Healthcare privacy & erasure

P11.applied-llm-systems.04 · Audience: guest, it-ml, language-pro · Prerequisites: Applied LLMOps

A symptom typed into a search box is health data, and under the GDPR health data is not ordinary personal data — Article 9 classifies it as special-category and prohibits processing it at all unless a specific condition applies, such as explicit consent or the provision of health or social care. For the search and assistant we have been building, that changes the design itself, not just the paperwork around it. This module draws the boundary that keeps identifying and health-revealing data out of prompts, logs, and third-party model providers, then follows a right-to-erasure request outward from the system of record to every derived copy — embeddings, indexes, and caches included. Related operational and governance angles live in P13's MLOps material and P16's governance pillar.

Step 1 / 4 — Health data is Art. 9 special-category

Ordinary personal data follows GDPR's general rules. Health data — and anything from which health can be inferred — is special-category under Article 9, which prohibits processing unless a specific condition applies (explicit consent, or health/social-care provision).

ConceptWhat it means here
Special category (Art. 9)symptoms, conditions, a cardiology booking — process only under an Art. 9 condition
Lawful basisexplicit consent, or health/social-care provision — documented
EU data residencya third-party LLM API call can be a cross-border transfer needing safeguards
Inference riskeven a search query (“Spanish-speaking oncologist”) can reveal a condition

⚠️ A symptom typed into a search box is health data — including in logs, caches, and anything sent to a model provider.

⚡ Interview Ref — the quick-scan Reference face
  • Art. 9: health data (and anything health-inferring) is special-category — processing prohibited without a condition (explicit consent / health-care provision). A search query can reveal a condition.
  • Before the model: PII-before-LLM boundary; prompts/logs/caches are not safe stores; vendor API = new processor + cross-border; purpose limitation (no silent reuse for training).
  • Privacy-by-design + DPIA: minimization/pseudonymization/access control built in; DPIA required for high-risk special-category processing.
  • Right to erasure: propagate outward — source → embeddings → ANN index → caches → logs → trained weights (hard, only approximable).
Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send

Try it yourself

A scratch console for this page's ideas — ungraded, nothing you run here is recorded.

Scratch console

A scratch console with the scientific stack (pandas, numpy, scikit-learn). Runs on the server — no network, resource-limited and measured.

Output appears here.

My notes on this module

Loading your notes...

Where next?

Continue

LLM economics & agentic design →

Applied LLM Systems & Agents · P11

Later in Applied LLM Systems & Agents

Healthcare privacy & erasure — TransformerLab