Industry starterIndustry-Specific

Healthcare (EU — GDPR) policy template

Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.

Start with controls for special-category health data under GDPR Article 9. The template adds data minimization, purpose limits and safeguards for automated decisions. It also maps bias monitoring, transparency and human oversight to EU AI Act risk programs. Complete an independent legal and risk assessment before use.

Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.

Regions

EU, EEA, UK

Source references

8 source references

Control areas

5 mapped control areas

Deployment options

Regulated SaaS, Sovereign region

Source frameworks, standards and obligations

GDPR Art. 9 (Special Category Health Data)GDPR Art. 22 (Automated Decision-Making)GDPR Art. 35 (Data Protection Impact Assessment)EU AI Act (High-Risk — Annex III §5)Medical Device Regulation 2017/745 (MDR)Clinical Trials Regulation 536/2014ePrivacy Directive 2002/58/ECNIS2 Directive (Healthcare Sector)

Control areas mapped by this template

Data privacy
AI governance
Audit logging
Human oversight
Bias monitoring

Deployment options

Regulated SaaS
Sovereign region

Adapt the template in three steps

1

Review the scope

Confirm that the regions, source references, control areas and deployment options fit your use case.

2

Adapt the configuration

Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.

3

Test before deployment

Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.