Personal data: electronic capture, storage and security

Slides:



Advertisements
Similar presentations
HES Data Management Ari Haukijärvi. Planning of HES Data Management Purpose of the data management The data will be available for analysis The available.
Advertisements

National Update: The information revolution and the 2012 Caldicott Review Simon Richardson – Information Rights Manager.
Keeping on top of the Cloud - Compliance from a Regulator’s Perspective Henry Chang, IT Advisor Office of the Privacy Commissioner for Personal Data, Hong.
Data management in the field Ari Haukijärvi 2nd EHES training seminar.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
Data Protection Property Management Conference. What’s it got to do with me ? As a member of a management committee responsible for Guiding property you.
Collection and Analysis of Data CPH 608 Spring 2015.
Using REDCap (Research Electronic Data Capture) as a tool to perform research studies Abstract ID no. IRIA-1076.
Data Protection and research Rachael Maguire Records Manager.
Privacy Audit and Privacy Seal Barbara Körffer & Dr. Thomas Probst Independent Centre for Privacy Protection Independent Centre for Privacy ProtectionSchleswig-Holstein.
The EU General Data Protection Regulation Frank Rankin.
Business Challenges in the evolution of HOME AUTOMATION (IoT)
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Maciej Pęciak Robert Dąbroś
TRUSTED | PROTECTED | SECURED
Issues of personal data protection in scientific research
A secure communication platform
Viewing the GDPR Through a De-Identification Lens
General Data Protection Regulation
SIMS Reporting Enhancement supporting GDPR
General Data Protection Regulation (GDPR)
Museums + Heritage webinar, 30 November 2017
GDPR Readiness Project
GDPR Overview Gydeline – October 2017
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
GDPR Security: How to do IT? IT reediness for competitive advantage
GDPR Road map to Compliance.
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
All data occupies physical space, even if we don't think of it as such.
The General Data Protection Regulation (GDPR)
New Data Protection Legislation
SIMS Reporting Enhancement supporting GDPR
Appropriate Data Sharing in Health and Social Care
G.D.P.R General Data Protection Regulations
ScHARR Bite Size Research Ethics and GDPR: legal requirements for research - what you need to know.
The GDPR and research data
The GDPR & Schools - An Introduction -

General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
Preparing for GDPR Sharing experiences of the process and using the British Canoeing Toolkit bit.ly/BCGDPRToolkit
Data Mapping On the Journey to Accountability
REDCap and Data Governance
Data transfers to non-EU countries under the new GDPR
where can you begin rolling out?
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
By The Data Protection Commissioner
GDPR & Accountability ISACA Ireland Annual Conference 2018
Recording Clinical Data
Information Handling Research Student Induction Day
Data Management Ethical considerations for educational research
Recording Clinical Data
GDPR – General Data Protection Regulation
GDPR PERSONDATAFORORDNINGEN I PRAKSIS
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
General Data Protection Regulation “11 months in”
Data Privacy by Design Expanding Security for bepress Users
ScHARR Bite Size Research Ethics and GDPR: legal requirements for research - what you need to know.
General Data Protection Regulation Community Councils
GDPR Workshop – Partnerships for Jewish Schools
Getting Ready For GDPR Simon Marks Director
GDPR what do we need to do?
School of Medicine Orientation Information Security Training
Presentation transcript:

Personal data: electronic capture, storage and security Dr David W. Evans Centre of Precision Rehabilitation for Spinal Pain School of Sport, Exercise and Rehabilitation Sciences

Researchers are professional data generators! In the eyes of the ICO, we are also: Data controllers Data processors In the health, life and social sciences, most data is: From / about living people Potentially identifiable

Is the data ‘personal’? Question 1 Can a living individual be identified from the data, or, from the data and other information in your possession, or likely to come into your possession? No - The data is not ‘personal data’ for the purposes of the DPA  Yes - Go to question 2 Information Commissioner’s Office

Is the data ‘personal’? Question 2 Does the data ‘relate to’ the identifiable living individual, whether in personal or family life, business or profession?  No - The data is not ‘personal data’ for the purposes of the DPA Yes - The data is ‘personal data’ for the purposes of the DPA Information Commissioner’s Office

Personal data Most data in the health, life and social sciences is ‘personal’

Personal data Data Protection Act (1998) currently applies From May 2018, the GDPR will add (amongst others): Bigger £££ fines for non-compliance The subject’s ‘right to be forgotten’ Legal obligation to maintain records of both personal data and processing activities Appropriate ‘safeguards’ must be in place

Appropriate safeguards Only necessary personal data may be processed Principle of ‘data minimisation’ Data protection / privacy ‘by design and default’ Data Protection Impact Assessments (DPIAs) Data Management Plans (DMPs) ‘Pseudonymisation’ Data should not be attributable to a specific subject without the use of ‘additional information’ This additional information must be kept separately and subject to technical and organisational measures to ensure non-attribution to an individual

Electronic data storage Electronic data storage is now commonplace Local or remote Can be very secure

Electronic data storage Birmingham Environment for Academic Research (BEAR) Research Data Store (RDS) Research Data Archive (RDA)

Electronic data capture Electronic data capture is becoming more attractive:

Electronic data capture Electronic data capture is becoming more attractive: Saves trees More secure than paper? Data ultimately ends up in electronic format For analysis, reporting and archiving More time efficient 1-step vs 2-step process Can be ‘smarter’ than paper questionnaires Branching logic Can utilise sensors onboard / linked to the device ‘Active task’ data

Electronic data capture REDCapTM data collection and storage software www.project-redcap.org

REDCap Developed at Vanderbilt University, Tennessee Locally hosted Server hosted Free license, not open-source Currently used at 2752 institutions in 119 countries Active user forum / community Locally hosted Requires local server installation and IT support Phil Dimmock, IT Services Fully compliant with DPA & GDPR User privileges and rights can be controlled Can keep identifiable data separate from research data Exports anonymised research data in analysable format All interactions are logged and auditable

REDCap Encrypted data transit Uploaded to local secure database HTTPS transfer to server via ‘private’ browser ‘REDCap app’ transfers encrypted datafile to server Uploaded to local secure database Hosted on UoB servers Appropriate security measures Participant-hosted app under development MyCap Utilises ‘ResearchKit’ and ‘ResearchStack’ open-source frameworks

MyCap: participant-hosted app

MyCap: participant-hosted app

Thank you for listening!