Healthcare privacy & erasure
P11.applied-llm-systems.04 · Audience: guest, it-ml, language-pro · Prerequisites: Applied LLMOps
A symptom typed into a search box is health data, and under the GDPR health data is not ordinary personal data — Article 9 classifies it as special-category and prohibits processing it at all unless a specific condition applies, such as explicit consent or the provision of health or social care. For the search and assistant we have been building, that changes the design itself, not just the paperwork around it. This module draws the boundary that keeps identifying and health-revealing data out of prompts, logs, and third-party model providers, then follows a right-to-erasure request outward from the system of record to every derived copy — embeddings, indexes, and caches included. Related operational and governance angles live in P13's MLOps material and P16's governance pillar.
Ordinary personal data follows GDPR's general rules. Health data — and anything from which health can be inferred — is special-category under Article 9, which prohibits processing unless a specific condition applies (explicit consent, or health/social-care provision).
| Concept | What it means here |
|---|---|
| Special category (Art. 9) | symptoms, conditions, a cardiology booking — process only under an Art. 9 condition |
| Lawful basis | explicit consent, or health/social-care provision — documented |
| EU data residency | a third-party LLM API call can be a cross-border transfer needing safeguards |
| Inference risk | even a search query (“Spanish-speaking oncologist”) can reveal a condition |
⚠️ A symptom typed into a search box is health data — including in logs, caches, and anything sent to a model provider.
⚡ Interview Ref — the quick-scan Reference face
- Art. 9: health data (and anything health-inferring) is special-category — processing prohibited without a condition (explicit consent / health-care provision). A search query can reveal a condition.
- Before the model: PII-before-LLM boundary; prompts/logs/caches are not safe stores; vendor API = new processor + cross-border; purpose limitation (no silent reuse for training).
- Privacy-by-design + DPIA: minimization/pseudonymization/access control built in; DPIA required for high-risk special-category processing.
- Right to erasure: propagate outward — source → embeddings → ANN index → caches → logs → trained weights (hard, only approximable).
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Try it yourself
A scratch console for this page's ideas — ungraded, nothing you run here is recorded.
Scratch console
A scratch console with the scientific stack (pandas, numpy, scikit-learn). Runs on the server — no network, resource-limited and measured.
Output appears here.
My notes on this module
Loading your notes...
Where next?
Later in Applied LLM Systems & Agents