SlideShare una empresa de Scribd logo
1 de 28
Open Science & GDPR
Basic Concepts and Cases
Dr. Prodromos Tsiavos
Senior Legal & Policy Adviser
ARC/ ΟpenAIRE
https://www.athena-innovation.gr/ptsiavos@athenarc.gr
Open Science and GDPR
1. What is GDPR
2. Key DP structure
3. The setting
4. How is scientific research defined
5. Purpose
6. Legal Basis
7. Exercising data subject rights
8. Cases
What is GDPR?
Regulation (EU) 2016/679 of the European Parliament and of the
Council of 27 April 2016 on the protection of natural persons with
regard to the processing of personal data and on the free movement of
such data, and repealing Directive 95/46/EC (General Data Protection
Regulation)
1
Key DP structure
Personal Data
Type of processing
Purpose
Legal Basis
Be careful with
special categories
(sensitive) of
personal data
Make sure that the
legal basis covers
purpose and
personal data
2
The setting
Research within an RPO: check legal and ethics framework
EU or other collaborative projects - check WPs re who is processing what and
why:
Ethics and Data Protection Requirements (at the point/ WP of processing)
National Law
3rd countries
Call conditions (e.g. ethics report/ DPIA)
Tenders
Are you a data processor or (co)controller)?
Who is the DPO in a project (check the Consortium and Grant Agreement)?
3
How is scientific research defined
Sources:
- Recitals: 26, 33, 50, 52, 53, 62, 65, 113, 156, 157, 159, 160, 161, 162
- Relevant articles: 5(1)(b), (e), 89 (1), (2), (3), 9(j), 14(5)(b), 17(3)(d), 21(6).
Most important article:
- Art. 89
4
Defining Scientific Research I: Definitions
• It falls under the broader public interest legal basis (though this is not the
only possible legal basis)
• Could be a form of further processing (e.g. when obtaining data from a
public source or e.g. the government)
• Need to be subjected to appropriate safeguards
• Technical and organizational measures are in place
• Focus on data minimization (use only necessary data)
• Means: pseudonymization (without affecting research objectives)
Defining Scientific Research II: Special Categories
• In relation to special categories of data (art.9), the processing:
• shall be proportionate to the aim pursued
• needs to respect the right to data protection
• needs to provide suitable and specific measures to safeguard the
fundamental rights and interests of the data subject
The purpose
Possible purposes:
Overall: scientific research (art. 89 GDPR)
Specific type of research
Further use/ exploitation
What happens when the purpose changes over time?
Legal basis? [e.g. from public task to consent / collection by a public hospital – secondary use
by researchers)
Am I covered by the legal basis?
5
Legal Basis
Mostly forms of public interest (needs to be specifically documented per
institution and research project)
Contract (tender)
Consent (specific research)
Could change from collection, to retaining to sharing. There always needs to be
one covering the purpose of processing.
6
• Vital Interest
• Public Interest
• Legal Obligation
• Contract
• Consent
• Legitimate Interest
No discretion
discretion
Decision: both parties
Decision: data controller
Trace the life cycle
Follow the data (use the DMP as your backbone)
Different types of data processing may have different purposes and legal bases
Always stay within the legal basis
Data management plan
(processing/ purposes/ legal basis)
Data collection
- From the data
subject
- From 3rd party
- From publicly
available sources
Data Management
- Read
- Write (update/
improve/ enrich)
- Preservation
- Erasure
- Access
Data Sharing
- 3rd Parties
- Data processor
- Further use
- Subject
- Publishing
Purpose Α
Public Hospital
Public Interest A
Purpose C
Research Performing
Organisation
Legal Obligation
Purpose D
Research Performing
Organisation
Consent
Purpose Β
Research Performing
Organisation
Public Interest B
Exercising data subject rights
Limitation of rights of the data subject (arts. 14(5)/17(3)/ 21(6) GDPR))
Scientific research/ statistical purposes/ archiving
Public interest
Technical and organizational measures (mostly pseudonymization)
Condition: “it is likely to render impossible or seriously impair the achievement of
the objectives of that processing”
Notices (proactive data subject information)
7
Limitations to data subject’s rights:
(I) information
• Information to be provided where personal data have not been obtained
from the data subject (art. 14(5)(b)
• Researchers are exempt when:
• The provision of such information proves impossible or would involve a
disproportionate effort
• Such obligations would render impossible or seriously impair
achievement of the objectives of scientific research
• The controller takes appropriate measures to protect the data subject’s
legitimate interests
Limitations to data subject’s rights:
(II) erasure
