Home/Resources/Articles/KVKK and Special Category Data in the Health Sector
Back to Articles
KVKK11 min read

KVKK and Special Category Data in the Health Sector

A sector guide covering why health data counts as special category, the difference between explicit consent and the health-service exception, and reinforced security obligations.

JUS. Hukuk Ekibi
Uyum ve Veri Koruma
August 1, 2026
KVKK and Special Category Data in the Health Sector

Why Is Health Data Considered Special Category?

Health data falls under the "special categories of personal data" in KVKK. This is because disclosure of such data carries a risk of discrimination, stigma or harm to the data subject. A patient's diagnosis, medication history, laboratory results or genetic information is among the most sensitive personal data, and the law therefore provides reinforced protection for it.

This guide addresses, in a principle-based way, how health data should be managed under KVKK for hospitals, clinics, laboratories, pharmacies and health technology companies.

The Basic Rule for Processing Special Category Data

As a rule, special categories of data cannot be processed without the data subject's explicit consent. However, for health data the law grants narrow exceptions. Foremost among these is processing for the purpose of providing and managing health services, carried out by persons or authorised institutions under a duty of confidentiality. That is, a hospital processing health data through a physician for treatment purposes can rely on this exception.

This exception does not mean health data can be freely processed for any purpose. For marketing, research sharing or non-treatment purposes, explicit consent generally comes into play.

Explicit Consent or Exception?

Health organisations often confuse the two grounds. The table below summarises which approach fits typical activities.

ActivityLikely GroundNote
Appointment and patient recordsContract / exceptionLimited to the purpose
Billing and social-security processesLegal obligationMandatory records
Non-treatment marketingExplicit consentWithdrawable
Scientific research sharingExplicit consent / anonymisationAnonymous data where possible
Storing clinical data in the cloudException + security + transfer conditionExtra condition if abroad

Reinforced Security Obligations

For special categories of data, the Board expects additional security measures beyond the standard ones. The measures that stand out in health organisations are:

  • Limiting access to health data to authorised staff under a duty of confidentiality
  • Keeping access records (logging) and monitoring them regularly
  • Storing and transmitting data in encrypted form
  • Regular KVKK and confidentiality training for staff
  • Securing physical archives and devices

Cross-Border Transfer and Health Technologies

Modern healthcare involves telemedicine platforms, cloud-based patient record systems and laboratory integrations. When these tools host data abroad, a cross-border transfer arises. When special category data is involved this transfer is even more sensitive; the provider's obligations as a data processor must be clarified by contract and the transfer conditions set out in law must be met.

Retention, Destruction and Patient Rights

Health records are kept for the periods stipulated by the relevant legislation; these periods can be longer than for other data types. However, once the retention period expires or the processing purpose disappears, data must be erased, disposed of or anonymised via periodic destruction.

As data subjects, patients have the rights to access their data, have it rectified and, under certain conditions, request its erasure. Requests must be answered within a maximum of 30 days. However, records subject to a legal retention obligation may be kept for the relevant period despite an erasure request.

Common Mistakes

When working with special category data, health organisations should watch for these mistakes:

  • Collecting explicit consent unnecessarily where the health-service exception could apply, or conversely processing for non-treatment purposes without obtaining consent
  • Granting broad access to health data to staff whose job does not require it
  • Failing to keep access logs, or never reviewing them
  • Storing and transmitting data without encryption
  • Neglecting contracts and transfer conditions with health technologies that use servers abroad
  • Keeping patient records indefinitely without defining retention periods

These mistakes can have far heavier consequences when special category data is involved.

Compliance Steps for Health Organisations

  1. Prepare a data inventory covering all health data you process.
  2. Clarify, for each activity, whether you rely on the health-service exception or explicit consent.
  3. Limit access to health data to authorised staff under a duty of confidentiality.
  4. Apply additional measures such as access logging, encryption and physical security.
  5. Conduct a data impact assessment (DPIA) for high-risk processing.
  6. Identify all health technologies involving cross-border transfers and arrange the contracts.
  7. Define a retention period for each record type and establish a periodic destruction process.
  8. Create a process that answers patient requests within 30 days.
  9. Prepare a plan to notify the Board within 72 hours in a data breach.

Example Scenario

A private clinic keeps its patients' diagnosis and treatment data in an electronic patient record system. In diagnosis and treatment processes, the data is processed by physicians under a duty of confidentiality, relying on the health-service exception; no separate explicit consent is sought. When the clinic wishes to send non-treatment campaign emails to its patients, it collects separate, freely given explicit consent for this. Because the patient record system is hosted on a server abroad, this constitutes a cross-border transfer and the required contract and security conditions are met. If the system suffers unauthorised access, it is a data breach affecting special category data and is notified to the Board reasonably within 72 hours.

Frequently Asked Questions

Is explicit consent always required to process patient data?

No. For health data processed by staff under a duty of confidentiality within the provision of a health service, such as diagnosis and treatment, the exception set out in law can be relied on. However, non-treatment purposes generally require explicit consent.

Is it possible to store health data in the cloud?

It is, but reinforced security measures, data processor agreements and, if the provider is abroad, meeting the transfer conditions are required. Because it is special category data, the duty of care is higher.

How long should I keep patient data?

For the periods stipulated by the relevant legislation. When those periods expire and the processing purpose ends, data must be erased, disposed of or anonymised via periodic destruction.

What happens if a patient makes an erasure request?

You must assess the request within a maximum of 30 days. However, records subject to a legal retention obligation may continue to be kept for the duration of that obligation; you are expected to explain this to the patient.

This content is for general informational purposes only and does not constitute legal advice.

With JUS. you can request a free demo to securely manage your health data inventory, access permissions and patient requests.

Share this article

Need Help?

JUS. can help you implement best practices for compliance.

Book a Demo
Request Demo