Przejdź do treści
Medical You

Anonymised Data Commercialisation Consent

Last updated: 18 May 2026

This Anonymised Data Commercialisation Consent is currently available only in English. Localised versions will be published after legal review in each language.

MedicalYou Anonymised and De-identified Data Commercialisation Consent
FieldDetail
Document TitleMedicalYou Anonymised and De-identified Data Commercialisation Consent
Effective DateMonday, 18 May 2026
Version1.0
Intended AudienceUsers at signup, onboarding, and settings
PurposeSeparate consent and disclosure module permitting the commercial use, licensing, disclosure, and sale of anonymised, de-identified, and aggregated datasets derived from user-contributed health data
Data ControllerMedical You Pte. Ltd, 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914
Data Protection OfficerSamuel Banks — privacy@medicalyouglobal.com

Part A — Plain-English Explanation (Read This First)

What is this about?

When you use MedicalYou, you upload health information such as lab reports, prescriptions, wearable readings, and health notes. We can use that underlying data — after irreversibly stripping away everything that could identify you — to build anonymised or aggregated datasets. Think of it as pooling your readings together with thousands of others so that only patterns remain, not people.

What we would do with those datasets

We may use them ourselves for research and product improvement, or we may licence or sell them to third parties such as pharmaceutical companies, health researchers, insurers, or analytics firms. The buyer receives group-level trends and statistics — never a record that says “this is you.”

This is entirely optional

This consent is separate from everything else. Agreeing or disagreeing does not affect your ability to use the app. Your health records, AI summaries, and all core features work exactly the same either way.

What we will never do

We will never sell, licence, or otherwise disclose your identifiable personal information, your identifiable health data, or any pseudonymised data (data where a hidden key could still link a record back to you). Those are off limits regardless of whether you tick this box.

You can change your mind

You can withdraw this consent at any time in Settings → Privacy → Data Commercialisation. Withdrawal is prospective — we stop including your data in future datasets immediately. However, datasets that were released before your withdrawal cannot be recalled, because they are irreversibly anonymised and no longer contain or relate to your personal data. There is nothing left to delete.

Questions?

Contact our Data Protection Officer, Samuel Banks, at privacy@medicalyouglobal.com.

Part B — Full Legal Terms

1. Definitions

The following definitions apply throughout this document and are used consistently across all MedicalYou legal documents.

1.1 Personal Data means any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1) and the Singapore Personal Data Protection Act 2012 (PDPA) s 2.

1.2 Health Data / Data Concerning Health means a special category of personal data pertaining to the physical or mental health of a natural person, as defined in GDPR Article 4(15) and Article 9, and constituting sensitive personal information under the California Privacy Rights Act (CPRA), “consumer health data” under the Washington My Health My Data Act RCW 19.373, and sensitive or special-category data under the UAE Federal Decree-Law No. 45 of 2021 (PDPL).

1.3 Protected Health Information (PHI) has the meaning given in HIPAA 45 CFR § 164.514. MedicalYou operates as a direct-to-consumer personal health record app and is generally neither a HIPAA-covered entity nor a business associate. Accordingly, most user data held by MedicalYou does not constitute PHI under HIPAA. HIPAA standards are nonetheless applied as a best-practice floor for de-identification methodology.

1.4 Pseudonymised Data means personal data that has been processed so that it can no longer be attributed to a specific data subject without the use of additional information, as defined in GDPR Article 4(5). Pseudonymised data remains personal data. It cannot be re-identified by reference to the additional information held separately. Pseudonymised data is not anonymous data, is not de-identified data, and is not within any category that Medical You Pte. Ltd commercialises. This document does not authorise any commercialisation of pseudonymised data.

1.5 Anonymised Data means information that does not relate to an identified or identifiable natural person, or data that has been rendered anonymous in such a manner that the data subject is not or no longer identifiable. Pursuant to GDPR Recital 26, to determine whether a person is identifiable, account should be taken of all the means reasonably likely to be used — such as singling out — either by the controller or by any other person. Anonymised data falls outside the scope of GDPR and the UK GDPR. Consistent with ICO guidance on personal data, anonymisation is treated as an irreversible process; once complete the output ceases to be personal data.

