On 7 July 2026, the European Data Protection Board (“EDPB”) adopted its Guidelines 02/2026 on Anonymisation for public consultation (the “Guidelines”), replacing the Article 29 Working Party’s Opinion 05/2014 that served as one of the primary EU references on the topic for over a decade.

Since 2014, the legal landscape has, however, shifted considerably, most notably through the Court of Justice’s judgment in EDPS v SRB (Case C-413/23 P) (see our blog on that judgment), and the practical landscape even more so, with the proliferation of AI, large-scale data pooling, and cross-border research collaborations. For life sciences companies handling key-coded clinical data, safety reports, or real-world evidence, the Guidelines, once finalised and adopted, will set out a clear framework for determining when data is genuinely anonymous and therefore falls outside the GDPR’s scope.

Continue Reading EDPB Guidelines on Anonymisation: What Life Sciences Companies Need to Know

Welcome to the latest installment of Arnold & Porter’s Virtual and Digital Health Digest. This digest covers key virtual and digital health regulatory and public policy developments during May and early June 2026 from the United Kingdom and European Union.

May 2026 saw continued momentum across the European Union (EU) and United Kingdom (UK) toward modernizing and streamlining the regulatory landscape for digital health, with a particular focus on accommodating AI-enabled technologies while reducing unnecessary complexity. A central development was the provisional agreement on the Digital Omnibus package, which seeks to simplify the application of the EU AI Act by clarifying overlaps with sector-specific legislation, deferring key obligations, and introducing more proportionate requirements.

In parallel, regulators on both sides of the Channel are advancing reforms to ensure that medical device frameworks remain fit for purpose in an increasingly software-driven and data-centric environment. In the EU, the activation of key European Database on Medical Devices (EUDAMED) modules marks a major step toward enhanced transparency and traceability, while ongoing discussions on the Medical Devices Regulation 2017/745 (MDR)/In Vitro Diagnostic Regulation 2017/746 (IVDR) revisions highlight a strong policy drive toward simplification and better integration of AI. In the UK, the Medicines and Healthcare products Regulatory Agency’s (MHRA) proposed pre-market reforms and broader thinking on AI regulation signal a shift toward more flexible, lifecycle-based oversight, with greater emphasis on post-market monitoring and innovation support.

Data governance and cybersecurity also remain high on the agenda. Industry and regulators alike are emphasizing the need for coherent, proportionate frameworks that avoid duplication while enabling innovation, particularly in light of expanding AI use cases and global supply chains. Together, these developments reflect a broader trend toward risk-based, innovation-friendly regulation, coupled with increasing expectations around transparency, accountability, and data protection in digital health.

Continue Reading Virtual and Digital Health Digest – June 2026

On 19 March 2026, the Court of Justice of the European Union (CJEU or Court) issued its judgment in Case C-526/24, Brillen Rottler GmbH & Co. KG v TC. The case concerned a data subject who subscribed to a German optician’s newsletter and, thirteen days later, submitted an access request under Article 15 GDPR. The company refused the request, arguing it was abusive. The data subject maintained it was legitimate and claimed at least €1.000 in non-material damages.

The CJEU’s judgment addresses three questions of broad significance: (1) when a first access request can be refused as “excessive”; (2) whether a violation of the right of access alone can give rise to a compensation claim under Article 82 GDPR; and (3) how non-material damage should be assessed in that context. While the judgment is relevant to all companies subject tot GDPR, we examine below the considerations it raises for life sciences companies specifically.

Continue Reading CJEU rules on GDPR access rights and abuse of rights: what the Brillen Rottler judgment means for life sciences companies

On 19 November 2025, the European Commission published two legislative proposals – the Digital Omnibus on AI Regulation Proposal and the broader Digital Omnibus Regulation Proposal (“Proposals”) – as part of a wider initiative to simplify and streamline the EU’s digital regulatory framework. Together, the Proposals introduce targeted but significant amendments across a broad range of instruments, including the EU AI Act (Regulation (EU) 2024/1689), the GDPR (Regulation (EU) 2016/679), the ePrivacy Directive (2002/58/EC), the NIS2 Directive ((EU) 2022/2555), and the EU Data Act (Regulation (EU) 2023/2854).

Continue Reading EU Digital Omnibus: What the Proposed Reforms Mean for Pharma and MedTech

Welcome to the latest installment of Arnold & Porter’s Virtual and Digital Health Digest. This digest covers key virtual and digital health regulatory and public policy developments during September and early October 2025 from the the United Kingdom, and European Union.

