Reltronic, Inc.
For information technology, security, privacy and legal review
The legal basis for moving European health data to the United States has been rebuilt twice in ten years and is under appeal a third time. Clinical infrastructure procured today will still be running when that appeal is decided. An institution choosing where analysis happens is therefore making a decision with a longer life than the legal instrument that currently permits the alternative.
What the European Health Data Space actually requires, and when
Regulation (EU) 2025/327, establishing the European Health Data Space, entered into force on 26 March 2025. A good deal of confusion follows from that date, because entry into force and application are not the same thing. Most of the substantive obligations are not yet live, and they arrive in stages over the following decade.
- 26 March 2025. The Regulation enters into force.
- 26 March 2027. General application. The primary use provisions and the requirements on electronic health record systems begin to bite.
- 26 March 2029. Chapter III applies. This is the secondary use regime, covering most categories of electronic health record data.
- 26 March 2031. Sharing obligations extend to medical imaging studies and imaging reports, medical test results and discharge reports, and to previously excluded categories including genetic, molecular and clinical trials data.
The practical consequence is straightforward. A clinical system selected in 2026 and deployed over the following year will be operating inside the general application regime almost immediately, and inside the secondary use regime well within its service life. Institutions assessing infrastructure against today’s obligations alone are assessing against the wrong set.
The transfer question has been reopened twice already
For any architecture that moves patient data outside the jurisdiction where it was collected, the governing question is whether a lawful transfer mechanism exists. That question has an unusual history.
The Safe Harbor arrangement was invalidated by the Court of Justice of the European Union in 2015. Its replacement, Privacy Shield, was invalidated by the same court in 2020. The current instrument is the EU-US Data Privacy Framework, adopted by adequacy decision on 10 July 2023. It was challenged, and the General Court dismissed that challenge on 3 September 2025, upholding the Framework. The applicant appealed to the Court of Justice on 31 October 2025 in Case C-703/25 P, and that appeal is pending.
The Framework is valid law today. It remains in force unless the Commission repeals it or the Court annuls it, and nothing here should be read as advice that transfers under it are presently unlawful, because they are not. The point is narrower and more useful than that. Two of the last three instruments governing this question were struck down, the third is under appeal, and separate representations to the Commission during 2026 have questioned whether identified deficiencies can be remedied at all. An institution whose clinical architecture depends on the outcome is carrying a risk it did not choose and cannot price.
Contracts allocate liability. They do not move data.
The standard institutional response to this exposure is contractual. Standard contractual clauses, data processing agreements, business associate agreements, transfer impact assessments. Each is necessary, and none of them changes the underlying fact pattern.
A contract determines who is answerable when something goes wrong. It does not determine where the data physically sits, which jurisdictions can compel its production, or what happens to the arrangement if the adequacy decision underneath it is annulled. When Privacy Shield fell in 2020, the institutions affected did not have a contract problem that better drafting would have prevented. They had an architecture that assumed a legal instrument, and the instrument was withdrawn.
This is the distinction that matters during procurement. Contractual controls are remedies. Architectural choices are preventions, and only one of the two survives a change in the law.
What changes when the analysis moves to the data
Where computation happens inside the institution that already holds the record, several questions that dominate a cloud assessment do not arise at all. There is no onward transfer to assess, because nothing is transferred. There is no additional processor to enter on the register, because no third party processes the data. There is no cross-border question, because no border is crossed. There is no dependency on an adequacy decision, because no adequacy decision is engaged.
Institutions frequently expect an installed system to be reviewed more heavily than a hosted one, on the reasonable intuition that anything on the network is the institution’s problem. In practice the review is usually narrower, because the questions that consume the most time in a cloud assessment are the transfer, subprocessor and jurisdiction questions, and those questions have no subject matter when the data does not move.
This is not an argument that installed architecture is superior for every purpose. It is an argument that the two are assessed against different question sets, and that institutions which apply a cloud checklist to installed infrastructure will overstate the work involved, while institutions which apply an installed checklist to a cloud service will understate it.
Questions worth asking during procurement
The following separate architectures that hold data in place from those that move it and manage the consequences contractually.
- Where does computation occur, physically, and in which legal jurisdiction does that location sit? Not where the data is stored at rest, but where it is processed.
- Which entities other than the institution can technically access identifiable data, irrespective of whether they are contractually permitted to?
- If the applicable adequacy decision were annulled next year, what would have to change in the deployment, and how long would that take?
- Does the vendor require any standing access to the environment, and if access is granted for support, is it scoped, time-limited and logged in a record the institution controls?
- Who holds the encryption keys, and can the vendor decrypt without the institution’s participation?
- Under the EHDS secondary use regime arriving in 2029, which party is the data holder, and what obligations does the architecture place on the institution that a different architecture would not?
The decision has a longer life than the instrument
Clinical infrastructure is not replaced often. A system selected now will plausibly still be running in 2031, when the final tranche of EHDS sharing obligations reaches imaging, test results and genetic data. Over that period the transfer mechanism underpinning cross-border processing may be upheld, replaced, or struck down for a third time. None of those outcomes can be predicted, and none needs to be if the architecture does not depend on the answer.
The question for an institution is not which arrangement is compliant today. It is which arrangement remains compliant without renegotiation if the legal position changes, because the legal position has changed twice already within the service life of systems still in use.
Sources
- Regulation (EU) 2025/327 establishing the European Health Data Space. Entry into force 26 March 2025.
- European Commission implementing decision on the adequacy of the EU-US Data Privacy Framework, 10 July 2023.
- General Court of the European Union, Case T-553/23, judgment of 3 September 2025.
- Court of Justice of the European Union, Case C-703/25 P, appeal lodged 31 October 2025, pending.
- Court of Justice of the European Union, Case C-362/14 (2015) and Case C-311/18 (2020), invalidating Safe Harbor and Privacy Shield respectively.
Disclosure: this paper is published by Reltronic, Inc. It makes no claim about any Reltronic product and describes no proprietary method. It is not legal advice, and institutions should take their own counsel on the application of these instruments to their circumstances.

Leave a Reply