1.6 De-identified Data means data that has been processed using one of the two methods recognised by HIPAA 45 CFR § 164.514 and elaborated in HHS de-identification guidance:

  • Safe Harbor Method: all eighteen categories of direct and quasi-identifier specified in 45 CFR § 164.514(b)(2) are removed or generalised, and Medical You Pte. Ltd has no actual knowledge that the remaining information could be used alone or in combination with other information to identify an individual; or
  • Expert Determination Method: a qualified statistical or scientific expert applies generally accepted principles and methods and certifies that the risk of identifying an individual is very small.

1.7 Aggregated Data means statistical or group-level outputs derived by combining data from multiple users into counts, rates, averages, or similar summaries, where no individual-level record is present or recoverable.

1.8 Commercialisation means any act of creating, using, reproducing, disclosing, distributing, licencing, sub-licencing, or selling Anonymised Data, De-identified Data, or Aggregated Data, whether for monetary consideration or otherwise.

1.9 Recipient means any third party to whom Medical You Pte. Ltd discloses, licences, or sells a dataset under this consent. Recipients are subject to Document 7 — Anonymised Data Recipient Terms, which imposes contractual obligations including a strict prohibition on re-identification.

2. Scope of This Consent

2.1 This document is a standalone, granular consent module. It does not form part of the Terms of Service, and acceptance of the Terms of Service does not constitute acceptance of this consent. Acceptance of this document does not form part of the lawful-basis assessment for MedicalYou’s processing of your health data for core app functions (such as AI summaries and health insights), which is governed by a separate Health Data Processing Consent.

2.2 This consent is optional. A user who withholds or withdraws this consent retains full access to all MedicalYou features. Withdrawal or refusal will not result in reduced functionality, degraded service, or any form of detriment.

2.3 This consent is default-off. The corresponding toggle is unchecked at signup and at all times until the user affirmatively selects it. See Section 7 for the default-state analysis by jurisdiction.

3. Grant of Rights

3.1 Where a user has affirmatively enabled this consent, the user grants Medical You Pte. Ltd a perpetual, worldwide, royalty-free, sublicensable right and licence to:

  • process the user’s personal data and health data solely to the extent necessary to produce Anonymised Data, De-identified Data, and Aggregated Data as defined in Sections 1.5–1.7;
  • use, reproduce, store, and analyse such Anonymised Data, De-identified Data, and Aggregated Data internally for research, product development, quality assurance, and business intelligence purposes;
  • disclose, distribute, licence, and sell such Anonymised Data, De-identified Data, and Aggregated Data to third-party Recipients, including but not limited to pharmaceutical companies, health insurers, academic and clinical research institutions, public health authorities, and health analytics firms;
  • include such Anonymised Data, De-identified Data, and Aggregated Data in combined or derived datasets, publications, reports, and models.

3.2 For the avoidance of doubt, the grant in Section 3.1 does not extend to:

  • identifiable personal data;
  • identifiable health data;
  • pseudonymised data;
  • data that does not satisfy the standards in Sections 1.5–1.6 and Section 4 of this document; or
  • data obtained from users who have not enabled this consent.

3.3 The processing of personal data and special-category health data to create Anonymised or De-identified sets constitutes processing under GDPR Article 4(2) and GDPR Article 9 for EU/UK users. The lawful basis for that creation step is explicit consent under GDPR Article 6(1)(a) and GDPR Article 9(2)(a). Once the output is verified as anonymous, it falls outside GDPR and this document operates as the authorisation for its subsequent commercialisation.

4. The Red Lines — What Prevents Data from Being Anonymous or De-identified

Medical You Pte. Ltd applies the following criteria. If any criterion is met, the data is not treated as anonymous or de-identified and is not released or commercialised.

