Consent and confidentiality in health surveillance

Health surveillance must respect the principle of voluntariness within the legal framework, the right to inform the individual, and the confidentiality of their health information. Consent for medical treatment and the legal basis for processing personal data are related but distinct issues.

In short

In Spain, health surveillance is generally voluntary, with legally justified exceptions. The company receives the necessary preventive recommendations for its operations, while clinical data is kept under health and data protection safeguards.

Content
  1. Two issues that must be distinguished
  2. Rule of voluntariness and exceptions
  3. Information before the health assessment
  4. What information can the company receive?
  5. Custody, access, and digital tools
  6. Collective outcomes and individual rights
  7. Practical example
  8. Common mistakes and review
  9. Related concepts
  10. On the blog
  11. References

AZ Dictionary →

Two issues that must be distinguished

Accepting a health screening and authorizing the processing of personal data are distinct legal decisions. The former relates to medical procedures performed on the individual and the information provided to them; the latter, to the purpose, necessity, and legal basis for using the data. A single, ambiguous form can obscure this distinction and hinder the exercise of rights.

The Spanish Data Protection Agency (AEPD) explains that the processing of personal data necessary for preventive or occupational medicine can be based on the grounds established by regulations, without always relying on consent as the basis for data collection. This does not eliminate the duty to inform or the health safeguards. Nor does it automatically make any test proposed within a medical examination mandatory.

Rule of voluntariness and exceptions

Article 22 of the Occupational Risk Prevention Law establishes periodic monitoring based on the risks and, as a general rule, requires the worker’s consent. It provides for exceptions when the assessment is essential to evaluate the effects of work, verify a potential danger to the worker or others, or when required by legislation concerning specific risks and particularly hazardous activities.

These exceptions require a prior report from employee representatives, in accordance with legal requirements. Simply declaring all medical examinations mandatory as an internal policy is insufficient. The applicable circumstances must be justified, and proportionality must be maintained: selecting actions that cause the least disruption and are appropriate to the risk being assessed.

Information before the health assessment

The person must understand the purpose of the monitoring, what procedures it entails, and how they will receive the results. When monitoring is mandatory, they must be able to understand the rationale behind it. The information provided must be clear and allow for questions to be asked of healthcare staff, and should not simply be a signature obtained at the beginning of the appointment.

The content is aligned with the specific risks and health criteria. Tests unrelated to the purpose require their own analysis of necessity and legitimacy. The existence of a commercially available package of assessments does not justify including sensitive information that is not relevant to the corresponding preventive or health action.

What information can the company receive?

The company and those with preventive responsibilities receive the conclusions regarding job fitness and the need to introduce or improve protective measures. This communication should enable action: for example, specifying conditions that require adjustment. It should not become a routine delivery of diagnoses, treatments, or analytical results.

The law limits access to personal medical information and prohibits discriminatory or harmful uses. The protection of health data requires reviewing recipients and the necessity of such access. A supervisor’s ability to organize shifts does not grant them general access to medical records; they only need the relevant information to implement the appropriate measures.

Custody, access, and digital tools

Systems must distinguish between clinical documentation and preventive management. Access authorizations are assigned according to roles and reviewed when those roles change. Access logs, retention, backups, and communication channels must be considered, in a manner proportionate to the sensitivity of the information and applicable obligations.

A shared spreadsheet or an email with too many recipients can reveal more information than the report needs. Suppliers and inter-entity relationships should also be reviewed to determine responsibilities and warranties. Digitization makes work easier if it maintains separation of access and purpose, rather than centralizing all information for every user in the company.

Collective outcomes and individual rights

Collective information should help review risks and measures without identifying individuals. Removing names may be insufficient for small groups or single positions. Data breakdowns and combinations should be carefully considered before providing tables or charts to recipients who do not have access to individual clinical information.

Individuals receive their health results and can exercise their corresponding rights with the data controller. The handling of a request must follow a clear and secure channel. Offering universal retention or deletion periods is not appropriate without examining specific health and safety regulations, especially when there are exposures requiring long-term follow-up.

Practical example

A manager requests all medical reports to arrange a change of duties. The healthcare service distinguishes between the medical history and the findings necessary for the adjustment and communicates the latter through the established channel. The employee receives their results and can discuss their meaning with the appropriate professional.

The manager implements preventive measures without knowing the diagnosis and coordinates the modifications with the relevant departments. If clarification is needed, it is requested regarding the functional measures, avoiding unnecessary clinical details. This way, operational efficiency is maintained without turning work organization into a dissemination of health information.

Common mistakes and review

Common mistakes include confusing medical consent with unlimited authorization to use data, requesting a blanket waiver of privacy, or making all tests mandatory. Storing diagnoses in files accessible to any HR manager is also a mistake. Transparency must be accompanied by effective limits and access controls.

The review must verify purpose, proportionality, information, recipients, and security, in coordination with healthcare personnel and data protection officers. A clear procedure facilitates exercising rights and implementing recommendations. Safeguards are not an added obstacle to prevention: they allow surveillance to fulfill its health purpose with confidence and respect for individuals.

Related concepts

On the blog

References

  1. Official State Gazette. Law 31/1995, on Occupational Risk Prevention. Consolidated text. Official source
  2. Official State Gazette. Royal Decree 39/1997, Regulations for Prevention Services. Consolidated text. Official source
  3. Official State Gazette. Royal Decree 843/2011, organization of resources for the healthcare activity of prevention services. Consolidated text. Official source
  4. Spanish Data Protection Agency. Difference between healthcare consent and consent to process personal data. Official source
  5. European Union. Regulation (EU) 2016/679, General Data Protection Regulation. Official source

Editorial information

Publication date: October 10, 2026.

Editorial Manager: Sabentis Editorial Team.

Author: Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra