Civil Law And Wearable Device Data Ownership Disputes In Europe .

Civil Law and Wearable Device Data Ownership Disputes in Europe

Wearable-device data disputes are becoming an important area of European civil and digital law. Smartwatches, fitness trackers, smart rings, medical wearables and similar connected devices can generate enormous quantities of information, including:

heart rate;

pulse and oxygen saturation;

sleep patterns;

body temperature;

activity and exercise data;

location;

biometric information;

calorie expenditure;

stress indicators;

menstrual or reproductive information;

medical measurements;

device-generated behavioural profiles.

The expression “data ownership”, however, requires an important qualification. European law generally does not treat personal data as an ordinary item of property that is simply “owned” by the individual or manufacturer. Instead, the legal framework distributes rights of access, control, portability, use, sharing and protection among the data subject, user, manufacturer, platform and other data holders.

This distinction has become particularly important since the EU Data Act has applied from 12 September 2025. It gives users of connected products important rights to access and share data generated by those products, while the GDPR continues to govern personal-data processing. (EUR-Lex)

1. What Is Wearable-Device Data?

Wearable-device data can broadly be divided into several categories.

A. Raw sensor data

Examples:

heart-rate measurements;

accelerometer readings;

gyroscope readings;

temperature readings;

GPS coordinates.

B. Processed data

The manufacturer may transform raw measurements into:

sleep scores;

fitness scores;

recovery scores;

stress scores;

cardiovascular estimates.

C. Health information

Data may reveal:

disease;

physical condition;

disability;

medical risk;

physiological condition.

The GDPR defines health data broadly, covering information revealing past, current or future physical or mental health. The CJEU has emphasised that the concept should be interpreted broadly. (EUR-Lex)

D. Derived or inferred information

An algorithm may infer:

“This user is probably suffering from sleep deprivation.”

That inference may itself become legally important even though the wearable did not directly measure “sleep deprivation.”

2. The Central Question: Who Owns the Data?

The simplest answer is:

European law generally does not create a conventional ownership right over personal data comparable to ownership of a physical object.

Instead, different legal regimes provide different rights.

The individual may have:

GDPR access rights;

rectification rights;

erasure rights;

restriction rights;

objection rights;

data-portability rights;

rights concerning automated decision-making.

The user of a connected wearable may additionally have rights under the Data Act to access product and related-service data.

The manufacturer may have:

contractual rights;

database-related interests;

intellectual-property rights;

trade-secret protection;

rights concerning non-personal derived datasets.

Therefore:

“Who owns the data?” is usually the wrong legal question.

The better questions are:

Who is the data subject?

Who is the user of the connected product?

Who is the data holder?

Who is the controller under GDPR?

What data are personal?

What data are non-personal?

Who has a right to access them?

Who may use them?

For what purpose?

Can they be transferred to a third party?

3. The EU Data Act Changes the Position of Wearable Users

The Data Act is particularly important for smartwatches and fitness trackers.

It applies to connected products and related services and has applied since 12 September 2025. (EUR-Lex)

A connected product's user generally receives rights to access data generated by use of that product.

The Regulation specifically addresses situations in which manufacturers technically control access to product-generated data despite not necessarily having a legal ownership right over those data. (EUR-Lex)

4. What Does the User Receive Under the Data Act?

Article 3 requires connected products to be designed so that relevant product and related-service data are, by default:

easily accessible;

securely accessible;

free of charge to the user;

structured;

commonly usable;

machine-readable.

Where appropriate and technically feasible, the data should be directly accessible. (EUR-Lex)

If the data cannot be directly accessed, the data holder generally must make readily available data accessible to the user without undue delay.

5. Wearable Manufacturer Versus Wearable User

Consider:

A consumer buys a smartwatch for €500.

The watch generates:

10 million heart-rate measurements;

GPS data;

sleep information;

exercise information.

The manufacturer stores everything on its cloud platform.

The manufacturer might argue:

“The data are stored on our servers and generated by our proprietary technology.”

The Data Act substantially weakens the idea that technical possession automatically determines legal access.

The user can have legally protected access rights even though the manufacturer operates the server infrastructure. (EUR-Lex)

6. GDPR and Data Act Operate Together

This is extremely important.

The Data Act does not replace the GDPR.

The Data Act expressly preserves data-protection rights.

