27–29 Oct 2026
Santiago Compostela
Europe/Madrid timezone

EOSC-TITAN and Supporting Secure Processing Environments for Secondary Use of Health Data under the EHDS

28 Oct 2026, 16:10
15m
Santiago Compostela

Santiago Compostela

Facultad de Química Santiago de Compostela Aula Magna
Presentation (15' + 5' for questions) Trusted Research Environments Parallel track - III

Speaker

Natalia Borgoñós García (Universidad de Murcia)

Description

The European Health Data Space (EHDS) introduces a common framework for the secure use of electronic health data for research, innovation, public health and policy-making. A key element of this framework is the use of Secure Processing Environments (SPEs), which must ensure that personal health data can only be accessed and processed by authorised users for specific and approved purposes, while preventing unauthorised modification, access, removal, or download of the data. In addition, SPEs must ensure that only aggregated results or fully anonymised data can be extracted, following the principles of data minimisation and purpose limitation. These requirements introduce significant technical challenges for the deployment of trustworthy and interoperable infrastructures for health-data processing.

The EOSC-TITAN project (Trusted envIronments for confidenTiAl computiNg and secure data sharing) addresses these challenges by enriching the European Open Science Cloud (EOSC) with a software platform for confidential data collaboration and secure, privacy-preserving data processing. EOSC-TITAN develops an end-to-end approach combining Confidential Computing, Trusted Execution Environments (TEEs), Remote Attestation for those environments, distributed access control, privacy-enhancing technologies and end-to-end data protection across the whole data lifecycle: storage, transfer and processing.

The applicability of these capabilities to eHealth is demonstrated through EOSC-TITAN’s Collaborative Use of Machine Learning in Healthcare use case. The objective is to enable collaborative analysis and Machine Learning over sensitive healthcare models and datasets while preventing direct access to the underlying data. TEEs provide an isolated execution environment in which processing can take place over protected datasets, while remote attestation enables verification of the security properties of the execution environment. Federated and privacy-preserving Machine Learning further allows multiple parties to collaborate without requiring the centralisation or unrestricted sharing of sensitive health information.

EOSC-TITAN also addresses the governance requirements surrounding SPEs through distributed access control, identity and authorisation mechanisms, transaction logging, privacy-preserving technologies, and controlled data-sharing policies. Its architecture supports mechanisms to determine what data can be shared, with whom, and under which processing conditions, while confidential computing capabilities based on TEEs, secure enclaves, and federated learning can be provisioned according to the requirements of a particular processing task.

In this context, EOSC-TITAN provides a set of technical building blocks that can support the implementation of EHDS-compliant SPEs for eHealth, bridging regulatory requirements with practical secure-processing capabilities. By combining confidential data processing, privacy-preserving Machine Learning, distributed access control, and interoperability with EOSC and emerging European data-space architectures, EOSC-TITAN contributes to a new paradigm in which health data remain protected and under the control of their providers while enabling authorised research and innovation. The project therefore demonstrates how Confidential Computing and privacy-enhancing technologies can help transform the EHDS vision for secure secondary use of health data into deployable, interoperable, and trustworthy processing infrastructures.

Authors

Mr Antonio Skarmeta (Universidad de Murcia) Natalia Borgoñós García (Universidad de Murcia)

Presentation materials

There are no materials yet.