Issues of personal data protection in scientific research

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
The Data Protection (Jersey) Law 2005.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
ILONA GAVRONSKA GROUP IL-41 INTERNATIONAL LAW DEPARTMENT KYIV NATIONAL ACADEMY OF SCIENCES OF UKRAINE KYIV UNIVERSITY OF LAW.
Data Protection: The Law. EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection.
Attorney at the Bars of Paris and Brussels Database exploitation & Data protection Thibault Verbiest Amsterdam 1 April 2005
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Data Protection for Church of Scotland Congregations
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Data Protection Act AS Module Heathcote Ch. 12.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Ioannis Iglezakis Data Protection. Definition of Data Protection The legal protection of individuals with regard to automatic processing of personal information.
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Personal Data Protection
HIPSSA Project PRESENTATION ON SADC DATA PROTECTION MODEL LAW
DIRECTIVE (EU) 2016/680 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing.
Processing for archiving purposes in the GDPR
Luca De Matteis Justice counsellor (criminal law, data protection)
Data Protection: The Law
General Data Protection Regulation (GDPR)
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation
GDPR Overview Gydeline – October 2017
Data for Child Health: Promoting & Protecting Public Health through Custodianship EAP Brussels, 28 January 2016 Health Databases & Biobanks Promoting &
Data Protection Update – GDPR or bust
General Data Protection Regulation: Turning the black into white
Data Protection Legislation
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
The General Data Protection Regulation (GDPR)
New Data Protection Legislation
State of the privacy union
G.D.P.R General Data Protection Regulations
The GDPR and research data
FEK årskonferanse 28. februar 2018.
GDPR Overview and Use Cases.
General Data Protection Regulation
Data Protection principles
Relocation CARNIVAL come one…come all
Report on data protection legislation Case of Romania
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
GDPR Workshop MEU Symposium Prague 2018
Big Data & the General Data Protection Regulation
Information Handling Research Student Induction Day
PERSONAL INFORMATION BILL
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Public Privacy: juridical & ethical perspective
GDPR – General Data Protection Regulation
The EDPS: competences and processing of personal data in EU funds
Data Protection in Law Enforcement Area Chapter 9a of the draft law
General Data Protection Regulation Q & A Session
Legal Basis: CRITERIA FOR MAKING DATA PROCESSING LEGITIMATE
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Data Protection What can I do? GDPR Principles General Data Protection
Presentation transcript:

Issues of personal data protection in scientific research Prepared by: Marko Trošelj

The Croatian legal framework International Acts - Convention 108 and EU legislation Personal data and privacy protection – Constitutional category Article 37: The safety and secrecy of personal data shall be guaranteed for everyone. Without consent from the person concerned, personal data may be collected, processed, and used only under the conditions specified by law. includes the purpose limitation principle General act: Personal Data Protection Act (OG 103/03, 118/06, 41/08, 130/11)

Basic provisions Personal Data Protection Act regulates the personal data protection of natural persons The purpose of personal data protection is to protect the privacy of individuals, as well as other human rights and fundamental freedoms in the processing of personal data

Definitions Data controller: the entity that determines the purposes and means of processing personal data Processor: the entity that processes personal data on behalf of the controller Data subject: an identified or identifiable natural person whose personal data are processed Data processing: any operation or set of operations which is performed on personal data. (collection, recording, organization, storage, usage, disclosure, dissemination...)

Personal data processing Purpose of processing: Personal dana shall be collected for a purpose known to the data subject, explicitly stated and in accordance with the law Further processing only for the purposes it has been collected for, or for a purpose in line with the purpose it has been collected for EXCEPTION Further processing of personal data for historical, statistical or scientific purposes shall not be considered as incompatible provided that appropriate protection measures are in place

Personal data processing Proportionality principle - Personal data must be relevant to what is necessary in relation to the established purpose and it shall not be collected in quantities more extensive than necessary Personal data must be accurate, complete and up to date Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data are processed. Personal data may be stored for longer periods solely for historical, statistical or scientific purposes – appropriate protection measures are established by special acts.

Personal data processing Lawfulness of processing Personal data shall be collected and subsequently processed only if one of the following applies: with consent of the data subject in cases determined by law for the purpose of fulfilling legal obligations of the controller …

Special categories of personal data Processing of personal data pertaining to racial or ethnic origin, political opinions, religious or other beliefs, trade union membership, data concerning health or sexual orientation, as well as personal data regarding criminal and misdemeanour proceedings In principle, shall be prohibited Exceptions: - upon consent of the data subject - if the data processing is necessary to exercise the rights and obligations of the controller based on special regulations…

Information to data subject Prior to collecting any personal data, controller must inform the data subject whose personal data is being collected about: the identity of the controller, the purpose of processing this data, the right of access the right to rectification the recipients or categories of recipients

Usage of personal data by the recipience Controller shall allow the usage of personal data to other recipients based on written request if this is necessary for carrying out tasks within their activity as defined by law The written request must contain provisions on purpose, legal basis, and type of personal data requested Personal data processed for scientific research or statistical purposes must not allow for the identification of data subjects

Safeguards Personal data shall be adequately protected from accidental or deliberate abuse, destruction, loss, unauthorized alteration or access controller and recipient shall undertake appropriate technical, staffing and organisational measures

Rights of the data subject controller shall within 30 days provide the following to every data subject: whether or not data relating to the data subject are being processed allow access and copying of such files information on who obtained access to the data, for what purpose and on what legal basis Upon request or independently controller shall alter or delete personal data if this data is incomplete, inaccurate or outdated

General Data Protection Regulation It shall apply from 25 May 2018. Uniformity of personal data processing in all Member States New Challenges

Principles Lawfulness, fairness and transparency Purpose limitation Data minimisation Accuracy Storage limitation Integrity and confidentiality Accountability

New Definitions restriction of processing pseudonymisation profiling genetic data biometric data

Anonymisation The principles of data protection should apply to any information concerning an identified or identifiable natural person This Regulation does not concern the processing of anonymous information, including for statistical or research purposes

Data processing for scientific purposes The processing of personal data for scientific purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation Principle of data minimisation Principle of purpose limitation Principle of storage limitation

Thank you for attention