GDPR compliance for a health app
General Data Protection Regulation (Regulation (EU) 2016/679). This page applies it to one kind of product (health app), so you get the obligations that are actually yours instead of a summary of the whole statute.
Does it apply to you?
Any organisation processing personal data of people in the EU, regardless of where it is established.
What a health app typically processes
- health and wellbeing data, which is sensitive in most jurisdictions
- explicit consent as the usual lawful basis
- data shared with practitioners or providers
Each of these is processing you have to disclose. Adding an SDK later adds to this list — which is why a policy written once goes stale.
Documents you need
The intersection of what GDPR requires and what a health app actually does:
- Privacy policy
- Data processing agreement (DPA)
Rights you must honour
GDPR gives people in the European Union the right to:
- Access a copy of their data
- Correct inaccurate data
- Have their data deleted
- Receive their data in a portable format
- Object to certain processing
- Restrict processing
- Withdraw consent at any time
- Ask for human review of an automated decision
Cookies and trackers
Nothing non-essential may load before the visitor agrees. Analytics and marketing scripts must be blocked until then — a banner that only informs is not enough.
See what your site is actually missing
Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.
No signup · result in seconds
Primary sources
- GDPR — General Data Protection Regulation (Regulation (EU) 2016/679) · official text
- Art. 6 — Lawful bases for processing
- Art. 13 — Information to provide when collecting data
- Art. 15–22 — Data subject rights
- Art. 28 — Processor contracts (DPA)
- Art. 44–49 — International transfers
GDPR for other kinds of product
Other frameworks for a health app
This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.