ScHARR Bite Size Research Ethics and GDPR: legal requirements for research - what you need to know.

Slides:



Advertisements
Similar presentations
Data Protection.
Advertisements

HIPAA PRIVACY AND SECURITY AWARENESS.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
Session 11 Data protection. 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4:
Sharing Information Legally Lindsay Ould London Borough of Lewisham.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
General Data Protection Regulation (EU 2016/679)
Tony Sheppard Mobile Guardian
Key changes with the GDPR
The future of data protection: General Data Protection Regulation
Processing for archiving purposes in the GDPR
Issues of personal data protection in scientific research
Presentation to GTMC on GDPR
GDPR – What’s it all about???
General Data Protection Regulations: what you really need to know
Data Protection The Current Regime
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
GDPR Overview Gydeline – October 2017
General Data Protection Regulation: Turning the black into white
GDPR Overview GDPR - General Data Protection Regulations
GDPR support January GDPR support January 2018.
GDPR Overview Gydeline – October 2017
Data Protection & Freedom of Information- An Introduction
General Data Protection Regulation (GDPR)
Radar Watchkeeping: Have you monitored your Communication department’s radar to avoid collisions with the new Regulation? 43rd EDPS-DPO meeting, 31 May.
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection Reform in Local Government
The General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Interview Study Patient Information Leaflet
New Data Protection Legislation
GDPR and Health and Safety
Information Governance
G.D.P.R General Data Protection Regulations
The GDPR and research data
The new data protection rules
The GDPR & Schools - An Introduction -
General Data Protection Regulation
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation (GDPR)
A whistle stop tour of GDPR
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
How we use Your Health Records
GDPR (General Data Protection Regulation)
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
General Data Protection Regulations 2018
General Data Protection Regulations (GDPR) Training
GDPR enforcement begins
CCG COMMISSIONS HIU COLLATING PROVIDER: A&E BI TEAM CSU
GDPR Quiz Today’s trainer: Click here to use Kahoot! 1
The General Data Protection Regulation Six months on – What’s changed
Recording Clinical Data
Information Handling Research Student Induction Day
Data Management Ethical considerations for educational research
Recording Clinical Data
GDPR – General Data Protection Regulation
The EDPS: competences and processing of personal data in EU funds
Understanding Data Protection
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
General Data Protection Regulation Q & A Session
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
The General Data Protection Regulations 2016
General Data Protection Regulation (GDPR)
GDPR Session
General Data Protection Regulation “11 months in”
ScHARR Bite Size Research Ethics and GDPR: legal requirements for research - what you need to know.
HIU Process Map The collating provider has primacy, and must have/had a direct relationship with the patient CCG COMMISSIONS HIU COLLATING PROVIDER: A&E.
Presentation transcript:

ScHARR Bite Size Research Ethics and GDPR: legal requirements for research - what you need to know

GDPR – General Data Protection Regulation There is a 4% turnover fine for non-compliance which would be a huge financial loss for the University. In research, the GDPR requirements are applicable to ‘Personal Data’ – structured information about or relating to a living person which is identifiable.

Transparency You must inform your participants of the following… The legal basis for processing their data. Who the Data Controller is. Their right to contact the Data Protection Officer and ICO to complain regarding the use of their data. Detailed information on how their data will be used including: - who will have access to the data - where will it be stored - when will it be destroyed. The above information should be included in the online ethics application form and the participant information sheet.

Legal Basis for processing data The legal basis for research is usually ‘a task in the public interest’. However, if Special Category data is being used, you must additionally state that the legal basis is also ‘necessary for archiving, research or statistics’ Special Category Data is potentially sensitive information such as: Race/ethnicity, political opinion, religious/other beliefs, trade union membership, sexuality/sexual activity, criminal records/allegations, genetic data, biometric data and (especially relevant to ScHARR)…HEALTH!

Data Controller The Data Controller is the organisation which determines the purposes and means of processing personal data. This would usually be The University of Sheffield If you are collaborating on a project with another institution you would need to agree who will be named as the Data Controller and document this in the collaboration agreement.

Right to complain about the use of data Anne Cutler is The University of Sheffield Data Protection Officer (DPO). Complaints about the handling of personal data should be directed to Anne in the first instance at: dataprotection@Sheffield.ac.uk If the participant is not satisfied with how their complaint has been handled, they may then escalate the matter to the ICO (Information Commission Office).

How data will be used Will the data be identifiable, anonymised or pseudonymised and at which points in the research process will it take these forms. Who will have access to the data – state that members of the research team will have access and explain any collaborators who may have access. Where will the data be stored – in an access restricted folder in the University’s Shared Networked Filestore. When will the data be destroyed – the data should be destroyed as soon as it is no longer required for the research.

Ongoing Projects If your project is continuing data collection which started prior to the 25th May, you must provide participants with the required information if you have not already done so. If the only data you need to provide is the Data Controller, How to complain and Legal Basis, you may send the information via email or a letter at the next opportunity, such as when contacting participants to collect data. Please send a copy of the communication you have sent to scharr-rec@Sheffield.ac.uk to file in our records. However, if more significant changes required to adhere to GDPR, for example, you had not already told participants who would have access to data, where it would be stored and when it will be destroyed, you will need to send a formal amendment request to scharr-rec@Sheffield.ac.uk to send out a more comprehensive communication to participants.

Using existing data GDPR requirements do not apply if: Data is obtained from a 3rd party AND Data is pseudonymised and only non-identifiable data will be used for the research AND It is either impossible or a disproportionate effort to contact participants OR providing information would either impair the research or make it impossible. Existing data – if data was anonymised in the original project, this is not personal data. There must be either original consent for use in future research and to share with others or you will need to contact the participants again for consent unless the data is from a 3rd party or non-identifiable.

NHS The Data Controller is likely to be the Healthcare Research Governance Sponsor. Consult the HRA webpages for guidance https://www.hra.nhs.uk/planning-and-improving-research/policies- standards-legislation/data-protection-and-information-governance/

Key Messages Use the information sheet and consent form templates on the ScHARR ethics webpages. Consider the future uses of data from the outset, consent must be given to contact the participant in the future, publish, use data in future research and be shared with others. Anonymise or pseudonymise the data as quickly as possible As Supervisors, ensure your students ethics applications adhere to GDPR regulations! Check the Research Services webpages for further guidance and updates https://sites.google.com/a/sheffield.ac.uk/gdpr/homec