• Right to erasure (‘right to be forgotten’) (art. 17(3)(d)
• Researchers are exempt when:
• Such obligations would render impossible or seriously impair
achievement of the objectives of scientific research
Limitations to data subject’s rights:
(III) objection
• Right to object (art. 21(6)
• Researchers are exempt when:
• the processing is necessary for the performance of a task carried out
for reasons of public interest.
Limitations to data subject’s rights:
(IV) Member States Derogations
• Member State derogations in relation to data-subject rights:
• Right of access by the data subject (art.15)
• Right to rectification (art.16)
• Right to restriction of processing (art.18)
• Right to object (art.21)
Cases
• Harvesting personal data from publicly available sources
• Data sharing with 3rd countries (international collaborations) – model
licences
• Initial collection for legitimate interest – secondary research use –
notification process - objection process
• Balancing reuse of research data and the GDPR principles of accuracy and
data minimization
• Health data and GDPR protection
• Data Sharing Codes of Conduct
• GDPR application for small projects
8
Cases
• Harvesting personal data from publicly available sources
• Check the original purpose of processing
• Check the original legal basis for processing
• It is a form of allowed further processing (art.5(b))
• Need to provide the following information to the data subject (art.14(1),(2)):
1. the identity and the contact details of the controller and, where applicable, of the controller's
representative
2. the contact details of the data protection officer, where applicable;
3. the purposes of the processing for which the personal data are intended as well as the legal
basis for the processing;
4. The categories of personal data concerned;
5. The recipients or categories of recipients of the personal data, if any;
6. When there is data transfer to 3rd countries, reference to the appropriate or suitable
safeguards and the means to obtain a copy of them or where they have been made available.
7. from which source the personal data originate, and if applicable, whether it came from
publicly accessible sources;
8a
Cases
• Conditions for further processing (arts.6(4)) + 13(3) + 14(4) + 89(1)):
1. Legal basis Consent; or
2. Legal obligations (by Member States); or
3. There is a new legal basis; or
4. Examine whether further processing is compatible with the purpose for which the personal
data were original collected:
1. What is the link between original and further processing
2. Context
3. If special categories exist and how they are protected
4. Consequences for the data subjects
5. Safeguards (e.g. encryption and pseudonymization)
5. When information is collected by the data-subject or third party, inform the data subject
regarding the further processing (prior to it) and any other relevant information (art.13(3) and
art.14(4))
6. Pseudonymize (if it is for research) art. 89(1)
8b
Cases
Transfers to 3rd countries
• Items:
• Conditions (contract or legal act) art.28
• Notifications and notices (data subject rights information – access ) (arts.13(1)(f), 14(1)(f),
15(1), (2))
• Keep records (art.30)
• Use of Codes of Conduct (art.40)
• Explore certification schemes, seals and marks (art.42(2))
• See entire Chapter V (arts.44-50)
• Adequacy decision
• Appropriate Safeguards
• Binding corporate rules
• Authorization by Union Law
• See EC Standard Contractual Clauses (SCC)
• Standard contractual clauses for data transfers between EU and non-EU countries.
8c
Cases
Initial collection for legitimate interest – secondary research use – notification process -
objection process
• Form of further processing
• Need to notify the data subject
• Include all notification principles of art.14
• There needs to be a clear opt-out/ objection process in the notification document:
• URL for automated opt-out
• At least email
• Always documented and confirmed
8d
Cases
Further processing and accuracy – minimization
• Adhere to all conditions of further processing
• Remain accurate through notices and notification
• Use only what is needed for the research purpose
• Erase data once the required processing is over (or retain data under archiving purposes)
8e
Cases
Health data and GDPR
- Special category of data (art.9)
- Form of Further Processing
- Emphasis on the legal basis
8f
Cases
Data Sharing CoCs
- ICO (UK)
[https://ico.org.uk/media/for-
organisations/documents/1068/data_sharing_code_of_practice.pdf]
- OECD
[http://www.oecd.org/gov/ethics/ethicscodesandcodesofconductinoecdcountries.htm]
8g
Cases
Personal data for small projects (excel rules…)
- Specify your research purpose and define data range
- Specify and document legal basis
- Manage and document consent
- Use DMP as your backbone
- Consult with your Ethics Committee and DPO
8h
q
a
ptsiavos@athenarc.gr

