Skip to main content
The Evidence Base Post

Public consultation opens on new TEHDAS2 draft guidelines and technical specifications for EHDS implementation

  • Katie KcCool
Night view of Europe from space symbolizing digital infrastructure for EHDS and TEHDAS2 guidelines

Stakeholders across Europe are invited to provide feedback on a new series of draft guidelines and technical specifications supporting the implementation of the European Health Data Space (EHDS). The consultation, open from September 30, 2025 to November 30, 2025, will help refine the operational and technical tools needed to put the EHDS Regulation into practice across Member States.

The second raft of public consultation materials from TEHDAS2, the Second Joint Action Towards the European Health Data Space, represents another step toward harmonized secondary use of health data across Europe. The documents provide practical guidance for health data access bodies (HDABs), data holders, and other organizations that will operate under the EHDS framework, ensuring consistent, secure, and transparent implementation across Europe.

As Helena Lodenius, Senior Project Coordinator at CSC - IT Center for Science, explains,

“Your feedback will help refine practical tools that support Member States in putting the EHDS Regulation into practice. All stakeholder input will be carefully reviewed to ensure the final guidelines and specifications are relevant, usable and fit-for-purpose.”


Draft guidelines for HDABs

A comprehensive set of guidelines for HDABs addresses procedural, technical, and citizen-focused aspects of EHDS implementation. These include guidance on data access procedures and formats; data minimization and pseudonymization; fees and penalties; implementation of opt-out mechanisms; and notification of significant findings identified through secondary data use.

The Data Access Procedures Guideline outlines the full workflow HDABs must follow under Articles 67–73 of the EHDS Regulation, from checking the completeness of applications to assessing and approving data access requests. It ensures that “all necessary requirements for information included in an application deemed complete are met according to the provisions of the EHDS regulation.” The guideline also outlines post-approval actions, including coordination with data holders and secure data provision via Secure Processing Environments (SPEs).

The Data Minimisation and Pseudonymisation Guideline details how HDABs can protect privacy while maintaining analytical value. It reiterates that:

“Only the minimum amount of personal health data that is adequate, relevant, and limited to what is necessary for a specific purpose should be processed.”

The document also explains how pseudonymization enables linkage across datasets “without revealing the individual's direct identity,” and how anonymization and synthetic data generation can be applied for broader public use or export while protecting privacy.

Financial and compliance frameworks are also addressed. The Fees Guideline, prepared by the French Health Data Hub, defines eligible cost categories and invoicing models, aiming to “promote transparency, fairness, and operational efficiency in line with the principles of non-discrimination, proportionality, and competition neutrality.” It also:

“Emphasizes the importance of allowing flexibility to Member States in implementation modalities to ensure the proposed models can be applied efficiently without disrupting existing mechanisms.”

The same document also distinguishes between marginal and fixed costs, outlines several invoicing models, and recommends a “centralized model… as the sole financial interface” for simplicity and transparency. It discusses challenges such as cost disparities across Member States and highlights the importance of maintaining reduced fees for academic and small-enterprise research.

Complementing this, the Penalties Guideline sets out proportionate and transparent enforcement measures aligned with national legal systems. Meanwhile, the Data Reuse Categories Guideline clarifies which types of data can be reused under Article 51 of the EHDS Regulation, and defines safeguards that balance innovation with privacy and ethical standards.

Two further documents focus on citizen rights and trust. The Opt-Out Guideline supports implementation of Article 71, which grants individuals the right to exclude their personal health data from secondary use. It clarifies that “the guideline provides recommendations on the national mechanism of opt-out via centralized or decentralized national systems,” helping HDABs design transparent and trustworthy procedures that balance citizen rights and research needs.

Finally, the Significant Findings Guideline defines how HDABs should handle reports from data users and forward them to data holders. It clarifies that HDABs “are not responsible for clinically validating findings or directly informing individuals,” as these responsibilities lie with national frameworks.


Guideline for data holders

Beyond HDABs, TEHDAS2 has also released the Data Holder Responsibilities Guideline, which provides operational direction under Article 60. Health data holders, including providers, public authorities, researchers, and insurers, are reminded that they must:

“Provide the required personal electronic health data… in a timely manner — no later than three months, extendable once by another three months in justified cases.”

The document distinguishes between personal and non-personal data flows, requires metadata submission to national catalogues, and encourages regular dataset updates. It also recommends that data holders strengthen internal systems for dataset quality, coordinate closely with HDABs, and ensure data transfers occur securely through authorized environments.


Technical specifications for EHDS infrastructure

Three technical specifications complement the policy and governance guidance, defining the digital infrastructure that will underpin the EHDS.

The DAAMS Specification describes a national platform that “manages the full application lifecycle and interacts with both national applicants and the cross-border EHDS infrastructure,” outlining functional and interoperability requirements.

The HealthData@EU IT Infrastructure Specification defines the architecture connecting national contact points for secondary use with the central interoperability platform. It explains that HealthData@EU “enables secure and standardized secondary use of electronic health data across national borders” and supports encrypted, authenticated, GDPR-compliant data exchange.

Finally, the Secure Processing Environments (SPE) Specification sets technical and security requirements for environments handling sensitive data. SPEs are described as:

“A central component of the European Health Data Space… designed to enable the safe secondary use of electronic health data while ensuring compliance with data protection, confidentiality, and information security obligations.”

The report also “goes beyond the obligatory demands of the EHDS to define minimal requirements of interoperability between compatible services that form an SPE-based federation.”


Supporting harmonized EHDS implementation

Through this public consultation, TEHDAS2 aims to align Member States around coherent procedures and interoperable systems for the secondary use of health data. By contributing feedback, stakeholders can help ensure that the final guidelines and technical frameworks are practical, equitable, and ready for adoption.

The consultation on all draft guidelines and technical specifications remains open until November 30, 2025, with final versions expected to inform future European Commission implementing acts.

Register for free today to become a member of The Evidence Base and receive the latest news straight to your inbox.