About this service
Health data — information on physical or mental health, tests, diagnoses, treatment history — is among the most intimate information about a person, and that is precisely why the law gives it a special regime. In Georgia the framework for health-data protection is defined by the law on personal data protection: this is special-category data, whose processing is subject to strict conditions. This service helps medical institutions, insurance and technology companies work with health data lawfully and safely — from interpretation to risk management.
What health data is and why it is special
Article 3 of the law defines the terms precisely: health-related data is information on the data subject's physical or mental health, as well as information on the provision of medical services to the subject, insofar as it gives information about health. Health data is included in the list of special categories of data — the category that touches the most sensitive spheres of a person and demands exceptional protection. This classification is practical: wherever the list applies, the general rules no longer suffice, and special bases and guarantees follow.
The legal basis — a special rule for the health sphere
Article 6 of the law sets a special regime for special-category data. As a general rule, processing of such data is permitted with the subject's written consent. For health, however, the law also gives a special basis: processing is necessary in the sphere of health care for the purposes of preventive, prophylactic, diagnostic, curative, rehabilitative and palliative care, services, the quality and safety of medical devices and products, public health and the management of the health-care system — in accordance with Georgian legislation or a contract concluded with a health-care professional, where the data are processed by a person bound by an obligation of professional secrecy. This formulation explains the entire architecture: consent is not always required for the treatment process, but the price of that is the processor's obligation of professional secrecy.
The subject's rights and their limitation
The law grants data subjects broad rights — information on processing, access, rectification, cessation of processing and others. In the health sphere, however, these rights carry defined limitations: under Article 21 of the law, the subject's rights may be restricted where this is directly provided by legislation, does not violate human fundamental rights, constitutes a necessary and proportionate measure, and the exercise of the right may threaten the interests of public health or other protected values. Restriction is thus an exception, not a rule — and its substantiation lies on the processor.
Security measures
Article 27 regulates the security obligation: the controller must take appropriate technical and organisational measures to ensure processing in conformity with the law and be able to demonstrate this. The law names concrete measures too: pseudonymisation, logging of access to data, and information-security mechanisms ensuring confidentiality, integrity and availability. For health data these measures are of particular importance: a leak of medical information becomes not merely an administrative but a reputational catastrophe. The effectiveness of the measures is assessed periodically — and this assessment too must be documented.
Practical context
Health data today is no longer only the internal business of medical institutions. Insurance companies assess risks, technology platforms manage records, employers arrange health programmes — and for each of these players the question is the same: on which basis, for which purpose and with which guarantees the processing occurs. That is why our approach begins not with a list of documents but with a map of data flows: where information comes from, where it is stored, into whose hands it passes and what happens after the purpose is achieved. On this map each processing receives its own legal qualification — and the organisation can answer any question not by conjecture but by a substantiated position.
How we can help
Our specialists determine which data in your systems falls into the health-related category and which regime applies to each processing; we build a map of bases — where written consent is needed and where the special basis applies; we re-verify the security measures and assess the lawfulness of restrictions on the subject's rights. For medical institutions, insurers and technology companies the result is the same: a complete picture of where your data is protected and where it needs correction. Contact us for a concrete assessment.
Remember the reputational dimension too: society forgives a technical failure more easily than carelessness with medical secrecy. A patient who entrusts a clinic with their history expects it to remain between them and the physician — and this expectation is protected not only by the norms of professional secrecy but by the general regime of special-category data. Investment in the right processing architecture therefore pays back not merely by avoiding fines — it builds the trust that is a medical organisation's principal asset. And one more thing: an audit of data flows is best conducted before an incident or an inspection — an organisation that knows its own map passes through both calmly, because it has a prepared answer to every question: basis, purpose, measures, responsible person.