Más contenido relacionado

La actualidad más candente

GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and LibrariesGDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and LibrariesLIBER Europe
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
Open if Possible, Protected if Needed: Services and tools for the sharing of...
Open if Possible, Protected if Needed:  Services and tools for the sharing of...Open if Possible, Protected if Needed:  Services and tools for the sharing of...
Open if Possible, Protected if Needed: Services and tools for the sharing of...OpenAIRE
 
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...OpenAIRE
 
Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Axon Lawyers
 
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...ioannis iglezakis
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeDavid Erdos
 
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...Kinfe Micheal Yilma
 
The interface between data protection and ip law
The interface between data protection and ip lawThe interface between data protection and ip law
The interface between data protection and ip lawFrancesco Banterle
 
Privacy and Data Protection in Research
Privacy and Data Protection in ResearchPrivacy and Data Protection in Research
Privacy and Data Protection in ResearchMarlon Domingus
 
The Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanThe Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanKrowdthink
 
Data Protection Forum meetup 23052017
Data Protection Forum meetup   23052017 Data Protection Forum meetup   23052017
Data Protection Forum meetup 23052017 John M Walsh
 
Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018MRS
 
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...FutureTDM
 
Key principles for data protection & lawful protection in GDPR
Key principles for data protection & lawful protection in GDPRKey principles for data protection & lawful protection in GDPR
Key principles for data protection & lawful protection in GDPRDr. Marinos Papadopoulos
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiKrowdthink
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsUlf Mattsson
 
Data, databases and what you can do with them
Data, databases and what you can do with themData, databases and what you can do with them
Data, databases and what you can do with themBrowne Jacobson LLP
 

La actualidad más candente (19)

GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and LibrariesGDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Open if Possible, Protected if Needed: Services and tools for the sharing of...
Open if Possible, Protected if Needed:  Services and tools for the sharing of...Open if Possible, Protected if Needed:  Services and tools for the sharing of...
Open if Possible, Protected if Needed: Services and tools for the sharing of...
 
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
 
Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics'
 
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & Change
 
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
 
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
 
The interface between data protection and ip law
The interface between data protection and ip lawThe interface between data protection and ip law
The interface between data protection and ip law
 
Privacy and Data Protection in Research
Privacy and Data Protection in ResearchPrivacy and Data Protection in Research
Privacy and Data Protection in Research
 
The Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanThe Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth Boardman
 
Data Protection Forum meetup 23052017
Data Protection Forum meetup   23052017 Data Protection Forum meetup   23052017
Data Protection Forum meetup 23052017
 
Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018
 
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
 
Key principles for data protection & lawful protection in GDPR
Key principles for data protection & lawful protection in GDPRKey principles for data protection & lawful protection in GDPR
Key principles for data protection & lawful protection in GDPR
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
Data, databases and what you can do with them
Data, databases and what you can do with themData, databases and what you can do with them
Data, databases and what you can do with them
 

Similar a 20200504_Research Data & the GDPR: How Open is Open?

Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...Plan de Calidad para el SNS
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson LLP
 
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral ResearchersAdjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral ResearchersTravis Greene
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
Engage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To GoEngage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To Gopanagenda
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterBrowne Jacobson LLP
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamBrowne Jacobson LLP
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonBrowne Jacobson LLP
 
The Policy Framework: GDPR and all that
The Policy Framework: GDPR and all thatThe Policy Framework: GDPR and all that
The Policy Framework: GDPR and all thatEUDAT
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamBrowne Jacobson LLP
 
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...EUDAT
 
Data Protection & Risk Management
Data Protection & Risk Management Data Protection & Risk Management
Data Protection & Risk Management Endcode_org
 
Are You GDPR Ready?
Are You GDPR Ready?Are You GDPR Ready?
Are You GDPR Ready?NICSA
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Michael Adamberry
 
GDPR - New European Union Legislation
GDPR - New European Union LegislationGDPR - New European Union Legislation
GDPR - New European Union LegislationTekwill
 

Similar a 20200504_Research Data & the GDPR: How Open is Open? (20)

GDPR and Research Data Management
GDPR and Research Data ManagementGDPR and Research Data Management
GDPR and Research Data Management
 
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
 
VIAF GDPR
VIAF GDPRVIAF GDPR
VIAF GDPR
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
 
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral ResearchersAdjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Engage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To GoEngage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To Go
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, Manchester
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, Nottingham
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, London
 
The Policy Framework: GDPR and all that
The Policy Framework: GDPR and all thatThe Policy Framework: GDPR and all that
The Policy Framework: GDPR and all that
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
 
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
 
Data Protection & Risk Management
Data Protection & Risk Management Data Protection & Risk Management
Data Protection & Risk Management
 
Are You GDPR Ready?
Are You GDPR Ready?Are You GDPR Ready?
Are You GDPR Ready?
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
GDPR - New European Union Legislation
GDPR - New European Union LegislationGDPR - New European Union Legislation
GDPR - New European Union Legislation
 

Más de OpenAIRE

10th OpenAIRE Content Providers Community Call
10th OpenAIRE Content Providers Community Call10th OpenAIRE Content Providers Community Call
10th OpenAIRE Content Providers Community CallOpenAIRE
 
9th Content Providers Community Call\
9th Content Providers Community Call\9th Content Providers Community Call\
9th Content Providers Community Call\OpenAIRE
 
OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE in the European Open Science Cloud (EOSC)OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE in the European Open Science Cloud (EOSC)OpenAIRE
 
8th Content Providers Community Call
8th Content Providers Community Call8th Content Providers Community Call
8th Content Providers Community CallOpenAIRE
 
7th Content Providers Community Call
7th Content Providers Community Call7th Content Providers Community Call
7th Content Providers Community CallOpenAIRE
 
OpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE PROVIDE Dashboard for Turkish repository managersOpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE PROVIDE Dashboard for Turkish repository managersOpenAIRE
 
What will it cost to manage and share my data?
What will it cost to manage and share my data?What will it cost to manage and share my data?
What will it cost to manage and share my data?OpenAIRE
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)OpenAIRE
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)OpenAIRE
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)OpenAIRE
 
6th Content Providers Community Call
6th Content Providers Community Call6th Content Providers Community Call
6th Content Providers Community CallOpenAIRE
 
COVID-19: Activities, tools, best practice and contact points in Greece
 COVID-19: Activities, tools, best practice and contact points in Greece COVID-19: Activities, tools, best practice and contact points in Greece
COVID-19: Activities, tools, best practice and contact points in GreeceOpenAIRE
 
5th Content Providers Community Call
5th Content Providers Community Call5th Content Providers Community Call
5th Content Providers Community CallOpenAIRE
 
4th Content Providers Community Call
4th Content Providers Community Call4th Content Providers Community Call
4th Content Providers Community CallOpenAIRE
 
3rd Content Providers Community Call
3rd Content Providers Community Call3rd Content Providers Community Call
3rd Content Providers Community CallOpenAIRE
 
2nd Content Providers Community Call
2nd Content Providers Community Call2nd Content Providers Community Call
2nd Content Providers Community CallOpenAIRE
 
1st Content Providers Community Call
1st Content Providers Community Call1st Content Providers Community Call
1st Content Providers Community CallOpenAIRE
 
20200130_Mannocci_OpenAIRE_ResearchGraph
20200130_Mannocci_OpenAIRE_ResearchGraph20200130_Mannocci_OpenAIRE_ResearchGraph
20200130_Mannocci_OpenAIRE_ResearchGraphOpenAIRE
 
IPR and Exploitation
IPR and Exploitation IPR and Exploitation
IPR and Exploitation OpenAIRE
 
Eosc_OpenAIRE_onboarding_v2
Eosc_OpenAIRE_onboarding_v2Eosc_OpenAIRE_onboarding_v2
Eosc_OpenAIRE_onboarding_v2OpenAIRE
 

Más de OpenAIRE (20)

10th OpenAIRE Content Providers Community Call
10th OpenAIRE Content Providers Community Call10th OpenAIRE Content Providers Community Call
10th OpenAIRE Content Providers Community Call
 
9th Content Providers Community Call\
9th Content Providers Community Call\9th Content Providers Community Call\
9th Content Providers Community Call\
 
OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE in the European Open Science Cloud (EOSC)OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE in the European Open Science Cloud (EOSC)
 
8th Content Providers Community Call
8th Content Providers Community Call8th Content Providers Community Call
8th Content Providers Community Call
 
7th Content Providers Community Call
7th Content Providers Community Call7th Content Providers Community Call
7th Content Providers Community Call
 
OpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE PROVIDE Dashboard for Turkish repository managersOpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE PROVIDE Dashboard for Turkish repository managers
 
What will it cost to manage and share my data?
What will it cost to manage and share my data?What will it cost to manage and share my data?
What will it cost to manage and share my data?
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
 
6th Content Providers Community Call
6th Content Providers Community Call6th Content Providers Community Call
6th Content Providers Community Call
 
COVID-19: Activities, tools, best practice and contact points in Greece
 COVID-19: Activities, tools, best practice and contact points in Greece COVID-19: Activities, tools, best practice and contact points in Greece
COVID-19: Activities, tools, best practice and contact points in Greece
 
5th Content Providers Community Call
5th Content Providers Community Call5th Content Providers Community Call
5th Content Providers Community Call
 
4th Content Providers Community Call
4th Content Providers Community Call4th Content Providers Community Call
4th Content Providers Community Call
 
3rd Content Providers Community Call
3rd Content Providers Community Call3rd Content Providers Community Call
3rd Content Providers Community Call
 
2nd Content Providers Community Call
2nd Content Providers Community Call2nd Content Providers Community Call
2nd Content Providers Community Call
 
1st Content Providers Community Call
1st Content Providers Community Call1st Content Providers Community Call
1st Content Providers Community Call
 
20200130_Mannocci_OpenAIRE_ResearchGraph
20200130_Mannocci_OpenAIRE_ResearchGraph20200130_Mannocci_OpenAIRE_ResearchGraph
20200130_Mannocci_OpenAIRE_ResearchGraph
 
IPR and Exploitation
IPR and Exploitation IPR and Exploitation
IPR and Exploitation
 
Eosc_OpenAIRE_onboarding_v2
Eosc_OpenAIRE_onboarding_v2Eosc_OpenAIRE_onboarding_v2
Eosc_OpenAIRE_onboarding_v2
 

Último

module for grade 9 for distance learning
module for grade 9 for distance learningmodule for grade 9 for distance learning
module for grade 9 for distance learninglevieagacer
 