4.1 Retention of Direct Identifiers. Any output that retains a name, email address, national identity number, passport number, telephone number, date of birth (day and month), full postal address, account username, or any other field that directly identifies a natural person is not anonymous. All such identifiers are removed before any dataset leaves the anonymisation pipeline.

4.2 Retention of a Re-identification Key. Where technical pseudonymisation is used during internal processing, the key or mapping table that would permit linkage back to the data subject must not be accessible to any Recipient and must not appear in any released dataset. Any dataset accompanied by or linked to a re-identification key is pseudonymised, not anonymous.

4.3 Combination with External Datasets. Medical You Pte. Ltd assesses, prior to each release, whether the proposed dataset — when combined with publicly available or reasonably obtainable external datasets (e.g., voter rolls, property records, social media profiles, commercial data brokers) — could enable singling out of an individual. Datasets that fail this linkage attack assessment are not released.

4.4 Small-Cell and Low-k Outputs. Any cell, stratum, or record group in a dataset that contains fewer than a defined suppression threshold of individuals (the exact threshold is set by the Medical You anonymisation team following expert review, but is no less than five and typically at least ten) is suppressed or generalised before release. Datasets that do not meet a minimum k-anonymity value of k=5 or such higher value as the expert review specifies are not released.

4.5 Free-Text Health Notes Containing Identifiers. Unstructured text such as health diary entries, notes added by the user, or free-text fields may contain proper names, locations, treating clinician names, hospital names, or other quasi-identifiers. Such free-text fields are excluded from released datasets unless a natural-language processing review confirms that identifying content has been removed and the risk of re-identification is very small.

4.6 Precise Geolocation. GPS coordinates, home address, or any location accurate to street level or postcode/ZIP level are removed. Only coarse-grained location data (country or broad region) may appear in a dataset where it has been reviewed and poses no re-identification risk in context.

4.7 Rare Disease and Location Combinations. Where a user’s health data relates to a rare condition (broadly, a condition with a prevalence of 1 in 2,000 or fewer in a population), and where the dataset would disclose that rare-condition status in combination with any location information — even coarse — the record is excluded or the rare-condition field is further generalised, because the combination may be sufficient to identify the data subject in small communities.

4.8 Device Identifiers. Device IDs, advertising identifiers, IMEI numbers, and IP addresses are removed. Wearable device serial numbers and model identifiers are removed or generalised to device category.

4.9 Expert Review and Suppression Commitments. Before any dataset is first released to a new category of Recipient or for a new purpose, Medical You Pte. Ltd will conduct — or commission from a qualified statistical or scientific expert — a documented re-identification risk assessment consistent with the HHS Expert Determination guidance. The assessment will be retained and made available to regulators upon request.

4.10 Contractual Obligations on Recipients. Every Recipient receives the dataset subject to Document 7 — Anonymised Data Recipient Terms, which includes:

  • a strict prohibition on any attempt, direct or assisted, to re-identify any data subject;
  • an obligation to apply equivalent anonymisation standards to any derived dataset;
  • a prohibition on combining the dataset with external data for the purpose of re-identification;
  • a requirement to notify Medical You Pte. Ltd immediately upon discovery of any re-identification or suspected re-identification event;
  • an obligation to delete the dataset upon termination of the licence; and
  • flow-down of these obligations to any sub-licencee.

5. No-Re-identification Commitments by Medical You Pte. Ltd

Medical You Pte. Ltd commits that it will not:

  • attempt to re-identify any data subject from any anonymised or de-identified dataset it produces, retains, or licences;
  • make available any information, key, or auxiliary data to any Recipient that would facilitate re-identification;
  • combine anonymised datasets with identifiable personal data in a manner that re-identifies data subjects; or
  • release any dataset that has not passed the quality controls in Section 4.

Medical You Pte. Ltd commits that it will:

  • maintain written anonymisation and de-identification policies reviewed at least annually;
  • retain expert-determination reports for a minimum of five years;
  • upon discovery of a re-identification event or suspected re-identification event, notify the affected users and relevant supervisory authorities in accordance with applicable breach-notification obligations; and
  • immediately suspend release of the affected dataset pending investigation.

