Skip to main page content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Access keys NCBI Homepage MyNCBI Homepage Main Content Main Navigation
. 2020 Apr 17;8(4):e14604.
doi: 10.2196/14604.

Impact of the European General Data Protection Regulation (GDPR) on Health Data Management in a European Union Candidate Country: A Case Study of Serbia

Affiliations

Impact of the European General Data Protection Regulation (GDPR) on Health Data Management in a European Union Candidate Country: A Case Study of Serbia

Branko Marovic et al. JMIR Med Inform. .

Abstract

As of May 2018, all relevant institutions within member countries of the European Economic Area are required to comply with the European General Data Protection Regulation (GDPR) or face significant fines. This regulation has also had a notable effect on the European Union (EU) candidate countries, which are undergoing the process of harmonizing their legislature with the EU as part of the accession process. The Republic of Serbia is an example of such a candidate country, and its 2018 Personal Data Protection Act mirrors the majority of provisions in the GDPR. This paper presents the impact of the GDPR on health data management and Serbia's capability to conduct international health data research projects. Data protection incidents reported in Serbia are explored to identify common underlying causes using a novel taxonomy of contributing factors across aspects and health system levels. The GDPR has an extraterritorial application for the non-EU data controllers who process the data of EU citizens and residents, which mainly affects private practices used by medical tourists from the EU, public health care institutions frequented by foreigners, as well as expatriates, dual citizens, tourists, and other visitors. Serbia generally does not have well-established procedures to support international research collaborations around its health data. For smaller projects, contractual arrangements can be made with health data providers and their ethics committees. Even then, organizations that have not previously participated in similar ventures may require approval or support from health authorities. Extensive studies that involve multisite data typically require the support of central health system institutions and relevant research data aggregators or electronic health record vendors. The lack of a framework for preparation, anonymization, and assurance of privacy preservation forces researchers to rely heavily on local expertise and support. Given the current limitation and potential issues with the legislation, it remains to be seen whether the move toward the GDPR will be beneficial for the Serbian health system, medical research, protection of personal data and privacy rights, and research capacity. Although significant progress has been made so far, a strategic approach is needed at the national level to address insufficient resources in the area of data protection and develop the personal data protection environment further. This will also require a targeted educational effort among health workers and decision makers, aiming to improve awareness and develop skills and knowledge necessary for the workforce.

Keywords: data sharing; ethical issues; health care systems; information disclosure; international aspects; legal aspects; medical tourists; patient data privacy; policy compliance; privacy act; public policy.

PubMed Disclaimer

Conflict of interest statement

Conflicts of Interest: None declared.

References

    1. The European Parliament and the Council of the European Union EUR-Lex. [2019-05-03]. General Data Protection Regulation (EU) 2016/679 (GDPR) https://eur-lex.europa.eu/eli/reg/2016/679/oj .
    1. Birnbaum D, Gretsinger K, Antonio MG, Loewen E, Lacroix P. Revisiting public health informatics: patient privacy concerns. Int J Health Gov. 2018;23(2):149–59. doi: 10.1108/IJHG-11-2017-0058. - DOI
    1. The Commissioner For Public Information And Protection of Personal Data. [2019-05-03]. https://www.poverenik.rs/
    1. The Commissioner For Public Information And Protection of Personal Data. 2019. [2019-05-01]. Report on the implementation of the Free Access to Information of Public Importance Act and Personal Data Protection Act in 2018 https://www.poverenik.rs/images/stories/dokumentacija-nova/izvestajiPove... .
    1. Personal Data Protection Agency in Bosnia and Herzegovina. 2019. [2019-05-01]. Report on Personal Data Protection in Bosnia and Herzegovina for 2018 http://azlp.ba/publikacije/Archive.aspx?pageIndex=1&langTag=en-US&fromDa... .

LinkOut - more resources