A practical GDPR guide for offshore telemedicine: health-data lawful bases, controller roles, contracts, transfers, security, DPIAs and emergencies.

An offshore telemedical consultation can move information through several organisations and jurisdictions in minutes. A technician or seafarer speaks to a first aider or medic; an employer, vessel operator or duty holder activates a service; a clinician assesses the case; a platform stores the record; and an emergency service or receiving hospital may need a handover. The vessel can change territorial waters while the provider, hosting environment and support teams remain elsewhere. Each step is processing of personal data, and much of it is data concerning health.
GDPR does not prohibit this model, require paper records or automatically require every system to be hosted in the EU. It requires the organisations involved to identify whether the Regulation applies, define their real roles and purposes, establish lawful conditions for processing health data, inform people, limit and protect the data, govern suppliers and international transfers, respect individual rights, and be able to demonstrate those decisions. Offshore complexity makes that mapping more important; it does not create an exemption.
This guide explains the EU GDPR baseline for buyers and providers. UK GDPR and other national healthcare, employment, professional-secrecy, medical-record and medicines rules may apply alongside or instead of it. The exact result depends on the entities, establishments, people, processing and jurisdictions involved, so the contract and data-flow design should receive qualified legal and data-protection review before service launch.
Yes, when information reveals a person's physical or mental health status or the provision of healthcare. GDPR Article 9 generally prohibits processing special categories of personal data unless one of its listed conditions applies. That is an additional layer: the controller must also identify a lawful basis under Article 6. An Article 9 condition does not replace Article 6, and a general operational need does not by itself satisfy either article.
Healthcare processing may rely on Article 9(2)(h) where it is necessary for medical diagnosis, provision or management of health or social care or treatment under Union or Member State law or a qualifying contract with a health professional, subject to Article 9(3)'s professional-secrecy safeguards. Employment and occupational-health processing may engage Article 9(2)(b) where authorised by applicable law or collective agreement with suitable safeguards. Which route is available depends on national law and the actual purpose; a contract clause cannot manufacture a statutory condition that is not present.
The vital-interests conditions are deliberately narrow. Article 6(1)(d) and Article 9(2)(c) can support processing necessary to protect vital interests when the person is physically or legally incapable of giving consent. They should not be turned into a standing basis for every routine consultation merely because offshore cases can become urgent. Record the normal pathway and the exceptional emergency pathway separately, including who can invoke each and how the decision is documented.
| Decision | What must be identified | Common error |
|---|---|---|
| Article 6 basis | The lawful basis for each purpose and controller | Naming Article 9 only |
| Article 9 condition | The applicable special-category condition and supporting national law or safeguards | Treating 'medical' as a condition in itself |
| Purpose | Clinical care, employment response, safety management, billing, audit or another defined purpose | Bundling every use under 'health and safety' |
| Emergency route | When vital interests genuinely apply and how incapacity and necessity are recorded | Using emergency language for routine processing |
Not automatically. Valid GDPR consent must be freely given, specific, informed and unambiguous, and explicit consent is one possible Article 9 condition. It must also be as easy to withdraw as to give. In an employment or offshore emergency setting, imbalance, dependency, safety pressure and the practical consequences of refusal can mean the person lacks a genuine free choice. EDPB consent guidance says employers are unlikely to be able to rely on employee consent for most workplace processing unless refusal or withdrawal produces no detriment.
Clinical consent to examination or treatment is a separate question from the data-protection basis for processing records. A clinician may need valid clinical consent while the controller relies on another lawful basis and Article 9 condition for necessary record processing. Conversely, a signed privacy form does not establish informed consent to treatment. Procedures and notices should keep those concepts distinct so that neither is overstated.
If explicit consent is genuinely selected for an optional processing purpose, document the choice, information provided, affirmative action, withdrawal method and consequences of withdrawal. Do not make necessary emergency care or mandatory employment processing appear optional, and do not promise deletion after withdrawal when another legal duty requires retention.
Controller and processor are functional roles. The controller determines the purposes and essential means of processing; a processor handles personal data on a controller's behalf and instructions. Contract labels are relevant evidence but are not decisive if the real activity differs. The same provider can be a processor for one operation and an independent controller for another, and two parties can be joint controllers where they jointly determine purposes and essential means.
A telemedicine provider should not be assumed to be only a processor. Where regulated clinicians decide what clinical information to collect, how to assess and document the patient, who receives a clinical handover and how long professional records must be retained, the provider may determine purposes or essential means for at least part of the clinical processing. The employer or operator may separately control activation lists, occupational follow-up, incident management or service-performance reporting. The correct answer must be mapped purpose by purpose.
EDPB Guidelines 07/2020 require the allocation to reflect factual roles. If a party is a processor, Article 28 requires a binding contract covering subject matter, duration, nature and purpose, data types, data subjects, instructions, confidentiality, security, subprocessors, rights assistance, breach and DPIA assistance, deletion or return, and audit information. If parties are joint controllers, Article 26 requires a transparent arrangement allocating responsibilities, without reducing the individual's ability to exercise rights against each controller.
| Processing activity | Role question | Evidence |
|---|---|---|
| Clinical consultation and record | Who decides the clinical purpose, necessary content, recipients and professional retention? | Clinical governance, record policy and applicable healthcare law |
| Employee activation and eligibility | Who decides which workers are enrolled and what administrative data is supplied? | Employer or operator process and privacy notice |
| Platform hosting and support | Does the supplier act only on documented instructions? | Article 28 terms, subprocessors and access logs |
| Anonymised or aggregated reporting | Is re-identification reasonably possible, and who defines the reporting purpose? | Aggregation method, small-cell controls and role assessment |
| Incident and occupational follow-up | Is information used for a new employment, safety or insurance purpose? | Purpose, lawful basis, access boundaries and retention |
The ship's position is not the only location that matters. Start with GDPR Article 3: processing can fall within GDPR because it occurs in the context of an EU establishment or because a non-EU organisation offers goods or services to, or monitors the behaviour of, people in the Union. Then analyse Chapter V separately. Under EDPB Guidelines 05/2021, a transfer generally involves a controller or processor subject to GDPR disclosing or making personal data available to a different controller or processor in a third country or international organisation.
