Pseudonymisation in the context of GDPR-compliant medical research

被引:0
|
作者
Basdekis, Ioannis [1 ]
Kloukinas, Christos [2 ]
Agostinho, Carlos [3 ]
Vezakis, Ioannis [4 ]
Pimenta, Andreia [5 ]
Gallo, Luigi [1 ,6 ]
机构
[1] SPHYNX Technol Solut AG, Zug, Switzerland
[2] City Univ London, Dept Comp Sci, London, England
[3] Univ Nova Lisboa, Ctr Technol & Syst, Caparica, Portugal
[4] SPHYNX Analyt Ltd, Nicosia, Cyprus
[5] Secretaria Reg Saude Protecao Civil, SRS, Madeira, Portugal
[6] CNR, Inst High Performance Comp & Networking, Rome, Italy
基金
欧盟地平线“2020”;
关键词
pseudonymisation; privacy; data minimisation; GDPR; observational studies; GENETIC RESEARCH; PROTECTION;
D O I
10.1109/DRCN57075.2023.10108370
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Pseudonymisation is a data protection technique often used to protect the privacy of individuals when their personal data are being used for research purposes. Not only is it a key ingredient of the General Data Protection Regulation (GDPR) that requires organisations to ensure that the personal data they process is handled in a secure manner, but it is particularly important in assisting medical research given that often relies on sensitive personal data, since it reduces the risk that medical data could be misused or mishandled. For managing their medical data, it is important to ensure that such data are protected against unauthorised access, and can be reutilised in an anonymous fashion, while still authorised personnel is able to identify the study participant that some data belong to (e.g., for personalised interventions, technical alerts, technical support). In addition, the re-identification of a study participant is a pre-requisite for exercising their rights under the GDPR, since it assists organisations in meeting GDPR requirements (such as the right to access, rectify and portability of data). We argue that the application of pseudonymisation is particularly effective when considered during the early stages (Privacy by Design) of digital services implementation, as well as when defining the complementary to these organizational procedures. Aim of this paper is to present the way in which the pseudonymisation mechanism of the SMART BEAR H2020 project supports the triptych of research activities conducted within the context of an observational medical study, legal obligations arising from the regulatory framework for the protection of personal data, and reutilisation of data for research purposes. Evidence-based security and privacy assessments will be conducted on two different H2020 projects to evaluate such privacy practice.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] GDPR-Compliant Reputation System Based on Self-certifying Domain Signatures
    Kutylowski, Miroslaw
    Lemiesz, Jakub
    Slowik, Marta
    Slowik, Marcin
    Kluczniak, Kamil
    Gebala, Maciej
    INFORMATION SECURITY PRACTICE AND EXPERIENCE, ISPEC 2019, 2019, 11879 : 341 - 361
  • [32] Towards a GDPR-compliant cloud architecture with data privacy controlled through sticky policies
    Cambronero, M. Emilia
    Martinez, Miguel A.
    Llana, Luis
    Rodriguez, Ricardo J.
    Russo, Alejandro
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [33] Is Automated Consent in Solid GDPR-Compliant? An Approach for Obtaining Valid Consent with the Solid Protocol
    Florea, Marcu
    Esteves, Beatriz
    INFORMATION, 2023, 14 (12)
  • [34] GDPR-Compliant Personal Health Record Sharing Mechanism With Redactable Blockchain and Revocable IPFS
    Yeh, Lo-Yao
    Hsu, Wan-Hsin
    Shen, Chih-Ya
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3342 - 3356
  • [35] GDPR-compliant AI-based automated decision-making in the world of work
    Lukacs, Adrienn
    Varadi, Szilvia
    COMPUTER LAW & SECURITY REVIEW, 2023, 50
  • [36] privacyTracker: A Privacy-by-Design GDPR-Compliant Framework with Verifiable Data Traceability Controls
    Gjermundrod, Harald
    Dionysiou, Ioanna
    Costa, Kyriakos
    CURRENT TRENDS IN WEB ENGINEERING, ICWE 2016 INTERNATIONAL WORKSHOPS, 2016, 9881 : 3 - 15
  • [37] A GDPR-compliant information system to improve community primary care in a middle income country
    Oliveira, V. A.
    David, R. B.
    Mota, L. G.
    Barral-Netto, M.
    Carreiro, R. P.
    Botelho, D. F.
    EUROPEAN JOURNAL OF PUBLIC HEALTH, 2020, 30
  • [38] Blockchain-based access control system for efficient and GDPR-compliant personal data management
    Dauden-Esmel, Cristofol
    Castella-Roca, Jordi
    Viejo, Alexandre
    COMPUTER COMMUNICATIONS, 2024, 214 : 67 - 87
  • [39] A GDPR-compliant solution for analysis of large-scale genomics datasets on HPC cloud infrastructure
    Silvia Gioiosa
    Beatrice Chiavarini
    Mattia D’Antonio
    Giuseppe Trotta
    Balasubramanian Chandramouli
    Juan Mata Naranjo
    Giuseppa Muscianisi
    Mirko Cestari
    Elisa Rossi
    Journal of Big Data, 12 (1)
  • [40] A GDPR-Compliant Dynamic Consent Mobile Application for the Australasian Type-1 Diabetes Data Network
    Wang, Zhe
    Stell, Anthony
    Sinnott, Richard O.
    HEALTHCARE, 2023, 11 (04)