Reconciling the biomedical data commons and the GDPR: three lessons from the EUCAN ELSI collaboratory
- PMID: 37322132
- PMCID: PMC10267538
- DOI: 10.1038/s41431-023-01403-y
Reconciling the biomedical data commons and the GDPR: three lessons from the EUCAN ELSI collaboratory
Abstract
The coming-into-force of the EU General Data Protection Regulation (GDPR) is a watershed moment in the legal recognition of enforceable rights to informational self-determination. The rapid evolution of legal requirements applicable to data use, however, has the potential to outstrip the capabilities of networks of biomedical data users to respond to the shifting norms. It can also delegitimate established institutional bodies that are responsible for assessing and authorising the downstream use of data, including research ethics committees and institutional data custodians. These burdens are especially pronounced for clinical and research networks that are of transnational scale, because the legal compliance burden for outbound international data transfers from the EEA is especially high. Legislatures, courts, and regulators in the EU should therefore implement the following three legal changes. First, the responsibilities of particular actors in a data sharing network should be delimited through the contractual allocation of responsibilities between collaborators. Second, the use of data through secure data processing environments should not trigger the international transfer provisions of the GDPR. Third, the use of federated data analysis methodologies that do not provide analysis nodes or downstream users access to identifiable personal data as part of the outputs of those analyses should not be considered circumstances of joint controllership, nor lead to the users of non-identifiable data to be considered controllers or processors. These small clarifications of, or modifications to, the GDPR would facilitate the exchange of biomedical data amongst clinicians and researchers.
© 2023. The Author(s).
Conflict of interest statement
The authors declare no competing interests.
Similar articles
-
The GDPR and the research exemption: considerations on the necessary safeguards for research biobanks.Eur J Hum Genet. 2019 Aug;27(8):1159-1167. doi: 10.1038/s41431-019-0386-5. Epub 2019 Apr 17. Eur J Hum Genet. 2019. PMID: 30996335 Free PMC article.
-
Impact of the European General Data Protection Regulation (GDPR) on Health Data Management in a European Union Candidate Country: A Case Study of Serbia.JMIR Med Inform. 2020 Apr 17;8(4):e14604. doi: 10.2196/14604. JMIR Med Inform. 2020. PMID: 32301736 Free PMC article.
-
Data Sharing Under the General Data Protection Regulation: Time to Harmonize Law and Research Ethics?Hypertension. 2021 Apr;77(4):1029-1035. doi: 10.1161/HYPERTENSIONAHA.120.16340. Epub 2021 Feb 15. Hypertension. 2021. PMID: 33583200 Free PMC article. Review.
-
Bridging the European Data Sharing Divide in Genomic Science.J Med Internet Res. 2022 Oct 19;24(10):e37236. doi: 10.2196/37236. J Med Internet Res. 2022. PMID: 36260387 Free PMC article.
-
Federated Machine Learning, Privacy-Enhancing Technologies, and Data Protection Laws in Medical Research: Scoping Review.J Med Internet Res. 2023 Mar 30;25:e41588. doi: 10.2196/41588. J Med Internet Res. 2023. PMID: 36995759 Free PMC article.
Cited by
-
Ensuring General Data Protection Regulation Compliance and Security in a Clinical Data Warehouse From a University Hospital: Implementation Study.JMIR Med Inform. 2025 Apr 17;13:e63754. doi: 10.2196/63754. JMIR Med Inform. 2025. PMID: 40244890 Free PMC article.
-
Data sharing ethics toolkit: The Human Cell Atlas.Nat Commun. 2024 Nov 20;15(1):9901. doi: 10.1038/s41467-024-54300-3. Nat Commun. 2024. PMID: 39567529 Free PMC article. Review.
-
Managing genetic information sharing at family and population level.Eur J Hum Genet. 2024 Jan;32(1):1-2. doi: 10.1038/s41431-023-01514-6. Eur J Hum Genet. 2024. PMID: 38185746 Free PMC article. No abstract available.
-
Challenges and solutions to system-wide use of precision oncology as the standard of care paradigm.Camb Prism Precis Med. 2024 Mar 26;2:e4. doi: 10.1017/pcm.2024.1. eCollection 2024. Camb Prism Precis Med. 2024. PMID: 38699518 Free PMC article. Review.
-
A call to action to scale up research and clinical genomic data sharing.Nat Rev Genet. 2025 Feb;26(2):141-147. doi: 10.1038/s41576-024-00776-0. Epub 2024 Oct 7. Nat Rev Genet. 2025. PMID: 39375561 Review.
References
-
- Svantesson, DJB (2021). International data transfers post schrems–moving towards solutions. Gdańskie Studia Prawnicze, 4 (52)/2021), 21–37.
-
- Wouters B, Shaw D, Sun C, Ippel L, van Soest J, van den Berg, et al. Putting the GDPR into practice: difficulties and uncertainties experienced in the conduct of big data health research. Eur Data Prot Law Rev (EDPL) 2021;7:206–16. doi: 10.21552/edpl/2021/2/9. - DOI
MeSH terms
Grants and funding
LinkOut - more resources
Full Text Sources