This month, the EU and UK have been actively processing the future of AI development and regulation in life sciences and health care through a combination of legislative initiatives, opportunities for stakeholder engagement, and investment in infrastructure. In the EU, the European Commission has published draft guidance on reporting serious AI incidents under the AI Act, and the European Medicines Agency has initiated a stakeholder survey to define AI priorities in medicines regulation. In the UK, the UK government has announced a National Commission on the Regulation of AI in Healthcare and a new AIR-SP cloud platform. These developments signal a shift from theoretical regulation to practical implementation. There have also been two important decisions from the Court of Justice of the European Union refining the legal boundaries of digital health services and data protection.

Continue Reading Virtual and Digital Health Digest – October 2025

On 8 September 2025, the Court of Justice of the European Union (CJEU) received a preliminary request from the Bundesverwaltungsgericht, the German Federal Administrative Court BVerwG, referring a series of questions seeking interpretation on the applicability of certain rules to parallel trade of medicines, including whether German language and packaging requirements are proportionate or compatible with EU law.  The request follows an order for a preliminary reference made by the BVerwG in March 2025.  Notably, the request does not disclose the identity of the parallel importer, the manufacturer of the medicinal product, or the name of the product itself.

Continue Reading CJEU to Clarify Rules on Packaging Requirements in Parallel Trade of Medicines

On 4 September 2025, the Court of Justice of the European Union (“CJEU”) delivered a notable judgment on what is considered pseudonymised personal data under EU data protection law. While, technically speaking, the judgment concerns the interpretation of Regulation (EU) 2018/1725 (which governs the processing of personal data by the EU institutions and bodies), it fully applies to the interpretation of the concepts of personal data and pseudonymised data under Regulation (EU) 2016/679 (“GDPR”).

This question is essential for many companies operating in the EU, and in particular Life Sciences companies handling key-coded or otherwise pseudonymised patients’ personal data in the context of research and development, supply of healthcare products and related safety monitoring.

Continue Reading CJEU clarifies the concept of pseudonymised data

The European Court of Justice (the “Court”) has ruled that Poland’s law prohibiting advertising by pharmacies and pharmaceutical outlets is overly restrictive and contrary to EU law.

The Polish legislation (Article 94a(1) of the Law on Medicines, as amended) which had been in force since 2012, prohibits pharmacies and pharmaceutical outlets from engaging in any form of advertising or promotional activity other than providing limited information on their location and opening hours. Any person who is found to be in breach of the provisions is liable to a fine of up to 50,000 Polish zloty (PLN) (approximately EUR 12,000).

Continue Reading The European Court of Justice rules that Poland’s laws prohibiting pharmacies from advertising are overly restrictive

Do discount campaigns on prescription-only medicines (POMs) run by mail order pharmacies lure patients into consuming medicinal products? The European Court of Justice (CJEU) in the case of Apothekerkammer Nordrhein (C-517/23) has held that they do not.

Following on from the AG Opinion of Advocate General Szpunar, which we provided an update on earlier in the year, this case is the latest in a stream of cases on advertising practices involving DocMorris, a Dutch mail-order pharmacy that supplies medicines to end customers in Germany. The CJEU concluded that the discount campaigns regarding unspecified POMs do not fall within the definition of “advertising of medicinal products” (Article 86(1) Directive 2001/83) as the discount is implemented at the point of purchase of the POM.  The decision of which product to prescribe has already been taken by a doctor and all the patient is left to do is choose the dispensing pharmacy. As such, the Court held that the purpose of the discount campaign is not to encourage patients to purchase medicinal products. Rather, it is simply to attract them to a specific pharmacy.

The facts of the case are set out in our previous blog available here.

Continue Reading An update from the European Court of Justice on discount campaigns run by mail order pharmacies

In the last month, both the European Data Protection Board (“EDPB”) and the Court of Justice of the European Union (“CJEU”) provided their interpretation of key data protection concepts that are crucial for ensuring compliance with Regulation (EU) 2016/679 (“GDPR”).

In Opinion 22/2024, the EDPB provided guidance to data controllers on how to effectively oversee the activities of their (sub-)processors in a GDPR-compliant manner. The opinion was requested by the Danish data protection authority and likely related to the enforcement actions against Danish hospitals which allegedly failed to oversee processors (see our blog – https://www.biosliceblog.com/2024/02/proposed-fine-against-danish-hospital-for-failure-to-supervise-data-processors/).

In early October, the CJEU provided an answer to a key question raised by the courts in the Netherlands – can the legitimate interests legal basis be used for processing of personal data for commercial purposes (e.g., sharing with third parties for advertising and promotion) (Case C‑621/22).

Continue Reading Notable developments in the interpretation of key GDPR concepts – why should Life Sciences companies care?