For example:

A user may request wearable data from the manufacturer.

But if the dataset also contains information about another person, the manufacturer cannot simply disclose that person's personal data without an appropriate legal basis.

The Data Act therefore interacts with:

GDPR Article 6;

GDPR Article 9;

GDPR Article 15;

GDPR Article 20.

The Data Act can provide broader access to product-generated data, including non-personal data, while GDPR continues to govern personal-data processing. (EUR-Lex)

7. Health Data Is Particularly Sensitive

Wearable data frequently qualify as health data.

For example:

A smartwatch records resting heart rate, sleep patterns and oxygen saturation.

Individually, a measurement may appear innocuous.

But combined datasets may reveal a person's health condition.

Under GDPR, health data belong to a special category of personal data.

Processing therefore receives enhanced protection.

8. Case Law 1 — CJEU, C-434/16, Nowak v Data Protection Commissioner

Facts

Mr Nowak requested access to information relating to a professional examination, including his written answers and examiner comments.

Legal issue

The Court had to determine what constitutes “personal data.”

Judgment

The CJEU adopted a broad approach to personal data.

Information can qualify as personal data where it is linked to an identifiable individual and is relevant to that individual's circumstances, evaluation or rights. (EUR-Lex)

Wearable-data significance

This reasoning is important because wearable datasets can contain enormous quantities of information about the individual.

It supports the proposition that:

Personal data is not restricted to conventional identifiers such as name and address.

A person's physiological measurements and behavioural records may fall within the concept.

9. Case Law 2 — CJEU, C-582/14, Breyer v Germany

Facts

Patrick Breyer challenged the storage of dynamic IP addresses by German public websites.

Judgment

The Court held that dynamic IP addresses can constitute personal data where the website operator has legal means enabling the individual to be identified using additional information held by another party. (EUR-Lex)

Importance for wearables

This case demonstrates that identification does not require the data holder to possess every piece of identifying information itself.

Wearable information can therefore remain personal data even where:

the device uses a pseudonymous ID;

the manufacturer does not display the user's name;

identification requires another dataset.

Principle

Pseudonymisation or indirect identification does not automatically remove data from the personal-data regime.

10. Case Law 3 — CJEU, C-210/16, Wirtschaftsakademie Schleswig-Holstein

Facts

A company operated a Facebook fan page.

Facebook processed visitor information for analytics and advertising.

The question was whether the fan-page administrator could itself be regarded as a controller.

Judgment

The CJEU recognised that more than one entity can participate in determining the purposes and means of processing and can therefore be a joint controller. (EUR-Lex)

Wearable significance

Imagine:

User → smartwatch manufacturer → health platform → insurance analytics provider

The legal responsibility may not necessarily rest exclusively with the manufacturer.

Different entities can have different roles in processing.

Principle

Control over personal-data processing can be shared among multiple actors.

This is extremely important in wearable ecosystems.

11. Case Law 4 — CJEU, C-25/17, Jehovan todistajat

The CJEU further developed the concept of joint controllership.

The Court emphasised that an entity does not need to possess the data physically to have a role as controller; what matters is whether it exercises influence over the purposes and means of processing.

Wearable application

A fitness platform might argue:

“The smartwatch manufacturer owns the servers, so we are merely receiving data.”

That statement would not necessarily determine the GDPR classification.

The court would examine:

who determines purposes;

who determines means;

who benefits from processing;

who decides how the data are used.

12. Case Law 5 — CJEU, C-683/21, Nacionalinis visuomenės sveikatos centras

This 2023 judgment concerned a mobile health application and the concepts of:

controller;

processor;

responsibility for processing.

The Court emphasised that controller status depends on whether an entity actually influences the purposes and means of processing, rather than simply on formal designation. (EUR-Lex)

Wearable significance

This is highly relevant to wearable ecosystems.

Imagine:

Smartwatch → manufacturer app → hospital app → cloud provider

The contractual labels do not necessarily determine who is legally responsible.

The factual reality of the data-processing relationship matters.

13. Case Law 6 — CJEU, C-252/21, Meta Platforms

Facts

The case concerned Meta's processing of personal data and the interaction between:

GDPR;

consent;

legitimate interests;

competition law.

Judgment

The Court examined the lawfulness of extensive personal-data processing and the conditions under which consent and other legal bases can justify processing. (EUR-Lex)

Wearable significance

Suppose a wearable company says:

“You accepted our general terms, so we can use all your health and activity information for advertising.”

