The European Data Protection Regulation and research Graham Love Chief Executive Health Research Board 1.

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

NIGB International Data Sharing Conference Oxford Tuesday 21 st September 2010 National Information Governance Board Alan Doyle - Director Karen Thomson.
NIGB Legal requirements for use of personal data in research OnCore UK / NRES Training workshop Ethical Principles relating to consent for use of samples.
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
Department of Arts and Culture Briefing on the Use of Official Languages Bill to the Select Committee on Education and Recreation Date:15 August 2012.
MF Regulations & Separate Collections Linda Crichton.
The Victims of Crime Bill 2011 As proposed by:  AdVIC  Dublin Rape Crisis Centre  Support After Homicide (SAH) Maria McDonald BL 1.
Data-Sharing and Governance Consultation ANALYSIS OF RESPONSES.
European Federation of Waste Management and Environmental Services Pierre Rellet President.
EU: Bilateral Agreements of Member States
EU: Bilateral Agreements of Member States. Formerly concluded international agreements of Member States with third countries Article 351 TFEU The rights.
RATIFICATION OF FINAL ACTS AND DECISIONS OF THE 1999 BEIJING CONGRESS – UNIVERSAL POSTAL UNION.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Vigdis Kvalheim Norwegian Social Science Data Services (NSD) New Legal Challenges - New EC Privacy Regulation Data Preservation and Data Sharing in danger?
Clinical Research Conference 2012 Legal, Ethical, and Social Dimensions of Clinical Research Takis Vidalis, Ph. D., Hellenic National Bioethics Commission.
1 INTERREG IIIB “ATLANTIC AREA” Main points of community regulation 438/2001 financial management and control systems EUROPEAN COMMISSION SPAIN.
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
EUROPEAN COMMISSION - DG Internal Market 1 "Reviewing the Review: The European Commission's Third Review of the Product Liability Directive"
Overview of the EU Food Safety Requirements
Implementation of EU Electronic Communication Directives.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
Expert group meeting on draft delegated act on the European code of conduct on partnership (ECCP) under cohesion policy
Joana Mendes Amsterdam Centre for European Law and Governance, University of Amsterdam Jean Monnet Seminar, University of Macau 27 October 2011 Participation.
The 4 th Railway Package: Impact for the keepers Clio Liégeois.
16-17 November 2005 COSCAP – NA Project Steering Group Guangzhou, China 1 Co-operating with the European Aviation safety Agency.
©2012 Morrison & Foerster (UK) LLP | All Rights Reserved | mofo.com Data Protection Masterclass: The New Draft EU Data Protection Regulation 19 September.
The EU Directive on "Services in the internal market", COM(2004) 2 final/3 Agnese Knabe Project coordinator European Public Health Alliance Civic Alliance.
PRESENTATION TO THE PORTFOLIO COMMITTEE ON TRADE AND INDUSTRY COMPANIES BILL [B ] 13 August 2008 By: Bernard Peter Agulhas – Acting Chief Executive.
CRIMINAL LAW OF THE EUROPEAN UNION 1 April 2015 THE LISBON TREATY AND CRIMINAL LAW Dr. sc. Zoran Burić Department of Criminal Procedural Law University.
EU Politics CHAPTER 13: Other Institutions. Outline 1) European Economic and Social Committee (EESC) 2) Committee of the Regions (CoR) 3) European Agencies.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule.
Selina Stewart Lead associate: Prevent duty Further Education and Sixth Form Colleges Seminar.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
An agency of the European Union Guidance on the anonymisation of clinical reports for the purpose of publication in accordance with policy 0070 Industry.
Brussels Privacy Symposium on Identifiability
EU Law Law 326.
Brussels Privacy Symposium on Identifiability
The Citizen in the centre in EU, Bratislava November,2005
Public Participation in Biofuels Voluntary
European (Sector) Social Dialogue overview & update
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Issues of personal data protection in scientific research
Viewing the GDPR Through a De-Identification Lens
Research on human biological materials: Lithuanian perspective
General Data Protection Regulation
Data for Child Health: Promoting & Protecting Public Health through Custodianship EAP Brussels, 28 January 2016 Health Databases & Biobanks Promoting &
EU perspective – Sustainable development means….
Business environment in the EU Prepared by Dr. Endre Domonkos (PhD)
Data workshop WhOSE DATA IS IT ANYWAY? Alexia Christie
Data Protection & Freedom of Information- An Introduction
Introduction to GDPR 09/11/2018.
Dan Tofan | Expert in NIS 21st Art. 13a WG| LISBON |
Appropriate Data Sharing in Health and Social Care
G.D.P.R General Data Protection Regulations
The GDPR and research data
General Data Protection Regulation
The role of the ECCP (1) The involvement of all relevant stakeholders – public authorities, economic and social partners and civil society bodies – at.
The activity of Art. 29. Working Party György Halmos
IESS Agenda point 7.3 DSS Meeting September 2014.
Is Data Protection a Fundamental Right Protecting the Individual?
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
AERODROME CERTIFICATION COURSE
The EDPS: competences and processing of personal data in EU funds
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
European Commission proposals for data protection
European Union Law Daniele Gallo
Revision of Decision 2010/477/EU
Meeting Of The European Directors of Social Statistics
Jeannette Monier and Louise Reid
Presentation transcript:

The European Data Protection Regulation and research Graham Love Chief Executive Health Research Board 1

Background to the Regulation Proposal from Commission in January 2012 Regulation = directly binding Covers use of personal data across most sectors except for law enforcement Under Commission’s proposal, consent is not required to legitimise the use of data in research – vital exemption. 2

Legislative process Council (Member States ) Parliament (LIBE) Commission TRILOGUE 3

Legislative procedure for EU Data Protection Regulation 4

The political context 5

The European Parliament’s position LIBE committee agreed 91 compromise amendments from over 3000 tabled European Parliament voted on 12 March in a ‘block vote’ all amendments. Almost unanimous in favour of the amendments because agreed by political groups in advance. 6

Debate in the European Parliament We cannot allow people to run into doctors’ offices and take our personalised, private profiles It is vital that the changes to Articles 81 and 83 are reconsidered and that expert advice is taken 7

Impact Special provisions for the use of data concerning health in research Member States able to create an exemption from specific consent, but very narrow. Only: –for pseudonymous data; –in “high public interest”; and –where the research “cannot possibly be carried out otherwise” Much research using routine data, biobanks, registries or cohorts could become impossible or unworkable 8

Article 81 (2) Research using data concerning health Amendment outline Processing of personal data concerning health which is necessary for historical, statistical or scientific research purposes, such as patient registries set up for improving diagnoses and differentiating between similar types of diseases and preparing studies for therapies, is shall be permitted only with the consent of the data subject, and shall be subject to the conditions and safeguards referred to in Article 83. Analysis This amendment makes the exemption from consent for the use of data concerning health in research very narrow. This will prevent valuable health research that is currently legal and already tightly regulated under European and Member State law. 9 KEY Text added by the LIBE committee is in bold italics Text deleted by the LIBE committee is struck through bold italics Text of proposed amendments is in bold underlined italics

Article 81 (2a) Research using data concerning health Amendment outline Member States law may provide for exceptions to the requirement of consent for research, as referred to in paragraph 2, with regard to research that serves a high public interests, if that research cannot possibly be carried out otherwise. The data in question shall be anonymised, or if that is not possible for the research purposes, pseudonymised under the highest technical standards, and all necessary measures shall be taken to prevent unwarranted re- identification of the data subjects. However, the data subject shall have the right to object at any time in accordance with Article 19. Analysis While the amendment enables Member States to legislate for an exemption, the permitted exemption is very narrow: The exemption could only apply to the use of pseudonymised, not identifiable, data. A very high bar is set for research using pseudonymised data to be eligible for the exemption, which lacks any assessment of proportionality or reasonableness. 10

