European Health Data Space in Action: From Regulation to Real-World Implementation

The European Health Data Space (EHDS) is the European Union’s most ambitious initiative in the field of Digital Health policy. Aimed at unlocking the value of Health Data, at its core, the EHDS has been designed to enable the secure and interoperable use of Health Data across Member States, to strengthen Healthcare systems, support innovation, and improve public health and policymaking while maintaining high standards of Data Protection and Data quality.

To accomplish these objectives, the EHDS establishes a structured and interoperable framework for the exchange of personal and non-personal electronic Health Data across Europe. It is built around two complementary objectives:

Primary use of Health Data, aimed at improving Healthcare delivery by ensuring that Patients’ Health information is accessible when and where it is needed, including across borders.

Secondary use of Health Data, enabling research, innovation, public health initiatives, and policymaking through secure and controlled access to de-identified or Pseudonymized Data.

As the regulation moves from years of policy development into its implementation phase, attention is increasingly focused on how the EHDS will function in practice. At My Data-TRUST’s Summit organized in January, one of the panel discussions, moderated by Michelle Ayora , brought together experts from industry, academia, and public health to explore the key challenges, risks, and solutions associated with making the EHDS operational. Claire François , Anouk Berger , Mikel Recuero , and Wannes Van Hoof shared their expertise across a range of topics, offering insights that resonate with the diverse industries affected by the EHDS.

🧠 What are the main challenges related to awareness, understanding, and trust in the EHDS?

1. Complexity of the framework and trust

A central theme of the discussion was the complexity of the EHDS framework. Panelists noted that the regulation introduces broad concepts, such as Health Data holders, Health Data access bodies, and secondary use, that remain high-level and depend heavily on forthcoming implementing and delegated acts.

Further, this complexity is compounded by the potential for divergent national interpretation in areas left to Member States’ competence. The EHDS adds a new layer of regulation on top of the GDPR, the Clinical Trials Regulation, and other legal instruments, making compliance obligations less straightforward. While the EHDS seeks harmonization, Member States retain discretion in areas such as governance structures, opt-out mechanisms, and certain technical standards, thereby increasing the likelihood of inconsistent national implementation. The resulting risk is the continuation of current regulatory fragmentation, particularly in cross-border contexts.

Trust emerged as a parallel concern. Panelists Claire F. and Anouk B. both emphasized that trust depends on striking the right balance between enabling Data access for research and innovation and protecting confidential information, intellectual property, and trade secrets. Industry stakeholders worry about whether Pseudonymization standards will be applied consistently and whether Health Data Access Bodies (HDABs) will operate with transparency and efficiency. Any perception of weak governance could undermine confidence in the system. Without clear and consistent guidance, stakeholders may hesitate to fully engage with the EHDS.

2. Patient awareness and opt-out mechanisms

Anouk B., legal lead at a pharmaceutical company, emphasized another major challenge related to patient awareness and consent choices, particularly opt-out mechanisms for the secondary use of Health Data. Effective communication is essential: patients must understand how their Data will be used, what safeguards will apply, and how they can exercise their rights.

Fragmented implementation of opt-out systems across Member States risks confusion and mistrust. From an industry perspective, high opt-out rates could significantly affect Data representativeness and, consequently, the quality of research outcomes. Transparency and consistent information were seen as critical to maintaining public confidence in the system.

3. Legal and technical interoperability

The panel stressed that the EHDS does not replace existing legal frameworks. Instead, it operates alongside the GDPR, Clinical Trials legislation, and other sectoral rules, adding another regulatory layer. This creates legal complexity, particularly for organizations conducting cross-border research or operating in multiple Member States.

The panelists shared similar uncertainties, including:

  • How intellectual property and trade secrets will be protected when Data are shared under EHDS access rules
  • How to avoid unintentionally creating competitive disadvantages when proprietary Data are made available
  • How international Data transfers will be handled, given that GDPR Chapter V continues to apply and the EHDS does not fully resolve global Data-sharing challenges

From a technical perspective, interoperability remains uneven. While the EHDS envisions a federated infrastructure, differences in Data standards, electronic health record systems, and digital maturity across Member States continue to hinder seamless Data exchange.