That proposition cannot simply be assumed to be lawful.

The company must identify an appropriate GDPR legal basis, and special-category data may require additional conditions.

Principle

Contractual acceptance does not automatically make every form of personal-data processing lawful.

14. Case Law 7 — CJEU, C-667/21, ZQ v Medizinischer Dienst

This 2023 judgment concerned processing of employee health data.

The Court confirmed the particularly protected nature of health information and emphasised requirements concerning:

lawful processing;

confidentiality;

technical and organisational security;

appropriate safeguards. (EUR-Lex)

The Court also explained that compensation under GDPR Article 82 is compensatory rather than punitive. (EUR-Lex)

Wearable significance

If an employer requires employees to wear health-monitoring devices, the resulting data can create serious legal issues concerning:

employer access;

employee privacy;

health-data processing;

security;

monitoring;

compensation for unlawful processing.

15. Case Law 8 — CJEU, C-21/23, ND v DR

This case is especially relevant to the broad concept of health data.

The Court examined whether information can constitute health data even where it does not directly state a medical diagnosis.

The Court accepted that information can qualify where it permits conclusions to be drawn about an individual's health. (EUR-Lex)

Wearable significance

This is crucial.

Suppose a wearable records:

sleep;

exercise;

heart rate;

medication-related behaviour.

An algorithm may infer:

“The user may have cardiovascular problems.”

The underlying data and resulting inferences may therefore have significant GDPR consequences.

16. Case Law 9 — CJEU, C-131/12, Google Spain

The Google Spain litigation established important principles concerning personal-data protection and the right to request removal of certain search results.

Wearable significance

It reinforces a broader principle:

Personal-data protection gives individuals legally enforceable control over certain uses of information concerning them.

However, this does not mean a person acquires conventional ownership over every digital representation of themselves.

17. What Exactly Is “Owned”?

It is useful to divide wearable information into categories.

DataPossible legal position
Raw heart-rate dataPersonal data; user access rights
GPS locationPersonal data
Sleep recordsPotentially health data
Device serial numberIdentifier
Aggregated anonymous statisticsMay cease to be personal data
Manufacturer algorithmIntellectual property
Fitness scorePotential personal data
AI-generated health inferencePotential personal/health data
Proprietary softwareManufacturer's IP
Database structurePossible database/IP protection

Thus, ownership of the wearable device, ownership of software, control of servers and rights over generated data are separate legal questions.

18. The Data Act and “Data Holder”

The Data Act introduces the concept of a data holder.

A data holder is broadly the person or entity with the right or obligation, under the Regulation, other EU law or national law, to use and make available relevant data. (EUR-Lex)

This is important because:

The manufacturer may be the data holder without becoming the “owner” of the user's personal data in a traditional property-law sense.

19. User Rights Under the Data Act

A wearable user may have rights to:

access product data;

receive relevant metadata;

obtain data in machine-readable form;

share data with a third party;

use another service provider;

facilitate switching;

challenge unlawful contractual restrictions.

The Regulation expressly seeks to make product-generated data more accessible to users. (EUR-Lex)

20. Example: Switching Fitness Platforms

Suppose a consumer has used a smartwatch for ten years.

The manufacturer has accumulated:

3,000 workouts;

2,000 sleep records;

years of heart-rate information.

The consumer switches to another fitness platform.

The manufacturer says:

“Your historical data cannot leave our ecosystem.”

The Data Act substantially changes this type of dispute.

The user may have statutory rights to access and share relevant product-generated data, subject to GDPR, trade-secret and other legal safeguards.

21. Contractual Clauses Attempting to Claim Exclusive Data Ownership

A manufacturer's terms might say:

“All data generated by your device belong exclusively to the manufacturer.”

Such a clause should not automatically be treated as decisive.

The court would ask:

Is the data personal?

Is the user a data subject?

Does the Data Act apply?

Is the clause compatible with mandatory EU law?

Is the clause transparent?

Does it unlawfully restrict statutory access rights?

Does it concern non-personal data or personal data?

Does another person's data appear in the dataset?

22. Unfair Contract Terms

Consumer contracts can also be challenged under European consumer-protection law.

