Case C-546/26, Ministar na zdraveopazvaneto – a health record with no filter
A national medical record is only as private as the rules on who may open it. The Bulgarian Supreme Administrative Court has sent six questions to Luxembourg, and the same three words run through almost all of them: the system uses no filter.
Facts
Bulgaria operates a common national health information system. Entry is mandatory, and what must be entered is the whole of a person’s medical life — identifying data, examinations, referrals, diagnostic results, hospital stays, vaccinations, prescriptions, prophylactic care, blood group, allergies, infectious diseases, chronic conditions and disabilities, pharmacological treatments, medical devices, and cosmetic surgery. The basic parameters of that processing are laid down not in a statute but in Regulation No N-6 of 21 December 2022, an act of the executive adopted under a general delegation of powers. Access is granted to primary, outpatient and inpatient healthcare professionals, to insurance companies, and to prosecutors — in each case, on the referring court’s account, to the entire file, with the scope of what is consulted left to the reader’s own judgement. Patients are told their data has been accessed only “where necessary”, a term the referring court notes is defined neither in the law nor in the regulation. The proceedings involve the Ministar na zdraveopazvaneto (Minister for Health) and two individuals; the Varhoven administrativen sad has referred six questions.
Questions Referred
According to the Official Journal notice, the Varhoven administrativen sad asks:
1. Must Article 9 of Regulation (EU) 2016/679 (GDPR), read in conjunction with Articles 7 and 8 and Article 52(1) of the Charter of Fundamental Rights of the European Union, be interpreted as allowing national arrangements under which basic parameters of the centralised processing of personal data concerning health are determined not by a law but by a regulatory act adopted by a body of the executive branch on the basis of a general statutory delegation of powers?
2. Must Article 9(2)(c), (g), (h) and (i) of the GDPR and Articles 7 and 8 of the Charter be interpreted as allowing the creation and operation of a common national information system into which it is mandatory to enter data identifying the person (name, personal identification number, identity document, citizenship) and all of the person’s medical data, such as medical examinations carried out, medical referrals issued, results of medical diagnostic tests, hospital stays, vaccinations, prescriptions issued, prophylactic care, blood group, allergies, acute infectious diseases suffered, chronic conditions or disabilities diagnosed, pharmacological treatments carried out, medical devices used, etc., including data on cosmetic surgery carried out by medical centres, including any carried out on patients’ private parts?
3. Must Article 9(2)(c), (g), (h) and (i) of the GDPR and Articles 7 and 8 of the Charter be interpreted as allowing full access to an information system with the characteristics of the system described in the previous question, without the patient’s consent, in ‘emergencies’ in which it is not possible to obtain the patient’s consent in good time?
4. Must Article 9(2)(c), (g), (h) and (i) of the GDPR and Articles 7 and 8 of the Charter be interpreted as allowing full access to an information system with the characteristics of the system described in the second question, with the patient’s consent, where consent cannot be given in part (for only part of the information in the electronic file, limited to the information necessary for the examination, treatment or other medical intervention in question, or for only a specific period of time), and in respect of which provision is made for the following:
a. unrestricted access to all health records in patients’ electronic health files granted to medical professionals in primary healthcare facilities ‘during and for the purposes of the performance of their duties’, but without the system using a ‘filter’, which is to say that assessing what part of the data the medical professional needs to consult is entirely at his or her discretion …;
b. unrestricted access to all health records … granted to medical professionals in outpatient healthcare facilities … for a period of no more than 30 calendar days from the initial examination carried out by them, but without the system using a ‘filter’ …;
c. unrestricted access to all health records … granted to medical professionals in inpatient healthcare facilities … in connection with the hospital stay for a period of no more than 30 calendar days from the patient’s discharge, but without the system using a ‘filter’ …;
d. unrestricted access to all health records … granted to medical professionals in healthcare facilities in relation to the exercise of their particular function in respect of the patient, but without any time limit and without the system using a ‘filter’ …;
e. unrestricted access to all health records … granted to insurance companies in relation to ‘the relevant health records of the patient, during and for the purposes of the performance of their duties in connection with a specific insurance claim’ in the context of voluntary health insurance based on a health insurance contract, but without the system using a ‘filter’ …?
