Specialized legal assistance for entrepreneurs, organizations, and directors.
View all areas of expertiseLegal assistance with conflicts, claims, negotiations, and proceedings.
View legal assistanceLegal assistance with outstanding invoices, disputed claims, and collection proceedings.
View collectionMeet MKB Juristen, our founders, and the way we organize legal assistance for entrepreneurs.
About SME LawyersHealthcare organizations process special categories of personal data and, in addition to the GDPR, must comply with healthcare-specific laws such as the WGBO and the Wabvpz. Our lawyers and in-house counsel help you demonstrably get this in order.
The General Data Protection Regulation (GDPR) stipulates that healthcare institutions must comply with additional rules when processing personal data. In addition, specific legislation and regulations for the healthcare sector include extra rules regarding privacy. Examples of such laws include the Medical Treatment Agreement Act, the Act on Supplementary Provisions on the Processing of Personal Data in Healthcare, or the Act on General Provisions regarding the Citizen Service Number.
The processing of personal data within a healthcare institution or organization must be in order and comply with laws and regulations. Within our Privacy and Data Protection practice group, we can provide legal advice in this regard.
Questions regarding care and privacy? Please contact us.
This page is part of our Privacy and Data Protection. Within that main area of expertise, the healthcare sector requires a specific approach. In addition to the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG), a layer of sectoral legislation applies in the healthcare sector that is stricter than the general rules. Under Article 9 of the GDPR, health data are considered special categories of personal data: processing such data is prohibited in principle, unless a specific exception applies. Therefore, for every processing activity, a healthcare organization must be able to identify both a legal basis (Article 6 of the GDPR) and an exception to the processing prohibition (Article 9 of the GDPR).
Our mixed teams of lawyers and in-house counsel are familiar with both privacy law and health law. Whether you are a university hospital, a mental healthcare institution, a healthcare group, or an independent GP or physiotherapist: from international corporations to the baker on the corner, we translate complex regulations into workable policy.
Medical professional secrecy is regulated in the Medical Treatment Agreement Act (WGBO), which is included in Book 7, Title 7, Section 5 of the Dutch Civil Code (Articles 7:446 to 7:468 BW). The healthcare provider's duty of confidentiality follows from Article 7:457 BW: without the patient's consent, no information or access to the file may be provided to anyone other than the patient. In addition, the WGBO regulates, among other things, the duty to maintain a file (Article 7:454 BW), the patient's right of access (Article 7:456 BW), and the right to destruction of data (Article 7:455 BW).
Medical professional secrecy exists alongside the GDPR and is therefore not amended. In cases of overlap, professional secrecy takes precedence as a lex specialis; the GDPR further specifies the rules regarding lawful processing. We advise healthcare professionals and healthcare organizations on the scope of professional secrecy, on when breaching is permitted (consent, statutory obligation, or conflict of duties), and on the position of locum tenens and directly involved healthcare professionals.
The exchange of patient data is a common bottleneck. The general rule is that healthcare providers may share data among themselves insofar as this is necessary for the execution of their own treatment agreement with the patient; professional secrecy does not apply to persons directly involved in the treatment (Article 7:457 paragraph 2 of the Dutch Civil Code). If information is shared with parties outside the care provider, explicit consent from the patient is required in principle, unless there is a statutory obligation (for example, reporting an infectious disease). Furthermore, for electronic exchange, the Act on Supplementary Provisions on the Processing of Personal Data in Healthcare (Wabvpz) sets additional requirements, including specified consent for making data available via an electronic exchange system and the use of the citizen service number (BSN) pursuant to the Act on Supplementary Provisions on the Processing of Personal Data in Healthcare and the Act on General Provisions on the Citizen Service Number. We assess partnerships, integrated care systems, and registries against these rules and record agreements.
The GDPR imposes concrete obligations on healthcare organizations, which we implement in practice:
With a privacy audit , we map out where your organization stands.
The Dutch Data Protection Authority (AP) monitors compliance with the GDPR and the UAVG; the AP can impose substantial fines for violations. In the healthcare sector, the Health and Youth Care Inspectorate (IGJ) additionally supervises quality and safety, including information security. We assist healthcare organizations in supervisory investigations, enforcement, and data breaches that may need to be reported, and act as counsel in objection and appeal proceedings where necessary.
The digitalization of healthcare brings new obligations. The Healthcare Electronic Data Exchange Act (Wegiz) mandates a phased implementation of standardized, secure electronic exchange between healthcare providers. In addition, AI applications are being deployed increasingly often for diagnosis and treatment support; in this regard, alongside the GDPR, the European AI Regulation and, for medical devices, the Medical Device Regulation (MDR) are relevant. We monitor these developments and advise on a future-proof setup.
Medical professional secrecy under the WGBO (Article 7:457 of the Dutch Civil Code) continues to apply alongside the GDPR and is not amended by the GDPR. In practice, both regimes complement each other; in the event of overlap, professional secrecy takes precedence as a special provision.
A Data Protection Officer is mandatory when special categories of personal data are processed on a large scale. As a rule, this applies to hospitals, pharmacies, healthcare groups, and GP out-of-hours services, among others.
With healthcare providers directly involved in the treatment, this is permitted to the extent necessary for your own treatment agreement. For parts beyond that, explicit consent is in principle required, or a legal basis.
Our lawyers and in-house counsel help healthcare organizations of all sizes to demonstrably get their data processing in order. Privacy and data protection is our home base; for the healthcare sector, we provide tailored advice. Please feel free to contact us.
In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.
We combine privacy law and health law in practical advice.
Careless handling of health data directly affects patient privacy and trust in your organization. The legal and business risks are substantial.
We begin with a pragmatic analysis of your processing activities and assess them against both the GDPR and healthcare-specific laws. We then translate this into workable policies, binding agreements, and clear protocols tailored to the scale of your organization. Our mixed teams of lawyers and in-house counsel liaise with healthcare and employment law where necessary.
From inventory to a demonstrably compliant organization.
We discuss your organization, your processing activities, and your question, and review existing agreements and protocols.
We assess your situation against the GDPR, the UAVG, and healthcare laws such as the WGBO and the Wabvpz, and map out the legal bases and risks.
We draft policies, data processing agreements, and protocols, and guide the appointment of the DPO and DPIA.
We assist you with data breaches and supervision by the Dutch Data Protection Authority or the IGJ.
We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.
Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.
Answers to questions that healthcare organizations often ask us.
Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.
Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.
Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.
Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.
Our lawyers and in-house counsel are happy to assist you. Please feel free to contact us.
Also view the other sections within this area of law.
Leave your details. We will contact you to briefly discuss your situation.
Want to know more about our services?
Then contact our specialists.