A particularly problematic clause might say:

“The manufacturer may use all data generated by the device for any purpose whatsoever, permanently and worldwide.”

Questions may arise regarding:

transparency;

fairness;

scope;

purpose limitation;

consent;

statutory rights.

A contractual clause cannot simply override mandatory GDPR or Data Act rights.

23. Health-Insurance Use

A particularly contentious issue is insurance.

Suppose:

An insurer offers lower premiums if a customer shares smartwatch data demonstrating regular exercise.

The customer agrees.

Later, the insurer wants to use the same information to increase premiums because the customer sleeps poorly.

Potential issues include:

purpose limitation;

transparency;

consent;

health-data protection;

contractual fairness;

automated decision-making.

The original consent or contract does not necessarily authorise every subsequent purpose.

24. Employer Use of Wearable Data

Employer monitoring creates even greater risks.

Imagine:

An employer provides employees with smartwatches measuring heart rate, movement and sleep.

The employer claims the information is necessary to improve workplace productivity.

Potential legal issues include:

GDPR;

employment law;

proportionality;

health-data restrictions;

employee consent;

workplace surveillance.

A worker cannot necessarily be expected to surrender comprehensive physiological information simply because the device is employer-provided.

25. Medical Wearables

A wearable may qualify as a medical device or operate as part of a medical service.

This creates overlapping regulation concerning:

medical-device law;

GDPR;

health records;

patient rights;

cybersecurity.

If the wearable produces clinically significant information, the legal consequences of data misuse may be much greater.

26. Data Portability Versus Data Access

These concepts should not be confused.

GDPR portability

Article 20 GDPR provides a right to receive certain personal data and transmit it to another controller under specified conditions.

Data Act access

The Data Act creates broader access rights for product and related-service data.

It can cover:

personal data;

non-personal data;

passively generated data;

actively generated data.

The Data Act therefore complements, rather than simply duplicates, GDPR portability. (EUR-Lex)

27. Raw Data Versus Derived Data

This is likely to become one of the most important future litigation issues.

Suppose a smartwatch measures:

Heart rate: 95 bpm.

The manufacturer calculates:

“Cardiovascular fitness score: 78.”

Who has rights over the score?

The legal analysis may differ from that for the raw measurement.

The manufacturer may argue that:

the score is generated by proprietary algorithms;

the methodology is a trade secret;

the score constitutes derived information.

The user may argue that:

the score concerns them;

it was generated from their device use;

it should be accessible.

The Data Act's treatment of product and related-service data will therefore become increasingly important.

28. Trade Secrets

The Data Act does not abolish trade-secret protection.

Suppose:

A manufacturer uses proprietary algorithms to convert sensor data into health predictions.

The user may have a right to the relevant data, but that does not necessarily give the user a right to demand:

source code;

proprietary algorithms;

internal model parameters.

The legal system attempts to balance:

user access ↔ innovation/trade secrets.

29. Intellectual Property

A wearable manufacturer may possess intellectual-property rights over:

software;

algorithms;

interface design;

databases;

device technology.

But:

IP ownership in the technology does not automatically mean ownership of every personal datum generated through its operation.

This distinction is fundamental.

30. Anonymised Data

Suppose the manufacturer aggregates information from:

10 million users.

It produces:

“Average heart rate among users aged 30–40.”

If genuinely anonymised, the dataset may fall outside the GDPR.

However, anonymisation must be genuine.

Pseudonymisation is not the same as anonymisation.

31. Re-identification

A manufacturer may say:

“The data are anonymous because we removed the names.”

That may not be sufficient.

If the person can reasonably be re-identified through:

account IDs;

device IDs;

location;

timestamps;

external databases,

the information may remain personal data.

The logic of Breyer is important here: indirect identifiability can be legally sufficient. (EUR-Lex)

32. Multiple Users of One Wearable

The Data Act expressly contemplates situations in which several persons use a connected product.

For example:

A family shares a smart fitness device.

Different people may have different rights concerning data generated through their use.

The Data Act recognises the need for mechanisms allowing separate users to access their relevant data. (EUR-Lex)

This creates potentially difficult civil disputes concerning:

shared accounts;

spouses;

family members;

children;

carers.

33. Children and Wearable Data

Children's wearable data create heightened privacy concerns.

Examples include:

GPS location;

sleep;

heart rate;

school movement patterns.

