Pseudonymisation in the context of GDPR-compliant medical research

被引:0
|
作者
Basdekis, Ioannis [1 ]
Kloukinas, Christos [2 ]
Agostinho, Carlos [3 ]
Vezakis, Ioannis [4 ]
Pimenta, Andreia [5 ]
Gallo, Luigi [1 ,6 ]
机构
[1] SPHYNX Technol Solut AG, Zug, Switzerland
[2] City Univ London, Dept Comp Sci, London, England
[3] Univ Nova Lisboa, Ctr Technol & Syst, Caparica, Portugal
[4] SPHYNX Analyt Ltd, Nicosia, Cyprus
[5] Secretaria Reg Saude Protecao Civil, SRS, Madeira, Portugal
[6] CNR, Inst High Performance Comp & Networking, Rome, Italy
基金
欧盟地平线“2020”;
关键词
pseudonymisation; privacy; data minimisation; GDPR; observational studies; GENETIC RESEARCH; PROTECTION;
D O I
10.1109/DRCN57075.2023.10108370
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Pseudonymisation is a data protection technique often used to protect the privacy of individuals when their personal data are being used for research purposes. Not only is it a key ingredient of the General Data Protection Regulation (GDPR) that requires organisations to ensure that the personal data they process is handled in a secure manner, but it is particularly important in assisting medical research given that often relies on sensitive personal data, since it reduces the risk that medical data could be misused or mishandled. For managing their medical data, it is important to ensure that such data are protected against unauthorised access, and can be reutilised in an anonymous fashion, while still authorised personnel is able to identify the study participant that some data belong to (e.g., for personalised interventions, technical alerts, technical support). In addition, the re-identification of a study participant is a pre-requisite for exercising their rights under the GDPR, since it assists organisations in meeting GDPR requirements (such as the right to access, rectify and portability of data). We argue that the application of pseudonymisation is particularly effective when considered during the early stages (Privacy by Design) of digital services implementation, as well as when defining the complementary to these organizational procedures. Aim of this paper is to present the way in which the pseudonymisation mechanism of the SMART BEAR H2020 project supports the triptych of research activities conducted within the context of an observational medical study, legal obligations arising from the regulatory framework for the protection of personal data, and reutilisation of data for research purposes. Evidence-based security and privacy assessments will be conducted on two different H2020 projects to evaluate such privacy practice.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] A Comparative Study of Access Analysis Service Utilization on Japanese Medical Institutions' Websites with GDPR-Compliant Cases
    Seki, Tomohisa
    Kawazoe, Yoshimasa
    Ohe, Kazuhiko
    Studies in Health Technology and Informatics, 316 : 1238 - 1242
  • [22] Speed Kit: A Polyglot & GDPR-Compliant Approach For Caching Personalized Content
    Wingerath, Wolfram
    Gessert, Felix
    Witt, Erik
    Kuhlmann, Hannes
    Bucklers, Florian
    Wollmer, Benjamin
    Ritter, Norbert
    2020 IEEE 36TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2020), 2020, : 1603 - 1608
  • [23] GDPR-Compliant Data Breach Detection: Leveraging Semantic Web and Blockchain
    Ansar, Kainat
    Ahmed, Mansoor
    Khalid, Muhammad Irfan
    Helfert, Markus
    GOOD PRACTICES AND NEW PERSPECTIVES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 6, WORLDCIST 2024, 2024, 990 : 3 - 11
  • [24] Exploring Deep Federated Learning for the Internet of Things: A GDPR-Compliant Architecture
    Abbas, Zahra
    Ahmad, Sunila Fatima
    Syed, Madiha Haider
    Anjum, Adeel
    Rehman, Semeen
    IEEE ACCESS, 2024, 12 : 10548 - 10574
  • [25] AuthApp - Portable, Reusable Solid App for GDPR-Compliant Access Granting
    Both, Andreas
    Kastner, Thorsten
    Yeboah, Dustin
    Braun, Christoph
    Schraudner, Daniel
    Schmid, Sebastian
    Kaefer, Tobias
    Harth, Andreas
    WEB ENGINEERING, ICWE 2024, 2024, 14629 : 199 - 214
  • [26] Application of Blockchain in Education: GDPR-Compliant and Scalable Certification and Verification of Academic Information
    Delgado-von-Eitzen, Christian
    Anido-Rifon, Luis
    Fernandez-Iglesias, Manuel J.
    APPLIED SCIENCES-BASEL, 2021, 11 (10):
  • [27] Risk Analysis of a GDPR-Compliant Deletion Technique for Consortium Blockchains Based on Pseudonymization
    Campanile, Lelio
    Cantiello, Pasquale
    Iacono, Mauro
    Marulli, Fiammetta
    Mastroianni, Michele
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2021, PT VIII, 2021, 12956 : 3 - 14
  • [28] Data cart - designing a tool for the GDPR-compliant handling of personal data by employees
    Tolsdorf, Jan
    Dehling, Florian
    Iacono, Luigi Lo
    BEHAVIOUR & INFORMATION TECHNOLOGY, 2022, 41 (10) : 2070 - 2105
  • [29] Lightweight Blockchain-based Platform for GDPR-Compliant Personal Data Management
    Dauden-Esmel, Cristofol
    Castella-Roca, Jordi
    Viejo, Alexandre
    Domingo-Ferrer, Josep
    2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 68 - 73
  • [30] Enabling Integrity and Compliance Auditing in Blockchain-Based GDPR-Compliant Data Management
    Wang, Lipeng
    Guan, Zhi
    Chen, Zhong
    Hu, Mingsheng
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (23) : 20955 - 20968