Evidence map›Paper›PMID 42304949›Full record

ReviewJMIR medical informatics2026

Dynamic Consent for Secondary Use of Health Data: Challenges and Opportunities Under European Law.

Sudip Phuyal, Manila Bhandari, Ricardo Correia Bezerra, Rabindra Bista, João Carlos Ferreira

Abstract readReview
In one paragraph

Review in JMIR medical informatics, 2026. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Cited by 1 paper.

0numbers the graph read from it
0cells of the map it votes in
1citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

1 citing paper in PubMed.

  1. Review
4 · The record

Corrections and comments

PubMed lists nothing against this paper. Absence here is not a guarantee, only a check that was made.

5 · Who and what money

Authors and funding

5 authors.

Sudip PhuyalInformation Sciences, Technology and Architecture Research Center (ISTAR), Iscte - Instituto Universitário de Lisboa, Lisbon, Portugal.ORCID 0000-0001-7524-1843
Manila BhandariInformation Sciences, Technology and Architecture Research Center (ISTAR), Iscte - Instituto Universitário de Lisboa, Lisbon, Portugal.ORCID 0000-0002-8354-581X
Ricardo Correia BezerraBioGHP - Global Health Platform S.A., Porto, Portugal.ORCID 0009-0005-1237-6632
Rabindra BistaDepartment of Computer Science and Engineering, Kathmandu University, Dhulikhel, Nepal.ORCID 0000-0002-0638-5840
João Carlos FerreiraInformation Sciences, Technology and Architecture Research Center (ISTAR), Iscte - Instituto Universitário de Lisboa, Lisbon, Portugal.ORCID 0000-0002-6662-0806

Funding

No grant is acknowledged in the PubMed record.

6 · The paper itself

Abstract

Unlabelled: Secondary use of health data is essential for advancing medical research, innovation, and public health policy across Europe. Traditional static or broad consent models are increasingly inadequate in complex, multistakeholder digital ecosystems. Dynamic consent, which enables granular, interactive, and ongoing management of individual preferences, including revocation, has emerged as a patient-centered alternative. This integrative review examines the legal feasibility and practical challenges of implementing dynamic consent for secondary health data use under the General Data Protection Regulation (GDPR) and the European Health Data Space (EHDS) Regulation. Drawing on doctrinal legal analysis, European policy documents, national derogations, and technical standards including Health Level Seven Fast Healthcare Interoperability Resources, electronic Identification, Authentication and Trust Services 2.0, European Digital Identity Wallet, and distributed ledger approaches, the study synthesizes legal, governance, and informatics perspectives. Findings indicate that while the GDPR establishes parameters supportive of specific, informed, and revocable consent, significant barriers persist due to national fragmentation, divergent lawful bases for processing, and limited cross-border revocation mechanisms. The EHDS, with provisions phasing in from 2029, shifts governance toward institutional authorization via Health Data Access Bodies and secure processing environments, reducing reliance on individual consent for many large-scale uses. Technical prerequisites, machine-readable consent artifacts, high-assurance digital identity, and policy-based enforcement remain unevenly developed. Nevertheless, integration with data altruism mechanisms under the Data Governance Act and emerging interoperability tools offers promising pathways. A 3-stage operational architecture (consent administration, decision, and enforcement) is proposed to embed dynamic consent within the hybrid EHDS-GDPR framework. However, challenges including blockchain immutability conflicts with the right to erasure, revocation propagation across systems, implementation costs, consent fatigue, and digital divides must be addressed. Dynamic consent cannot serve as a universal solution but can meaningfully enhance transparency and trust when deployed contextually alongside institutional safeguards. Coordinated EU-level harmonization, standardization, and inclusive design will be essential for its successful operationalization.

Indexed as

Computer SecurityConfidentialityElectronic Health RecordsInformed ConsentDigital HealthEuropeHumansblockchaindigital identitydynamic consentEHDSEuropean Health Data SpaceGDPRGeneral Data Protection Regulationinteroperabilitysecondary use of health data

Identifiers

PMID42304949
PMCPMC13272879

What OpenQuestion holds

Textmetadata
LicenceCC BY
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the OpenQuestion graph.