6. Default-State and Jurisdiction Analysis

6.1 Summary Table

JurisdictionLegal FrameworkIs Anonymised Data “Personal Data”?Commercialisation MechanismRequired Default StateMedical You Recommendation
SingaporePDPA 2012No — anonymised data is outside PDPA “personal data”Disclosure/opt-out acceptable for the anonymised output; pre-anonymisation processing requires consent/notificationOpt-out acceptable but notice recommendedOpt-in, default-off (see narrative)
EU / EEAGDPRNo — outside GDPR once anonymous (Recital 26); but creation step is processing of special-category dataExplicit consent (Art 9(2)(a)) for creation step; opt-inDefault-off, opt-in mandatoryOpt-in, default-off
United KingdomUK GDPR / DPA 2018No — same as GDPR (ICO confirmed)Explicit consent for creation step; opt-inDefault-off, opt-in mandatoryOpt-in, default-off
UAE (mainland)PDPL (Federal DL No. 45/2021)No, but creation from sensitive data needs explicit consentExplicit consent for sensitive data processingOpt-in, default-offOpt-in, default-off
UAE (DIFC)DIFC DPL No. 5/2020No, once anonymousExplicit consent for special-category creation stepOpt-in, default-offOpt-in, default-off
California (US)CPRADe-identified outside “personal information” if standards metDisclosure acceptable; offer opt-out as best practiceOpt-out (CPRA); opt-in recommendedOpt-in, default-off (global alignment)
Washington State (US)MHMDA (RCW 19.373)Consumer health data if not conclusively de-identified; if truly de-identified, exemptIf sale: separate signed valid authorization; if genuinely de-identified and exempt: no auth needed, but use opt-in for certaintyOpt-in; signed authorization for any saleOpt-in, default-off; signed authorization variant available (Section 8.3)

6.2 Singapore Narrative

Under the PDPA, “personal data” is defined as data about an individual who can be identified from that data or from that data combined with other information to which the organisation has or is likely to have access. Properly anonymised data — where the data subject cannot be identified by any means reasonably likely to be used — falls outside this definition, and the PDPA’s obligations do not apply to the anonymised output itself (PDPC obligations). The act of processing personal data to create an anonymised dataset remains subject to the PDPA’s consent and purpose-limitation obligations. Medical You Pte. Ltd therefore covers that creation step through this consent. Although an opt-out model would be legally defensible for the anonymised output under Singapore law, Medical You Pte. Ltd adopts opt-in, default-off globally for coherence, user trust, and compliance with stricter GDPR and MHMDA standards applicable to overlapping user populations.

6.3 GDPR and UK GDPR Narrative

GDPR Recital 26 confirms that GDPR “does not therefore apply to the processing of such anonymous information, including for statistical or research purposes.” However, the process of taking special-category health data and rendering it anonymous is itself processing under GDPR Article 4(2). Because health data is special-category data under GDPR Article 9, a condition in Article 9(2) is required. Medical You Pte. Ltd relies on the data subject’s explicit consent under Article 9(2)(a), which requires a freely given, specific, informed, and unambiguous indication by a statement or clear affirmative action. A pre-ticked box does not satisfy this standard. The consent must be default-off and opt-in. The ICO confirms that organisations relying on explicit consent for special-category data must ensure the individual has been informed of the specific purpose and has actively opted in. The same analysis applies under UK GDPR and the Data Protection Act 2018.

6.4 UAE Narrative

The UAE Federal Decree-Law No. 45 of 2021 (PDPL) and the DIFC Data Protection Law No. 5 of 2020 both treat health data as sensitive or special-category personal data requiring explicit consent. The creation of anonymised sets from health data requires explicit consent. Default-off opt-in is required.

6.5 California CPRA Narrative

Under the CPRA, “personal information” does not include truly de-identified information (where the organisation has implemented technical safeguards, business processes to prevent re-identification, and no-re-identification commitments). Where data meets this standard, commercialisation does not engage opt-out-of-sale rights. Nonetheless, health information is sensitive personal information under CPRA, and as a matter of best practice Medical You Pte. Ltd provides an opt-in default-off toggle consistent with its global posture.

