noyb published an ad‑hoc paper outlining how the GDPR permits processing personal data to combat the coronavirus pandemic. The paper cites Articles 6(1)(d) and 9(2)(i) as legal bases and stresses the need for privacy‑by‑design, data minimisation and user control. It advises voluntary, locally stored and encrypted contact‑tracing solutions.
Why it matters: The guidance clarifies that GDPR does not need to be waived for epidemic response, but must be observed, shaping how health data can be used responsibly.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.