GDPR
Health research in Ireland: explicit consent, and the way around it
The regulations are written around the activity rather than the institution, so a commercial medtech is inside them on the same terms as a hospital.
By Oscar CobbeCurrent as at 8 minute read6 sources
What the instrument is
The Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018, S.I. No. 314 of 2018, made by the Minister for Health and in operation since 8 August 2018.
They sit under section 36(2) of the Data Protection Act 2018, which is the provision letting a Minister prescribe suitable and specific measures for processing that would otherwise be restricted. So this is Irish law layered on top of the GDPR rather than a transposition of it, and it is stricter than the GDPR alone.
They were amended by S.I. No. 18 of 2021. If you have seen this cited as S.I. No. 188 of 2021, that is a different instrument about anti-money-laundering commencement and it has nothing to do with health research.
Why it reaches private companies
Regulation 3(1) binds a controller who is processing or further processing personal data for the purposes of health research. It does not say a university, a hospital, a research institution or a public body.
The definition of health research is equally activity-based, and it expressly includes research specifically concerned with innovative strategies, devices, products or services for the diagnosis, treatment or prevention of human disease or injury.
So a commercial diagnostics company validating an algorithm on patient records, a medtech running a study on device data, or a digital health company analysing outcomes is inside these regulations. Being a private company is not a distinguishing feature and never was.
The suite of measures, not just consent
Regulation 3(1) sets out a list of suitable and specific measures that all have to be in place before the processing starts, and the explicit consent requirement in Regulation 3(1)(e) is only one of them.
The others include ethical approval from a research ethics committee, a data protection impact assessment where the processing is likely to result in a high risk, controls on access to the data, logging, and training for the people carrying out the research.
The DPIA requirement is worth pausing on because it connects to the ordinary regime. Health data is special category data, and processing it at any scale sits close to Article 35(3)(b) as well as to the Data Protection Commission's own list of processing requiring an assessment. In practice, if you are in these regulations, the assessment question is already answered.
What the consent requirement asks for
The 2021 amendment rewrote Regulation 3(1)(e). Explicit consent now has to be recorded and retained by the controller, with a copy provided to the data subject, in accordance with international best practice on the ethical conduct of health research.
Two operational consequences follow from that wording, and both are things engineering teams get wrong. The consent has to be an artefact you hold, so a tick recorded as a boolean in a database is not sufficient evidence of what was consented to. And the participant gets a copy, which means the consent flow has to produce a document rather than a database row.
The amendment also inserted Regulations 3A and 3B, which deal with deferring consent where a person is not capable of giving it.
The pre-screening carve-out, added in 2021
Establishing whether an individual is suitable or eligible for inclusion in health research does not require explicit consent or ethical approval, where it is carried out by a health practitioner employed by the controller, by a relevant employee, or by an authorised person acting under a health practitioner's direction. This is the amendment that made recruitment into studies workable, and it is narrower than it sounds: it is about eligibility screening and it does not extend to the research itself.
The consent declaration route
Regulation 5 provides the way out for research where consent is genuinely not obtainable. A controller can apply for a declaration that the explicit consent requirement does not apply, where the public interest in carrying out the research significantly outweighs the public interest in requiring the explicit consent of the data subject.
The body that decides is the Health Research Consent Declaration Committee, appointed by and reporting to the Minister for Health.
Two conditions come before the application rather than after it: the controller has to have carried out a data protection impact assessment, and has to have obtained ethical approval. So the declaration is not an alternative to the rest of Regulation 3, it is a route around one item on the list once the others are done.
That sequencing is the practical planning point. A company that discovers this regime late has to do the DPIA and get ethics approval before it can even ask about the consent problem.
Where this most often goes wrong commercially
Three patterns, and all three come from treating health data as ordinary customer data.
Using data collected for care, or for a product's normal operation, to validate or train something later. That is further processing for a new purpose, it is health research if it is aimed at diagnosis, treatment or prevention, and it is item 1 on the Irish DPIA list as well.
Assuming a research partner's ethics approval covers your processing. Regulation 3(1) binds the controller, and being the party holding the data usually makes you one.
Sending the dataset to an analytics supplier outside the EEA without the transfer question being asked separately. Ethics approval is not a Chapter V safeguard, and the transfer analysis is its own exercise.
What to do about it
Short list, in order.
- 1Decide honestly whether what you are doing is health research under the definition. Aimed at diagnosis, treatment or prevention of human disease or injury is the test, and product improvement framing does not change it.
- 2If it is, do the DPIA and get ethical approval before designing the consent flow, because both are conditions of everything else.
- 3Build a consent flow that produces a retained record and gives the participant a copy. Not a checkbox.
- 4If consent is genuinely unobtainable, work out whether the public interest test is arguable before building anything, and plan for the Committee's timetable.
- 5Treat the transfer, retention and processor questions as separate exercises. This regime adds requirements; it does not answer the ordinary ones.
Sources
- 1.S.I. No. 314 of 2018, Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018 · Irish Statute Book, Office of the Attorney General
- 2.S.I. No. 18 of 2021, the amending regulations · Irish Statute Book, Office of the Attorney General
- 3.Health Research Consent Declaration Committee · Health Research Consent Declaration Committee
- 4.Health Research Consent Declaration Committee, background and role · Health Research Board
- 5.Data Protection Act 2018, as revised · Law Reform Commission
- 6.Data protection impact assessments, and the Article 35(4) list · Data Protection Commission
Free, and the answers stay in your browser
Whether an assessment is mandatory before you start
These regulations require a DPIA where the risk is high, and health data raises the bar. The free check runs the Irish list and says whether one is mandatory on the ordinary regime as well.
Run the free checkThe assessment, written from what the system does
We write the DPIA from the actual data flows rather than from a template, which matters more here than anywhere else: an ethics committee reading a generic assessment will send it back, and the delay costs more than the document did.
DPIA and AI risk assessmentWho wrote this
Oscar Cobbe · Founder, FourWinds Digital
Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.
More about how we work →Read next
GDPR
Do you need a DPIA? Ireland has its own list, and it is specific
Most guidance answers this with European criteria. Ireland has a published list of its own, and it is the one that decides the question here.
GDPR
Sending personal data to the US from Ireland, in 2026
Yes, and with conditions. The Framework holds, the checks are specific, and the part people skip is whether the particular company is actually on the list for the particular data.
GDPR
You have had a data breach. What the first 72 hours require
The 72 hours runs from when you became aware, not from when you finished investigating. That is the sentence most people get wrong on the day.
Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.