Data protection & evidence
Health data in passenger transport: what Article 9 GDPR means for patient and disability transport
Wheelchair requirements, an emergency note, a call to say someone is ill. A transport operator processes health data whether it intends to or not. This article shows which fields fall under Article 9 GDPR and how to govern access, disclosure and deletion.
Key takeaways
Diagnoses, care level, aids and medication notes in a passenger file are health data within the meaning of Article 9 GDPR. Processing them stays prohibited unless one of the narrow exceptions applies. In practice that means a dedicated legal basis, a tight permission model, and no blanket display of those fields.
- Article 9(1) GDPR prohibits the processing of health data as a matter of principle; it only becomes lawful through one of the exemptions listed exhaustively in paragraph 2.
- Wheelchair requirements, emergency medication, seizure risks and sickness reports are health data within the meaning of Article 9 GDPR, because Recital 35 expressly names disabilities and disease risks.
- In practice, transport operators base the processing on Article 9(2)(h) GDPR in conjunction with section 22(1) no. 1(b) BDSG (the German Federal Data Protection Act), which expressly applies to private bodies as well.
- Article 9(3) GDPR only permits processing by people who are subject to an obligation of secrecy. Section 22(2) BDSG additionally requires access restrictions and training.
- Diagnoses do not belong in the passenger record. They raise your risk without making the journey any safer.
The word diagnosis rarely appears in a transport operator’s passenger records, and yet health data in passenger transport is the norm. Wheelchair or carry chair, the need for an escort, an emergency note for the driver, the funding approval notice attached as a scan. Anyone who takes a sickness report from a sheltered-workshop employee at 6:40 in the morning and pulls the journey out of the tour has just processed health data. The GDPR treats these entries more strictly than anything else in the record, and the typical mistake is rarely bad faith. It happens where an entry gets captured because it is useful, then stays visible to everyone because nobody decided who actually needs it. This article reflects the legal position as of July 2026.
Why health data in passenger transport falls under a statutory prohibition
Article 9 GDPR inverts the usual test. For ordinary data you look for a legal basis under Article 6 and you are done. For special categories, paragraph 1 starts with a prohibition. Processing only becomes permissible if one of the exemptions listed exhaustively in paragraph 2 also applies. Both layers have to hold.
There is one point where operators get stuck particularly often. The usefulness of an entry does not create a permission. The fact that dispatch plans better when it knows the reason for a slow boarding process does not make recording that reason lawful. The test runs through the action required, not through the underlying cause.
Classification as a special category brings three duties that smaller operators often assume do not apply to them.
- The record of processing activities becomes mandatory. The relief for organisations with fewer than 250 employees under Article 30(5) GDPR falls away as soon as special categories are processed.
- A data protection impact assessment under Article 35(3)(b) GDPR comes into play where processing is carried out on a large scale. With several hundred passengers, that is a question worth taking seriously.
- The technical and organisational safeguards under Article 32 GDPR are made concrete for sensitive data by section 22(2) BDSG, among other things through access restrictions, encryption, pseudonymisation and training.
Which fields in a passenger record are health data?
Article 4(15) GDPR defines health data as personal data that reveal information about a person’s state of health. Recital 35 reads this broadly and expressly names disabilities, disease risks and medical treatment. Whether a field sounds medical is irrelevant. What matters is whether it allows a conclusion about health to be drawn.
| Field in the passenger record | Classification | Why |
|---|---|---|
| Wheelchair, carry chair or stretcher transport | Article 9 | Points to a physical impairment. |
| Escort requirement, ability to orientate | Article 9 | Describes an impairment, even without a diagnosis. |
| Emergency medication, seizure risk, allergies | Article 9 | The most sensitive field in the entire record. |
| Merkzeichen aG, Bl, H (codes on the German severely disabled pass) or Pflegegrad (German long-term care level) as grounds for approval | Article 9 | Status entries with a direct link to health. |
| Absence reason ‘ill’ in tour planning | Article 9 | A statement about the current state of health. |
| Name, address, phone number, time window | Article 6 | Ordinary data, as long as no health link arises. |
The Merkzeichen in the second-to-last row are a good example of an entry that looks harmless. Under section 3 of the Schwerbehindertenausweisverordnung (the German regulation on severely disabled passes), aG stands for exceptional walking impairment, Bl for blindness, H for helplessness. Two letters in the approval field therefore carry a medical statement.
