Compliance

Built for GDNG, EHDS, and EU AI Act from Day One

Three converging regulations define what compliant health AI looks like in Germany. Here is what they require, and how Loretta meets each one.

Regulatory Overview

Three regulations. One infrastructure requirement.

GDNG, EHDS, and the EU AI Act converge on a shared principle: health AI must be sovereign, auditable, and fair. Each adds specific obligations.

GDNG German Health Data Use Act (Gesundheitsdatennutzungsgesetz)
In force since March 2024
Core Requirement

Creates the legal framework for using health data for research, quality assurance, and AI training in Germany. Requires pseudonymisation, purpose limitation, and a legitimate basis for every processing operation.

Strongly favours privacy-preserving architectures like federated learning, where patient data stays within institutional boundaries.

How Loretta addresses this

Federated learning ensures data never leaves your institution. Models travel to data, not the reverse. Full audit trails for every training run.

EHDS European Health Data Space
In force March 2025. Secondary use by March 2029.
Core Requirement

EU-wide framework for primary and secondary use of health data. Promotes interoperability through standardised data exchange formats, requires audit trails for data access, and establishes national Health Data Access Bodies.

Article 54 explicitly prohibits using health data for insurance underwriting or coverage decisions. Full purpose limitations apply.

How Loretta addresses this

Standards-based data layer with structured export formats. Tamper-proof processing logs for every data access event.

EU AI Act EU AI Act: High-Risk Classification
Standalone AI: August 2026. Medical devices: August 2027.
Core Requirement

Health AI systems classified as high-risk under Annex III. Requires conformity assessments, data governance, explainability, human oversight, risk management, and post-market monitoring.

Providers must maintain quality management systems, complete technical documentation, and report serious incidents within 15 days.

How Loretta addresses this

Causal models provide interpretable recommendations. Built-in monitoring for model performance and outcome fairness. Designed from the ground up for high-risk classification requirements.

Enforcement Timeline

The compliance window is closing

Key milestones across GDNG, EHDS, and the EU AI Act. Some are already in force.

Mar 2024
GDNG enters into force
In force
2025
ePA rollout begins
In force
Oct 2025
Health Data Lab at BfArM
In force
Mar 2025
EHDS enters into force
In force
Aug 2026
EU AI Act (standalone)
Upcoming
Mar 2027
EHDS core provisions
Upcoming
Aug 2027
EU AI Act (medical devices)
Upcoming
Compliance Mapping

How Loretta Addresses Each Requirement

Regulation Requirement Loretta Capability
GDNG Pseudonymisation and data protection safeguards (§6 GDNG, GDPR Art. 9) Federated learning: models train locally, only encrypted parameters aggregate
GDNG Purpose limitation and data minimisation Role-based access control with per-operation audit logging
GDNG Legitimate basis for each processing operation Configurable consent and legal basis mapping per data type
EHDS Cross-border interoperability HL7 FHIR-native data layer with standardised export formats
EHDS Audit trail for secondary data use Immutable processing logs with cryptographic verification
EHDS Anonymisation and pseudonymisation Built-in differential privacy and k-anonymity guarantees
EU AI Act Explainability and human oversight Causal models with interpretable intervention recommendations
EU AI Act Risk management and post-market monitoring Continuous model performance monitoring with drift detection
Resources

GDNG Compliance Checklist for Health AI

A practical guide to meeting GDNG requirements when deploying AI in German health organisations.

This page is provided by Loretta Health UG for informational purposes only. It does not constitute legal advice. Regulatory requirements are subject to change. Organisations should consult qualified legal professionals for binding compliance assessments. References based on publicly available legal texts as of February 2026.