EHDS Compliance Overview
HDAB approval chain · Regulation (EU) 2025/327, Art. 67 to 73
The EHDS Compliance Matrix shows the approval chain status for every dataspace participant. Under Regulation (EU) 2025/327, secondary use of health data requires a complete chain:
- Access Application · the data user applies with purpose, justification and ethics assessment (Art. 67)
- HDAB decision · the health data access body assesses the Art. 68(1) criteria and issues or refuses a data permit within three months (Art. 68)
- Dataset Grant · the permit names the dataset it grants access to (Art. 68(3))
- Contract · the data user accesses the data only under that permit, in a secure processing environment (Art. 61(1), Art. 73)
Decision due: the date by which the access body must issue or refuse the data permit: three months after it received the application (Art. 68(4)). Late means the body has done neither by that date. The applicant may not access any data until it decides (Art. 61(1)), and the application and the decision must be published (Art. 57(1)(j)). The delay is the access body's compliance issue, not the applicant's.
Click a row for the application and the chain. Signed in as the access body, the row also carries the decision: a refused or missing permit blocks the transfer in step 5.
Participant Compliance Matrix
EHDS Verifiable Credentials
DCP credential definitions registered on IssuerService — presented during DSP negotiation
DCP Trust Chain — Credential Presentation Flow
Trust Center — Pseudonym Resolution
EHDS Art. 50/51 — HDAB-designated trust centers enabling cross-provider longitudinal patient linkage without exposing real identities to researchers. Provider pseudonyms are resolved to research pseudonyms inside the Secure Processing Environment only.