Parents may purchase the device, but that does not necessarily mean the parent acquires unlimited rights to every piece of the child's personal data.

Questions of:

parental authority;

GDPR;

best interests of the child;

national family law

can become relevant.

34. Data Breach Liability

Suppose a fitness company's database is hacked and millions of wearable records are disclosed.

Potential claims can involve:

GDPR;

contractual liability;

tort/delict;

confidentiality;

damages.

Under GDPR Article 82, a person suffering qualifying damage from unlawful processing may seek compensation.

The CJEU's health-data jurisprudence confirms the importance of appropriate security and confidentiality measures. (EUR-Lex)

35. Civil Damages

Possible damages include:

Material damage

financial loss;

fraud resulting from disclosure;

costs of protective measures.

Non-material damage

distress;

loss of control over personal information;

privacy harm.

But compensation is not automatically available simply because a technical GDPR violation occurred. The claimant must establish the legally relevant damage under the applicable framework.

36. Data Ownership After Sale of the Device

Suppose:

A consumer sells a smartwatch to another person.

The physical device changes owner.

Does the buyer automatically obtain the previous owner's data?

No.

Physical ownership of the wearable and legal rights over personal data are distinct.

The previous user may need to:

delete the account;

erase locally stored information;

terminate cloud access;

disconnect the device.

The Data Act itself recognises situations involving changes in ownership or usage and contemplates mechanisms for deleting accounts and terminating data access. (EUR-Lex)

37. Data Stored in the Cloud

A common misconception is:

“The data are on the manufacturer's servers, so the manufacturer owns them.”

Server possession is not equivalent to ownership.

A cloud provider may simply process information on behalf of another controller.

The Nacionalinis visuomenės sveikatos centras judgment demonstrates why actual control over purposes and means matters when determining responsibility. (EUR-Lex)

38. Civil Contract Disputes

A wearable data dispute can be framed as a contractual dispute where:

the company promised data access;

the company promised deletion;

the company promised portability;

the company promised a particular data-retention period;

the company changed terms;

the company restricted third-party integration.

The user might seek:

specific performance;

access to data;

injunction;

damages;

termination;

restitution.

39. Hypothetical Case

Facts

A consumer purchases a smart ring.

It collects:

sleep data;

heart-rate data;

temperature;

exercise information.

The manufacturer stores everything on its cloud.

The consumer changes providers.

The manufacturer refuses to provide the historical dataset and claims:

“All data belong to us under the terms of service.”

Legal analysis

The consumer may argue:

the information is personal data;

health information receives special protection;

GDPR access rights apply;

GDPR portability may apply;

the Data Act provides connected-product data access rights;

the contractual clause cannot override mandatory statutory rights.

The manufacturer may argue:

some information constitutes proprietary derived data;

trade secrets must be protected;

some data concern other persons;

certain algorithms are intellectual property.

A court would need to separate:

personal data + product data + derived data + proprietary technology + third-party data.

40. Important Case-Law Table

CaseCourtCore principleWearable relevance
Nowak, C-434/16CJEUBroad concept of personal dataSensor and behavioural information
Breyer, C-582/14CJEUIndirect identifiability can make data personalDevice IDs/pseudonymous data
Wirtschaftsakademie, C-210/16CJEUJoint controllershipManufacturer/platform relationships
Jehovan todistajat, C-25/17CJEUFunctional approach to controller statusWearable ecosystem responsibility
Nacionalinis visuomenės sveikatos centras, C-683/21CJEUActual influence determines controller statusHealth apps/cloud providers
Meta Platforms, C-252/21CJEULawfulness, consent and extensive data processingAdvertising/analytics using wearable data
ZQ, C-667/21CJEUStrong protection and security for health dataHealth-monitoring wearables
ND v DR, C-21/23CJEUBroad concept of data concerning healthAlgorithmic health inferences

41. Six Core Cases to Memorise

If the requirement is specifically at least six case laws, the strongest set for an examination is:

1. Nowak — C-434/16

Personal data is interpreted broadly.

2. Breyer — C-582/14

Indirectly identifiable information can constitute personal data.

3. Wirtschaftsakademie — C-210/16

Multiple parties may be controllers.

4. Jehovan todistajat — C-25/17

Controller status depends on actual influence over purposes and means.

5. Nacionalinis — C-683/21

Formal contractual labels do not alone determine responsibility.

