Health data and data protection

Health data is the most heavily regulated category of personal data on both sides of the Atlantic, and for a US company with European operations the GDPR and the Swiss DSG are only the start. The European Health Data Space compels secondary-use access from 2029, the EU Data Act overrides much of what a standard cloud contract says about access and switching, transatlantic transfers rest on a Data Privacy Framework whose premises a US Supreme Court ruling has unsettled, and the Digital Omnibus would rewrite the GDPR's own definitions without yet being law. The analyses below cover trial data under two regimes, cloud contracts across jurisdictions, Swiss professional secrecy against US e-discovery, and the reforms that decide what a compliance program can plan for and what it cannot.

9 insights ยท latest July 2026

Insights on Health data and data protection

No. 03 Data Privacy

Data Privacy in Clinical Trials: GDPR Meets DSG

Multi-jurisdictional clinical research faces an increasingly complex web of data protection requirements. How do GDPR and the Swiss DSG intersect, and where do they diverge?

No. 49 Emerging Issue

One Consent Form, Two Regimes: What HFG Trial Consent Does Not Settle for the Swiss DSG

One HFG informed-consent form does not discharge the DSG duties attaching to the same sensitive health data. For US sponsors, the unresolved legal-basis question surfaces in protocol design and site contracts, not during the trial.

No. 54 Emerging Issue

The European Health Data Space: A Three-Year Runway for US Biotech Secondary-Use Access

The European Health Data Space compels holders to make health data available through public access bodies, from 2029 for general records and 2031 for genomic and clinical-trial data; a US biotech's EU subsidiary may itself be a holder.

No. 64 Cross-Border

Transatlantic Data Transfers in 2026: The DPF After the Supreme Court Challenge

The EU-US Data Privacy Framework rests on the independence of three American institutions, and the 2026 Supreme Court ruling on at-will removal of Federal Trade Commission members unsettles that premise for companies that retired their standard contractual clauses.

No. 66 Emerging Issue

GDPR, Cookies and the Digital Omnibus: What US SaaS Can Re-Plan, and What It Cannot

The Digital Omnibus would make the GDPR's personal-data definition relative to the holder, put AI training on an express legitimate-interest footing, and route cookie consent into a new Art. 88a GDPR. None of it is yet law.

No. 63 Strategic Risk

The EU Digital Omnibus at Two Speeds: An Adopted AI Act Deferral and a Contested GDPR Reset

The EU Digital Omnibus moves at two speeds: an adopted AI Act track defers high-risk deadlines to December 2027 and August 2028, while the GDPR, ePrivacy and Data Act rewrite remains an unagreed proposal.

No. 17 Cross-Border

Cloud Service Contracts: Jurisdictional Complexity

When your data resides in multiple jurisdictions simultaneously, which law governs? Cloud service agreements often create legal uncertainties that surface only during disputes.

No. 40 Cross-Border

The EU Data Act in Force: Where US Cloud and IoT Contract Terms Stop Binding

The EU Data Act has applied since 12 September 2025 to any provider serving Union customers, wherever established, and its switching, access and unfair-terms rules override much of what standard US cloud and connected-product contracts still say.

No. 09 Cross-Border

Swiss Professional Secrecy and International E-Discovery

Swiss professional secrecy meets US e-discovery: criminal exposure for compliance, sanctions for refusal. Strategies for life sciences companies.

Good questions deserve specific answers.

Get in Touch