Written answer
Data Protection
The Department is assessing EU-governed cloud options for health data, subject to GDPR, cybersecurity, resilience, procurement law and emerging geopolitical risks.
3329. Deputy Pádraig Rice asked the Minister for Health if her Department has assessed the potential role that European-based, fully EU governed and data infrastructure sovereign cloud services could play in supporting the storage, processing, protection and governance of Irish patient data; and if she will make a statement on the matter. [55810/26]
Comment on this
The Government is committed to ensuring that health information systems are secure, resilient, interoperable and capable of protecting patient information in accordance with the General Data Protection Regulation (GDPR), the Data Protection Act 2018 and other relevant Irish and European legislation.
As Ireland progresses the implementation of Digital for Care and the development of a National Electronic Health Record (EHR), a range of considerations are being taken into account, including data protection, cybersecurity, digital resilience, governance arrangements and compliance with relevant national and EU legislation.
My Department and the Health Service Executive continue to monitor developments at European level in relation to digital sovereignty, cloud infrastructure, the European Health Data Space (EHDS), the AI Act and wider initiatives designed to strengthen Europe's digital capabilities and resilience. Ireland also participates in a range of European forums and initiatives relating to digital health, health data and emerging technologies.
The potential role of different hosting, cloud and infrastructure models, including services that are European-based or subject to EU governance arrangements, forms part of the wider consideration of how best to support the storage, processing, protection and governance of health information. Such considerations are assessed having regard to cybersecurity requirements, data protection obligations, digital resilience, operational requirements and compliance with applicable national and European legislation.
Procurement decisions relating to national digital health systems will be made in accordance with public procurement law. The Department will continue to monitor developments at European level, factoring in threats posed by emerging cybersecurity and geopolitical risks.