GDPR and the DPC, for Irish businesses

GDPR

Health research in Ireland: explicit consent, and the way around it

The regulations are written around the activity rather than the institution, so a commercial medtech is inside them on the same terms as a hospital.

By Oscar CobbeCurrent as at 8 minute read6 sources

What the instrument is

The Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018, S.I. No. 314 of 2018, made by the Minister for Health and in operation since 8 August 2018.

They sit under section 36(2) of the Data Protection Act 2018, which is the provision letting a Minister prescribe suitable and specific measures for processing that would otherwise be restricted. So this is Irish law layered on top of the GDPR rather than a transposition of it, and it is stricter than the GDPR alone.

They were amended by S.I. No. 18 of 2021. If you have seen this cited as S.I. No. 188 of 2021, that is a different instrument about anti-money-laundering commencement and it has nothing to do with health research.

Why it reaches private companies

Regulation 3(1) binds a controller who is processing or further processing personal data for the purposes of health research. It does not say a university, a hospital, a research institution or a public body.

The definition of health research is equally activity-based, and it expressly includes research specifically concerned with innovative strategies, devices, products or services for the diagnosis, treatment or prevention of human disease or injury.

So a commercial diagnostics company validating an algorithm on patient records, a medtech running a study on device data, or a digital health company analysing outcomes is inside these regulations. Being a private company is not a distinguishing feature and never was.

The suite of measures, not just consent

Regulation 3(1) sets out a list of suitable and specific measures that all have to be in place before the processing starts, and the explicit consent requirement in Regulation 3(1)(e) is only one of them.

The others include ethical approval from a research ethics committee, a data protection impact assessment where the processing is likely to result in a high risk, controls on access to the data, logging, and training for the people carrying out the research.

The DPIA requirement is worth pausing on because it connects to the ordinary regime. Health data is special category data, and processing it at any scale sits close to Article 35(3)(b) as well as to the Data Protection Commission's own list of processing requiring an assessment. In practice, if you are in these regulations, the assessment question is already answered.

What the consent requirement asks for

The 2021 amendment rewrote Regulation 3(1)(e). Explicit consent now has to be recorded and retained by the controller, with a copy provided to the data subject, in accordance with international best practice on the ethical conduct of health research.

Two operational consequences follow from that wording, and both are things engineering teams get wrong. The consent has to be an artefact you hold, so a tick recorded as a boolean in a database is not sufficient evidence of what was consented to. And the participant gets a copy, which means the consent flow has to produce a document rather than a database row.

The amendment also inserted Regulations 3A and 3B, which deal with deferring consent where a person is not capable of giving it.

The pre-screening carve-out, added in 2021

Establishing whether an individual is suitable or eligible for inclusion in health research does not require explicit consent or ethical approval, where it is carried out by a health practitioner employed by the controller, by a relevant employee, or by an authorised person acting under a health practitioner's direction. This is the amendment that made recruitment into studies workable, and it is narrower than it sounds: it is about eligibility screening and it does not extend to the research itself.

The consent declaration route

Regulation 5 provides the way out for research where consent is genuinely not obtainable. A controller can apply for a declaration that the explicit consent requirement does not apply, where the public interest in carrying out the research significantly outweighs the public interest in requiring the explicit consent of the data subject.

The body that decides is the Health Research Consent Declaration Committee, appointed by and reporting to the Minister for Health.

Two conditions come before the application rather than after it: the controller has to have carried out a data protection impact assessment, and has to have obtained ethical approval. So the declaration is not an alternative to the rest of Regulation 3, it is a route around one item on the list once the others are done.

That sequencing is the practical planning point. A company that discovers this regime late has to do the DPIA and get ethics approval before it can even ask about the consent problem.

Where this most often goes wrong commercially

Three patterns, and all three come from treating health data as ordinary customer data.

Using data collected for care, or for a product's normal operation, to validate or train something later. That is further processing for a new purpose, it is health research if it is aimed at diagnosis, treatment or prevention, and it is item 1 on the Irish DPIA list as well.

Assuming a research partner's ethics approval covers your processing. Regulation 3(1) binds the controller, and being the party holding the data usually makes you one.

Sending the dataset to an analytics supplier outside the EEA without the transfer question being asked separately. Ethics approval is not a Chapter V safeguard, and the transfer analysis is its own exercise.

What to do about it

Short list, in order.

  1. 1Decide honestly whether what you are doing is health research under the definition. Aimed at diagnosis, treatment or prevention of human disease or injury is the test, and product improvement framing does not change it.
  2. 2If it is, do the DPIA and get ethical approval before designing the consent flow, because both are conditions of everything else.
  3. 3Build a consent flow that produces a retained record and gives the participant a copy. Not a checkbox.
  4. 4If consent is genuinely unobtainable, work out whether the public interest test is arguable before building anything, and plan for the Committee's timetable.
  5. 5Treat the transfer, retention and processor questions as separate exercises. This regime adds requirements; it does not answer the ordinary ones.

Sources

  1. 1.S.I. No. 314 of 2018, Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018 · Irish Statute Book, Office of the Attorney General
  2. 2.S.I. No. 18 of 2021, the amending regulations · Irish Statute Book, Office of the Attorney General
  3. 3.Health Research Consent Declaration Committee · Health Research Consent Declaration Committee
  4. 4.Health Research Consent Declaration Committee, background and role · Health Research Board
  5. 5.Data Protection Act 2018, as revised · Law Reform Commission
  6. 6.Data protection impact assessments, and the Article 35(4) list · Data Protection Commission

Free, and the answers stay in your browser

Whether an assessment is mandatory before you start

These regulations require a DPIA where the risk is high, and health data raises the bar. The free check runs the Irish list and says whether one is mandatory on the ordinary regime as well.

Run the free check

The assessment, written from what the system does

We write the DPIA from the actual data flows rather than from a template, which matters more here than anywhere else: an ethics committee reading a generic assessment will send it back, and the delay costs more than the document did.

DPIA and AI risk assessment

Who wrote this

Oscar Cobbe · Founder, FourWinds Digital

Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.

More about how we work →

Read next

More on GDPR and the DPC, for Irish businesses

Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.