6.6 Washington My Health My Data Act Narrative

The Washington My Health My Data Act, RCW 19.373, imposes stringent requirements on the sale of “consumer health data.” Where data is genuinely de-identified under the Act’s standards, it falls outside the definition of consumer health data and the Act’s authorization requirement does not apply. However, because Medical You Pte. Ltd cannot guarantee that every dataset component satisfies the Act’s de-identification standard with certainty at the time of collection, and because any uncertainty means a signed valid authorization is required for any sale, Medical You Pte. Ltd implements: (a) opt-in, default-off; and (b) a Washington-specific signed authorization variant (see Section 8.3) as a fallback for any element of Commercialisation that could be characterised as a sale of consumer health data not conclusively de-identified. The FTC Health Breach Notification Rule also applies to Medical You Pte. Ltd as a personal health record vendor not regulated by HIPAA for US users, and Medical You Pte. Ltd maintains compliance with that Rule separately.

6.7 Global Recommendation

Medical You Pte. Ltd implements the consent in this document as an opt-in, default-off, separately presented granular toggle across all jurisdictions. This is the safest compliant posture for the combination of GDPR, UK GDPR, UAE PDPL, DIFC DPL, Washington MHMDA, and CPRA requirements that apply across Medical You Pte. Ltd’s user base.

7. Withdrawal of Consent and Prospective Effect

7.1 Right to Withdraw. A user who has enabled this consent may withdraw it at any time without giving any reason and without detriment, by navigating to Settings → Privacy → Data Commercialisation and toggling the switch to off, or by contacting privacy@medicalyouglobal.com.

7.2 Prospective Effect. Withdrawal takes effect from the date and time it is recorded. Upon withdrawal, Medical You Pte. Ltd will:

  • immediately cease including the user’s personal data or health data in any new anonymisation or de-identification processing conducted for commercialisation purposes; and
  • cease transmitting the user’s data to any new Recipients under this consent.

7.3 Why Already-Released Datasets Cannot Be Recalled. Under GDPR Recital 26 and consistent legal authority, data that has been irreversibly anonymised no longer relates to an identified or identifiable natural person. It is therefore no longer personal data. Because the anonymisation process is irreversible and no re-identification key is retained or accessible, Medical You Pte. Ltd is technically unable to identify which aggregate records, statistical cells, or model parameters were derived from any individual user’s data. There is no personal data to delete, and no right of erasure arises in respect of that anonymised output. This is not a limitation of GDPR rights — it is the consequence of those rights being fulfilled: the data no longer relates to the user.

7.4 Prospective Stopping Commitment. Withdrawal is fully effective in stopping the user’s contribution to future datasets. Medical You Pte. Ltd will document the withdrawal in its processing records and exclude the user from all subsequent commercialisation pipelines within a reasonable technical period, not exceeding 30 days.

7.5 Effect on Other Processing. Withdrawal of this consent has no effect on the separate Health Data Processing Consent, Terms of Service, or any other lawful basis for processing that Medical You Pte. Ltd relies upon. Core app functionality is unaffected.

8. On-Screen Consent Interface and Checkbox Text

8.1 Standard Global Consent Toggle (All Jurisdictions)

Heading displayed to user:

Optional: Help advance health research

Supporting microcopy displayed immediately below the heading:

MedicalYou can turn your health data into fully anonymised, aggregated datasets — where no one can identify you — and may use, licence, or sell those datasets to health researchers and partners. This is completely optional. Turning it on or off does not affect any app feature. You can change this any time in Settings. We will never sell your personal or identifiable health information. Read the full Anonymised Data Commercialisation Consent

Checkbox label:

☐ I agree that MedicalYou may process my health data to create anonymised and aggregated datasets, and may use, licence, and sell those datasets to third parties, as described in the Anonymised and De-identified Data Commercialisation Consent.

