Health data protection in occupational safety and health

Health data protection in occupational safety and health (OSH) is the set of legal and organizational safeguards that regulate the processing of information on the health of workers generated in the context of workplace risk prevention: medical examinations, occupational health records, test results, fitness-for-work assessments, job adaptations, situations of special sensitivity, pregnancy, incapacity, or sick leave. Health data constitutes a special category under Article 9 of the General Data Protection Regulation (GDPR), the processing of which is only lawful in specific circumstances, including occupational medicine and the assessment of work capacity under professional secrecy. Article 22 of Law 31/1995 adds that the results of health surveillance are communicated to the worker, that the employer is only informed of the conclusions regarding fitness for work, and that access to medical information is limited to healthcare personnel and health authorities.

In short

Guarantees governing the processing of health information generated during prevention: special category of data (Article 9 of the GDPR) processable only for occupational health and work capacity assessment under professional secrecy. The company receives only fitness conclusions (Article 22 of Law 31/1995); clinical access is limited to healthcare personnel. It requires data minimization, access by role, security, retention periods, and impact assessments for high-risk processing.

Content
  1. What does the protection of health data in occupational safety and health entail?
  2. Principles and obligations
  3. Frequent situations
  4. Organizational application: how to protect health data
  5. Limits and common mistakes
  6. Practical example
  7. Regulatory framework in Spain and the European Union
  8. Related concepts
  9. References

A–Z dictionary →

What does the protection of health data in occupational safety and health entail?

Occupational risk prevention requires information about people’s health to protect them: determining if a job is compatible with the occupant’s condition, detecting early signs of illness, adapting tasks, or protecting pregnancy. But this same information, in the wrong hands, can lead to discrimination, pressure, or loss of privacy. Therefore, the legal framework distinguishes between two systems: the healthcare system, where occupational health and nursing staff handle clinical data under professional confidentiality, and the business system, which only receives functional conclusions (fit, fit with restrictions, unfit, need for adaptation) without diagnoses.

Regulation (EU) 2016/679 generally prohibits the processing of health-related data, permitting it only in exceptional circumstances such as when necessary for compliance with obligations in the areas of labor law and social protection (Article 9.2.b), preventive or occupational medicine, and the assessment of a worker’s capacity to work (Article 9.2.h), provided that the processing is carried out by a professional bound by professional secrecy. Organic Law 3/2018 implements these provisions, and Law 31/1995 establishes the specific rules of confidentiality for health surveillance, reinforced by Law 41/2002 on patient autonomy and by Royal Decree 843/2011 on the healthcare activity of prevention services.

The digitization of preventive management and the emergence of sensors, wearable devices and analytics systems multiply the data that can reveal the state of health (vital signs, fatigue, exposure, absences), which requires designing systems with data protection by design and by default, separation of access and impact assessments when the processing is high risk.

Principles and obligations

  • Lawfulness and purpose. Health data is processed only for preventive and health surveillance purposes, with the legal basis of Article 9.2 of the GDPR; it cannot be reused for selection, performance evaluation or disciplinary decisions.
  • Minimization. Collect only the data necessary for the risk of the position, in accordance with the specific health surveillance protocols, and communicate to the company only the fitness and the necessary measures.
  • Confidentiality and access. Access to medical information is limited to healthcare personnel from the occupational health service and health authorities; the company, management, and human resources only have access to fitness and adaptations. Systems must implement access controls by role and record queries.
  • Information and rights. Employees must be informed of the processing and may exercise their rights of access, rectification, erasure, restriction and objection, subject to the limits derived from legal retention obligations.
  • Security. Technical and organizational measures proportionate to the risk: encryption, authentication, database segregation, backups, incident management and notification of breaches to the Spanish Data Protection Agency within 72 hours when appropriate.
  • Preservation. Clinical-occupational records are kept for the periods established by health regulations and those specific to certain risks (carcinogenic agents, biological agents, ionising radiation ), which can last for decades, and are transferred to the new prevention service or to the health authority when the activity ceases.
  • Controllers, processors and third parties. External prevention services, mutual insurance companies and software providers act as data controllers or processors, as appropriate, with contracts that establish instructions, security and confidentiality.
  • Impact assessment. Mandatory when the large-scale processing of health data or the use of new technologies (sensors, wearables, analytics) poses a high risk to people’s rights.

