research purposes, such as epidemiological research or machine learning. The legal framework of this secondary use derives from data protection law, in particular shaped by the GDPR, as well as confidentiality obligations. Data protection law, in particular the GDPR, apply when personal data are processed; their specific requirements are examined against the background of secondary use. To the
... [Show full abstract] extent that the GDPR applies, the requirements of informed consent as a legal basis are evaluated. Possibilities for data processing without consent are also considered and discussed. Finally, the paper examines the relationship between data protection law and confidential obligations and makes proposals de lege lata and de lege ferenda.