General Data Protection Regulation
In the European Union Sensitive data are regulated by the General Data Protection Regulation, or VDAR (English: General Data Protecion Regulation or GDPR ). Research projects working with for sensitive data, it is necessary to observe GDPR principles.
|
VDAR principles |
How to implement them in research projects? |
| 1 |
Legality, integrity and Transparency |
- Ensure informed consent of participants
- Clearly explain how data will be processed, used and what risks participants need to consider
- Ensure transparent conditions for data storage, sharing and access
|
| 2 |
Purpose restrictions |
- Clarify the purposes of the research and data processing before collecting personal data
- Use the data collected only for the purpose for which it was collected
- If the purpose of the data use is changed, obtain the informed consent of the participants again for the new purpose
|
| 3 |
Data minimisation |
- Only collect the personal data necessary to achieve the objectives of the study
- Use data anonymisation and pseudonymisation techniques to reduce the amount of identifiable information
|
| 4 |
Accuracy |
- Implement procedures to ensure the accuracy and updating of personal data
- Allows study participants to correct inaccurate or incomplete information
- Regularly review and update the personal data you collect
|
| 5 |
Storage restriction |
- Determine the duration of the retention of personal data in accordance with the objectives and needs of the study
- Regularly delete or anonymise personal data when they are no longer necessary for their original purpose or when the specified retention period has expired
|
| 6 |
Integrity and confidentiality |
- Implement appropriate security measures to protect personal data and prevent unauthorised access, disclosure and misuse
- Train your research team in data protection and privacy
- Implement access control and data encryption during storage and transfer
|
| 7 |
Transparency |
- Document data processing activities, legal basis, compliance with certain requirements
- Carry out a Data Protection Impact Assessment (DPA) when working with highly sensitive data
- Demonstrates compliance with GDPR principles
|