Frequent situations

  • Communication of fitness. The fitness certificate arrives at the company without a diagnosis; the restrictions are formulated in functional terms (for example, not handling loads exceeding a certain weight) and are communicated only to the person who must apply them.
  • Sick leave and temporary incapacity. The company is aware of the existence and duration of the leave, but not the diagnosis; medical reports do not include the pathology.
  • Special sensitivity and pregnancy. Communication is voluntary and confidential; the company acts on the adaptation without disclosing the reason.
  • Accidents and investigation. The accident report and investigation record the injury to the extent necessary; the full clinical reports remain within the healthcare system.
  • Sensors and wearables. Data on vital signs or fatigue only with a clear legal basis, prior information, preventive purpose, aggregation when possible and without disciplinary use.
  • Analytics and dashboards. Aggregated or anonymized health data for collective analysis, prepared by healthcare personnel.

Organizational application: how to protect health data

  1. Inventory the processing of health data in preventive management (health surveillance, fitness assessments, adaptations, accidents, special sensitivity, sensors) and include them in the record of processing activities.
  2. Separate the healthcare circuit from the business circuit: separate databases and access, with healthcare personnel as the only access to clinical information.
  3. Define in writing what each role (management, supervisors, human resources, prevention technicians) receives and limit it to the necessary fitness information and measures.
  4. Inform workers about the processing and their rights, and establish a procedure for exercising those rights.
  5. Conduct an impact assessment when sensors, wearables, advanced analytics or large-scale processing are incorporated, in consultation with representatives.
  6. Formalize data-processing agreements with external prevention services, mutual insurance companies and software providers, with confidentiality, security and subprocessor clauses.
  7. Periodically audit access and security, manage incidents, and maintain retention periods by data type.

Preventive management software designed with data protection from the design stage allows you to separate health modules from management modules, apply access by role, record each consultation, and keep the data for the legally required periods with traceability.

Limits and common mistakes

  1. Communicating diagnoses or clinical results to management or human resources instead of fitness and adaptations.
  2. Storing medical reports in shared folders, emails, or personnel files accessible outside the healthcare system.
  3. Using health data for selection, promotion or disciplinary decisions, or to profile people.
  4. Deploying sensors or wearables that record physiological data without legal basis, information or impact assessment.
  5. Do not formalize the data-processing agreement with the external prevention service or the technology provider.
  6. Maintaining or destroying records without regard to the deadlines of health regulations and specific risks.

The legal classification of each processing activity must be carried out with the data protection officer or specialized advice; this sheet is for informational purposes only.

Practical example

Situation: A service company with 500 people implements a new preventive management software that integrates the health surveillance carried out by its external prevention service.

  • Design. A health module is configured with exclusive access for medical and nursing staff from the external service and a management module where the company only sees fitness-for-work conclusions, functional restrictions and review dates.
  • Contracts and registration. Data-processing agreement with the software provider and agreement with the external prevention service as controller of the clinical data; updating of the record of processing activities.
  • Impact assessment. Carried out through the processing of health data of all staff, with encryption measures, strong authentication, access logging and consultation with the health and safety committee.
  • Operational. Information for staff, procedure for exercising rights and semi-annual audit of access; job adaptations are managed without disclosing the health reason.

Regulatory framework in Spain and the European Union

The Spanish Data Protection Agency publishes guides on data processing in labor relations and on data protection and the prevention of occupational risks; in Colombia, Law 1581 of 2012 classifies health data as sensitive and Resolution 2346 of 2007 regulates the custody of occupational medical records.

Related concepts

References

  1. European Union. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Official source
  2. Official State Gazette. Organic Law 3/2018, of December 5, on the Protection of Personal Data and the guarantee of digital rights. 2018, current consolidated text. Official source
  3. Official State Gazette. Law 31/1995, of November 8, on Occupational Risk Prevention, Article 22. 1995, current consolidated text. Official source
  4. Official State Gazette. Law 41/2002, of November 14, basic law regulating patient autonomy and rights and obligations regarding information and clinical documentation. 2002, current consolidated text. Official source
  5. Official State Gazette. Royal Decree 843/2011, of June 17, establishing the basic criteria for the organization of resources to carry out the healthcare activities of prevention services. 2011, current consolidated text. Official source

Editorial information

Publication date: August 30, 2026 .

Editorial Manager: Sabentis Editorial Team .

Editorial review by Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra