Protection of Personal Health Data: GDPR Compliance Guidelines for Pharmaceutical Companies
1. What is Health Data and Why is it Sensitive?
Health data refers to any information relating to an individual's physical or mental health. Examples include:
-
Disease diagnoses,
-
The medications used,
-
Blood tests or genetic information,
-
Medical device usage records.
Why is it Sensitive?
Health data directly relates to a person's private life. If it falls into the wrong hands, it can lead to discrimination or privacy violations. For this reason, both the Turkish Personal Data Protection Law (KVKK) and the EU GDPR classify health data as "sensitive personal data" and introduce stricter rules for its protection.
2. Where do pharmaceutical companies use this data?
Pharmaceutical companies process health data in the following areas:
-
Clinical trials: Monitoring the health status of participants,
-
Patient support programs: Services aimed at improving treatment adherence,
-
Marketing activities: Statistical data presented to physicians during product promotion,
-
Pharmacovigilance: Reporting and monitoring of adverse drug reactions.
3. Rules to be Followed Under the Personal Data Protection Law (KVKK)
The Personal Data Protection Law (KVKK) is the fundamental law in Türkiye that regulates the processing of personal data and aims to protect the privacy of individuals. It came into force on April 7, 2016, and its number is 6698.
➤ Explicit Consent and Exceptions
As a general rule, explicit consent is required to process health data.
However, consent may not be required in some cases. For example:
-
Data processing for the purpose of protecting public health (e.g., Ministry of Health audits),
-
Data processing under contractual obligations (e.g., clinical research contracts).
➤ Obligation to Provide Information
The relevant individuals should be informed in a clear and understandable manner:
-
What data was collected,
-
Why it was gathered,
-
Who it will be shared with,
-
How long should it be stored?.
➤ Data Security Measures
The company needs to take the following measures:
-
Technical measures (e.g., encryption, antivirus),
-
Administrative measures (e.g., confidentiality protocols, staff training).
➤ Mandatory Registration with VERBIS
Companies with more than 50 employees or an annual balance sheet exceeding 25 million TL are required to register with VERBIS (Data Controllers Registry).
4. Rules to be Followed Under GDPR
GDPR (General Data Protection Regulation) is the European Union's General Data Protection Regulation and entered into force on May 25, 2018. This regulation sets out the rules for the processing and protection of personal data and aims to give individuals living within the European Economic Area (EEA) more control over their personal data.
➤ Principle of Legality
Data must be collected for specific, explicit, and legitimate purposes. For example, collecting doctor information for marketing purposes may be legitimate; however, collecting data without patient consent is a GDPR violation.
➤ Distinction between Data Controller and Data Processor
-
Data Controller: The person/organization that determines the purposes and means of data processing (e.g., a pharmaceutical company).
-
Data Processor: A person/entity that processes data only as instructed (e.g., call center service provider).
➤ Data Protection Officer (DPO)
If a company processes large amounts of sensitive data, it must appoint a Data Protection Officer (DPO). The DPO oversees the company's compliance with GDPR.
➤ Data Breach Report
In the event of a personal data breach (e.g., a database attack), notification to the relevant European authority must be made within 72 hours.
5. Can health data be transferred abroad?
According to the Personal Data Protection Law (KVKK):
Data transfer from Türkiye to abroad is possible under the following conditions:
-
If the person concerned has given explicit consent,
-
If the data is transferred to a country declared a safe country by the Personal Data Protection Authority,
-
If there is a data transfer agreement approved by the institution.
According to GDPR:
For data transfers outside the EU:
-
A safe country designation issued by the European Commission, or
-
Appropriate safeguards, such as Standard Contract Clauses (SCCs), are required.
6. Compliance Checklist
-
Prepare a data inventory (What data is being collected? For what purpose?).
-
Create information and consent forms.
-
Implement security measures (encryption, access controls, training).
-
If it falls under GDPR, appoint a DPO.
-
Enter into data processing agreements with third parties.
-
Create an emergency plan for a potential data breach.
Why is an Adaptation Strategy Important?
KVKK and GDPR are not only legal obligations; they are also critically important for patient safety and corporate reputation.
In case of non-compliance:
-
Under the Personal Data Protection Law (KVKK), administrative fines of up to 2 million TL can be imposed
-
Under GDPR, fines of up to 4% of annual global turnover can be imposed.
The secure processing of health data is also an indicator of the ethical stance of pharmaceutical companies.
Conclusion
In the pharmaceutical industry, the accurate and secure processing of personal health data is not only a legal obligation but also fundamental to corporate reputation.
Complying with the Turkish Personal Data Protection Law (KVKK) and GDPR helps avoid penalties and builds trust among patients and healthcare professionals.