Copenhagen: Denmark’s electronic health record infrastructure, often cited as among the most mature in Europe, is being recalibrated to align with the European Health Data Space Regulation as the Commission works through the dense stack of implementing acts that must arrive before the regime becomes operational. Danish officials have used the run-up to view their own digital-health architecture less as a head start and more as a blueprint that will need editing.
The regulation, in force since March 2025, sets a phased application calendar that prioritises the primary use of health data, that is, patient access and cross-border portability of records for treatment purposes, ahead of the more contested secondary-use pillar. The bulk of obligations enter into application by March 2029, although certain categories such as image studies, genomic data, and laboratory results gain longer transition periods. Implementing acts on the European electronic health record exchange format, the technical specifications for health data access bodies, the catalogue requirements for secondary-use datasets, and the rules governing the cross-border infrastructure all face a March 2027 Commission deadline.
The secondary-use framework, which permits the reuse of pseudonymised health data for scientific research, regulatory decision-making, public-health policy, and the training of artificial-intelligence systems, has emerged as the regulation’s most administratively demanding component. Member States must designate national health data access bodies that will issue permits to research organisations, public bodies, and industry sponsors, evaluating each request against a defined set of public-interest grounds. Data holders, ranging from hospital trusts to insurance funds and biobanks, will be required to publish dataset descriptions and respond to access requests through a federated catalogue. Processing must occur within secure analytical environments rather than via raw-data transfer, with the European Data Protection Supervisor and national supervisory authorities retaining oversight throughout.
Copenhagen has tracked the implementing-act timetable with some apprehension. Danish researchers have benefited for years from a permissive national regime that permits broad linkage of clinical, administrative, and registry data under a single ethics-approval framework. The European model is more procedural and less permissive in some respects, more harmonised and more enabling in others. The interaction between the EHDS permit regime and the General Data Protection Regulation’s research provisions has been the subject of intensive guidance from the European Data Protection Board, which insists that the EHDS does not displace the lawful-basis assessment under Article 6 GDPR but layers a public-interest framework on top of it.
Industry stakeholders, particularly pharmaceutical sponsors, view the regime as the most significant unlock for European clinical research since the Clinical Trials Regulation. Access to harmonised, federated health-data catalogues could shorten feasibility studies, improve external-control-arm methodologies, and accelerate post-authorisation safety surveillance. The trade-off is the discipline of working through national access bodies whose capacity is still being built and whose decision-making turnaround the regulation only loosely specifies. Cross-border permits, where datasets in multiple Member States must be combined, will be the test case for whether the federated architecture genuinely operates as a single space.
For Copenhagen, the next twelve months will be largely about translating Danish regulatory practice into the European procedural template without losing the speed advantages that domestic researchers have come to expect.




