When Health Data Moves Beyond Its Original Purpose

pexels-photo-6823406.jpeg

When Health Data Moves Beyond Its Original Purpose

Large-scale health screening programs can generate datasets of exceptional value. Information initially collected to assess an individual’s health may later be useful for population-health planning, epidemiological studies, academic research, development of healthcare technologies, or collaboration among public authorities, hospitals and research institutions. At the same time, such projects illustrate one of the more difficult questions under the Personal Data Protection Act (PDPA): when may health data collected for one purpose subsequently be used or disclosed for another?

A recent consultation submitted to the data protection regulator in connection with health information collected through a large-scale screening program brings several of these issues into focus. Rather than discussing the regulator’s conclusions in that particular matter, this article examines the compliance questions the scenario raises for organizations handling health and data collection.

Health information requires a two-layer legal analysis:

The starting point is that health information is expressly classified as sensitive personal data under Section 26 of the PDPA. As a general rule, collecting such information without the data subject’s explicit consent is prohibited unless one of the statutory exceptions applies.

This is important because organizations sometimes begin their analysis with Section 24, particularly Section 24(1), which permits the collection of personal data without consent for historical or archival purposes in the public interest, or for research or statistical purposes, provided appropriate safeguards are implemented.  For ordinary personal data that may be the principal legal-basis analysis. For health data, however, satisfying Section 24 does not by itself resolve the issue. The processing must also be capable of being justified under the special rules applicable to sensitive personal data in Section 26.

Section 26 contains several potentially relevant exceptions, including processing necessary for certain health-related purposes where the statutory requirements are satisfied. The applicable exception will depend on the nature of the project, the statutory functions of the organizations concerned, who performs the processing, and the purpose for which the health information is being used.  Consequently, describing a project simply as “research” or “public health” should not be treated as a substitute for identifying the precise statutory basis supporting each processing operation.

Secondary use is a separate question:

A second issue is purpose limitation. Section 21 requires a controller to collect, use or disclose personal data in accordance with the purpose communicated to the data subject. Using the information for a different purpose generally requires notification of the new purpose and consent, unless the PDPA or another law permits the new processing.

This distinction becomes particularly important where information was originally collected to provide an individual health screening service but is later proposed to be used for research, analytics, public-health planning or development of new systems. The question is not merely whether research can, in the abstract, be conducted without consent. The organization should identify what the original purpose was, what the subsequent purpose is, and what provision of law permits the transition from one to the other.

The PDPA recognizes research and statistical activities in a number of places and also contemplates situations in which providing an individual notice may be impossible or seriously obstruct the achievement of scientific, historical or statistical research. In such circumstances, however, appropriate safeguards for the rights, freedoms and interests of data subjects remain important.  This makes research governance more than an exercise in selecting a lawful basis: data minimization, access restrictions, security controls, retention limits and the manner in which research results are disclosed all become part of the compliance analysis.

Removing names may not end the PDPA analysis:

Another recurring issue is whether health data can simply be “de-identified” before being transferred or used for research.

The distinction between genuinely anonymous information and information from which direct identifiers have merely been removed is critical. Removing a person’s name, identification number or telephone number does not necessarily mean that the person can no longer be identified. Health datasets frequently contain combinations of age, location, diagnosis, treatment history, dates and other variables that may permit identification when combined with other information.

The PDPA itself distinguishes between personal data and information that has been made incapable of identifying the data subject. For example, it expressly recognizes anonymization as one possible means of dealing with data in connection with a deletion request.  Organizations should therefore avoid treating “de-identification”, “pseudonymization” and “anonymization” as interchangeable concepts.

As a practical matter, data linked to a code while a corresponding key remains available should normally be treated cautiously as personal data. Whether a dataset has become genuinely anonymous should be assessed against the realistic possibility of re-identification, including identification through combination with information held separately. For valuable health datasets, this may require both technical controls and organizational restrictions rather than simply deleting direct identifiers.

Who is the controller when several organizations participate?

