Skip to content

Spotlight on Future Researchers: Modesty Chang

Reimagining Digital Health Privacy: What Australia Can Learn from EU Regulations and the Medical Humanities
Modesty Chang

Australian Digital Health Agency. (2025). My Health Record. https://www.digitalhealth.gov.au/initiatives-and-programs/my-health-record

I’ll never forget my unease as my GP’s screen lit up with my medical history—data I never explicitly agreed to share. Being in Australia all these years, I’ve heard elderly relatives mentioning their old handwritten medical history form, which has shifted to cloud systems absorbing my sensitive data. Yet no one clearly explained who accesses it or how. This disconnection between health’s intimacy and digital systems’ opacity in Australia makes me wonder if this gap can be filled through regulation reform.

Australia’s passive consent model erodes the Australian residents’ trust and the EU’s policies prove we can do better. I will discuss how Australia’s digital health record regulations can evolve by learning from the perspectives of the European Union and the medical humanities. My first focus will be the substantial difference between the EU’s General Data Protection Regulations (GDPR) and the Australian My Health Record Act 2012 (MHR Act), upon which we will explore how medical humanities shape this debate by supporting one side.

Consent Laws for Digital Health Data and Their Implications: Australia versus the EU
The underlying principle of consent to data processing in the MHR Act of the Australian legislation is substantially and foundationally different from the GDPR. 

Definitions and Details: Yay or Nay
The MHR Act currently in practice requires only standing consent from the patient, which gives all healthcare organisations involved in their care the right to upload clinical information to their record without consent for individual occasions of upload. In fact, both sub-section 9(3) and subsection 41(4) of the MHR Act authorise registered healthcare providers to upload the patient’s health information if consent was “given expressly” or “in a particular way”. This ambiguity in regulatory limits illustrates how the Australian legislature sees the definition of consent as unproblematic, potentially aggravating future legal problems regarding healthcare data privacy.

On the other hand, the collection, storage, and analysis of large data sets have been strictly regulated by the EU’s GDPR since 2018. The GDPR marks the historical reinforcement of data privacy regulatory measures since the emergence of technologies that require human data to achieve effective outcomes. Similar to the MHR Act, the GDPR requires “explicit consent to the processing of those personal data” (Article 9(2)(a)). However, the GDPR spends 4 sections in Article 7 detailing the “Conditions for consent”, ensuring its “freely given” nature (Article 7(4)). Unlike the MHR Act’s seemingly unconcerned attitude towards definitions of consent, the GDPR took the lead in attempting to define terms with meanings that are often taken for granted, demonstrating the EU’s more comprehensive approach to the digital data protection of individuals than Australia.

Opt-out versus Opt-in
In the second reading speech of the 2018 amendment of the MHR Act, the Australian Minister of Health underlines their “opt-out” approach. The Minister states that the Australian Digital Health Agency has been working to inform consumers of their right to opt-out.  That, the onus is on the consumers to “make up their own minds” and choose not to participate. Though, in most cases, Australian residents would not be informed enough to confidently acknowledge their right to opt out of the digital health record. This opt-out model is perhaps a representation of Australia’s passive take on the patients’ will to protect their health data privacy.

In comparison with the MHR Act’s placement of an onus on the patient to opt-out, the GDPR places the accountability on the data controllers and processors. Following “the principle of transparency” (section 39), section 42 holds the healthcare providers responsible for ensuring that “the data subject is aware of the fact that and the extent to which consent is given”. In her speech regarding the GDPR, Commissioner Jourová of the European Commission repetitively highlights how this informative approach empowers users and benefits companies in multiple ways. This speech therefore encourages companies to comply with the GDPR to secure users’ right to be informed of the implications behind their consent. Without a doubt, the GDPR aims to tackle the challenge of data privacy by enfranchising the patients to balance the long-tilting scale towards the corporations, while the MHR Act expects the patient to opt-out as the corporations of privilege process the data collected by default.

The Medical Humanities’ Standing in This Debate
As the EU and Australia approach digital data privacy differently, the medical humanities can offer cultural insights to suggest whether Australia should follow the lead of the EU.

The MHR Act lacks definitions of key terms involved in health data processing such as consent, taking the definitions for granted. This takes the opposite approach of the medical humanities, which often finds itself questioning the traditional definition of terms, under the idea that the words to be defined are not stable constructs, but rather something ever-changing in a complex and dynamic system of human interactions or organs. Similarly, the GDPR’s approach is to provide detailed definitions of common yet broad terms such as personal data and acknowledge potential future amendments to the established laws. The EU’s approach therefore aligns with the medical humanities’ approach more closely than Australia’s, making it the leading force of digital health data protection legislation. 

Knowing Australian historical context, the data governance of First Nations Australians under the existing Anglo-centric value system should be explored specifically in the scope of the medical humanities. In The Declaration on the Rights of Indigenous Peoples (UNDRIP) adopted by The United Nations in 2007, Article 31 includes the standards for Indigenous Peoples to exercise control over their intellectual properties, including health data tied to genetic resources or derived from traditional knowledge. One could argue that the Australian health providers’ current right to collect data unless the patients suggest otherwise does not provide the First Nations people sufficient control over their health data in general, especially considering the lack of information about the right to opt out from the healthcare providers, hence undermining their data sovereignty. Thus, to settle this debate, perhaps it is best to hand the full decision-making power to the Indigenous peoples and have them make an affirmative decision of whether to opt in, like what the GDPR rules, with sufficient knowledge of the data processing systems as informed by the healthcare providers.

United Nations. (2007). The Declaration on the Rights of Indigenous Peoples (pp. 1).

Conclusion
My health data was collected for years without my full awareness. Australia’s opt-out model stemming from the MHR Act mirrors this silence. By embracing GDPR-style transparency and medical humanities’ ethical rigour—particularly the indigenous-led opt-in frameworks—Australia can bridge privacy gaps, empower patients, and align with global standards in digital health equity. This is, reclaiming our bodily narratives in a world that too often speaks for us, never with us.