Compliance/GDPR Art. 22/Healthtech

GDPR Art. 22 compliance for Healthtech

Clinical-decision-support outputs that materially affect treatment access can engage Art. 22. Most CDS deployments include clinician review, which (if meaningful) addresses Art. 22 — but the bar for 'meaningful' is post-Schufa scrutinised.

Updated 15 May 2026·Adjacent application·Primary source ↗

What applies

Articles + provisions of Regulation (EU) 2016/679 — GDPR, Article 22 (automated decisions) most directly engaged by Healthtech deployments:

  • Art. 22
  • GDPR Art. 9 (health data)

What this looks like in Healthtech

Clinical-decision-support outputs that materially affect treatment access can engage Art. 22. Most CDS deployments include clinician review, which (if meaningful) addresses Art. 22 — but the bar for 'meaningful' is post-Schufa scrutinised.

Flagship exampleSymptom triage → emergency-dept routing: chain shows whether clinician sign-off actually happened on the routing decision or just on the chart.

Where Promethean's evidence layer fits

The substrate emits specific evidence kinds that map to GDPR Art. 22 obligations. Most directly relevant for Healthtech:

For the full sector view including LLM-feature catalogue, tier recommendation, and reviewer-gate examples, see the Healthtech sector page.

Adjacent cells

Other regulations for Healthtech