1 Data Protection and Research – Implications for a National Out-of-Hospital Cardiac Arrest Register NUI Galway Dept of General Practice Lunchtime seminar.

Slides:



Advertisements
Similar presentations
1 Enforcement Powers of National Data Protection Authorities and Experience gained of the Data Protection Directive Safe Harbour Conference Washington.
Advertisements

NIGB Legal requirements for use of personal data in research OnCore UK / NRES Training workshop Ethical Principles relating to consent for use of samples.
NATIONAL INFORMATION GOVERNANCE BOARD
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Data Protection: Health. Data Protection & Health Data Data on physical or mental health or condition or sexual life are ‘sensitive personal data’ with.
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
University Research Ethics Committee Workshop on procedure and data protection issues 30th May 2008.
The Data Protection (Jersey) Law 2005.
Data Protection.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
Data Protection and Records Management
The European Union legal framework for clinical data access: The European Union legal framework for clinical data access: potential challenges and opportunities.
Legal and ethical issues EHES Training Material. Definition of “legislation” and “ethics” and their relationship Legislation A law or legal regulation.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
National Smartcard Project Work Package 8 – Information Law Report.
Data Protection: The Law. EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection.
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Data Protection for Church of Scotland Congregations
What Does the Right to Health Mean from a Human Rights Perspective?
Data Protection in the Health Sector. Survey Results (2005) (1) Is privacy important? important very important Crime Prevention 7%91% Personal Privacy9%89%
Oviedo Convention and Its Protocols – Impact on Polish Law International Bioethics Conference Oviedo Convention in Central and Eastern European Countries.
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
Health research and the protection of personal information rights in international ethics and human rights law Colin M Harper Promoting Health Research.
Amicus Legal Consultants THE DEPLOYMENT OF SPECIAL INVESTIGATIVE MEANS IN PROACTIVE ANTI-CORRUPTION INVESTIGATIONS.
European Standards on Confidentiality and Privacy in Healthcare Dr Colin M Harper Division of Psychiatry & Neuroscience Queen’s University.
Access to Public Information in Slovenia Nataša Pirc Musar, LL.B. Commissioner for Access to Public Information The Hague – 24 th -25 th November, 2004.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Established in 1996 to enforce standards for electronic health information & enhance the security and privacy of health information.
Data Protection & FOI Data Protection: Background Human Right to Privacy Unenumerated right under Irish Constitution Explicit right under European Convention.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Data protection and compliance in context 19 November 2007 Stewart Room Partner.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Data Protection in a Workplace Context. Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection.
Human Rights Act, Privacy in the context of auditing Phil Huggins Chief Technologist, IRM PLC
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
Sharing Personal Data ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Article 19, 21and 22 chapter 111 of ICCPR Right to freedom of expression Right to Peaceful assembly Right to freedom of association.
Uses of brain imaging data: privacy and governance implications Dr. Hester Ward Medical Director, Information Services Division, (ISD) Consultant in Public.
Week 12. Lecture 2. Health Law & the EU Cross-border healthcare: patients’ rights.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Disclaimer This presentation is intended only for use by Tulane University faculty, staff, and students. No copy or use of this presentation should occur.
Ethical, legal and social aspects of public health genomics Mark Taylor, School of Law, University of Sheffield 7 th November 2014.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Privacy and ‘Big Data’: the European perspective Human Subjects’ Protections in the Digital Age: IRB, Privacy and Big Data Peter Elias, University of Warwick.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
Rights and responsibilities of providers and individuals
Data Protection: The Law
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Issues of personal data protection in scientific research
Data Protection: EU & International
General Data Protection Regulation
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
Data Protection & Human Rights
Data Protection principles
Public Privacy: juridical & ethical perspective
Presentation transcript:

1 Data Protection and Research – Implications for a National Out-of-Hospital Cardiac Arrest Register NUI Galway Dept of General Practice Lunchtime seminar 20 November Gary Davis Deputy Data Protection Commissioner

2 Presentation Outline Data Protection: Human Right to Privacy Data Protection Principles Protecting Personal Health Information Draft Guidelines on Health Research

3 Survey Results (2005) (1) Is privacy important? important very important Crime Prevention 7%91% Personal Privacy9%89% Consumer protection 12%85% Workplace equality 11%82% Ethics in public office 14%78%

4 Survey (2): Privacy most important in relation to- 1.Financial records 2.Medical Records 3.PPS Number 4.Credit Card Details 5.Telephone No 6.Home Address 7.Date of Birth 8.Marital Status

5 Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society Not absolute: other necessary Rights on a Democratic Society ( e.g. Freedom of Expression, Rights of Others)

6 Constitution Implicit Right to Personal Privacy under Article …The State guarantees in its laws to respect, and, as far as practicable, by its laws to defend and vindicate the personal rights of the citizens Court Interpretation: the right to privacy is one of the fundamental personal rights of the citizen which flow from the Christian and democratic nature of the State

7 European Human Rights Convention Explicit Right to Personal Privacy under Article 8 of European Convention for the Protection of Human Rights & Fundamental Freedoms (ECHR) ECHR now indirectly part of domestic law due to ECHR Act 2003

8 ECHR Article 8: Privacy (1) Everyone has the right to respect for his private and family life, his home and his correspondence. (2) There shall be no interference by a public authority with the exercise of this right except as in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others

9 EU/EEA Directives Directive 95/46/EC Protection of Individuals with regard to the Processing of Personal Data and on the Free Movement of such Data Directive 2002/58/EC Privacy and Electronic Communications

10 EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection Acts 1988 & 2003 EC Electronic Privacy Regulations 2003 (SI 535/2003) Corresponding Acts Good Friday Agreement Disability Act 2005