GBSN - Microbiology (Unit 3)
GBSN - Microbiology (Unit 3)GBSN - Microbiology (Unit 3)
GBSN - Microbiology (Unit 3)Areesha Ahmad
 
Formation of low mass protostars and their circumstellar disks
Formation of low mass protostars and their circumstellar disksFormation of low mass protostars and their circumstellar disks
Formation of low mass protostars and their circumstellar disksSérgio Sacani
 
Feature-aligned N-BEATS with Sinkhorn divergence (ICLR '24)
Feature-aligned N-BEATS with Sinkhorn divergence (ICLR '24)Feature-aligned N-BEATS with Sinkhorn divergence (ICLR '24)
Feature-aligned N-BEATS with Sinkhorn divergence (ICLR '24)Joonhun Lee
 
Pests of cotton_Sucking_Pests_Dr.UPR.pdf
Pests of cotton_Sucking_Pests_Dr.UPR.pdfPests of cotton_Sucking_Pests_Dr.UPR.pdf
Pests of cotton_Sucking_Pests_Dr.UPR.pdfPirithiRaju
 
GBSN - Microbiology (Unit 1)
GBSN - Microbiology (Unit 1)GBSN - Microbiology (Unit 1)
GBSN - Microbiology (Unit 1)Areesha Ahmad
 
GBSN - Microbiology (Unit 2)
GBSN - Microbiology (Unit 2)GBSN - Microbiology (Unit 2)
GBSN - Microbiology (Unit 2)Areesha Ahmad
 
IDENTIFICATION OF THE LIVING- forensic medicine
IDENTIFICATION OF THE LIVING- forensic medicineIDENTIFICATION OF THE LIVING- forensic medicine
IDENTIFICATION OF THE LIVING- forensic medicinesherlingomez2
 
Vip profile Call Girls In Lonavala 9748763073 For Genuine Sex Service At Just...
Vip profile Call Girls In Lonavala 9748763073 For Genuine Sex Service At Just...Vip profile Call Girls In Lonavala 9748763073 For Genuine Sex Service At Just...
Vip profile Call Girls In Lonavala 9748763073 For Genuine Sex Service At Just...Monika Rani
 
Proteomics: types, protein profiling steps etc.
Proteomics: types, protein profiling steps etc.Proteomics: types, protein profiling steps etc.
Proteomics: types, protein profiling steps etc.Silpa
 
Seismic Method Estimate velocity from seismic data.pptx
Seismic Method Estimate velocity from seismic  data.pptxSeismic Method Estimate velocity from seismic  data.pptx
Seismic Method Estimate velocity from seismic data.pptxAlMamun560346
 
COST ESTIMATION FOR A RESEARCH PROJECT.pptx
COST ESTIMATION FOR A RESEARCH PROJECT.pptxCOST ESTIMATION FOR A RESEARCH PROJECT.pptx
COST ESTIMATION FOR A RESEARCH PROJECT.pptxFarihaAbdulRasheed
 
Asymmetry in the atmosphere of the ultra-hot Jupiter WASP-76 b
Asymmetry in the atmosphere of the ultra-hot Jupiter WASP-76 bAsymmetry in the atmosphere of the ultra-hot Jupiter WASP-76 b
Asymmetry in the atmosphere of the ultra-hot Jupiter WASP-76 bSérgio Sacani
 
Kochi ❤CALL GIRL 84099*07087 ❤CALL GIRLS IN Kochi ESCORT SERVICE❤CALL GIRL
Kochi ❤CALL GIRL 84099*07087 ❤CALL GIRLS IN Kochi ESCORT SERVICE❤CALL GIRLKochi ❤CALL GIRL 84099*07087 ❤CALL GIRLS IN Kochi ESCORT SERVICE❤CALL GIRL
Kochi ❤CALL GIRL 84099*07087 ❤CALL GIRLS IN Kochi ESCORT SERVICE❤CALL GIRLkantirani197
 
Chemical Tests; flame test, positive and negative ions test Edexcel Internati...
Chemical Tests; flame test, positive and negative ions test Edexcel Internati...Chemical Tests; flame test, positive and negative ions test Edexcel Internati...
Chemical Tests; flame test, positive and negative ions test Edexcel Internati...ssuser79fe74
 
Forensic Biology & Its biological significance.pdf
Forensic Biology & Its biological significance.pdfForensic Biology & Its biological significance.pdf
Forensic Biology & Its biological significance.pdfrohankumarsinghrore1
 
Pests of cotton_Borer_Pests_Binomics_Dr.UPR.pdf
Pests of cotton_Borer_Pests_Binomics_Dr.UPR.pdfPests of cotton_Borer_Pests_Binomics_Dr.UPR.pdf
Pests of cotton_Borer_Pests_Binomics_Dr.UPR.pdfPirithiRaju
 