4. Fragmentation, inequities, and Member State diversity

Several panelists highlighted the risk that the EHDS could exacerbate existing disparities between Member States. Countries with advanced Digital Health infrastructures, e.g., Finland, are better positioned to benefit quickly, while others may struggle with Data quality, registration, and system readiness.

At the same time, Member State autonomy was recognized as both a strength and a limitation. Wannes V. highlighted that full unification is unrealistic in Europe, but harmonization and interoperability are achievable. By ensuring systems can communicate efficiently and adopting standards that support cross-border compatibility, the EHDS can function without forcing identical national solutions. He encouraged viewing fragmentation as an opportunity for creativity and innovation, pointing to the evolution of GDPR implementation as a precedent for systems maturing over time.

💡 What are the potential solutions and good practices?

Despite these challenges, the panel identified a range of practical solutions to support effective implementation.

1. Clear guidance and sector-specific training

There was broad agreement on the need for clear, harmonized guidance tailored to specific sectors, including pharmaceuticals, medical devices, research institutions, and public authorities. New EHDS concepts, such as HDAs, opt-out models, and interoperability standards, require practical interpretation rather than abstract legal explanation.

Training and explanatory materials were seen as essential to building consistent understanding and compliance.

2. Collaborative platforms and early engagement

Anouk B. emphasized the value of early and continuous stakeholder engagement. Collaborative platforms where regulators, industry, researchers, and public bodies can share interpretations, challenges, and best practices would help reduce divergent approaches and build trust.

Mikel Recuero highlighted that such cooperation could also limit “forum shopping” and encourage convergence in procedural approaches.

3. Mutual recognition and cross-border cooperation

Mikel R. also suggested solutions to address procedural barriers in cross-border projects. The panel proposed:

  • Mutual recognition of Data permits issued by Health Data access bodies
  • Mutual recognition of research ethics committee approvals
  • Inter-state cooperation agreements on jurisdiction and applicable law

These mechanisms could significantly reduce delays and administrative burden while respecting national competencies.

4. Incentives and funding mechanisms

Wannes V. also mentioned that rather than relying solely on top-down obligations, he advocated for positive incentives. Linking funding to Data quality, registration practices, and interoperability readiness could encourage organic harmonization. Showcasing successful national or sectoral examples may also accelerate the adoption of best practices.

🔄 A necessary cultural shift?

Beyond legal and technical fixes, the panel repeatedly returned to the need for a cultural shift. The GDPR has reshaped how people think about Data, often framing it as something inherently risky and in need of strict protection. While this awareness is important, it can also reinforce defensive attitudes that limit responsible Data use.

The EHDS seeks to demonstrate that Health Data can be used safely, ethically, and transparently for both individual care and collective benefit. A clear definition of purpose, with a precise explanation of why Data are used and which societal objectives they aim to advance, was identified as the strongest driver of public trust. When individuals understand that their Data contribute to well-defined goals in the common interest, many subsequent technical and operational challenges become more manageable.

📌 Conclusion

The European Health Data Space is more than a regulatory framework, it is the foundation for a new European Health Data ecosystem. Its success will depend on trust, legal and technical coherence, and genuine cross-border collaboration.

Clear guidance, strong governance, effective communication, and practical solutions for interoperability and intellectual property protection are all essential. Equally important is sustained collaboration across borders and sectors, and a shared commitment to building public trust.

While implementation will undoubtedly be complex, the discussion reflected cautious optimism. With thoughtful execution and an emphasis on alignment rather than uniformity, the EHDS has the potential to deliver significant benefits for patients, researchers, public authorities, and industry, while helping to shape the future of healthcare innovation in Europe.

Author:Chim Kei Chan

Prev post
Next post
Powered by MyData-TRUST

Want to subscribe to our newsletter ?

Name(Required)
Privacy(Required)