Service decision and evidence guide

Health-app monitoring with an overseas cloud processor: which facts should the brief include?

The EDPB health-app example links personal health/lifestyle indicators, EU use and monitoring with the controller’s scope, then separately examines its overseas cloud processor’s related activity. This is not a conclusion about every health app or every hosting provider. Prepare the actual purposes and processing chain before commissioning representation or additional privacy work.

Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.

Sourced criteria · EU · GDPR

What changes the service scope?

Decision or taskWhat the source describesWhat to prepare
Indicators and purpose in the worked exampleThe example records sleep, weight, blood pressure and heartbeat and provides food/sport advice. Its monitoring conclusion depends on the described activity; a “health app” name alone is insufficient. [1]Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
Related cloud activityThe guidance examines the cloud processor carrying out storage on instructions for the controller’s targeted processing, rather than treating the processor’s overseas location as decisive. [1]Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
Exception and contract questions remain distinctArticle 27 contains the combined occasional-processing, scale/data and risk exception conditions; Article 28 governs relevant processor arrangements. No exception or complete contract outcome is inferred for the reader. [3] [4]Compare the stated example/criterion with the evidence tasks below; retain any factual differences.

The EDPB document is Guidelines 3/2018, version 2.1, adopted 12 November 2019. Its worked examples are guidance and dated assumptions, not a new law or a conclusion about your organisation. EU scope is assessed here; UK and Swiss rules require separate evidence. Novel or disputed scope/role interpretations need specialist legal review.

Prepare the evidence and engagement scope

Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.

  1. Map data, features and purposes

    Record which indicators are collected and whether they support monitoring, profiling, recommendations or other functions.

    Useful evidence: A feature/data/purpose map with unresolved sensitive-data questions.

  2. Map cloud and downstream processing

    Identify responsible entities, instructions, actual storage/use and any downstream processing related to EU users.

    Useful evidence: A controller/processor chain and data-flow/contract inventory.

  3. Define the specialist scope

    Request separate territorial, exception and contract assessments; ask which additional privacy evidence the actual features justify.

    Useful evidence: A conditional appointment scope and a separate privacy-gap work package.

Work packages and dependencies

Questions for providers

Sources and data dates

Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.

EDPB territorial-scope guidance — PDF page 21 ↗

Guidelines 3/2018 version 2.1; 2020-01-07 formatting change · retrieved 2026-10-07

Audit details: precise locators and snapshot identifiers

Source key D17 · snapshot d6910de864b8bbbdd7ed11e7509391a21ac9b627c8745dde87e8acd7c63b4862

  • [1] PDF page 21 · record 19e62a2e4e66974d1487452797b28bc8c6bf14c77b8dd7f73727555ec71c446b

European Union — GDPR (Regulation (EU) 2016/679) ↗

Consolidated text dated 2016-05-04 · retrieved 2026-10-06

Audit details: precise locators and snapshot identifiers

Source key D05 · snapshot 149156a8f8dfc90bead21c89c32eb84f92b7414602c3e00e058755810b48ef8a

  • [2] #art_3 · record e971d61ba2966f81cde250e8814a8e3d60e16da6212a0f1fd180e1dd9869819d
  • [3] #art_27 · record 6b75ebac1e370f3020c6d5dc7f0117ed27d1bf4a4c7c47b155b12f0c3984a10e
  • [4] #art_28 · record e269a9f1e3177f13d0d5ca39633c0f97c2ac9019b7471a563b30dfc16e6a0b9b

Prepare an editable project brief

Confirm the facts, scope and contact preference before sharing your project. Preparing this page sends no provider outreach.

Choose work packages to discuss

Compare GDPR Article 27 EU/UK Representative