection and patient safety

The GDPR does not conflict with the provision of healthcare services. The regulations provide specific grounds for processing health data, including situations related to protecting a patient's life and health. In practice, this means that the application of data protection principles must take into account the specific nature of healthcare activities, where rapid access to information can be crucial.

2. The principle of data minimization in medical practice

The principle of data minimization (Article 5, Section 1, Letter c of the GDPR) requires that data be adequate and limited to what is necessary to achieve the purpose. In healthcare, the assessment of "necessity" should be made in the context of the treatment process. Healthcare providers may process contact data (e.g., telephone number, email address) if this is justified by the organization of service provision, e.g., confirming appointments. The scope of data should be justified in each case by the specific purpose and cannot be expanded unnecessarily.

3. Patient identification

Correct patient identification is an important element of treatment safety.

  1. The use of identification wristbands is standard practice to prevent mistakes.
  2. Where possible, you should limit the disclosure of personal data to third parties (e.g., using numbers or names).
  3. In situations requiring unambiguous identification, including emergency situations, the use of full patient data is permissible if justified by safety reasons.

4. Labeling of medicinal products

Labeling medications, blood, or medical devices with patient data may be justified by the need to ensure treatment safety. Such actions should be based on the data processing grounds provided for in the GDPR, particularly those related to the protection of health and life.

5. Privacy in medical facilities

Ensuring patient privacy, especially in multi-person rooms, requires appropriate organizational solutions:

  1. Staff should limit sharing detailed medical information to situations where it is necessary.
  2. Whenever possible, discussions about health should take place in conditions that ensure confidentiality.
  3. The use of bedside cards is permissible as long as the data is appropriately protected against access by unauthorized persons.

6. Emergencies and contact with loved ones

In situations where the patient is unable to express consent, data processing is permitted to the extent necessary to protect his or her life or health.

It is possible to obtain information from third parties if it is used to provide health services, but the transmission of information by telephone should be carried out with particular caution and appropriate verification of the caller's identity.

7. Patient rights and medical records

The GDPR grants patients certain rights, but their implementation in healthcare is subject to specific regulations:

  1. The patient has the right to access medical records and obtain a copy thereof.
  2. Medical records are subject to mandatory retention periods, which limits their ability to be deleted.
  3. Data rectification is possible to a certain extent, while respecting the principles of maintaining medical records.

8. Monitoring and recording

The use of video surveillance in medical facilities is permitted provided that the GDPR requirements are met:

  1. must have a clearly defined purpose (e.g. security),
  2. should be proportional to the risk,
  3. patients should be informed accordingly.

Recording of health services may be permissible if it is medically justified and adequately secured.

9. Technical and organizational measures

Healthcare entities, as data controllers, are obliged to implement measures appropriate to the risk, including:

  1. conducting risk analysis,
  2. use of technical security measures (e.g. encryption),
  3. ensuring appropriate organization of data processing,
  4. appointing a data protection officer if required by law.

Summary

The GDPR does not constitute a barrier to the provision of healthcare services, but rather introduces a framework for ensuring the security of patient data. Striking the right balance between privacy protection and the needs of the treatment process is crucial. In practice, this requires a case-by-case assessment of the adequacy of data processing and a thorough justification of any actions taken.

This article is for informational purposes only and does not constitute legal advice

Legal status as of April 30, 2026.

Author:

Series editor:

    Have any questions? Contact us – we'll respond as quickly as possible.