Article 81 (2a) Further Analysis Particular concerns include: “High public interest” suggests the exemption is to be used only in a very limited set of circumstances. This is likely to be problematic for many studies, particularly because the results and impact of the study are not known at the outset. “Cannot possibly be carried out otherwise” creates a strict test that does not take into account the nature of research, for example, it is not clear how one could show that a particular research project “cannot possibly be carried out otherwise” where it is theoretically possible, but not practicable (because of the sample size needed), to seek consent. The requirement for pseudonymisation to be at “the highest technical standards” lacks an assessment of reasonableness. This is problematic because research resources are often used over many years. Even where a study can demonstrate “highest technical standards” when it is first established, it would be impractical to ensure compliance with this requirement every single time data are used in the future, as this would require continual updating of standards and processes. These amendments also produce an overlap between Articles 81 and 83, creating legal uncertainty. Research is an international activity and would benefit from clear and harmonised rules that facilitate research across Member States. However, Member State-based exemptions will limit the potential for harmonisation. 11

Recital 123a Processing of personal data concerning health Amendment outline The processing of personal data concerning health, as a special category of data, may be necessary for reasons of historical, statistical or scientific research. Therefore this Regulation foresees an exemption from the requirement of consent in cases of research that serves a high public interest. Analysis The concept of “high public interest” is problematic. “High public interest” suggests the exemption is to be used only in a very limited set of circumstances. This is likely to be problematic for many studies, particularly because the results and impact of the study are not known at the outset. 12

Article 83 (1) Processing for historical, statistical or scientific research purposes Amendment outline Analysis This amendment makes the exemption from consent for the use of health data in research very narrow, which will prevent valuable research that is currently legal. The amendment only applies to the use of pseudonymised, not identifiable, data. In addition, the requirement for pseudonymisation to be at “the highest technical standards” lacks an assessment of reasonableness. This is problematic because research resources are often used over many years. Even where a study can demonstrate “highest technical standards” when it is first established, it would be impractical to ensure compliance with this requirement every single time data are used in the future, as this would require continual updating of standards and processes. 13 In accordance with the rules set out in this Regulation, personal data may be processed for historical, statistical or scientific research purposes only if: (a) these purposes cannot be otherwise fulfilled by processing data which does not permit or not any longer permit the identification of the data subject; (b) data enabling the attribution of information to an identified or identifiable data subject is kept separately from the other information as long as theses purposes can be fulfilled in this manner under the highest technical standards, and all necessary measures are taken to prevent unwarranted re-identification of the data subjects.

The Council’s position Council of Ministers still considering Commission’s proposal Research has been discussed in Council working group in January and February Unclear when Council’s position (‘general approach’) will be agreed 14

Next steps Council Parliament Commission TRILOGUE Impact of elections? 15

What is being done? 16

“Regulation should be sufficiently flexible to continue to facilitate processing of personal data for health historical, statistical and scientific research purposes while providing appropriate safeguards for the protection of personal data”. Irish Department of Justice What are we doing in Ireland ? HRB alignment with the EU Wellcome Trust-led approach Engaging with the Department of Justice, other government Departments and with Irish MEPs Informing the research community 17

In order to protect valuable research while protecting privacy, we urge: Council of Ministers to maintain the EU Commission’s text on Articles 81 and 83 and associated provisions when agreeing its general approach MEPs to seek a more positive outcome for research in trilogue negotiations Council of Ministers and EU Commission to oppose the EU Parliament’s amendments to Articles 81 and 83 in trilogue negotiations. 18

Further information or guidelines-and-grant-conditions/eu-data-protection- regulation/ guidelines-and-grant-conditions/eu-data-protection- regulation/ Any questions? Contact Dr Patricia Clarke, HRB Senior Policy Analyst, Tel: Special thanks to Dr Beth Thompson, Wellcome Trust for all of her assistance and advice. 19