Uses of brain imaging data: privacy and governance implications Dr. Hester Ward Medical Director, Information Services Division, (ISD) Consultant in Public.

Slides:



Advertisements
Similar presentations
Introduction to Information Governance (IG)
Advertisements

TEAM 4 Case Study Mauritius: Mrs Nandini Kissoon-Luckputtya
Archive, Records Management and Museum Services Confidentiality, Personal Data and the Data Protection Act 1998 Alan R Bell Records Manager and Information.
The Data Protection (Jersey) Law 2005.
Getting data sharing right for every child
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Data Protection & Freedom of Information The Practical Implications of Data Protection and Freedom of Information Caroline Dominey Data Protection Officer.
1 Pertemuan 7 Points of Exposure Matakuliah:A0334/Pengendalian Lingkungan Online Tahun: 2005 Versi: 1/1.
University of Sunderland Professionalism and Personal Skills Unit 11 Professionalism and Personal Skills Computer Legislation.
Duncan Woodhouse – Assistant Registrar for Information Security, Risk Management and Business Continuity Helen Wollerton – Administrative Officer (Legal.
A European View of Privacy Protection John Woulds Director of Operations UK Data Protection Commissioner National Conference on Privacy, Technology & Criminal.
Information Commissioner’s Office: data protection Judith Jones Senior Policy Officer Strategic Liaison – public security 16 November 2011.
DATA PROTECTION AND PATIENT CONFIDENTIALITY IN RESEARCH Nic Drew Data Protection Manager University Hospital of Wales   
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Data Protection for Church of Scotland Congregations
CENTRAL SCOTLAND POLICE Data Protection & Information Security Stuart Macfarlane Information Governance Unit Police Service of Scotland.
The Information Commissioner’s Office David Evans.
Implementation of Security and Confidentiality in GP Practices.
Care.Data an ICO Update EMIS National User Group Conference East Midlands Conference Centre Nottingham 3 rd October 2013 Lynne Shackley Lead Policy Officer.
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
Research Paper Presentation Software Engineering in agent systems.
The Data Protection Act 1998 The Eight Principles.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
GEOG3025 Confidentiality and social implications.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
What is personal data? Personal data is data about an individual which they consider to be private.
The Data Protection Act - Confidentiality and Associated Problems.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Local Government Reform and Compliance with the DPA Ken Macdonald Assistant Commissioner (Scotland & Northern Ireland) Information Commissioner’s Office.
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
Data Protection Property Management Conference. What’s it got to do with me ? As a member of a management committee responsible for Guiding property you.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Computing, Ethics & The Law. The Law Copyright, Designs and Patents Act (1988) Computer Misuse Act (1990) Data Protection Act (1998) (8 Main Principles)
Data Protection and research Rachael Maguire Records Manager.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
Session 11 Data protection. 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4:
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
The Data Protection Act 1998
The Data Protection Act 1998
Data Protection and Confidentiality
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Level 2 Diploma in Customer Service
Issues of personal data protection in scientific research
Data Protection : A Practical Guide
Privacy Impact Assessments (PIAs)
Data Protection The Current Regime
General Data Protection Regulation
Data Protection Act.
The Data Protection Act 1998
GDPR Overview GDPR - General Data Protection Regulations
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection principles
Data Protection and You
General Data Protection Regulations 2018
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Presentation transcript:

Uses of brain imaging data: privacy and governance implications Dr. Hester Ward Medical Director, Information Services Division, (ISD) Consultant in Public Health medicine SINAPSE, Glasgow, 2010

Outline Information Services Division (ISD) Privacy Information governance Implications of use of brain imaging data Scottish perspective legal NHS governing bodies

Information Services Division (ISD) National Services Scotland (NSS) –special Health Board National organisation for health information and statistics Health service: patient and activity data – Scottish Morbidity Records (SMRs) Required to operate to highest information governance standards – regulated by UK Statistics Authority

Privacy UK Information Commissioner’s Office (ICO) UK’s independent authority set up to uphold information rights in the public interest Promotes- openness by public bodies data privacy for individuals Scottish Regional Office Ken Macdonald, the Assistant Commissioner for Scotland main focus data protection Scottish Information Commissioner Kevin Dunion regulates Freedom of Information (Scotland) Act

Privacy “ the integrity of the individual…..encompasses many aspects of the individual’s social needs” Consider the privacy of :- – personal information (or data/ information privacy) – the person (or bodily privacy) – personal communications – personal behaviour Personal behaviour- eg. sexual preferences & habits, political/ trade union activities, religious practices – relates to private & public spaces – ? thoughts

Privacy Growing awareness by public High profile losses

Privacy Growing awareness by public High profile losses Media worthy- privacy is a “risk” Risk to individual - rights, personal info (loss, damage, misuse, abuse) organisation - reputational, funding, staff, legal

Governance Information Governance? “A framework that enables information to be handled in a confidential and secure manner to appropriate ethical, legal and quality standards”

Laws & protections European Convention on Human Rights Human Rights Act 1998 Data Protection Act 1998 Common law duty of confidentiality Freedom of Information (Scotland) Act 2002 Professional guidance- BMA/ GMC etc. NHS Scotland guidance Caldicott Guardians

Data Protection Act- principles 1.Processed fairly and lawfully 2.Obtained only for one or more specified and lawful purposes; not be further processed in a manner incompatible with that purpose “function creep” 3.Adequate, relevant and not excessive 4.Accurate and up to date 5.Kept no longer than necessary 6.Processed according to rights of the subject 7.Safeguard the data against unauthorised or unlawful use of the data 8.Not to transfer outside EEC unless adequate levels of protection

Data Protection Act 1989 Data shall be processed fairly and lawfully and, in particular, shall not be processed unless – 1.at least one of the conditions in Schedule 2 is met, and 2. in the case of sensitive personal (including health & mental health) data, at least one of the conditions in Schedule 3 is also met. Schedule 2 Consent Vital interests of subject Public interests, including administration of justice …. Schedule 3 Explicit consent Vital interests of subject or others Necessary for medical purposes, including research Necessary for legal proceedings….

Information Commissioner, 2002 “ the creation of a national system of electronic health records is likely to raise fresh questions about who is responsible for those records and who should be allowed access to them”

Implications for wider societal uses Many potential uses of brain imaging data some unknown Same principles:- rights of individuals use of data for ‘society’

Implications for wider societal uses Issues: ● Ethical ● Social ● Legal Validity of data?- are brain images measuring what we think they are?- thoughts, preferences, prejudices, deception etc Use in law, by employers, by insurers?

Implications for wider societal uses Issues: Consent? Are brain images identifiable? Does Data Protection Act cover social characteristics (eg. individual preferences, deception, social evaluation)?- not physical or mental health Incidental findings?

Implications for wider societal uses Issues: Do all individuals have the right to privacy of their own thoughts? Validity (diagnostic/ predictive) of brain imaging data? Thank you!