Home / Insights / How GDPR Affects Offshore Medical Telemedicine
Data protection2026-10-06 · 11 min read

How GDPR Affects Offshore Medical Telemedicine

A practical GDPR guide for offshore telemedicine: health-data lawful bases, controller roles, contracts, transfers, security, DPIAs and emergencies.

Secure telemedicine workstation with rugged laptop and satellite communications aboard an offshore wind vessel

Why is GDPR more complicated offshore?

An offshore telemedical consultation can move information through several organisations and jurisdictions in minutes. A technician or seafarer speaks to a first aider or medic; an employer, vessel operator or duty holder activates a service; a clinician assesses the case; a platform stores the record; and an emergency service or receiving hospital may need a handover. The vessel can change territorial waters while the provider, hosting environment and support teams remain elsewhere. Each step is processing of personal data, and much of it is data concerning health.

GDPR does not prohibit this model, require paper records or automatically require every system to be hosted in the EU. It requires the organisations involved to identify whether the Regulation applies, define their real roles and purposes, establish lawful conditions for processing health data, inform people, limit and protect the data, govern suppliers and international transfers, respect individual rights, and be able to demonstrate those decisions. Offshore complexity makes that mapping more important; it does not create an exemption.

This guide explains the EU GDPR baseline for buyers and providers. UK GDPR and other national healthcare, employment, professional-secrecy, medical-record and medicines rules may apply alongside or instead of it. The exact result depends on the entities, establishments, people, processing and jurisdictions involved, so the contract and data-flow design should receive qualified legal and data-protection review before service launch.

Is offshore medical information special-category data?

Yes, when information reveals a person's physical or mental health status or the provision of healthcare. GDPR Article 9 generally prohibits processing special categories of personal data unless one of its listed conditions applies. That is an additional layer: the controller must also identify a lawful basis under Article 6. An Article 9 condition does not replace Article 6, and a general operational need does not by itself satisfy either article.

Healthcare processing may rely on Article 9(2)(h) where it is necessary for medical diagnosis, provision or management of health or social care or treatment under Union or Member State law or a qualifying contract with a health professional, subject to Article 9(3)'s professional-secrecy safeguards. Employment and occupational-health processing may engage Article 9(2)(b) where authorised by applicable law or collective agreement with suitable safeguards. Which route is available depends on national law and the actual purpose; a contract clause cannot manufacture a statutory condition that is not present.

The vital-interests conditions are deliberately narrow. Article 6(1)(d) and Article 9(2)(c) can support processing necessary to protect vital interests when the person is physically or legally incapable of giving consent. They should not be turned into a standing basis for every routine consultation merely because offshore cases can become urgent. Record the normal pathway and the exceptional emergency pathway separately, including who can invoke each and how the decision is documented.

DecisionWhat must be identifiedCommon error
Article 6 basisThe lawful basis for each purpose and controllerNaming Article 9 only
Article 9 conditionThe applicable special-category condition and supporting national law or safeguardsTreating 'medical' as a condition in itself
PurposeClinical care, employment response, safety management, billing, audit or another defined purposeBundling every use under 'health and safety'
Emergency routeWhen vital interests genuinely apply and how incapacity and necessity are recordedUsing emergency language for routine processing

Is consent the right lawful basis?

Not automatically. Valid GDPR consent must be freely given, specific, informed and unambiguous, and explicit consent is one possible Article 9 condition. It must also be as easy to withdraw as to give. In an employment or offshore emergency setting, imbalance, dependency, safety pressure and the practical consequences of refusal can mean the person lacks a genuine free choice. EDPB consent guidance says employers are unlikely to be able to rely on employee consent for most workplace processing unless refusal or withdrawal produces no detriment.

Clinical consent to examination or treatment is a separate question from the data-protection basis for processing records. A clinician may need valid clinical consent while the controller relies on another lawful basis and Article 9 condition for necessary record processing. Conversely, a signed privacy form does not establish informed consent to treatment. Procedures and notices should keep those concepts distinct so that neither is overstated.

If explicit consent is genuinely selected for an optional processing purpose, document the choice, information provided, affirmative action, withdrawal method and consequences of withdrawal. Do not make necessary emergency care or mandatory employment processing appear optional, and do not promise deletion after withdrawal when another legal duty requires retention.

Who is the controller: employer, operator or telemedicine provider?

Controller and processor are functional roles. The controller determines the purposes and essential means of processing; a processor handles personal data on a controller's behalf and instructions. Contract labels are relevant evidence but are not decisive if the real activity differs. The same provider can be a processor for one operation and an independent controller for another, and two parties can be joint controllers where they jointly determine purposes and essential means.

