Authors: Oana Stefan
The question of what constitutes health data is not a new one; it has existed since the concept was first introduced into data protection legislation.
For data controllers, identifying the data they collect or intend to collect as health data is not always straightforward, as health data does not exclusively refer to a diagnosis, a medical certificate, or the results of medical tests.
An employer may know that certain employees are unable to perform specific tasks or have certain limitations, and an insurer may be aware of certain treatments administered to the insured without having seen the medical diagnosis that led to the prescription of the treatment. In such situations, the question naturally arises: when does this information become “health data” within the meaning of Article 9 of the General Data Protection Regulation (GDPR)?
The answer to this question and, consequently, the ability to distinguish between ordinary personal data and sensitive data is particularly important, as such a classification triggers the applicability of the special, restrictive regime provided by the GDPR for special categories of personal data.
A recent judgment of the Court of Justice of the European Union (CJEU) provides relevant guidance in this respect. In Case C-474/24, the CJEU examined the publication by Austrian anti-doping bodies of information concerning athletes sanctioned for breaches of anti-doping rules. The information published included the names of the sanctioned athletes, the infringement committed, the sanction imposed and the duration of the ban from participating in competitions. The athletes involved in the main proceedings argued, among other things, that such information could constitute data concerning health within the meaning of Article 9 GDPR.
When can inferred information become health data?
The CJEU begins by reaffirming the broad interpretation of the concept of “data concerning health”. For certain information to fall within the scope of Article 9 GDPR, it is not strictly necessary for it to explicitly indicate a diagnosis or clearly describe a person’s health status or medical condition. In essence, it is sufficient for the information to be capable of revealing data concerning the physical or mental health of the data subject when subjected to an intellectual process of correlation or deduction.
Applying this principle, the CJEU draws an important distinction in the present case. The mere fact that a person has breached an anti-doping rule and has been sanctioned does not, in itself, constitute information concerning that person’s health.
The situation may be different, however, where the information processed also includes the name or category of the prohibited substance or method. If that information, when considered together with other elements, makes it possible to infer information concerning the data subject’s past, present or future health status, the data may fall within the scope of Article 9 GDPR.
It is important to note that, even when all this information is put together, the information processed is not automatically classified as health data. What we are dealing with is, therefore, inferred health data, which presupposes both the existence of additional information about the data subject and a process of correlation and/or deduction.
What does this mean in practice?
In practice, the value of the NADA judgment lies primarily in showing how much the classification of certain information may depend on the context in which it is processed and on the other data available about the data subject.
The judgment is particularly important because it draws attention to a grey area. Not every piece of information that has a connection with health automatically becomes health data. At the same time, the fact that information is not obviously medical in nature does not automatically rule out such a classification.
The judgment is, of course, relevant beyond the sporting context. Similar situations may arise in the business environment, for example in connection with information about occupational restrictions, adjustments to working schedules, the use of certain medication, or alcohol and drug testing in the workplace.
For companies, the NADA case therefore provides a useful framework for assessing situations in which the nature of the data being processed is not immediately apparent. While borderline cases will continue to require a case-by-case assessment, the judgment points to the relevant elements of that analysis: the information processed, the wider factual context, the additional data available about the individual and, ultimately, whether these elements, taken together, allow conclusions to be drawn about the person’s health.
The remaining practical challenge is therefore to draw the line between a mere possibility of association with health, such as in the case of a positive alcohol/ drug test result, and information that, through context and correlation with other available data, actually reveals information concerning a person’s health.



