Skip to content
compliancebase

GDPR vs HIPAA

GDPR vs HIPAA for SaaS and health technology: compare protected data, territorial scope, legal roles, individual rights, security, and breach rules.

Key differences

DimensionGDPRHIPAA
Protected informationGDPR covers personal data about an identifiable person; health data is a special category under Article 9.HIPAA covers PHI created or received by covered entities and business associates; not all US health data is PHI.
Territorial and entity scopeApplies to covered EU establishments and Article 3 offering or monitoring, regardless of where the vendor is incorporated.Applies by regulated role and PHI relationship in the United States, not simply because data is medically sensitive.
Organizational rolesControllers determine purposes and means; processors act on documented instructions and manage subprocessors under Article 28.Covered entities and business associates allocate duties through law and BAAs; subcontractors can also be business associates.
Legal basisProcessing needs an Article 6 basis and, for health data, an Article 9 condition unless an exception applies.Uses and disclosures are allowed or required under Privacy Rule categories, authorizations, and minimum-necessary rules.
Individual rightsArticles 12–22 include access, correction, erasure, restriction, portability, objection, and automated-decision protections.HIPAA provides access, amendment requests, accounting of disclosures, restrictions requests, and confidential communications, with different limits.
Security standardArticle 32 requires risk-appropriate technical and organisational measures for personal data.The Security Rule specifies administrative, physical, and technical safeguards for ePHI at 45 CFR §§164.308–312.
Breach timingControllers generally notify authorities within 72 hours where Article 33’s risk threshold is met; processors notify controllers without undue delay.Notices are due without unreasonable delay and no later than 60 days after discovery, with different individual, media, and HHS paths.

Control overlap

Both regimes require accountable protection of health information, but the covered datasets are not coextensive. A single data inventory can tag GDPR personal and special-category data alongside HIPAA PHI/ePHI. Article 32 measures overlap with /controls/hipaa/164-308-a-1 risk analysis, /controls/hipaa/164-312-a-2-iv encryption, /controls/hipaa/164-312-b audit controls, and /controls/hipaa/164-312-e-1 transmission security. Vendor files can hold Article 28 DPAs and /controls/hipaa/baa-requirements evidence. Separate overlays are still needed for GDPR lawful basis, Chapter V transfers and broad rights, and HIPAA permitted-use, minimum-necessary, Notice of Privacy Practices, and BAA rules.

Sequencing advice

A SaaS or health-tech team should classify data by legal status before selecting controls: identify EU personal data, special-category health data, PHI/ePHI, the relevant entity role, purpose, geography, and recipient. Establish DPAs and BAAs as separate contractual tracks, then implement shared IAM, encryption, logging, retention, vendor, and incident operations. Design the incident playbook with two clocks and decision trees—GDPR’s 72-hour authority assessment and HIPAA’s discovery-based notification framework—plus customer escalation terms. Test access and amendment workflows using realistic support tickets, and obtain counsel review for lawful basis, authorizations, de-identification, and international transfers rather than assuming one regime’s permission covers the other.

Frequently Asked Questions

No. Health data in a fitness or consumer app may be GDPR special-category data but not HIPAA PHI if no covered entity or business-associate relationship exists. Classification depends on the data, actor, purpose, and jurisdiction.

A DPA addresses controller-processor requirements under GDPR Article 28; a BAA allocates HIPAA business-associate duties. When both laws apply, organizations commonly need both sets of terms, even if combined in one contract package.

De-identification tests differ. HIPAA provides Safe Harbor and Expert Determination pathways, while GDPR asks whether a person is identifiable using means reasonably likely to be used; HIPAA de-identification does not automatically make data anonymous under GDPR.

Run one incident process with jurisdictional branches. Capture discovery time, data and people affected, safeguards, likely harm, controller or covered-entity contacts, and decisions supporting both GDPR risk thresholds and HIPAA compromise analysis.

Both provide access rights, but deadlines, verification, scope, fees, exceptions, and appeal or complaint handling differ. Route requests through one case system with separate rule sets and auditable deadline calculations.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679
  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above