A telemedicine provider should not be assumed to be only a processor. Where regulated clinicians decide what clinical information to collect, how to assess and document the patient, who receives a clinical handover and how long professional records must be retained, the provider may determine purposes or essential means for at least part of the clinical processing. The employer or operator may separately control activation lists, occupational follow-up, incident management or service-performance reporting. The correct answer must be mapped purpose by purpose.

EDPB Guidelines 07/2020 require the allocation to reflect factual roles. If a party is a processor, Article 28 requires a binding contract covering subject matter, duration, nature and purpose, data types, data subjects, instructions, confidentiality, security, subprocessors, rights assistance, breach and DPIA assistance, deletion or return, and audit information. If parties are joint controllers, Article 26 requires a transparent arrangement allocating responsibilities, without reducing the individual's ability to exercise rights against each controller.

Processing activityRole questionEvidence
Clinical consultation and recordWho decides the clinical purpose, necessary content, recipients and professional retention?Clinical governance, record policy and applicable healthcare law
Employee activation and eligibilityWho decides which workers are enrolled and what administrative data is supplied?Employer or operator process and privacy notice
Platform hosting and supportDoes the supplier act only on documented instructions?Article 28 terms, subprocessors and access logs
Anonymised or aggregated reportingIs re-identification reasonably possible, and who defines the reporting purpose?Aggregation method, small-cell controls and role assessment
Incident and occupational follow-upIs information used for a new employment, safety or insurance purpose?Purpose, lawful basis, access boundaries and retention

What counts as an international data transfer offshore?

The ship's position is not the only location that matters. Start with GDPR Article 3: processing can fall within GDPR because it occurs in the context of an EU establishment or because a non-EU organisation offers goods or services to, or monitors the behaviour of, people in the Union. Then analyse Chapter V separately. Under EDPB Guidelines 05/2021, a transfer generally involves a controller or processor subject to GDPR disclosing or making personal data available to a different controller or processor in a third country or international organisation.

Map storage, backup, clinical access, technical support, subprocessors and onward disclosure. Access granted to a separate overseas supplier can be a transfer even when the database remains in Europe. By contrast, an employee of the same controller remotely accessing its own systems while travelling is not, on that fact alone, a transfer between two separate parties under the EDPB test—although security, territorial law and accountability risks still need assessment.

Where Chapter V applies, identify a valid route such as an adequacy decision or appropriate safeguards under Article 46, which can include the European Commission's Standard Contractual Clauses. Safeguards are not a paperwork endpoint: following the Court of Justice's Schrems II judgment and EDPB recommendations, exporters must assess whether the destination's law and practice affect the safeguard and adopt supplementary measures where necessary. Article 49 derogations are exceptions and should not become the routine architecture for a standing telemedicine service.

What security and clinical-record controls are expected?

Article 32 requires controllers and processors to implement technical and organisational measures appropriate to risk, considering the state of the art, implementation cost, processing context and the likelihood and severity of harm. The Regulation names measures such as pseudonymisation and encryption where appropriate, ongoing confidentiality, integrity, availability and resilience, timely restoration, and regular testing. It does not prescribe one universal encryption product, hosting region or certification.

For offshore telemedicine, the security design should follow the actual data flow: authenticated users and role-based access; least privilege for employer, clinical and technical teams; secure primary and fallback communications; protected local devices and cached data; encryption in transit and at rest where appropriate; audit logs; controlled record export; tested backup and restoration; subprocessor oversight; access removal; and procedures for lost devices or communications. Confidentiality must survive a crowded bridge, control room or accommodation environment, not only a penetration test.

Data minimisation does not mean collecting too little for safe care. Collect what is adequate, relevant and necessary for the defined clinical and operational purpose, separate access where purposes differ, and retain records according to applicable healthcare, employment and limitation rules rather than an arbitrary short period or 'forever'. Provide the information required by Articles 13 or 14 in a form workers can actually understand before routine use, with an emergency pathway for information that cannot be delivered immediately.

A personal-data breach is broader than disclosure: loss of availability or integrity can qualify too. A processor must notify its controller without undue delay after becoming aware. A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk people's rights and freedoms; high-risk breaches can also require communication to affected people. Contractual targets should leave the controller enough time to assess and meet its own deadline.

When is a DPIA required?

Article 35 requires a data protection impact assessment before processing likely to result in high risk to individuals, particularly when new technologies, nature, scope, context and purposes are considered. It specifically identifies large-scale processing of special-category data as a case requiring a DPIA. Supervisory authorities publish additional required-processing lists, so the applicable national list must also be checked.

Not every individual telemedical call automatically makes the service 'large scale', and the GDPR does not define the conclusion by vessel count alone. But a fleet-wide platform combining health data, employee identity, continuous availability, multiple jurisdictions, new technology, vulnerable or dependent workers, remote access and emergency decision support can accumulate several high-risk indicators. If there is doubt, documenting a DPIA is often the clearer accountability route, but the assessment must remain specific rather than a generic vendor questionnaire.

