2018-GDPR对医疗研究人员意味着什么_(英文版)
报告摘要
GDPR Summary for Healthcare Researchers
Core Content
The General Data Protection Regulation (GDPR) is a significant EU legislation that aims to strengthen the rights of citizens in the digital age and simplify data protection rules for businesses. It replaces the outdated Data Protection Directive 95/46/EC and introduces stricter compliance requirements, with potential fines up to 4% of global turnover. The regulation was enacted on 25th May 2018, following a 2-year implementation period that began on 14th April 2016.
Main Points
- Scope of GDPR: Applies to all organizations that process the personal data of EU residents, regardless of their location. This includes companies that collect and process data from EU citizens even if they are not based in the EU.
- Research and GDPR: Research is now a recognized legitimate interest under GDPR, allowing data processing without explicit consent in certain cases. However, this exemption does not apply to healthcare data.
- Healthcare Research: Healthcare research, including clinical trials and real-world research, is considered a subset of scientific research. It still requires informed consent, especially for sensitive data such as health information.
- Public Health Research: This is treated as a separate category under GDPR and may be exempt from some data subject rights, but requires consultation with supervisory authorities and authorization due to its "high risk" nature.
- UK Post-Brexit: The UK will implement GDPR regardless of the outcome of Brexit. The Information Commissioner's Office (ICO) has already outlined an international strategy to support compliance.
- Compliance Requirements: Healthcare researchers must ensure they:
- Provide clear privacy notices.
- Conduct data minimization and pseudonymization.
- Identify and manage appropriate safeguards.
- Perform Privacy Impact Assessments (PIA) and Data Protection Impact Assessments (DPIA).
- Handle data subject requests effectively.
- Review contracts and liability clauses with third parties.
- Ensure data storage periods are defined and justified.
- Provide training on GDPR compliance and individual accountability.
Key Information
- Research Exemption: While research is allowed as a legitimate interest, it is not a blanket exemption. Researchers must ensure that data processing aligns with the intended purpose and meets "appropriate safeguards."
- Healthcare Data: Falls under "special categories" and requires explicit consent for processing, unless specific exceptions apply (e.g., public interest, legal obligation, or prior consent).
- Data Transfer: GDPR allows data transfers outside the EEA without specific mechanisms, but only for research purposes where appropriate safeguards are in place.
- Ethical Considerations: Ethical standards and oversight by Ethics Committees are essential for healthcare research. Researchers must balance GDPR requirements with ethical guidelines.
- Implementation Challenges: Researchers face challenges in identifying all research purposes in advance and in responding to data subject rights, such as access and erasure.
Conclusion
GDPR represents a major shift in data protection law, enhancing individual rights and introducing stricter compliance obligations. While it offers some flexibility for research, healthcare researchers must remain vigilant, especially regarding the handling of sensitive data. The regulation is not just a legal requirement but also an opportunity to improve data governance and ethical practices. Compliance with GDPR is crucial for all organizations involved in healthcare research, and a thorough implementation plan is recommended to meet the regulation's demands.
试读结束,高清完整版pdf/doc/ppt,请点下载