Pulmonary drug delivery system M.pharm -2nd sem P'ceutics
Pulmonary drug delivery system M.pharm -2nd sem P'ceuticsPulmonary drug delivery system M.pharm -2nd sem P'ceutics
Pulmonary drug delivery system M.pharm -2nd sem P'ceuticssakshisoni2385
 
dkNET Webinar "Texera: A Scalable Cloud Computing Platform for Sharing Data a...
dkNET Webinar "Texera: A Scalable Cloud Computing Platform for Sharing Data a...dkNET Webinar "Texera: A Scalable Cloud Computing Platform for Sharing Data a...
dkNET Webinar "Texera: A Scalable Cloud Computing Platform for Sharing Data a...dkNET
 
biology HL practice questions IB BIOLOGY
biology HL practice questions IB BIOLOGYbiology HL practice questions IB BIOLOGY
biology HL practice questions IB BIOLOGY1301aanya
 

Último (20)

module for grade 9 for distance learning
module for grade 9 for distance learningmodule for grade 9 for distance learning
module for grade 9 for distance learning
 
GBSN - Microbiology (Unit 3)
GBSN - Microbiology (Unit 3)GBSN - Microbiology (Unit 3)
GBSN - Microbiology (Unit 3)
 
Formation of low mass protostars and their circumstellar disks
Formation of low mass protostars and their circumstellar disksFormation of low mass protostars and their circumstellar disks
Formation of low mass protostars and their circumstellar disks
 
Feature-aligned N-BEATS with Sinkhorn divergence (ICLR '24)
Feature-aligned N-BEATS with Sinkhorn divergence (ICLR '24)Feature-aligned N-BEATS with Sinkhorn divergence (ICLR '24)
Feature-aligned N-BEATS with Sinkhorn divergence (ICLR '24)
 
Pests of cotton_Sucking_Pests_Dr.UPR.pdf
Pests of cotton_Sucking_Pests_Dr.UPR.pdfPests of cotton_Sucking_Pests_Dr.UPR.pdf
Pests of cotton_Sucking_Pests_Dr.UPR.pdf
 
GBSN - Microbiology (Unit 1)
GBSN - Microbiology (Unit 1)GBSN - Microbiology (Unit 1)
GBSN - Microbiology (Unit 1)
 
GBSN - Microbiology (Unit 2)
GBSN - Microbiology (Unit 2)GBSN - Microbiology (Unit 2)
GBSN - Microbiology (Unit 2)
 
IDENTIFICATION OF THE LIVING- forensic medicine
IDENTIFICATION OF THE LIVING- forensic medicineIDENTIFICATION OF THE LIVING- forensic medicine
IDENTIFICATION OF THE LIVING- forensic medicine
 
Vip profile Call Girls In Lonavala 9748763073 For Genuine Sex Service At Just...
Vip profile Call Girls In Lonavala 9748763073 For Genuine Sex Service At Just...Vip profile Call Girls In Lonavala 9748763073 For Genuine Sex Service At Just...
Vip profile Call Girls In Lonavala 9748763073 For Genuine Sex Service At Just...
 
Proteomics: types, protein profiling steps etc.
Proteomics: types, protein profiling steps etc.Proteomics: types, protein profiling steps etc.
Proteomics: types, protein profiling steps etc.
 
Seismic Method Estimate velocity from seismic data.pptx
Seismic Method Estimate velocity from seismic  data.pptxSeismic Method Estimate velocity from seismic  data.pptx
Seismic Method Estimate velocity from seismic data.pptx
 
COST ESTIMATION FOR A RESEARCH PROJECT.pptx
COST ESTIMATION FOR A RESEARCH PROJECT.pptxCOST ESTIMATION FOR A RESEARCH PROJECT.pptx
COST ESTIMATION FOR A RESEARCH PROJECT.pptx
 
Asymmetry in the atmosphere of the ultra-hot Jupiter WASP-76 b
Asymmetry in the atmosphere of the ultra-hot Jupiter WASP-76 bAsymmetry in the atmosphere of the ultra-hot Jupiter WASP-76 b
Asymmetry in the atmosphere of the ultra-hot Jupiter WASP-76 b
 
Kochi ❤CALL GIRL 84099*07087 ❤CALL GIRLS IN Kochi ESCORT SERVICE❤CALL GIRL
Kochi ❤CALL GIRL 84099*07087 ❤CALL GIRLS IN Kochi ESCORT SERVICE❤CALL GIRLKochi ❤CALL GIRL 84099*07087 ❤CALL GIRLS IN Kochi ESCORT SERVICE❤CALL GIRL
Kochi ❤CALL GIRL 84099*07087 ❤CALL GIRLS IN Kochi ESCORT SERVICE❤CALL GIRL
 
Chemical Tests; flame test, positive and negative ions test Edexcel Internati...
Chemical Tests; flame test, positive and negative ions test Edexcel Internati...Chemical Tests; flame test, positive and negative ions test Edexcel Internati...
Chemical Tests; flame test, positive and negative ions test Edexcel Internati...
 