Map storage, backup, clinical access, technical support, subprocessors and onward disclosure. Access granted to a separate overseas supplier can be a transfer even when the database remains in Europe. By contrast, an employee of the same controller remotely accessing its own systems while travelling is not, on that fact alone, a transfer between two separate parties under the EDPB test—although security, territorial law and accountability risks still need assessment.
Where Chapter V applies, identify a valid route such as an adequacy decision or appropriate safeguards under Article 46, which can include the European Commission's Standard Contractual Clauses. Safeguards are not a paperwork endpoint: following the Court of Justice's Schrems II judgment and EDPB recommendations, exporters must assess whether the destination's law and practice affect the safeguard and adopt supplementary measures where necessary. Article 49 derogations are exceptions and should not become the routine architecture for a standing telemedicine service.
Article 32 requires controllers and processors to implement technical and organisational measures appropriate to risk, considering the state of the art, implementation cost, processing context and the likelihood and severity of harm. The Regulation names measures such as pseudonymisation and encryption where appropriate, ongoing confidentiality, integrity, availability and resilience, timely restoration, and regular testing. It does not prescribe one universal encryption product, hosting region or certification.
For offshore telemedicine, the security design should follow the actual data flow: authenticated users and role-based access; least privilege for employer, clinical and technical teams; secure primary and fallback communications; protected local devices and cached data; encryption in transit and at rest where appropriate; audit logs; controlled record export; tested backup and restoration; subprocessor oversight; access removal; and procedures for lost devices or communications. Confidentiality must survive a crowded bridge, control room or accommodation environment, not only a penetration test.
Data minimisation does not mean collecting too little for safe care. Collect what is adequate, relevant and necessary for the defined clinical and operational purpose, separate access where purposes differ, and retain records according to applicable healthcare, employment and limitation rules rather than an arbitrary short period or 'forever'. Provide the information required by Articles 13 or 14 in a form workers can actually understand before routine use, with an emergency pathway for information that cannot be delivered immediately.
A personal-data breach is broader than disclosure: loss of availability or integrity can qualify too. A processor must notify its controller without undue delay after becoming aware. A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk people's rights and freedoms; high-risk breaches can also require communication to affected people. Contractual targets should leave the controller enough time to assess and meet its own deadline.
Article 35 requires a data protection impact assessment before processing likely to result in high risk to individuals, particularly when new technologies, nature, scope, context and purposes are considered. It specifically identifies large-scale processing of special-category data as a case requiring a DPIA. Supervisory authorities publish additional required-processing lists, so the applicable national list must also be checked.
Not every individual telemedical call automatically makes the service 'large scale', and the GDPR does not define the conclusion by vessel count alone. But a fleet-wide platform combining health data, employee identity, continuous availability, multiple jurisdictions, new technology, vulnerable or dependent workers, remote access and emergency decision support can accumulate several high-risk indicators. If there is doubt, documenting a DPIA is often the clearer accountability route, but the assessment must remain specific rather than a generic vendor questionnaire.
The DPIA should describe purposes and data flows, assess necessity and proportionality, identify risks to people—not only corporate cyber risk—and record measures and residual risk. It should cover clinical confidentiality, inappropriate employer access, mistaken identity, unavailable or altered records, overseas access, excessive retention, inability to exercise rights, bystander disclosure and emergency workarounds. Consult the data protection officer where designated. If high residual risk remains that cannot be mitigated, Article 36 requires prior consultation with the supervisory authority before processing.
A buyer should ask for an evidence pack that joins the legal analysis to the operating model. Security certificates and a data-processing agreement can support that pack, but neither proves that purposes, roles, health-data conditions or offshore workflows are correct. The review should be repeated when the clinical model, platform, subprocessors, hosting, jurisdictions, worker population or data uses materially change.
| Check | Required decision or artefact | Red flag |
|---|---|---|
| Scope and data map | Entities, establishments, people, purposes, systems, access and countries | Only the server region is mapped |
| Lawful processing | Article 6 basis and Article 9 condition per purpose and controller | One blanket consent form |
| Roles | Factual controller, joint-controller and processor analysis per activity | Provider labelled processor for every clinical use |
| Contracts | Article 28 terms where applicable and Article 26 arrangement where jointly determined | DPA used instead of a role assessment |
| Transparency and rights | Layered notices, intake information and owned request workflow | Workers told only to ask their employer |
| Transfers | Importer map, adequacy or safeguard, assessment and supplementary measures | EU hosting claimed while overseas support has access |
| Security | Risk-based controls, testing, restoration, logs and offshore device procedure | Certification presented as the entire control set |
| Retention and exit | Purpose-specific schedule, legal basis, record handover and deletion boundaries | Immediate deletion promised despite clinical duties |
| DPIA and governance | Current DPIA decision, DPO input, owners and residual-risk approval | Generic supplier DPIA with no casualty pathway |
| Breach response | Processor escalation, controller assessment and 72-hour workflow | Contract permits notification after the legal window |
Alvyri Crew provides clinically-led telemedicine for offshore wind and maritime crews.