HIPAA focuses on healthcare organizations and how personal health information is used in the US. GDPR, on the other hand, is broader legislation that supervises any organization handling personally identifiable information (PII) of an EU or UK citizen.

GDPR governs the use of and applies to all personal data of persons within its scope. In contrast, HIPAA’s narrower scope only applies to HIPAA-protected health information (PHI).

GDPR sets compliance standards for all entities within its scope. HIPAA sets standards for covered entities and business associates (BAA).

Regarding consent, GDPR requires explicit consent for processing personal health data (which falls under sensitive data). However, the data may be processed without consent if it meets one of the processing conditions in Article 9 of GDPR and a legal basis applies.

A HIPAA authorization is consent obtained from an individual that permits a covered entity or business associate to use or disclose that individual’s protected health information to someone else for a purpose otherwise not permitted by the HIPAA Privacy Rule. HIPAA allows disclosure of some PHI for 12 national priority purposes, including treatment purposes, without the individual’s consent (authorization).

We’ve written some posts to help you understand GDPR requirements and how they might apply to you:

Be sure to also read our HIPAA-related content:


  • Banking website analytics for financial services: Tracking without compromising customer trust

    You don’t have to choose between insights and trust – modern banking analytics can deliver both when implemented correctly. This article explores best practices and recommended steps for banking website analytics, as well as ways to avoid common pitfalls to ensure compliance without sacrificing the quality of insights.

  • Five things every marketer should know about web analytics in 2026

    Web analytics is changing fast. AI is moving from buzzword to actual business impact, privacy rules keep shifting on both sides of the Atlantic, and marketing teams are rethinking their tool stacks. What does this mean for analytics strategy in 2026? We asked industry experts to share their predictions.