Forensic Biology & Its biological significance.pdf
Forensic Biology & Its biological significance.pdfForensic Biology & Its biological significance.pdf
Forensic Biology & Its biological significance.pdf
 
Pests of cotton_Borer_Pests_Binomics_Dr.UPR.pdf
Pests of cotton_Borer_Pests_Binomics_Dr.UPR.pdfPests of cotton_Borer_Pests_Binomics_Dr.UPR.pdf
Pests of cotton_Borer_Pests_Binomics_Dr.UPR.pdf
 
Pulmonary drug delivery system M.pharm -2nd sem P'ceutics
Pulmonary drug delivery system M.pharm -2nd sem P'ceuticsPulmonary drug delivery system M.pharm -2nd sem P'ceutics
Pulmonary drug delivery system M.pharm -2nd sem P'ceutics
 
dkNET Webinar "Texera: A Scalable Cloud Computing Platform for Sharing Data a...
dkNET Webinar "Texera: A Scalable Cloud Computing Platform for Sharing Data a...dkNET Webinar "Texera: A Scalable Cloud Computing Platform for Sharing Data a...
dkNET Webinar "Texera: A Scalable Cloud Computing Platform for Sharing Data a...
 
biology HL practice questions IB BIOLOGY
biology HL practice questions IB BIOLOGYbiology HL practice questions IB BIOLOGY
biology HL practice questions IB BIOLOGY
 

20200504_Research Data & the GDPR: How Open is Open?

