EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.

Slides:



Advertisements
Similar presentations
Identifying Data Protection Issues Developing Lifelong Learner Record Systems and ePortfolios in FE and HE: Planning for, and Coping with, Legal Issues.
Advertisements

NATIONAL INFORMATION GOVERNANCE BOARD
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
Administrative Systems and the Law What you need to know to produce an oral presentation for Unit 7 When the presentations will take place Resources you.
The data retention directive: data protection aspects Frank Robben General manager Crossroads Bank for Social Security Sint-Pieterssteenweg 375 B-1040.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
TEAM 4 Case Study Mauritius: Mrs Nandini Kissoon-Luckputtya
The Data Protection (Jersey) Law 2005.
Getting data sharing right for every child
EU: Bilateral Agreements of Member States. Formerly concluded international agreements of Member States with third countries Article 351 TFEU The rights.
University of Sunderland Professionalism and Personal Skills Unit 11 Professionalism and Personal Skills Computer Legislation.
A European View of Privacy Protection John Woulds Director of Operations UK Data Protection Commissioner National Conference on Privacy, Technology & Criminal.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
The Information Commissioner’s Office David Evans.
Implementation of Security and Confidentiality in GP Practices.
Health & Social Care Apprenticeships & Diploma
Opportunities and Challenges of Using Electronic Health Records to Enhance Patient Care Dr Amir Hannan Full-time General Practitioner Primary Care IT lead,
Research Paper Presentation Software Engineering in agent systems.
Computers, the law and ethics  Lesson Objective: Understand some of the legal & ethical issues in developing computer systems  Learning Outcome: Know.
Health research and the protection of personal information rights in international ethics and human rights law Colin M Harper Promoting Health Research.
The Data Protection Act 1998 The Eight Principles.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
What is personal data? Personal data is data about an individual which they consider to be private.
The Data Protection Act - Confidentiality and Associated Problems.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
Data Protection Property Management Conference. What’s it got to do with me ? As a member of a management committee responsible for Guiding property you.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
Data protection and compliance in context 19 November 2007 Stewart Room Partner.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Computing, Ethics & The Law. The Law Copyright, Designs and Patents Act (1988) Computer Misuse Act (1990) Data Protection Act (1998) (8 Main Principles)
What is the Data Protection Act (DPA)? 1998 The Data Protection Act 1998 seeks to strike a balance between the rights of individuals and the sometimes.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
DATA PROTECTION ACT DATA PROTECTION ACT  Gives rights to data subjects (i.e. people who have data stored about them on a computer)  Information.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Uses of brain imaging data: privacy and governance implications Dr. Hester Ward Medical Director, Information Services Division, (ISD) Consultant in Public.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Lost in Translations – An Examination of the Legal & Practical Problems Associated with the Implementation (or Non-Implementation) of Directive 2010/64/EU.
The Data Protection Act 1998
The Data Protection Act 1998
Making the Connection ISO Master Class An Overview.
Luca De Matteis Justice counsellor (criminal law, data protection)
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Level 2 Diploma in Customer Service
Issues of personal data protection in scientific research
Data Protection: EU & International
General Data Protection Regulation
Data Protection Act.
The Data Protection Act 1998
Anonymised information
Privacy: a work in progress
G.D.P.R General Data Protection Regulations
of social security systems, COM (2016)815”
Data Protection principles
Identify the laws and guidelines that affect day-to-day use of IT.
What is the Data Protection Act (DPA)? 1998
Is Data Protection a Fundamental Right Protecting the Individual?
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Presentation transcript:

eHRs and the European Union – current legislation and future directions. Dr Richard Fitton

The past, present and future data protection data legislation in the UK and Europe The European Declaration on Human Rights. The increasing role of the data subject. Points to address 2

E-intelligence overcomes national boundaries 3

Data protection enactment around the world Current The European Data Protection Directive 95/46/ 4

Life, health, independence, disease 5

6 (27 countries – 28 [Croatia] in July 2013) Member States of the European Union

PRISME Forum SIG 22/05/2012 EUROPEAN COMMISSION Brussels, XXX COM(2012) 11/4 draft Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (Text with EEA relevance) {SEC(2012) 72} {SEC(2012) 73}

UNIVERSAL DECLARATION OF HUMAN RIGHTS Article 3. – Everyone has the right to life, liberty and security of person. Article 12. – No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. 8

European Commission The European Commission is the executive body of the European Union. The body is responsible for proposing legislation, implementing decisions, upholding the Union’s Treaty and the general day-to-day running of the Union. 9

3. LEGAL ELEMENTS OF THE PROPOSAL 3.1. Legal Basis This proposal is based on Article 16 TFEU 1, which is the new legal basis for the adoption of data protection rules introduced by the Lisbon Treaty. 1 Treaty on the Functioning of the European Union 10

European Commission legislative terms Regulation – has a general scope, is obligatory in all its elements and is directly applicable to all member states of the European Union and constitutes the most powerful form of EU law. Directives – are only applicable in the member states when the objectives they contained have been transposed into national law. 11

“a proposal for a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data” (27 countries – 28 in July 2012) EUROPEAN COMMISSION 12

“a proposal for a Directive....with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences...and the free movement of such data.” EUROPEAN COMMISSION 13

Data Sharing Review Report 14 Richard Thomas, UK Information Commissioner, Sir Mark Walport, Director and Chief Executive of the Wellcome Trust

Data Sharing Review Richard Thomas Mark Walport 4.11 In summary, the poor level of public trust and confidence in the sharing of personal information provides a critical backdrop to this review.... and highlights the need for substantial improvements in the ways that organisations handle personal information. 15

Data Sharing Review Richard Thomas Mark Walport ‘The treatment of individual patients relies on data collected from others. “... use evidence from other people’s data to treat me, but don’t use my data to help them”.’ 16

17

Engaging with data/research subjects “Interdependence is a higher value than independence” Be proactive Begin with the end in mind Put first things first Think win/win Seek first to understand, then to be understood Synergise Balanced self renewal 18

Patients and information are the most under- utilised resources in health service provision 19

Lessons learned: 20

DPA 1 Principles for the data subject 1.Personal data shall be processed fairly and lawfully 2.Personal data shall be obtained only for one or more specified and lawful purposes 3.Personal data shall be adequate, relevant and not excessive 4.Personal data shall be accurate and, where necessary, kept up to date. 1 The UK Data Protection Act

DPA Principles 5.Personal data processed for any purpose or purposes shall not be kept for longer than is necessary 6.Personal data shall be processed in accordance with the rights of data subjects 7.Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing and... loss or destruction or damage 8.Personal data shall not be transferred to a country or territory outside the European Economic Area unless... 22

European Draft proposals reflect these Article 5 sets out the principles relating to personal data processing...in particular: – the transparency principle, – the clarification of the data minimisation principle and – responsibility and liability of the controller. 23

Article 11 introduces the obligation on controllers to provide transparent and easily accessible and understandable information, European Draft proposal 24

Article 12 obliges the controller to provide procedures and mechanism for exercising the data subject's rights Article 14 further specifies the controller's information obligations towards the data subject, Article 15 provides the data subject's right of access to their personal data, European Draft proposal 25

Article 17 provides the data subject's right to be forgotten and to erasure Article 18 introduces the data subject's right to data portability, i.e. to transfer data from one electronic processing system to and into another European Draft proposal 26

Lessons learned: 27

Conclusion The UK Biobank ( provides a classic exemplar of how patient data should be collected and managed.