Healthcare AI 2025

POLAND Law and Practice Contributed by: Barbara Kiełtyka, Jakub Gładkowski and Małgorzata Kiełtyka, Kieltyka Gladkowski KG Legal

Under the GDPR, patient consent is required for sec - ondary processing of personal data if the purpose of processing has changed, with the exception of research purposes. While such a purpose is impor - tant from the perspective of technological progress, it depends on the individual case. The EHDS Regulation requires the following measures to protect data when it is reused: • data minimisation – access to data and its pro - cessing only concerns the necessary minimum scope of data; • anonymisation and pseudonymisation – privacy is ensured through data protection techniques; and • secure processing environments – data is pro - cessed in controlled environments with a high level of securit The definition of processing indicated in Article 4 (2) of the GDPR is so broad that its understanding of “processing” includes activities such as data shar - ing, including the anonymisation procedure as defined in Article 4 (5) of the GDPR, carried out in order to process anonymised data by outsourcing such anonymised data. 6.3 Data Sharing and Access The legal landscape of data sharing, including medical data, is complex, including the GDPR, AI Act, EHDS Regulation and Data Act. In respect of the Data Act, the European Data Protection Board (EDPB) recently issued Statement 4/2025 (dated 14 July 2025) for draft non-binding model contractual terms (MCTs) on data sharing under the Data Act, in which the EDPB high - lighted areas needing clarification and improvement in the MCTs, particularly concerning user definitions, data distinctions, and overall structure. The EHDS Regulation provides, among other things, for the creation of digital infrastructures and organisa - tional units that will facilitate access to and processing of data for both primary and secondary use, includ - ing cross-border. Chapter II of the EHDS Regulation lays out comprehensive provisions regarding patients’ rights related to the primary use of electronic health data, focusing on access, portability and control. The framework strongly emphasises security and priva -

cy, ensuring that all data sharing takes place within secure processing environments. 6.4 De-Identification and Anonymisation Alongside encryption, pseudonymisation is one of the main technical and organisational measures for data processing under the GDPR. This is a general require - ment under the GDPR that data be processed in such a way that it cannot be attributed to a specific data subject without the use of additional information (so- called “pseudonymisation”, as defined in Article 4 (5)). This standard, which hinders the development of AI in healthcare, depends on the degree of data identifica - tion and its quality, which are necessary for training linguistic models necessary for the proper functioning of AI systems in individual healthcare procedures. EU law is very restrictive regarding anonymisation, establishing very high standards, including the defini - tion of anonymisation regarding any information that can be identified by a natural person. This issue is compounded by the requirement for AI systems to permanently record all AI actions, arising from Article 26 of the AI Act. Therefore, the anonymi - sation obligation certainly impacts the quality of train - ing data for a model running, for example, in a medi - cal device during the comparison of patient data in a trained model, eg, a diagnostic model. Data anonymisation law has been supplemented for many years with official interpretative documents. The Polish Ministry of Digital Affairs was among the first to issue such a document in the form of an annex in 2020 specifying data depersonalisation techniques. Guide - lines No 4/2019 on Article 25 of the GDPR, issued by the EDPB, may also provide useful guidance.

7. Intellectual Property Issues Regarding Healthcare AI 7.1 Patent Protection

From the perspective of an AI system as a component of a medical device, the definition of a medical device under the MDR and IVDR has a very broad scope which, in practice, in addition to such state-of-the- art devices, can also include simple elements used

100 CHAMBERS.COM

Powered by