What Is Secondary Use of Health Data?


Secondary use of health data means using health information for a purpose other than the one for which it was originally collected. Data recorded to deliver care to an individual patient — the primary use — is reused for research, public-health surveillance, health-system planning, regulatory decision-making, or the development and validation of medical AI. It is the concept that anchors the European Health Data Space (EHDS) and most national health-data strategies, and the central policy challenge it raises is how to enable that reuse at scale without eroding the privacy and trust on which health systems depend.
Why this matters now
Secondary use has moved from an academic term to a legislative one. The EHDS — Regulation (EU) 2025/327, which entered into force in March 2025 — devotes an entire chapter to secondary use of electronic health data, obliging data holders across the European Union to make defined categories of health data available for approved purposes, and requiring under Article 50 that access happens only within secure processing environments from which record-level data cannot be extracted. Member states must establish health data access bodies to receive applications, issue permits, and supervise that access. Finland anticipated this model years earlier: its Act on the Secondary Use of Health and Social Data (552/2019) created Findata, a single national permit authority, and France’s Health Data Hub plays a comparable role. Outside Europe, national genomics and population-health programmes — from the UK’s Genomics England to Singapore’s health-data initiatives — face the same design question in different regulatory dress.
The urgency is sharpened by what happens when secondary use is governed by policy alone. The May 2026 UK Biobank incident showed approved researchers exporting data through a centralised platform’s normal, permitted workflow — no rule was broken, yet the data left. For policy makers the lesson is that secondary use frameworks are only as strong as the architecture that enforces them.
Primary versus secondary use: the distinction that drives everything
The distinction matters because the legal basis, the consent model, and the risk profile all change when the purpose changes. A clinician reading a record to treat the patient in front of them operates under a care relationship. A researcher analysing a million such records operates under a different basis entirely — in the EU, typically the research provisions of the General Data Protection Regulation (GDPR), Articles 9(2)(j) and 89, which permit processing for scientific research subject to safeguards such as pseudonymisation and data minimisation; under the EHDS, a permit from a health data access body. The table below summarises the contrast.
| Dimension | Primary use | Secondary use |
|---|---|---|
| Purpose | Direct care of the individual patient | Research, planning, surveillance, regulation, AI development |
| Who accesses | The care team | Approved researchers, public bodies, industry under permit |
| Typical legal basis (EU) | Provision of care (GDPR Art. 9(2)(h)) | Research and public-interest bases (GDPR Art. 9(2)(i)–(j), Art. 89); EHDS permit |
| Data form | Identifiable — identity is essential to care | Pseudonymised or anonymised wherever possible |
| Scale | One patient at a time | Whole cohorts and populations |
| Governance instrument | Clinical confidentiality and professional duty | Access bodies, permits, secure processing environments, output control |
| Principal risk | Wrongful access to one record | Bulk egress, re-identification, loss of public trust |
How secondary use is governed in practice
The permit layer: who may use what, for which purpose
Mature secondary-use regimes separate the decision to allow access from the mechanics of providing it. An access body — Findata in Finland, the health data access bodies the EHDS mandates in every member state — assesses each application against permitted purposes. The EHDS enumerates these purposes explicitly (public health, policy making, scientific research, innovation, personalised medicine, AI training among them) and equally explicitly prohibits others, including advertising, insurance premium-setting, and any use adverse to the data subject. This purpose-limitation architecture echoes the Five Safes framework developed at the UK Office for National Statistics — safe projects and safe people are assessed before any data is touched; our explainer on the Five Safes framework unpacks each dimension.
The environment layer: where the analysis happens
The second layer is the Trusted Research Environment (TRE) — called a secure processing environment in EHDS language — a controlled setting where approved users analyse data they cannot download. Article 50 of the EHDS makes this mandatory for secondary use: data are made available only in environments that log activity, control what enters and leaves, and prevent extraction of record-level data. The design principles, and how they map to HIPAA and GDPR obligations, are covered in our guide to TRE compliance across HIPAA, GDPR and EHDS.
The architecture layer: where the data physically stays
The third layer is the one most strategies underspecify. A centralised TRE copies data from custodians into one national repository — creating a high-value target and requiring every custodian to surrender control. A federated Trusted Research Environment inverts this: the data never leaves the source, and the analysis travels to each custodian’s environment, executing locally and returning only aggregate, disclosure-checked results through an automated airlock. Federation is what makes secondary use compatible with data sovereignty — custodians participate without ceding custody, which in practice is the difference between a national programme that data holders join willingly and one they resist. The pattern is described in depth in our overview of the federated Trusted Research Environment.
A framework for policy makers: five questions that define a secondary-use regime
Whether drafting national legislation or a hospital data strategy, the same five questions determine whether secondary use works. First, purposes: which uses are permitted, which are prohibited, and who adjudicates the boundary? Second, permits: is there a single access body with statutory deadlines, or does every custodian negotiate separately — the fragmentation the EHDS exists to end? Third, environments: is analysis confined to secure processing environments, and is record-level extraction technically impossible rather than merely forbidden? Fourth, data preparation: are datasets pseudonymised, harmonised to common standards, and quality-labelled so that a permit translates into usable data in weeks rather than years? Fifth, transparency: can citizens see what their data was used for, and do opt-out rights (which the EHDS grants for secondary use, subject to defined exceptions) actually function? A regime that answers all five converts public data into public benefit; a regime that answers only the first two produces permits for data nobody can practically use. The sequencing matters as much as the answers: environments and data preparation take years longer to stand up than legislation, so infrastructure procurement should begin alongside drafting, not after royal assent — the recurring failure of national strategies is a statute in force with no platform behind it.
Secondary use in production: national programmes
The model is operational, not theoretical. Genomics England makes the genomic and clinical data of national sequencing programmes available to approved researchers through Lifebit’s federated platform — researchers bring analyses to the data, and the data stays under Genomics England’s custody. Singapore’s Ministry of Health applies the same architectural stance to national health data. Finland’s Findata has issued research permits under Act 552/2019 since 2020, demonstrating that a single statutory access body with defined purposes and secure environments shortens access timelines while keeping refusal rates and public trust measurable. These programmes converge on the same lesson: secondary use scales when governance is centralised but data is not.
The economic case follows the same logic. Health systems already bear the full cost of collecting clinical data; secondary use is how that sunk cost yields additional return — faster post-market safety signals, better-targeted screening programmes, evidence for reimbursement decisions, and training data for clinical AI that would otherwise be built on unrepresentative convenience samples. The Organisation for Economic Co-operation and Development (OECD) has long argued in its health-data governance work that the opportunity cost of unused health data is a public-policy failure in its own right. What has changed is that the infrastructure question is now answerable: the combination of statutory access bodies and federated Trusted Research Environments means a country no longer has to choose between reuse and sovereignty.
Common pitfalls
Three failures recur. The first is conflating anonymisation with safety: rich health data is notoriously hard to anonymise irreversibly, which is why modern regimes rely on controlled environments and output checking rather than release of “anonymised” files. The second is building the permit layer without the platform layer: an access body that issues permits faster than custodians can provision data simply relocates the queue. The third is centralising by default: pooling national health data into one repository maximises both the breach surface and custodian resistance, and — as May 2026 demonstrated — policy controls on a centralised architecture cannot prevent permitted-workflow egress. Federation addresses all three because analysis happens where the data already is, under controls the custodian operates.
What to do next
If you are shaping a secondary-use programme, map your current state against the five questions above, then examine how the EHDS’s secure-processing-environment requirement will bind your infrastructure choices — even organisations outside the EU increasingly treat Article 50 as the reference standard. Study Findata’s statutory model for the permit layer and Genomics England’s federated model for the architecture layer, and read our primer on what a Trusted Research Environment is to ground the vocabulary your procurement will use.
Frequently asked questions
What is the difference between primary and secondary use of health data?
Primary use is the use of health data for the purpose it was collected for — delivering care to the individual patient. Secondary use is any reuse for another purpose, such as research, public-health surveillance, health-system planning, regulatory assessment, or training medical AI models.
What does the EHDS say about secondary use?
The European Health Data Space (Regulation (EU) 2025/327) obliges data holders to make defined categories of electronic health data available for permitted secondary purposes, establishes health data access bodies in every member state to issue permits, and requires under Article 50 that access occurs only within secure processing environments that prevent extraction of record-level data.
Is patient consent required for secondary use of health data?
Not always. Many regimes, including the EHDS and GDPR’s research provisions (Articles 9(2)(j) and 89), permit secondary use without individual consent where safeguards apply — pseudonymisation, purpose limitation, secure environments. The EHDS pairs this with an opt-out right for secondary use, subject to defined public-interest exceptions.
What purposes are prohibited for secondary use under the EHDS?
The EHDS explicitly prohibits uses including advertising and marketing, calculating insurance premiums, making decisions adverse to the individual, and any activity incompatible with the permit. Purpose limitation is enforced through the permit system and the secure processing environment.
What is a secure processing environment?
A secure processing environment — the EHDS term for a Trusted Research Environment — is a controlled computing setting where approved users analyse health data without being able to download record-level records. It logs activity, restricts what enters and leaves, and applies disclosure control to outputs.
How does federation improve secondary use?
Federation keeps data at its source: analysis code travels to each custodian, runs locally, and only aggregate results return. Because data never leaves the source, custodians retain sovereignty, no central honeypot is created, and bulk egress of the kind seen in the May 2026 UK Biobank incident becomes architecturally impossible rather than merely against the rules.
Which countries have secondary-use legislation in force?
Finland’s Act on the Secondary Use of Health and Social Data (552/2019) is the longest-standing dedicated statute, operationalised by the Findata permit authority. The EU-wide EHDS entered into force in 2025 with secondary-use obligations phasing in over the following years, and countries including France (Health Data Hub) and the UK (NHS secure data environment policy) run national frameworks with equivalent aims.
