Health-app monitoring with an overseas cloud processor: which facts should the brief include?
The EDPB health-app example links personal health/lifestyle indicators, EU use and monitoring with the controller’s scope, then separately examines its overseas cloud processor’s related activity. This is not a conclusion about every health app or every hosting provider. Prepare the actual purposes and processing chain before commissioning representation or additional privacy work.
Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.
Sourced criteria · EU · GDPR
What changes the service scope?
Decision or task
What the source describes
What to prepare
Indicators and purpose in the worked example
The example records sleep, weight, blood pressure and heartbeat and provides food/sport advice. Its monitoring conclusion depends on the described activity; a “health app” name alone is insufficient. [1]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
Related cloud activity
The guidance examines the cloud processor carrying out storage on instructions for the controller’s targeted processing, rather than treating the processor’s overseas location as decisive. [1]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
Exception and contract questions remain distinct
Article 27 contains the combined occasional-processing, scale/data and risk exception conditions; Article 28 governs relevant processor arrangements. No exception or complete contract outcome is inferred for the reader. [3][4]
Compare the stated example/criterion with the evidence tasks below; retain any factual differences.
The EDPB document is Guidelines 3/2018, version 2.1, adopted 12 November 2019. Its worked examples are guidance and dated assumptions, not a new law or a conclusion about your organisation. EU scope is assessed here; UK and Swiss rules require separate evidence. Novel or disputed scope/role interpretations need specialist legal review.
Prepare the evidence and engagement scope
Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.
Map data, features and purposes
Record which indicators are collected and whether they support monitoring, profiling, recommendations or other functions.
Useful evidence: A feature/data/purpose map with unresolved sensitive-data questions.
Map cloud and downstream processing
Identify responsible entities, instructions, actual storage/use and any downstream processing related to EU users.
Useful evidence: A controller/processor chain and data-flow/contract inventory.
Define the specialist scope
Request separate territorial, exception and contract assessments; ask which additional privacy evidence the actual features justify.
Useful evidence: A conditional appointment scope and a separate privacy-gap work package.
Work packages and dependencies
Conditional: EU representative scope and engagement — Review the specific evidence task and unresolved territorial/role facts. Where appointment applies, agree the mandate, communication and handoff; justify additional privacy services separately.
Questions for providers
Which differences between our actual facts and the cited example change your scope conclusion?
Which processing activity and legal entity does your conclusion cover, and which facts remain unresolved?
Which appointment and evidence-handoff deliverables are included, and which additional services are separately justified?
Sources and data dates
Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.