  • 1. Open Science & GDPR Basic Concepts and Cases Dr. Prodromos Tsiavos Senior Legal & Policy Adviser ARC/ ΟpenAIRE https://www.athena-innovation.gr/ptsiavos@athenarc.gr
  • 2. Open Science and GDPR 1. What is GDPR 2. Key DP structure 3. The setting 4. How is scientific research defined 5. Purpose 6. Legal Basis 7. Exercising data subject rights 8. Cases
  • 3. What is GDPR? Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) 1
  • 4. Key DP structure Personal Data Type of processing Purpose Legal Basis Be careful with special categories (sensitive) of personal data Make sure that the legal basis covers purpose and personal data 2
  • 5. The setting Research within an RPO: check legal and ethics framework EU or other collaborative projects - check WPs re who is processing what and why: Ethics and Data Protection Requirements (at the point/ WP of processing) National Law 3rd countries Call conditions (e.g. ethics report/ DPIA) Tenders Are you a data processor or (co)controller)? Who is the DPO in a project (check the Consortium and Grant Agreement)? 3
  • 6. How is scientific research defined Sources: - Recitals: 26, 33, 50, 52, 53, 62, 65, 113, 156, 157, 159, 160, 161, 162 - Relevant articles: 5(1)(b), (e), 89 (1), (2), (3), 9(j), 14(5)(b), 17(3)(d), 21(6). Most important article: - Art. 89 4
  • 7. Defining Scientific Research I: Definitions • It falls under the broader public interest legal basis (though this is not the only possible legal basis) • Could be a form of further processing (e.g. when obtaining data from a public source or e.g. the government) • Need to be subjected to appropriate safeguards • Technical and organizational measures are in place • Focus on data minimization (use only necessary data) • Means: pseudonymization (without affecting research objectives)
  • 8. Defining Scientific Research II: Special Categories • In relation to special categories of data (art.9), the processing: • shall be proportionate to the aim pursued • needs to respect the right to data protection • needs to provide suitable and specific measures to safeguard the fundamental rights and interests of the data subject
  • 9. The purpose Possible purposes: Overall: scientific research (art. 89 GDPR) Specific type of research Further use/ exploitation What happens when the purpose changes over time? Legal basis? [e.g. from public task to consent / collection by a public hospital – secondary use by researchers) Am I covered by the legal basis? 5
  • 10. Legal Basis Mostly forms of public interest (needs to be specifically documented per institution and research project) Contract (tender) Consent (specific research) Could change from collection, to retaining to sharing. There always needs to be one covering the purpose of processing. 6
  • 11. • Vital Interest • Public Interest • Legal Obligation • Contract • Consent • Legitimate Interest No discretion discretion Decision: both parties Decision: data controller
  • 12. Trace the life cycle Follow the data (use the DMP as your backbone) Different types of data processing may have different purposes and legal bases Always stay within the legal basis
  • 13. Data management plan (processing/ purposes/ legal basis) Data collection - From the data subject - From 3rd party - From publicly available sources Data Management - Read - Write (update/ improve/ enrich) - Preservation - Erasure - Access Data Sharing - 3rd Parties - Data processor - Further use - Subject - Publishing Purpose Α Public Hospital Public Interest A Purpose C Research Performing Organisation Legal Obligation Purpose D Research Performing Organisation Consent Purpose Β Research Performing Organisation Public Interest B
  • 14. Exercising data subject rights Limitation of rights of the data subject (arts. 14(5)/17(3)/ 21(6) GDPR)) Scientific research/ statistical purposes/ archiving Public interest Technical and organizational measures (mostly pseudonymization) Condition: “it is likely to render impossible or seriously impair the achievement of the objectives of that processing” Notices (proactive data subject information) 7
  • 15. Limitations to data subject’s rights: (I) information • Information to be provided where personal data have not been obtained from the data subject (art. 14(5)(b) • Researchers are exempt when: • The provision of such information proves impossible or would involve a disproportionate effort • Such obligations would render impossible or seriously impair achievement of the objectives of scientific research • The controller takes appropriate measures to protect the data subject’s legitimate interests
  • 16. Limitations to data subject’s rights: (II) erasure • Right to erasure (‘right to be forgotten’) (art. 17(3)(d) • Researchers are exempt when: • Such obligations would render impossible or seriously impair achievement of the objectives of scientific research
  • 17. Limitations to data subject’s rights: (III) objection • Right to object (art. 21(6) • Researchers are exempt when: • the processing is necessary for the performance of a task carried out for reasons of public interest.
  • 18. Limitations to data subject’s rights: (IV) Member States Derogations • Member State derogations in relation to data-subject rights: • Right of access by the data subject (art.15) • Right to rectification (art.16) • Right to restriction of processing (art.18) • Right to object (art.21)
  • 19. Cases • Harvesting personal data from publicly available sources • Data sharing with 3rd countries (international collaborations) – model licences • Initial collection for legitimate interest – secondary research use – notification process - objection process • Balancing reuse of research data and the GDPR principles of accuracy and data minimization • Health data and GDPR protection • Data Sharing Codes of Conduct • GDPR application for small projects 8
  • 20. Cases • Harvesting personal data from publicly available sources • Check the original purpose of processing • Check the original legal basis for processing • It is a form of allowed further processing (art.5(b)) • Need to provide the following information to the data subject (art.14(1),(2)): 1. the identity and the contact details of the controller and, where applicable, of the controller's representative 2. the contact details of the data protection officer, where applicable; 3. the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; 4. The categories of personal data concerned; 5. The recipients or categories of recipients of the personal data, if any; 6. When there is data transfer to 3rd countries, reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available. 7. from which source the personal data originate, and if applicable, whether it came from publicly accessible sources; 8a
  • 21. Cases • Conditions for further processing (arts.6(4)) + 13(3) + 14(4) + 89(1)): 1. Legal basis Consent; or 2. Legal obligations (by Member States); or 3. There is a new legal basis; or 4. Examine whether further processing is compatible with the purpose for which the personal data were original collected: 1. What is the link between original and further processing 2. Context 3. If special categories exist and how they are protected 4. Consequences for the data subjects 5. Safeguards (e.g. encryption and pseudonymization) 5. When information is collected by the data-subject or third party, inform the data subject regarding the further processing (prior to it) and any other relevant information (art.13(3) and art.14(4)) 6. Pseudonymize (if it is for research) art. 89(1) 8b
  • 22. Cases Transfers to 3rd countries • Items: • Conditions (contract or legal act) art.28 • Notifications and notices (data subject rights information – access ) (arts.13(1)(f), 14(1)(f), 15(1), (2)) • Keep records (art.30) • Use of Codes of Conduct (art.40) • Explore certification schemes, seals and marks (art.42(2)) • See entire Chapter V (arts.44-50) • Adequacy decision • Appropriate Safeguards • Binding corporate rules • Authorization by Union Law • See EC Standard Contractual Clauses (SCC) • Standard contractual clauses for data transfers between EU and non-EU countries. 8c
  • 23. Cases Initial collection for legitimate interest – secondary research use – notification process - objection process • Form of further processing • Need to notify the data subject • Include all notification principles of art.14 • There needs to be a clear opt-out/ objection process in the notification document: • URL for automated opt-out • At least email • Always documented and confirmed 8d
  • 24. Cases Further processing and accuracy – minimization • Adhere to all conditions of further processing • Remain accurate through notices and notification • Use only what is needed for the research purpose • Erase data once the required processing is over (or retain data under archiving purposes) 8e
  • 25. Cases Health data and GDPR - Special category of data (art.9) - Form of Further Processing - Emphasis on the legal basis 8f
  • 26. Cases Data Sharing CoCs - ICO (UK) [https://ico.org.uk/media/for- organisations/documents/1068/data_sharing_code_of_practice.pdf] - OECD [http://www.oecd.org/gov/ethics/ethicscodesandcodesofconductinoecdcountries.htm] 8g
  • 27. Cases Personal data for small projects (excel rules…) - Specify your research purpose and define data range - Specify and document legal basis - Manage and document consent - Use DMP as your backbone - Consult with your Ethics Committee and DPO 8h