A dispensary in Denver, a pharmacy in Düsseldorf, a licensed producer in Ontario, and a telehealth clinic in Melbourne all capture roughly the same record: an identity document, a date of birth, a product, a cannabinoid profile, a quantity, a timestamp. Four nearly identical rows in four databases.

Legally, they are four different things. One is retail data with almost no sectoral protection. One is a special category of personal data whose mishandling can draw a percentage-of-global-revenue fine. One sits under a federal privacy law with a mandatory breach register and a health-information overlay. One is regulated health information the moment a prescriber’s name is attached to it.

Operators keep asking us the wrong question — “are we HIPAA compliant?” The question that actually determines your exposure is: what is this data classified as, in every jurisdiction where it lands? We’ve mapped the fragmented privacy landscape international operators face before. This piece narrows to the single most consequential variable in that mess: classification.

Why Classification Is the Variable That Matters

Classification is upstream of everything expensive. It determines your lawful basis for processing, your retention ceiling, whether you need a Data Protection Impact Assessment, whether encryption is advisory or effectively mandatory, how fast you must notify after a breach, and what a regulator multiplies your penalty by.

Two operators can run identical technology stacks and identical SOPs, and one carries five times the regulatory exposure — purely because of what the data is called where they operate.

The trap is that classification usually isn’t decided by the product you sell. It’s decided by inference. Most modern privacy regimes protect not only data explicitly labeled medical, but data from which a health condition can be deduced. That is precisely what a cannabis transaction record does: a high-CBD tincture bought fortnightly at 9 a.m. on a medical program ID is a clinical signal, whether or not a clinician ever touched the record.

The Map

United States: A Gap, Not a Standard

Most dispensaries are not HIPAA-covered entities. HIPAA attaches to health plans, clearinghouses, and providers billing electronically — not to a retailer selling a product a customer happens to use medicinally. That leaves a genuine vacuum, which is exactly the HIPAA gap we documented in the state health-data laws now closing it.

What fills the gap is state law, and state law increasingly uses inference-based definitions. Washington’s My Health My Data Act reaches “consumer health data” broadly enough to capture dispensary purchase histories and location data around a clinic or dispensary — with a private right of action attached. Nevada has a close analogue. Several of the 23 state comprehensive privacy laws now in force treat health data and, separately, biometric identifiers as sensitive categories requiring opt-in consent.

Practical consequence: a US operator can be simultaneously outside HIPAA and inside a stricter consumer-health regime with individual plaintiffs, not just regulators, holding the whip.

European Union: Special Category by Default

Under GDPR Article 9, data concerning health is a special category — processing is prohibited unless a narrow exception applies. For medical cannabis dispensed through a pharmacy channel, that classification is not arguable, it is automatic. For adult-use or wellness channels, EU regulators have consistently read Article 9 to cover data from which health status can be inferred, and a cannabinoid-therapy purchase pattern is a textbook inference.

Layer on the European Health Data Space (Regulation (EU) 2025/327), whose interoperability and security certification obligations for EHR systems and health data holders started landing in 2026. Any operator plugged into a prescription or dispensation flow — electronic prescriptions and electronic dispensations are explicitly in scope for primary use — is being pulled into a certified-systems world that most cannabis software vendors were never built for. Germany’s operators felt the first edge of this with the MedCanG amendment’s patient-data provisions, and the direction of travel across the EU’s broader cannabis compliance regime is the same: pharmacy-grade or nothing.

Canada: Federal Baseline, Provincial Teeth

PIPEDA governs commercial personal data federally, with provincial health-information statutes (PHIPA in Ontario, HIA in Alberta, and others) governing custodians. A retailer isn’t automatically a health custodian — but Canada’s mandatory breach reporting for “real risk of significant harm,” plus the reputational sensitivity of cannabis records, has made the distinction less protective in practice than on paper. Canadian licence holders moving product internationally inherit the receiving jurisdiction’s classification too, which compounds the supply-chain exposure in Canada’s export boom.

Australia: Health Information, Explicitly

Australia’s Privacy Act defines health information expressly and treats it as sensitive information requiring consent, with the Notifiable Data Breaches scheme on top. Critically, the definition covers information about a health service provided to an individual — which captures the telehealth-clinic model that now dominates Australian medicinal cannabis supply. Given the volume of prescribing running through those clinics, most Australian cannabis data is health information without any interpretive stretch. That’s the compliance floor beneath the TGA-side cybersecurity obligations we mapped for Australian operators.

United Kingdom, Israel, New Zealand: Prescription-Anchored

Where cannabis reaches patients only via prescription, the data is clinical data and the applicable framework is the national health-data regime, not retail privacy: UK GDPR plus NHS-aligned information governance for UK medical cannabis operators under MHRA oversight, Israel’s Privacy Protection Regulations with IMC-specific requirements, and the same pattern under New Zealand’s Medicinal Cannabis Scheme. The classification question is easy here. The engineering question — proving it to an auditor — is not.

Latin America and Asia: Sensitive Data With a Volatile Substrate

Brazil’s LGPD names health data as sensitive with its own processing rules; Mexico and Colombia carry comparable sensitive-data categories. The distinctive risk in these markets isn’t the classification, it’s the stability of the program above it. When a market reverses — as Thailand’s did, taking thousands of dispensaries with it — the sensitive records don’t disappear with the licence. They become orphaned data under a still-active privacy law, which is the exact failure mode in regulatory whiplash and orphaned data risk.

The Three Rules That Survive Every Border

Trying to run a per-jurisdiction data model is how multi-market operators end up with five schemas, three retention policies, and no defensible answer to a regulator. Build to the strictest reading instead, and the rest is free.

1. Classify by inference, not by label. Ask what a competent analyst could deduce from the record, not what the field name says. If a plausible answer is “this person is managing a medical condition,” treat it as health data everywhere — including in jurisdictions that would technically let you off.

2. Don’t retain what makes classification worse. The single highest-leverage control is not collecting the ID image at all. Verification and storage are separable problems, which is the whole argument in verify, don’t store — and it is what the operators in the year’s largest cannabis exposure got wrong. Nearly a million passport and photo-ID scans were reachable on the open internet in the CannaLeaks incident because someone kept the images. The same reasoning applies to biometric templates from ID scanners, which carry their own litigation profile under BIPA and its successors.

3. Tag records with jurisdiction at write time, not at audit time. Every row should carry the jurisdiction whose rules governed its collection. Retrofitting that field during a regulator’s inquiry — or during a cross-border transfer review — is the most predictable expensive project in this industry. Under the GDPR baseline, the machinery you need is already documented in our GDPR guide for dispensaries; every other regime is a subset of it.

Bottom Line

There is no global standard for cannabis health data, and there won’t be one soon. What there is, reliably, is a strictest standard: assume inference-based health classification, minimize to the point where a breach is boring, and stamp jurisdiction onto every record you keep.

Operators who build to that standard get to expand across borders as a business decision. Operators who classify jurisdiction by jurisdiction get to re-architect every time a market opens — and to explain to a regulator, under time pressure, why the record they’re looking at was filed under “retail.”