> For the complete documentation index, see [llms.txt](https://opora.gitbook.io/opora-health-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://opora.gitbook.io/opora-health-documentation/regulations.md).

# Regulations

### Why Legal Compliance Matters

Health data used for AI must meet strict legal and ethical standards. Failure to comply may lead to:

* Legal liability;
* Loss of research/commercial value;
* Ethical breaches impacting patients and institutions.

AI-Ready data must be **lawful, transparent, secure, and fair,** across jurisdictions.

***

### Key Legal Frameworks Covered by OPORA

#### 🇪🇺 General Data Protection Regulation (GDPR)

* Lawful basis for processing (consent, public interest, etc.);
* Data minimisation and purpose limitation;
* Right to access, erasure, portability;
* Anonymisation and pseudonymisation standards;
* Cross-border data transfer restrictions;
* Mandatory breach notification;

***

#### 🇪🇺 EU AI Act (2024)

* Classifies health AI as **high-risk;**
* Requires:
  * Human oversight;
  * Transparency in AI outputs;
  * Robust documentation of training and input data;
  * Bias monitoring.
* Prohibits use of certain sensitive attributes unless justified.

***

#### 🇬🇧 UK Data Protection Act (2018)

* Mostly mirrors GDPR post-Brexit;
* Maintains:
  * Lawful processing rules.
  * Special category data safeguards;
  * Regulatory alignment with NHS Digital and ICO.

***

#### 🇺🇸 HIPAA (if applicable)

* Covers de-identification for health data
* Mandates:
  * **Privacy Rule and Security Rule**
  * **Patient rights and disclosures**
  * **Breach reporting**

🔧 *OPORA can be configured to meet HIPAA standards for U.S.-based partnerships.*

***

### Cross-Jurisdiction Support

OPORA enables **region-specific deployments** with isolated databases and compliance-aware routing:

| Region        | Legal Basis                   | Data Residency | Consent Handling         |
| ------------- | ----------------------------- | -------------- | ------------------------ |
| EU/EEA        | GDPR, EU AI Act               | Required       | Explicit, auditable      |
| UK            | UK DPA, NHS Guidelines        | Required       | Consent + public task    |
| Global (R\&D) | Local + Aggregated Compliance | Optional       | Anonymised, opt-in basis |

> AI-Ready = Compliant-by-Design. OPORA handles the legal complexity so you can focus on outcomes.

***
