Recommendations for processing health data in an online store
The purpose of this guide is to indicate a GDPR-compliant method of action in situations where an online store offers products whose order may lead to disclosure of health data, which is a special category of data specified in Article 9 of the GDPR.
1. Consent to data processing
In the case of order fulfillment, the legal basis for processing most personal data is usually Article 6. B (1) of the GDPR (processing required for the performance of the contract). However, when information about the customer’s health status can be deduced from the order content,it also becomes necessary to obtain consent in accordance with Article 9 (2). a RODO.
2. Example of the content of the consent flag (Article 9. a RODO, paragraph 2)
When a customer orders a product that may disclose health information (for example, medical products, medications for certain diseases), it is recommended to add a separate checkbox (check box) during the purchase process, which will be marked with explicit consent.
Sample content:
I consent to the processing by XYZ of my health data resulting from the content of the order in order to fulfill it – in accordance with Article 9 (2). a RODO.
Consent is voluntary, but necessary to complete an order that includes products that may indicate a health condition.
This checkbox should only appear if the order actually contains products that may disclose information about the customer’s health status if they are sold in the store. It may appear, for example, in the order summary.
In addition, the order summary should include a standard checkbox for accepting terms and conditions and a privacy notice (for more information about checkboxes and messages in the order path, see the recommendations for an electronic seller that you received in the Legal Geek ad builder).
However, it should be noted that if the checkbox of consent to the processing of certain categories of data appears at the same stage as the checkbox of consent to the terms, these checkboxes should not be combined into one.
3. Revocation of consent – how to proceed?
The GDPR grants data subjects the right to withdraw their consent at any time (Article 7 (3) GDPR). After receiving such a request, it is recommended to conduct an individual analysis of each case to determine the extent to which data can be deleted. The situation here is somewhat ambiguous, because this consent is simultaneously necessary for the execution of the order, and, as a rule, we have other legal grounds for processing this data (for example, the order data will also be in the invoice, where we are dealing with processing based on accounting responsibilities). Each situation should be considered individually, and the procedure and content of confirming the withdrawal of consent should be adapted to the results of the analysis.
Examples of consent withdrawal scenarios and recommended messages for the client:
a) data contained in accounting documents (for example, an invoice):
They cannot be deleted before the deadline required by law.
Recommended information: we confirm receipt of the consent revocation request. Please note that data contained in accounting documents (such as invoices) will continue to be processed for the period required by law, in particular for tax and accounting purposes.
B) data in sales systems (for example, CRM):
If the data is not needed to complete the order and there is no other legal basis for storing it, it must be deleted or anonymized.
4. Data minimization-good practices
In accordance with article 5 (1). C of the GDPR, personal data must be adequate, up-to-date and limited to what is necessary.
Recommendations:
- Limiting the number of systems: health data should not be sent to marketing systems or external databases unless separate consent has been obtained for this purpose.
- Neutral product range: If possible, it is recommended to use neutral names on documents (for example, ‘product 123’) instead of detailed descriptions indicating ailments.
- Minimum processing volume: avoid collecting data in chat stories or forms if they are not necessary.
5. Data disclosed during contact
Health information can also be provided when contacting the client (chat, email, phone).
Recommendation:
In situations where the data is provided on the user’s initiative, it can be assumed that the user has given their consent through an explicit confirmation action (article 32 of the GDPR). In these cases, there is no need to add a checkbox, provided that:
- the data is not processed for other purposes,
- an appropriate level of technical and organizational security measures is provided.
6. Sharing your marketing agency’s health data
If you intend to provide certain categories of data (such as health data) to a third party, such as a marketing agency, you must obtain the separate, explicit and voluntary consent of the data subject. Such consent must be completely independent of consent to the processing of data for the execution of the order.
Key principles:
- Failure to provide information to the agency cannot lead to the impossibility of making a purchase.
- The customer must be able to consent to the processing of data for the execution of the order without consent to their transfer to other persons.
Approximate content of the consent:
I consent to the provision of my health data processed by XYZ, a marketing agency that cooperates with it, for marketing purposes. This consent is voluntary and can be revoked at any time.
This consent can be placed below the checkbox for consent to the processing of health data. We also recommend that you tailor your content by identifying planned marketing efforts, such as sending out personalized newsletters.
Example:
I consent to the provision of my health data processed by XYZ-a marketing agency working with it, for marketing purposes related to the display of relevant advertising. .This consent is voluntary and can be revoked at any time.
The underlined part is an example of such detail.