11 Presentation Outline Data Protection: Human Right to Privacy Data Protection Principles Protecting Personal Health Information Draft Guidelines on Health Research

12 Definitions: Personal Data –“Data relating to a living individual who is or can be identified either from the data or from the data in conjunction with other information that is in, or is likely to come into, the possession of the data controller “ (DP Act, Section 1) –Applies to any data that is processed (includes hosting) using any medium by a legal entity essentially. Paper, computer, network, web, phone etc. –Only relates to a living person

13 European Data Protection Rules 1.Fair obtaining & processing Consent 2.Specified purpose 3.No disclosure unless “compatible” 4.Safe and secure 5.Accurate, up-to-date 6.Relevant, not excessive 7.Retention period 8.Right of access 9.Independent Supervisory Authority

14 Restrictions on disclosure General rule – no disclosure for different purpose Exceptions made, to balance other interests of society Section 8 exceptions –Investigation of crime –Collection of taxes –Security of the State –Protect life & limb –Required by Law No general “public interest” test

15 Role of the Data Protection Commissioner Ombudsman Role: resolution of disputes between data subjects and data controllers or processors Enforcer Role: compliance by data controllers & processors Educational Role: Promotes DP rights and good practice Registration Authority: obligation on major holders of personal data to be placed on public register

16 Presentation Outline Data Protection: Human Right to Privacy Data Protection Principles Protecting Personal Health Information Draft Guidelines on Health Research

17 Data Protection & Health Data Data on physical or mental health or condition or sexual life are ‘sensitive personal data’ with special protection but some leeway for: –Processing of Data “kept for statistical or research or other scientific purposes” –Processing “necessary for medical purposes”(including medical research) and carried out by a “health professional” or someone who owes an equivalent duty of confidentiality DP and Medical Ethics mutually reinforcing

18 Presentation Outline Data Protection: Human Right to Privacy Data Protection Principles Protecting Personal Health Information Draft Guidelines on Health Research

19 Consultation on Personal Data use for Health Research Try to reach consensus on balanced approach reflecting Irish conditions Seminar November 2006 Addressed by speakers from different perspectives (HSE, public health, research) EUROSOCAP guidelines (

20 Draft Guidelines Paper Presented July 2007 (on Comments up to 21 September 11 Submissions received Final version in coming weeks

21 Draft Guidelines: Key Points Use anonymised/pseudonomised patient data wherever possible Where a health facility (e.g. hospital) anticipates research use of identifiable patient data, seek patient consent at earliest possible opportunity, backed by patient leaflet and research policy approved by ethics committee Treat identifiable personal data on “need to know” basis Recognises possibility within Acts for research to be undertaken by the Data Controller itself. Makes provision for context for seeking consent including where a person not in a position to give it.

22 Anonymisation Effectively anonymised data not subject to data protection acts – so anonymise where possible Pseudonimisation, subject to safeguards, acceptable where full anonymisation not possible

23 Guidelines Paper: Patient Consent “best practice would suggest that allowing the patient choice and providing them with information in relation to how their data is used should be the standard approach. “

24 Guidelines Paper: Patient Consent “What is being put forward here is a relatively simple model that every effort should be made to ensure that the patient knows what could happen to their data for purposes unrelated to their treatment and are given an opportunity to consent or refuse consent for such use. In this way, if any proposed use of a patient’s data for purposes unrelated to their treatment would likely come as a surprise to them, then a new and separate consent should be sought.”

25 Guidelines Paper: Patient Consent “ an informed and explicit consent [should] be sought as soon as possible after a patient presents at a health facility …… each data controller [should] consider in a thorough manner what such potential [research] uses might be and specifically capturing these in an appropriate consent supported by an informative patient leaflet Additional research initiatives, not envisaged at the time of seeking the initial consent, involving the use of patient data would need to be predicated on further specific consents going forward.”

26 Can anonymised data be used to achieve the aims of the proposed project? Yes/No? Yes – Proceed with proposed project using data anonymised by the data controller without requiring consent. No – Can pseudonymised data be used instead with appropriate safeguards? Yes/No? Yes – Proceed with proposed project ensuring that the key to a person’s identity is retained by the data controller only and not revealed to third parties. No – Patient consent is normally required. Has consent for research purposes been secured in relation to the files previously? Yes/No? Yes – Is this consent valid (specific enough) to cover this particular research proposal? Yes/No? No – Specific, informed, freely given consent must be captured from individuals by the data controller. Yes – Proceed with research project (subject to adequate safeguards being in place in relation to security etc). Once valid consent is in place, the research project can proceed (subject to adequate safeguards being in place in relation to security etc).

27 OHCAR – KEY POINTS Pilot Project limited to one HSE area Difficulties in obtaining explicit consent Largest part of data was not personal data as it related to dead persons Who is the data controller in this case? Attempt through collation of the data to provide better care to patients

28 OHCAR What about data in the private system and held by GPs? Security arrangements for both physical and systems put in place for access to the data by OHCAR project manager and personnel only Intended media campaign in relation to project

29 OHCAR From a DP perspective Methodology 1 preferred Methodology 2 –No difficulty with OHCAR gathering data from ambulance service and A+E Depts to identify surviving persons –Have to deal with reality that HSE could not be considered the Data Controller in relation to a large part of the data

30 Recommendations on Methodology 2 –Informed consent in unique circumstances of project –OHCAR to write to surviving patients outlining all relevant information in relation to the study and the safeguards in place for their privacy –21 days to raise any concerns and OHCAR to send reminder if doubt as to receipt –Any objections must be respected

31 Thank You Contact: