Connected medical devices and GDPR: where the health data goes
Connected medical devices: two regulators, one product
Your notified body and your data protection officer are asking different questions about the same device. Here is where health data is obtained, held and transferred, and what to do about it.
In brief
• A connected medical device faces MDR or IVDR and GDPR at the same time.
• Not every connected product is a medical device. Every one of them handles health data.
• Three questions decide most of the risk: where the data is obtained, where it is held, and where it goes.
• A DPIA is required, not optional. A CE or UKCA mark does not cover any of this.
• Companies outside the UK need a UK GDPR representative, just as they need a UK Responsible Person.
More of the devices crossing my desk are connected. The physical device is only half the product. The other half is an app, a cloud platform, a clinician dashboard, or all three. That second half is where most of the regulatory risk now sits, and it is the half manufacturers are least prepared for.
1. The device is only half the product
Examples of connected products across the market:
• Smartwatch ECG and irregular heart rhythm alerts
• Continuous glucose monitors and insulin pumps sending readings to a phone
• Home blood pressure cuffs, scales and pulse oximeters that sync to a cloud dashboard
• Seizure-detection wristbands that alert a carer
• Overnight oxygen and sleep monitors for suspected sleep apnoea
• Fall-detection pendants for older people
• Self-test kits for pregnancy, fertility or infection, with an app that reads the result
• Pacemakers and hearing aids with a phone link
• Remote patient monitoring platforms run by hospitals and GP practices
• AI software reading scans, ECGs or skin images
• Symptom-checker, mood-tracking and cycle-tracking apps
• Infusion pumps and patient monitors on a hospital network
Not all of these are medical devices. Whether they are depends on what the manufacturer claims. All of them handle health data, and GDPR does not care what the label says.
2. Two regimes, one product
The device question turns on intended purpose. If the manufacturer intends the product for diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease, it is a medical device under EU MDR, EU IVDR or UK MDR 2002. A fall alarm sold as a personal safety product is not a device. The same pendant sold as detecting a medical event is. A cycle-tracking app for general wellness is not a device. One intended for contraception is. MDCG 2019-11 rev.1, published in June 2025, is the guidance for software.
The data question does not wait for that decision. Data about a person’s physical or mental health is special category data under Article 9 of both EU GDPR and UK GDPR. Processing it is prohibited unless one of the Article 9(2) conditions applies, on top of an Article 6 lawful basis. A wellness app that avoids being a medical device is still processing Article 9 data.
Most companies have thought hard about one of these questions. Few have thought about both.
3. Where is the data obtained?
Manufacturers usually list the sensor. They less often list the rest:
• The phone’s own sensors: location, motion, microphone
• The hospital or practice system the device plugs into
• What the user types in: symptoms, medication, notes
• Third-party software development kits bundled into the app for analytics, crash reporting or advertising, which collect data the manufacturer has never mapped
A data map that stops at the sensor is incomplete. The privacy notice, the DPIA and the technical file all depend on knowing every source.
4. Where is it held?
• On the device
• On the phone
• In the manufacturer’s cloud
• With sub-processors used for hosting, analytics and customer support
• In a clinician or carer portal
It is common to find data in more places than the privacy notice says. Each location needs a named controller or processor, an Article 28 contract where a processor is involved, and appropriate security under Article 32.
5. Where is it transferred?
• From the EU or UK to servers elsewhere, usually the United States
• To engineers for troubleshooting
• To third parties for product improvement or research
• To a hospital, an employer or an insurer, depending on who is paying for the device
• Into post-market surveillance records that the regulator expects the manufacturer to keep
Where data leaves the EU or UK, a transfer mechanism is required. For the United States, the EU-US Data Privacy Framework remains in force following the EU General Court’s judgment of September 2025, and the UK Extension (the UK-US data bridge) has applied since 12 October 2023. Both depend on the US recipient being certified. Where it is not, standard contractual clauses (EU) or the International Data Transfer Agreement (UK) are needed, with a transfer risk assessment.
Health data is already treated as sensitive information under the Data Privacy Framework. Genetic data and biometric data used to identify a person are not, and the UK exporter must flag those to the US recipient separately. Wearables that authenticate the wearer by heartbeat, gait or fingerprint fall into that gap.
A CE mark or UKCA mark provides none of this.
6. The DPIA is not optional
The ICO’s published list of processing likely to result in high risk names smart technologies including wearables under innovative technology, and states that a DPIA is required where this is combined with any other criterion from the European guidelines. Special category data is one of those criteria. The list separately names hardware and software offering fitness, lifestyle or health monitoring under tracking. A connected health device meets the test on both counts. In the EU, the WP248 guidelines reach the same result.
7. Where MDR and GDPR pull in opposite directions
MDR Article 83 requires manufacturers to actively and systematically gather, record and analyse data on the quality, performance and safety of a device throughout its lifetime. GDPR Article 5 requires data to be limited to what is necessary and kept no longer than needed.
The retention rules make the tension concrete. Under MDR Article 10(8) and IVDR Article 10(7), technical documentation, the declaration of conformity and certificates must be kept for at least ten years after the last device is placed on the market, fifteen for implantables. Under UK MDR 2002 the period is at least five years after the last product is manufactured, fifteen for implantables.
None of this justifies keeping identifiable patient data for the same period. Post-market data should be pseudonymised or anonymised at the earliest point the surveillance purpose allows, and the retention schedule should treat the technical file and the patient dataset as two different things.
8. Companies outside the UK need a UK representative
Under UK GDPR Article 27, a controller or processor not established in the UK, but offering goods or services to people in the UK or monitoring their behaviour, must appoint a representative established in the UK. The exemption for occasional, low-risk processing does not extend to large-scale processing of special category data, so connected health device companies are in scope.
The representative must be designated in writing, named in the privacy notice, addressable by the ICO and by data subjects, and must hold the Article 30 record of processing on the controller’s behalf. This mirrors the UK Responsible Person obligation under UK MDR 2002 that non-UK manufacturers already meet, and the two roles are often best held by the same firm.
The Northern Ireland position needs stating precisely. Northern Ireland is inside the UK for data protection purposes: UK GDPR applies there in full, and a Northern Ireland company can act as UK GDPR representative. Northern Ireland is inside the EU goods regime under the Windsor Framework, which is why a Northern Ireland company can act as EU Authorised Representative under MDR and IVDR. But the Windsor Framework does not extend to data protection law. EU GDPR does not apply in Northern Ireland, and an EU GDPR Article 27 representative must be established in an EU member state.
A Northern Ireland entity can be an EU AR for the device and a UK representative for the data, but not an EU representative for the data.
9. What to do
1. Record the intended purpose decision and the reasoning, whether the product is a medical device or not
2. Map every data source, including phone sensors and third-party SDKs
3. Name the controller and processors for each location the data is held, and put Article 28 contracts in place
4. Identify the Article 6 lawful basis and the Article 9 condition for each purpose
5. Complete the DPIA before launch, not after
6. Confirm the transfer mechanism for every cross-border flow and check the certification status of US recipients
7. Split the retention schedule: technical file on one line, identifiable patient data on another
8. If the company is outside the UK, appoint a UK GDPR representative and name them in the privacy notice
9. Get the notified body questions and the data protection questions answered together. They are about the same product.
Talk to us
If you make, import or represent a connected device, the device questions and the data questions are best answered together. We act as EU Authorised Representative and UK Responsible Person for medical device and IVD manufacturers, and can act as UK GDPR representative alongside those roles.
Send us a short description of your product and where it is sold. We will tell you which obligations apply and what is missing. No charge for the first conversation.
Email: info@euukrep.com
Web: www.bspartnership.co.uk
Jonathan Phillips, Managing Director, EU-UK Authorised Representative Ltd