Ensuring General Data Protection Regulation Compliance and Security in a Clinical Data Warehouse From a University Hospital: Implementation Study
- PMID: 40244890
- PMCID: PMC12020775
- DOI: 10.2196/63754
Ensuring General Data Protection Regulation Compliance and Security in a Clinical Data Warehouse From a University Hospital: Implementation Study
Abstract
Background: The European Union's General Data Protection Regulation (GDPR) has profoundly influenced health data management, with significant implications for clinical data warehouses (CDWs). In 2021, France pioneered a national framework for GDPR-compliant CDW implementation, established by its data protection authority (Commission Nationale de l'Informatique et des Libertés). This framework provides detailed guidelines for health care institutions, offering a unique opportunity to assess practical GDPR implementation in health data management.
Objective: This study evaluates the real-world applicability of France's CDW framework through its implementation at a major university hospital. It identifies practical challenges for its implementation by health institutions and proposes adaptations relevant to regulatory authorities in order to facilitate research in secondary use data domains.
Methods: A systematic assessment was conducted in May 2023 at the University Hospital of Rennes, which manages data for over 2 million patients through the eHOP CDW system. The evaluation examined 116 criteria across 13 categories using a dual-assessment approach validated by information security and data protection officers. Compliance was rated as met, unmet, or not applicable, with criteria classified as software-related (n=25) or institution-related (n=91).
Results: Software-related criteria showed 60% (n=15) compliance, with 28% (n=7) noncompliant or partially compliant and 12% (n=3) not applicable. Institution-related criteria achieved 72% (n=28) compliance for security requirements. Key challenges included managing genetic data, implementing automated archiving, and controlling data exports. The findings revealed effective privacy protection measures but also highlighted areas requiring regulatory adjustments to better support research.
Conclusions: This first empirical assessment of a national CDW compliance framework offers valuable insights for health care institutions implementing GDPR requirements. While the framework establishes robust privacy protections, certain provisions may overly constrain research activities. The study identifies opportunities for framework evolution, balancing data protection with research imperatives.
Keywords: France; French; applicability; clinical data warehouse; compliance; data hub; experiential analysis; legislation; operational challenge; personal data; personal data protection; privacy; security; university hospitals.
© Christine Riou, Mohamed El Azzouzi, Anne Hespel, Emeric Guillou, Gouenou Coatrieux, Marc Cuggia. Originally published in JMIR Medical Informatics (https://medinform.jmir.org).
Conflict of interest statement
Similar articles
-
Synthetic Data and PETs for Privacy-Compliant mHealth Within the EHDS: A Viewpoint Analysis.Stud Health Technol Inform. 2025 May 15;327:1011-1012. doi: 10.3233/SHTI250531. Stud Health Technol Inform. 2025. PMID: 40380638
-
Federated Machine Learning, Privacy-Enhancing Technologies, and Data Protection Laws in Medical Research: Scoping Review.J Med Internet Res. 2023 Mar 30;25:e41588. doi: 10.2196/41588. J Med Internet Res. 2023. PMID: 36995759 Free PMC article.
-
Medical Information Protection in Internet Hospital Apps in China: Scale Development and Content Analysis.JMIR Mhealth Uhealth. 2024 Jun 21;12:e55061. doi: 10.2196/55061. JMIR Mhealth Uhealth. 2024. PMID: 38904994 Free PMC article.
-
Data Governance in Healthcare AI: Navigating the EU AI Act's Requirements.Stud Health Technol Inform. 2025 Apr 8;323:66-70. doi: 10.3233/SHTI250050. Stud Health Technol Inform. 2025. PMID: 40200447
-
The significance of general data protection regulation in the compliant data contribution to the European Society of Thoracic Surgeons database.Eur J Cardiothorac Surg. 2023 Sep 7;64(3):ezad289. doi: 10.1093/ejcts/ezad289. Eur J Cardiothorac Surg. 2023. PMID: 37589648 Review.
References
-
- National Academy of Medicine. The Learning Health System Series . In: Health Data Sharing to Support Better Outcomes: Building a Foundation of Stakeholder Trust. Carman KL, Grossmann C, Zirkle M, Adams I, Siddiqi S, Ahmed M, editors. National Academies Press (US); 2021. - PubMed
-
- Arrêté du 29 novembre 2019 portant approbation d’un avenant à la convention constitutive du groupement d’intérêt public "Institut national des données de santé" portant création du groupement d’intérêt public "Plateforme des données de santé" [Web page in French] Légifrance. [19-06-2023]. https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000039433105/ URL. Accessed.
-
- Décret n° 2021-848 du 29 juin 2021 relatif au traitement de données à caractère personnel Dénommé “système national des données de santé” [Web page in French] Légifrance. [19-06-2023]. https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000043715694 URL. Accessed.
MeSH terms
LinkOut - more resources
Full Text Sources
Miscellaneous