Pseudonymisation in the context of GDPR-compliant medical research

被引:0
|
作者
Basdekis, Ioannis [1 ]
Kloukinas, Christos [2 ]
Agostinho, Carlos [3 ]
Vezakis, Ioannis [4 ]
Pimenta, Andreia [5 ]
Gallo, Luigi [1 ,6 ]
机构
[1] SPHYNX Technol Solut AG, Zug, Switzerland
[2] City Univ London, Dept Comp Sci, London, England
[3] Univ Nova Lisboa, Ctr Technol & Syst, Caparica, Portugal
[4] SPHYNX Analyt Ltd, Nicosia, Cyprus
[5] Secretaria Reg Saude Protecao Civil, SRS, Madeira, Portugal
[6] CNR, Inst High Performance Comp & Networking, Rome, Italy
基金
欧盟地平线“2020”;
关键词
pseudonymisation; privacy; data minimisation; GDPR; observational studies; GENETIC RESEARCH; PROTECTION;
D O I
10.1109/DRCN57075.2023.10108370
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Pseudonymisation is a data protection technique often used to protect the privacy of individuals when their personal data are being used for research purposes. Not only is it a key ingredient of the General Data Protection Regulation (GDPR) that requires organisations to ensure that the personal data they process is handled in a secure manner, but it is particularly important in assisting medical research given that often relies on sensitive personal data, since it reduces the risk that medical data could be misused or mishandled. For managing their medical data, it is important to ensure that such data are protected against unauthorised access, and can be reutilised in an anonymous fashion, while still authorised personnel is able to identify the study participant that some data belong to (e.g., for personalised interventions, technical alerts, technical support). In addition, the re-identification of a study participant is a pre-requisite for exercising their rights under the GDPR, since it assists organisations in meeting GDPR requirements (such as the right to access, rectify and portability of data). We argue that the application of pseudonymisation is particularly effective when considered during the early stages (Privacy by Design) of digital services implementation, as well as when defining the complementary to these organizational procedures. Aim of this paper is to present the way in which the pseudonymisation mechanism of the SMART BEAR H2020 project supports the triptych of research activities conducted within the context of an observational medical study, legal obligations arising from the regulatory framework for the protection of personal data, and reutilisation of data for research purposes. Evidence-based security and privacy assessments will be conducted on two different H2020 projects to evaluate such privacy practice.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Trusted and GDPR-Compliant Research with the Internet of Things
    Bourgeois, Jacky
    Kortuem, Gerd
    Kawsar, Fahim
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS (IOT'18), 2018,
  • [2] Implementing GDPR-Compliant Surveys Using Blockchain
    Goncalves, Ricardo Martins
    da Silva, Miguel Mira
    da Cunha, Paulo
    FUTURE INTERNET, 2023, 15 (04)
  • [3] Designing a GDPR-Compliant and Usable Privacy Dashboard
    Raschke, Philip
    Kuepper, Axel
    Drozd, Olha
    Kirrane, Sabrina
    PRIVACY AND IDENTITY MANAGEMENT: THE SMART REVOLUTION, 2018, 526 : 221 - 236
  • [4] Modelling GDPR-Compliant Explanations for Trustworthy AI
    Sovrano, Francesco
    Vitali, Fabio
    Palmirani, Monica
    ELECTRONIC GOVERNMENT AND THE INFORMATION SYSTEMS PERSPECTIVE, EGOVIS 2020, 2020, 12394 : 219 - 233
  • [5] GDPR-Compliant Data Processing: Practical Considerations
    Almeida, Joao
    da Cunha, Paulo Rupino
    Pereira, Alexandre Dias
    INFORMATION SYSTEMS (EMCIS 2021), 2022, 437 : 505 - 514
  • [6] How GDPR Enhances Transparency and Fosters Pseudonymisation in Academic Medical Research
    Verhenneman, G.
    Claes, K.
    Dereze, J. J.
    Herijgers, P.
    Mathieu, C.
    Rademakers, F. E.
    Reyda, R.
    Vanautgaerden, M.
    EUROPEAN JOURNAL OF HEALTH LAW, 2020, 27 (01) : 35 - 57
  • [7] GDPR-Compliant Use of Blockchain for Secure Usage Logs
    Zieglmeier, Valentin
    Daiqui, Gabriel Loyola
    PROCEEDINGS OF EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING (EASE 2021), 2021, : 313 - 320
  • [8] POINTER: A GDPR-Compliant Framework for Human Pentesting (for SMEs)
    Archibald, J.
    Renaud, K.
    PROCEEDINGS OF THE TWELFTH INTERNATIONAL SYMPOSIUM ON HUMAN ASPECTS OF INFORMATION SECURITY & ASSURANCE (HAISA 2018), 2018, : 147 - 157
  • [9] Design principles for constructing GDPR-compliant blockchain solutions
    Molina, Fentanda
    Betarte, Gustavo
    Luna, Carlos
    2021 IEEE/ACM 4TH INTERNATIONAL WORKSHOP ON EMERGING TRENDS IN SOFTWARE ENGINEERING FOR BLOCKCHAIN (WETSEB 2021), 2021, : 1 - 8
  • [10] An Efficient GDPR-Compliant Data Management for IoHT Applications
    Chuang, I-Hsun
    Huang, ShihHao
    Hong, Wan-Hsuan
    Kuo, Yau-Hwang
    2023 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS, ICC WORKSHOPS, 2023, : 1950 - 1955