6. Meta Platforms — C-252/21

Personal-data processing must have a valid legal basis and comply with GDPR requirements.

7. ZQ — C-667/21

Health data requires particularly careful lawful processing and security.

8. ND v DR — C-21/23

Information capable of revealing health status can constitute health data.

42. The Most Important Legal Distinction

The European approach can be summarised as:

Physical ownership of wearable
≠
ownership of personal data
≠
control of data processing
≠
right to access product-generated data
≠
intellectual-property rights in algorithms

These are separate legal concepts.

43. How a Court Should Analyse a Wearable-Data Dispute

A useful litigation sequence is:

Step 1 — Identify the data

Is it:

raw;

processed;

inferred;

personal;

non-personal?

Step 2 — Identify the individual

Can the person be identified directly or indirectly?

Step 3 — Determine whether it is health data

Does it reveal information about physical or mental health?

Step 4 — Identify the actors

Who is:

data subject;

user;

controller;

processor;

data holder;

third-party recipient?

Step 5 — Identify the legal regime

Potentially:

GDPR;

Data Act;

consumer law;

contract;

intellectual property;

trade-secret law;

medical-device law.

Step 6 — Examine contractual terms

Did the user agree to:

collection;

storage;

sharing;

analytics;

advertising?

Step 7 — Test mandatory rights

Can the contract lawfully restrict statutory access or portability rights?

Step 8 — Determine remedy

Possible remedies include:

access;

portability;

deletion;

restriction;

injunction;

damages;

contractual termination.

44. Relationship Between GDPR and Data Act

The relationship can be represented as follows:

Wearable generates data

↓

Is it personal data?

→ Yes: GDPR applies.

→ No: Data Act may still apply if it is product/related-service data within scope.

↓

Is it health data?

→ Yes: GDPR Article 9 protection may apply.

↓

Is the individual the user/data subject?

→ Data Act and GDPR rights may operate together.

↓

Does the user want to transfer the information?

→ GDPR portability and/or Data Act access/share mechanisms may apply.

The Data Act specifically states that its access rights complement GDPR rights and can extend to product-generated data regardless of whether they are personal or non-personal, subject to the Regulation's conditions. (EUR-Lex)

45. Future Litigation Areas

The most significant future disputes are likely to concern:

1. AI-generated health predictions

Who controls inferred health information?

2. Insurance

Can insurers demand wearable data?

3. Employers

Can employers monitor employee physiology?

4. Data monetisation

Can manufacturers sell aggregated wearable information?

5. Switching platforms

Can users move years of fitness data to another provider?

6. Medical research

Can wearable datasets be reused for research?

7. Data after device resale

What happens to historical cloud data?

8. Family accounts

Who has rights when several people use the same device?

46. Exam-Ready Legal Proposition

Wearable-device data disputes in Europe should not be analysed through a simple proprietary concept of “data ownership.” European law instead distributes legal powers among data subjects, connected-product users, data holders, controllers and other participants. The GDPR provides individuals with rights concerning personal data, including access, erasure and portability, while imposing heightened protection on health and biometric information. The Data Act, applicable since 12 September 2025, adds significant rights for users of connected products to access and share product and related-service data, including certain non-personal data. CJEU jurisprudence such as Nowak, Breyer, Wirtschaftsakademie, Jehovan todistajat, Nacionalinis, Meta Platforms and ZQ demonstrates that personal-data concepts must be interpreted functionally, that multiple entities may share responsibility, and that health data require particularly strong safeguards. Accordingly, a manufacturer generally cannot rely solely on technical possession of wearable data or a contractual assertion of ownership to defeat statutory access, privacy and portability rights.

Conclusion

The emerging European position is therefore not “the user owns all wearable data” and not “the manufacturer owns all wearable data.”

It is closer to:

The individual has legally protected control and privacy rights over personal data; the connected-product user has statutory access and sharing rights over product-generated data; the manufacturer may retain legitimate interests in technology, algorithms, trade secrets and certain datasets; and contracts operate within these mandatory statutory boundaries.

The EU Data Act + GDPR combination is particularly significant because it is gradually moving European law from a model where manufacturers could effectively control access through technical architecture toward a model of legally enforceable data access, portability and sharing, while retaining strong protection for personal and health information. (EUR-Lex)

LEAVE A COMMENT