Harder than the form fields are the places where such data arise as a by-product.
- Free-text fields. ‘Needs two minutes, prone to circulatory problems’ is health data, even if it was only typed quickly into the notes box.
- Attachments and scans. A funding approval notice regularly contains more health information than all the form fields next to it put together.
- Destinations. A recurring journey to dialysis reveals the reason for treatment without anyone having entered it.
Which legal basis supports health data in passenger transport?
A workable construction has two layers. Underneath sits a legal basis under Article 6 GDPR, regularly paragraph 1(b) for the transport contract, or (c) or (e) for journeys commissioned by a Sozialleistungsträger (a public social benefits provider). Above it sits Article 9(2).
What is usually relied on there is Article 9(2)(h) GDPR, which permits processing for the purposes of preventive health care and for the provision of health or social care, provided it rests on member state law. That national basis is supplied by section 22(1) no. 1(b) BDSG, which expressly applies to public and private bodies alike. Article 9(3) GDPR comes on top of it. Only people bound by professional secrecy or an equivalent obligation of confidentiality may carry out the processing. Dispatchers, drivers and temporary staff therefore have to be placed under a written confidentiality obligation, and that is a condition of the permission itself. If the signed undertaking is missing from the personnel file, the permission is missing one of its conditions.
How the classification turns out in an individual case depends on the contractual set-up. Whether you act on your own responsibility or as a processor under Article 28 GDPR for a Kostenträger (the body funding the journey) determines the legal basis, the paperwork and who gives instructions. Where social data are processed on behalf of a social benefits provider, section 80 SGB X (Book X of the German Social Code) also applies, which among other things requires prior notification of the supervisory authority. Settle the allocation of roles in writing and have it confirmed from a data protection perspective. This article is no substitute for legal advice in an individual case.
Where consent is a sensible addition
Article 9(2)(a) GDPR permits processing on the basis of explicit consent. As the sole anchor it rarely works, because under Article 7(3) GDPR consent can be withdrawn at any time, and a withdrawal should not be able to remove an entry that safety depends on. Its place is where processing goes beyond what is necessary. An additional information channel to a daughter who wants to know every day whether her father has arrived is exactly such a case.
What belongs in the passenger record and what does not
Data minimisation under Article 5(1)(c) GDPR bites hardest here, because every additional field raises the risk. The guiding question when designing the form is what the driver has to do and what equipment the vehicle needs for it. A diagnosis does not answer that. It describes a cause from which every driver would have to work out for themselves what to do. The most sensitive information circulates and the instruction is still missing.
Four changes to the form do most of the work.
- The free-text field ‘illness, diagnosis’ becomes a picklist ‘support required when boarding and alighting’.
- ‘Type of disability’ becomes entries on restraint system, mobility aid and space requirement.
- The medication overview becomes an emergency note that states what to do and who to inform.
- ‘Medical history, pre-existing conditions’ becomes the field ‘escort required: yes, no, depends on the situation’.
Offer free-text fields and you will get free text. Picklists with a small number of care and equipment attributes keep the data volume down and, unlike running text, can be hidden by role. A free-text field should still exist. Its label then has to make clear that what goes there are instructions for action, not medical histories.
Who sees what inside the operation, and what leaves it
Section 22(2) BDSG expressly names access restrictions as an appropriate and specific measure for special categories. This requirement is not a recommendation. In practice it means that each role in the operation gets to see only a slice of the passenger record.
Dispatch works with care and capacity attributes, time windows and the accessibility of the address. It does not need emergency medication in detail, diagnoses, or approval notices in full text. Billing manages with approval status, journey records, kilometres and times. Management and the data protection officer access records in a justified individual case, with an audit trail, rather than having every free-text entry permanently open.
