Universität Bonn

Department of Law

Data Visiting as a legal and technical solution for the use of (sensitive) personal data 


Overview

Personal data - particularly highly sensitive data related to health or genetics - holds enormous potential for progress and innovation in preventive care, health care, and research.

Against this backdrop, the ZMDT examined the legal and technical approach of 'data visiting' for sharing personal data across healthcare and research institutions. The project was conducted in collaboration with the German Center for Neurodegenerative Diseases (DZNE), which provided key expertise in medical technology.

ChatGPT-Image-27.-Jan.-2026-10_09_05.webp
© KI-generiert

An Analysis of Data Processing Activities Under Data Protection Law in the Context of Data Visiting, Using Swarm Learning as an Example

Healthcare and research institutions collect, store, and analyze personal data - in particular, sensitive data (e.g., age, gender, blood type, genetic or biometric characteristics, and health data) - for the purposes of healthcare and medical research. These constitute special categories of personal data under Article 9(1) of the GDPR, the processing of which - even in pseudonymized form - falls within the scope of the GDPR. Since even indirect characteristics can enable identification, a legal basis under Article 6(1) in conjunction with Article 9(2) of the GDPR is required for every processing operation. This applies both to the use of primary data - i.e., initial processing or at least processing for a primarily specified purpose - and to the use of secondary data, i.e., “further processing of (sensitive) personal data for purposes other than those for which the data was originally collected.”

To ensure that the requirements of the GDPR do not need to be taken into account, while at the same time guaranteeing adequate protection of personal data in accordance with Article 8 of the Charter of Fundamental Rights of the European Union (CFREU) and patients’ right to informational self-determination pursuant to Article 2(1) in conjunction with Article 1(1) of the German Basic Law (GG), personal data is anonymized through aggregation during Data Visiting. Personal data within the meaning of Article 4(1) of the GDPR is aggregated in such a way that a Data Visitor has access only to the parameters derived from this aggregation as anonymized data, and these parameters become usable within the framework of swarm learning.

In this context, the key factors for ensuring adequate protection of personal data are determining when - and, in particular, until when - data is legally considered anonymized, and how this can be technically implemented.

The article “Data Visiting: The Case of Swarm Learning” in Issue 7 of the Journal of Artificial Intelligence and Law (KIR) examines in greater detail the aggregation models used in data visiting and algorithm sharing, based on the required level of anonymity according to the current state of law and technology.


KIR_07_2026_Mantel.webp
© KIR

Would you like to gain a detailed understanding of the legal and technical aspects – supplemented by clear medical illustrations? If so, we recommend taking a look at issue 7 of the Journal of Artificial Intelligence and Law (KIR). Please note that this article is in German. 


Wird geladen