Large-scale health projects commonly involve several participants: a government agency may establish the program, hospitals may collect samples and examination results, a university may analyze the information, an IT provider may host the database and separate researchers may later obtain datasets.

The labels used in the collaboration agreement are not necessarily decisive. The relevant question is who determines the purposes and essential means of each particular processing activity. A participant acting solely on documented instructions may have a processor role, whereas an institution that determines its own research question and decides how information will be analyzed may itself exercise controller functions.

The same institution may therefore occupy different roles at different stages of a project. That distinction matters because the PDPA imposes different obligations on controllers and processors, and because disclosure from one independent controller to another requires its own legal justification rather than merely a data processing agreement.

Organizations managing collaborative health projects should consequently map the data flow and the decision-making structure, rather than assigning a single PDPA label to each institution for the project as a whole.

Data sharing is itself a processing activity:

Where health information is disclosed to another organization, it is not enough that the recipient intends to conduct worthwhile research. Section 27 restricts the use and disclosure of personal data unless consent has been obtained or the information was collected under an applicable statutory exception. It also restricts a recipient from subsequently using the information for purposes beyond those communicated when obtaining the data.

This means that data-sharing arrangements should identify, among other matters, the purpose of disclosure, categories of information involved, respective legal bases, permitted uses, security measures, retention and deletion arrangements, onward disclosure restrictions, handling of data-subject rights, breach responsibilities and the respective controller or processor status of the parties.

The existence of a data-sharing agreement is valuable evidence of governance, but the agreement does not itself create a lawful basis that does not otherwise exist under the PDPA.

International research creates an additional layer:

Where research collaborators, cloud providers or analytical systems are located outside Thailand, the international-transfer provisions must also be considered independently of the lawful basis for the underlying research.

Section 28 establishes the principle that transfers should be made to destinations having an adequate standard of personal data protection, subject to specified statutory exceptions.  Section 29 provides mechanisms concerning transfers within groups and permits other safeguards in circumstances prescribed under the statutory framework.

Accordingly, an organization may have a valid domestic basis to process health information for a particular purpose but still need to address a separate transfer question before making the information accessible overseas. This is especially relevant where data is stored on international cloud infrastructure or foreign researchers are given remote access to a Thai database; an organization should not assume that the absence of a physical file transfer necessarily removes the cross-border issue.

Why these issues extend beyond healthcare:

Although health screening provides a particularly clear example because Section 26 applies, the underlying questions are much broader. Businesses increasingly seek to reuse datasets originally collected for operational purposes to train algorithms, develop AI systems, perform behavioral analytics or create new products. The same sequence of questions frequently arises: What was the original purpose? What is the proposed secondary purpose? Does the new processing have an independent legal basis? Are sensitive data involved? Can the information genuinely be anonymized? Who determines the new purpose? Will another organization receive the data? Will it become accessible outside Thailand?

The regulatory risk often arises not because the organization lacks a legitimate business or public-interest objective, but because these questions are addressed only after a valuable dataset has already been created. Building secondary-use governance into the data lifecycle from the beginning is therefore considerably safer than attempting to reconstruct the legal basis when a research or AI opportunity later emerges.

Key Takeaways:

  • Health data requires special treatment: An organization relying on a research basis under Section 24 must still address the sensitive-data requirements of Section 26.
  • Secondary use should be analyzed separately from original collection: A lawful basis for collecting health information does not automatically authorize every later research, analytics or development purpose.
  • Removing names is not necessarily anonymization: The ability to identify an individual through remaining data or other available information remains relevant.
  • Roles should be determined activity by activity: A university, hospital, government agency or technology provider may have different controller or processor roles at different stages of the same project.
  • A contract does not replace a lawful basis: Data-sharing agreements and processing agreements are governance tools; they do not themselves legalize a disclosure.
  • Cross-border access adds another compliance layer: International transfer requirements must be considered separately from the legal basis for the underlying research.
  • Research and AI projects benefit from governance by design. Organizations should determine secondary-use rules, access controls, anonymization standards and data-sharing procedures before datasets are repurposed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Posted in