The assigned driver is the most important case and the one most often solved wrongly. He needs the instructions for his tour, the emergency contact and the handover arrangements, and he needs them on the day of the journey. He does not need a complete record, and certainly not entries about passengers on other tours. Printed tour lists and messenger groups fail at this boundary systematically, because they know no roles, only recipients. Once distributed, a list stays distributed.
This is precisely where dispatch software helps if it ties visibility to role and tour assignment, logs access, and separates the channel for relatives from the operational system. At Vermo, dispatch and the driver app are cut along this role logic, as is the access for parents and carers.
- For every role it is set down in writing which field it sees and for what purpose.
- Drivers see passenger data only for assigned tours within the relevant period.
- There is a log of who opened a passenger record.
- All staff are placed under a written confidentiality obligation and trained.
- Access is withdrawn immediately when someone leaves, temporary staff included.
Disclosure to funding bodies, relatives and service providers
Every disclosure is a processing operation in its own right and needs its own justification. The fact that someone belongs to the passenger’s circle is no substitute. Towards funding bodies, what is permissible is what is necessary for billing and proof of service, meaning approval status, journey data and the agreed records. The emergency note is not part of that. Which entries actually support an approval is covered in the article on approval and Pflegegrad for patient journeys.
With relatives and carers, the telephone is the most common weak point. Anyone who calls and sounds plausible gets information in many places. Legally, though, what counts is not the relationship but the authority, meaning parental responsibility, a rechtliche Betreuung (court-appointed legal guardianship) with a matching scope of duties, or a power of attorney. An adult passenger decides what their children get to know, not the other way round.
- Establish identity. Calling back on a number already on file is the simplest protection against giving information to unauthorised people.
- Check the authority. Is there documented authority to act, or is a relationship simply being assumed?
- Limit the scope. A pickup time is not information about someone’s state of health.
- Note the disclosure. Without documentation, the accountability duty under Article 5(2) GDPR cannot be met.
Disclosure also covers the use of external service providers. Anyone using software, hosting or telematics has to settle the roles between controller and processor and conclude a contract under Article 28(3) GDPR. With tracking systems, the same question arises again for the workforce, which is covered in the article on GPS tracking and the works council.
How long sensitive entries may be stored
A single retention period for all passenger data does not work, because two kinds of data sit side by side in the record. Billing and evidence documents are subject to commercial and tax retention duties, whereas sensitive free-text entries are only subject to purpose limitation. Treat both the same way and you either store too long or delete what you would need to prove in a dispute.
- Separate the data types. Decide which fields serve as evidence and which only serve the safe execution of the journey.
- Assign the retention duties. Under section 147(3) AO (Abgabenordnung, the German Fiscal Code), books and records must be kept for ten years, accounting vouchers for eight years and other documents for six years; section 257(4) HGB (Handelsgesetzbuch, the German Commercial Code) contains the parallel commercial law periods. Both concern the billing document, not the free text beside it.
- Define the purpose of the sensitive fields. An emergency note serves the safe execution of the journey. Once transport ends for good, that purpose falls away, and any further storage needs its own justification.
- Anchor deletion and log it. Record who deletes or anonymises which data type and when, and document that it actually happened. A rule nobody carries out is no help in an audit.
Deleting does not always mean deleting everything
It is often enough to strip out the sensitive fields and leave the billing-relevant structure in place. An archived journey record without the emergency note and without the grounds for approval satisfies the tax retention duty and no longer contains any Article 9 data. Check whether your system allows this field-level clean-up before you adopt a deletion rule it cannot technically implement.
Frequently asked questions
Yes, if the entry is necessary for carrying out the journey safely. It is nevertheless health data within the meaning of Article 9 GDPR, because it allows a conclusion to be drawn about a physical impairment; Recital 35 GDPR expressly names disabilities. What follows from that is a clear legal basis, a restriction to what is necessary, role-based access and a defined retention period.
In practice, operators usually rely on Article 9 paragraph 2 letter h GDPR, which permits processing for the purposes of preventive health care and for the provision of health or social care. At national level this is made concrete by section 22 paragraph 1 number 1 letter b BDSG, the German Federal Data Protection Act, which expressly applies to private bodies as well. Article 9 paragraph 3 GDPR additionally requires that the people carrying out the processing are subject to an obligation of secrecy. The precise classification depends on the contractual set-up and should be checked with your own data protection officer.