Default state: Unchecked.

Presentation requirement: This checkbox must be rendered on a separate screen or clearly separated section from the Terms of Service checkbox and the Health Data Processing Consent checkbox. It must not be pre-checked and must not be bundled with any other acceptance.

8.2 Inline Withdrawal Notice (Settings Screen)

When the toggle is active, the settings screen shall display:

Anonymised data commercialisation is ON. MedicalYou may include your health data (in anonymised form) in datasets that may be licenced or sold to research partners. Toggle off at any time. Previously released anonymised datasets cannot be recalled as they no longer contain your personal data.

When the toggle is off:

Anonymised data commercialisation is OFF. Your health data will not be included in any commercialised anonymised datasets. This does not affect any app feature.

8.3 Washington State Signed Authorization Variant (Fallback)

For users located in Washington State (USA) where Medical You Pte. Ltd determines, in consultation with legal counsel, that any element of the proposed Commercialisation could constitute a sale of consumer health data under RCW 19.373 and the data does not satisfy the Act’s de-identification exemption with certainty, Medical You Pte. Ltd will present the following signed authorization in addition to the standard toggle:

WASHINGTON MY HEALTH MY DATA ACT — CONSUMER HEALTH DATA AUTHORIZATION

This authorization is required by Washington law (RCW 19.373) before MedicalYou may sell consumer health data.

I, the undersigned, being a consumer located in Washington State, hereby authorize Medical You Pte. Ltd (160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914) to sell consumer health data derived from my MedicalYou account, subject to the following terms:

  • Data categories authorized for sale: Anonymised, de-identified, and aggregated health datasets derived from health records, wearable data, and health metrics I have uploaded to MedicalYou, processed so that I cannot be identified.
  • Recipients: Third-party health research organizations, pharmaceutical companies, health insurers, and analytics firms, each bound by contractual no-re-identification obligations.
  • Purpose: Health research, epidemiological analysis, product development, and commercial purposes.
  • Duration: This authorization remains in effect until I withdraw it.
  • Right to withdraw: I understand that I may withdraw this authorization at any time by contacting privacy@medicalyouglobal.com or via Settings → Privacy → Data Commercialisation.
  • Effect of withdrawal: Prospective only. Previously sold de-identified datasets cannot be recalled.
  • No conditioning: I understand that refusing or withdrawing this authorization will not affect my access to MedicalYou services.

By typing my full name below and clicking “Authorize,” I provide my electronic signature and confirm that I have read and understood this authorization.

Full Name: [User types name] Date: [Auto-filled]

Medical You Pte. Ltd’s commercial position is that it will only sell datasets that are properly de-identified and thus exempt from consumer health data requirements under RCW 19.373. The signed authorization above is provided as a precautionary compliance measure for any scenario where that de-identification determination is contested.

9. Data Retention and Deletion

Underlying personal data processed to create anonymised datasets is retained only for the period necessary to complete the anonymisation process, and is then either deleted (if no longer needed for core app functions) in accordance with the Retention Limitation Policy, or retained solely for core app functions under the Health Data Processing Consent. The anonymised output, which is not personal data, is retained and may be used indefinitely.

10. Contact and Complaints

For questions about this consent, to exercise withdrawal, or to make a complaint, contact:

  • Data Protection Officer: Samuel Banks
  • Email: privacy@medicalyouglobal.com
  • Postal address: Medical You Pte. Ltd, 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914

Users may also lodge complaints with the relevant supervisory authority:

  • Singapore: Personal Data Protection Commission (PDPC) — https://www.pdpc.gov.sg
  • EU/EEA: The supervisory authority in the user’s Member State of habitual residence
  • United Kingdom: Information Commissioner’s Office (ICO) — https://ico.org.uk
  • UAE / DIFC: UAE Data Office; DIFC Commissioner of Data Protection
  • United States (California): California Privacy Protection Agency — https://cppa.ca.gov
  • United States (Washington): Washington State Attorney General — https://www.atg.wa.gov

Sources