5. Must Article 9(2)(c), (g), (h) and (i) of the GDPR and Articles 7 and 8 of the Charter be interpreted as allowing the authorities responsible for the pre-trial stage of the proceedings to have full access, without the patient’s consent, to an information system with the characteristics of the system described in the second question in connection with pending pre-trial or trial stages of proceedings, on the basis of a decision adopted by the public prosecutor in charge of the investigation, but without the system using a ‘filter’ …?
6. Must Article 9(2)(c), (g), (h) and (i) of the GDPR and Articles 7 and 8 of the Charter be interpreted as allowing patients not to be informed every time their data have been accessed in an information system like that at issue in the main proceedings but only to be informed ‘where necessary’ …, whereas the situations constituting ‘necessity’ are not set out in the law or in Regulation No N-6?
Sources
OJ notice C/2026/4393 (EUR‑Lex) · Case file on CURIA · Regulation (EU) 2016/679 (GDPR) · Charter of Fundamental Rights
Comment
Read the six questions together and they are not six complaints but one, asked from six angles. The recurring formula — “without the system using a ‘filter’” — describes an architecture in which nothing technical stands between a person authorised to open a file and the whole of that file. What is described as proportionality is in fact a promise: the reader will look only at what they need. The referring court is asking whether EU law accepts a promise where it has until now required a mechanism.
The Court’s answer to that in an adjacent field is already on record. In Case C‑439/19, Latvijas Republikas Saeima (ECLI:EU:C:2021:504) it held that the GDPR precludes national legislation obliging the body responsible for a register of driving penalty points to make those data accessible to the public without the person requesting access having to establish a specific interest in obtaining them. The principle is that access rights are not granted wholesale to a category of person; the requester must be tied to a purpose that justifies the particular disclosure. Bulgaria’s arrangement inverts that: the category — primary care, outpatient, inpatient, insurer, prosecutor — is the qualification, and the purpose is left to be supplied afterwards by the person already holding the key.
The second question is where Article 9 does its own work. The list of mandatory entries is striking not for its length but for its terminus: cosmetic surgery, expressly including procedures on intimate areas. That is a reminder that a health record is not a homogeneous category of “medical data” but a container in which some entries reveal far more than a diagnosis. In Case C‑184/20, OT (ECLI:EU:C:2022:601) the Court refused to let a publication scheme escape scrutiny merely because the disclosed data were formally neutral, holding that data liable to reveal sensitive information indirectly fall within the protective regime. A national database that stores every operation a citizen has undergone does not need to reveal anything indirectly; it states it.
Question 5 is the one that will travel furthest. Prosecutorial access to the entire medical file of any person, on the prosecutor’s own decision, with no filter and no prior independent check, runs directly into the line the Court built in Case C‑293/12, Digital Rights Ireland and continued in Case C‑203/15, Tele2 Sverige: access by national authorities to retained data must be subject to substantive and procedural conditions and, save in urgency, to prior review by a court or independent body. Health data sits at least as high in the Charter’s hierarchy as telecommunications metadata. If the telecoms line applies here — and it is hard to see what would keep it out — Article 27(9) of Regulation N-6 has a difficult afternoon ahead.
Behind all of it sits the first question, which is the quietest and possibly the most consequential. Article 52(1) of the Charter permits limitations on fundamental rights only if they are “provided for by law”. Bulgaria’s basic parameters live in a ministerial regulation made under a general delegation. If the Court holds that the essential elements of a national health database must be settled by the legislature rather than the executive, the answers to questions 2 to 6 become secondary — the whole scheme would need rebuilding at the level of statute, and every Member State running a comparable e-health system by administrative act would have reason to read the judgment carefully.