Only those who need it for their task. Dispatch needs capacity and care attributes, the assigned driver needs the instructions for his tour, and billing as a rule needs no medical detail at all. Section 22 paragraph 2 BDSG expressly names access restrictions as a required safeguard. This can be mapped through roles and visibility rules rather than through habits that have simply grown over time.
As a rule they do not. What matters for transport is which support, which equipment and which precaution is needed, not the diagnosis behind it. Recording diagnoses raises your risk under Article 9 GDPR without making the journey any safer. Action-based fields with short picklists are the better solution.
Sources
- Artikel 9 DSGVO: Verarbeitung besonderer Kategorien personenbezogener Datendsgvo-gesetz.de · Prohibition of processing in para. 1, health care in para. 2(h), obligation of secrecy in para. 3. Unofficial full-text source; official text: OJ L 119, 4.5.2016, p. 1
- Artikel 4 DSGVO: Begriffsbestimmungendsgvo-gesetz.de · No. 15 with the definition of health data. Unofficial full-text source
- Erwägungsgrund 35 DSGVO: Gesundheitsdatendsgvo-gesetz.de · Broad reading of the term, expressly including disabilities and disease risks
- Artikel 5 DSGVO: Grundsätze für die Verarbeitung personenbezogener Datendsgvo-gesetz.de · Para. 1(c) data minimisation, para. 2 accountability
- Artikel 6 DSGVO: Rechtmäßigkeit der Verarbeitungdsgvo-gesetz.de · Para. 1(b) contract, (c) legal obligation, (e) public task
- Artikel 7 DSGVO: Bedingungen für die Einwilligungdsgvo-gesetz.de · Para. 3: consent may be withdrawn at any time
- Artikel 28 DSGVO: Auftragsverarbeiterdsgvo-gesetz.de · Para. 3 with the mandatory content of a processing agreement
- Artikel 30 DSGVO: Verzeichnis von Verarbeitungstätigkeitendsgvo-gesetz.de · Para. 5: the exemption below 250 employees falls away for special categories
- Artikel 32 DSGVO: Sicherheit der Verarbeitungdsgvo-gesetz.de · Technical and organisational measures, pseudonymisation and encryption
- Artikel 35 DSGVO: Datenschutz-Folgenabschätzungdsgvo-gesetz.de · Para. 3(b): large-scale processing of special categories as a trigger
- § 22 BDSG: Verarbeitung besonderer Kategorien personenbezogener DatenBundesministerium der Justiz (gesetze-im-internet.de) · Para. 1 no. 1(b) for public and private bodies; para. 2 with access restrictions and training. As at July 2026
- § 3 Schwerbehindertenausweisverordnung: MerkzeichenBundesministerium der Justiz (gesetze-im-internet.de) · Meaning of the Merkzeichen aG, Bl, H and B
- Auftragsverarbeitung nach Art. 28 DSGVODer Landesbeauftragte für den Datenschutz Niedersachsen · Distinction between controller and processor, relevant when using external software
- § 80 SGB X: Verarbeitung von Sozialdaten im AuftragBundesministerium der Justiz (gesetze-im-internet.de) · Additional requirements for processing on behalf of social benefits providers, including prior notification of the supervisory authority
- § 147 AO: Ordnungsvorschriften für die Aufbewahrung von UnterlagenBundesministerium der Justiz (gesetze-im-internet.de) · Para. 3: ten, eight and six years depending on the type of document. As at July 2026
- § 257 HGB: Aufbewahrung von Unterlagen, AufbewahrungsfristenBundesministerium der Justiz (gesetze-im-internet.de) · Para. 4 with the parallel commercial law periods. As at July 2026
This article reflects the situation at the time of publication and does not replace individual legal or tax advice.
An access concept beats a question of trust
A clean Article 9 concept rarely fails on willingness. It fails because visibility cannot be steered in processes that have simply grown over the years. Vermo models passenger data so that dispatch, the assigned driver, billing and relatives each see a different slice, and access stays traceable. In a demo we go through your fields and roles in concrete terms.
Book a demo call