The DPIA should describe purposes and data flows, assess necessity and proportionality, identify risks to people—not only corporate cyber risk—and record measures and residual risk. It should cover clinical confidentiality, inappropriate employer access, mistaken identity, unavailable or altered records, overseas access, excessive retention, inability to exercise rights, bystander disclosure and emergency workarounds. Consult the data protection officer where designated. If high residual risk remains that cannot be mitigated, Article 36 requires prior consultation with the supervisory authority before processing.

The buyer's GDPR checklist for offshore telemedicine

A buyer should ask for an evidence pack that joins the legal analysis to the operating model. Security certificates and a data-processing agreement can support that pack, but neither proves that purposes, roles, health-data conditions or offshore workflows are correct. The review should be repeated when the clinical model, platform, subprocessors, hosting, jurisdictions, worker population or data uses materially change.

CheckRequired decision or artefactRed flag
Scope and data mapEntities, establishments, people, purposes, systems, access and countriesOnly the server region is mapped
Lawful processingArticle 6 basis and Article 9 condition per purpose and controllerOne blanket consent form
RolesFactual controller, joint-controller and processor analysis per activityProvider labelled processor for every clinical use
ContractsArticle 28 terms where applicable and Article 26 arrangement where jointly determinedDPA used instead of a role assessment
Transparency and rightsLayered notices, intake information and owned request workflowWorkers told only to ask their employer
TransfersImporter map, adequacy or safeguard, assessment and supplementary measuresEU hosting claimed while overseas support has access
SecurityRisk-based controls, testing, restoration, logs and offshore device procedureCertification presented as the entire control set
Retention and exitPurpose-specific schedule, legal basis, record handover and deletion boundariesImmediate deletion promised despite clinical duties
DPIA and governanceCurrent DPIA decision, DPO input, owners and residual-risk approvalGeneric supplier DPIA with no casualty pathway
Breach responseProcessor escalation, controller assessment and 72-hour workflowContract permits notification after the legal window
Add it to the SLA
Use the offshore telemedicine SLA checklist to document roles, data flows, subprocessors, breach cooperation, record access and exit requirements.
Written by Elia Malmsten, Clinical Lead at Alvyri Crew — Swedish-licensed physician, specialist trainee (ST) in anaesthesiology.

Frequently asked

Does GDPR apply when the vessel is outside EU waters?
Potentially. Territorial scope is not determined solely by the vessel's coordinates. GDPR can apply because processing occurs in the context of an EU establishment or, in some cases, because a non-EU organisation offers goods or services to or monitors people in the Union. Flag, establishments, people, entities and each processing activity must be mapped alongside other applicable national laws.
Do offshore workers need to consent to every telemedical consultation?
Not necessarily, and consent may be inappropriate where employment imbalance, emergency pressure or detriment means it is not freely given. Each controller needs an Article 6 lawful basis and an Article 9 condition for health data. Clinical consent to examination or treatment is related but legally distinct from the GDPR basis for processing the clinical record.
Is the telemedicine provider always a data processor?
No. Roles follow the real purposes and essential means, not the contract label. A provider may independently control part of the clinical record processing while acting as a processor for another administrative activity. Map roles purpose by purpose and use Article 28, Article 26 or controller-to-controller terms as the facts require.
Does GDPR require offshore medical data to stay in the EU?
No universal EU-hosting rule appears in GDPR. Transfers to third countries must comply with Chapter V, for example through an adequacy decision or appropriate safeguards such as Standard Contractual Clauses, with any necessary assessment and supplementary measures. Other healthcare, public-sector, contract or national localisation rules may still apply.
Is a DPIA mandatory for offshore telemedicine?
It is mandatory where the proposed processing is likely to create high risk, including large-scale processing of special-category data, and national supervisory-authority lists can add cases. Scale, technology, worker dependency, monitoring, jurisdictions, access and consequences should be assessed. Record the decision even where the conclusion is that a DPIA is not required.
Can emergency vital interests be the standard GDPR basis?
It should not be used as a blanket basis. Article 9(2)(c) addresses processing necessary to protect vital interests where the person is physically or legally incapable of consent. Routine consultations need their own documented Article 6 basis and Article 9 condition; the exceptional emergency route should be separately defined and recorded.

Planning medical coverage for your operation?

Alvyri Crew provides clinically-led telemedicine for offshore wind and maritime crews.

Alvyri Crew
Alvyri AB · Org. no. 559024-7952
Stockholm, Sweden
Registered healthcare provider
Company
Trust
Language