The GDPR and the research exemption: considerations on the necessary safeguards for research biobanks

The GDPR and the research exemption: considerations on the necessary safeguards for research biobanks
复制标题

DOI:
10.1038/s41431-019-0386-5
复制
发表时间:
2019-08-01
影响因子:
5.2
通讯作者:
Mascalzoni, Deborah
Mascalzoni, Deborah
中科院分区:
生物学2区
文献类型:
--
作者:
Staunton, Ciara;Slokenberga, Santa;Mascalzoni, Deborah

文献摘要

被引文献

相似文献

《通用数据保护条例》(GDPR)于2018年5月生效。为个人的个人数据提供高水平保护的愿望有可能对科学研究造成相当大的限制,这与整个欧盟的各种研究传统背道而驰。因此,沿着一系列精心概述的数据主体权利,GDPR提供了一个两级框架,以便在涉及科学研究时能够克减这些权利。首先,直接援引GDPR的规定,条件是必须采取包括“技术和组织措施”在内的保障措施;其次,通过成员国法律。尽管这些克减以科学研究的名义是允许的,但考虑到各种与研究有关的软法律的工具、国际条约和其他法律的文书中规定的生物库的伦理要求和既定标准,这些克减可能同时具有挑战性。在这篇文章中,我们回顾了这些软法律的工具,国际条约和其他法律的文书,规范健康研究数据的使用。我们报告了此次审查的结果,并分析了GDPR和GDPR第89条中包含的权利与这些文书的关系。还对这些文书进行了审查,以便就在实施任何克减时应遵循的可能保障措施提供指导。最后,我们将对GDPR下的减损限制和适当的保障措施提供一些评论,以确保遵守标准的道德要求。
The General Data Protection Regulation (GDPR) came into force in May 2018. The aspiration of providing for a high level of protection to individuals' personal data risked placing considerable constraints on scientific research, which was contrary to various research traditions across the EU. Therefore, along with the set of carefully outlined data subjects' rights, the GDPR provides for a two-level framework to enable derogations from these rights when scientific research is concerned. First, by directly invoking provisions of the GDPR on a condition that safeguards that must include 'technical and organisational measures' are in place and second, through the Member State law. Although these derogations are allowed in the name of scientific research, they can simultaneously be challenging in light of the ethical requirements and wellestablished standards in biobanking that have been set forth in various research-related soft legal tools, international treaties and other legal instruments. In this article, we review such soft legal tools, international treaties and other legal instruments that regulate the use of health research data. We report on the results of this review, and analyse the rights contained within the GDPR and Article 89 of the GDPR vis-a-vis these instruments. These instruments were also reviewed to provide guidance on possible safeguards that should be followed when implementing any derogations. To conclude, we will offer some commentary on limits of the derogations under the GDPR and appropriate safeguards to ensure compliance with standard ethical requirements.