Published February 11, 2022 | Version 1.0

Privacy Framework for (regional) FAIR data

  • 1. drs. CIPP/e, CIPM

Description

Readme: Privacy Framework for (regional)  FAIR data (Health-RI poster)

Problem to be solved:

Protecting the privacy of the European citizens (GDPR ) is an important topic in relation to the re-use of data ambition of institutes. However there is a tension in relation to common interest perspectives such as scientific research, big data insights (e.g. A.I. prediction modelling) and Personal Medicine medicine. At this moment the status is that common interest (e.g. patient benefits from scientific research) cannot take advantage because of the different GDPR interpretations within institutions.  The aim of privacy by design is to create a win-win situation for all stakeholders, as mentioned in  the GDPR informer 7 key articles. point 4.

Proposal Privacy framework open for discussion:

To address this problem, the coordinators of   two LCRDM RDM working groups, namely Erik Flikkenschild (secure data linking /SIG-VDK) and Marlon Domingus (Privacy wg)  presented a new Privacy Framework at the Health-RI conference, January 2020. Trust in privacy can be gained in the consistency of measures: GDPR, ethics, technology and institutional agreements thus working multidisciplinary together. They founded three major issues that are blocking data driven innovation in the Netherlands:

  1. The absence of ethical / legal agreement with respect to artificial intelligence, Personalised medicine and open science ambitions;
  2. Trust in anonymity of data is impossible as soon as you start harvesting different data sources;
  3. The absence of a national privacy by design view on the IT systems causing precious point to point solutions between institutions.

Adopting (discuss) a Privacy Framework could be the first step forwards. In the proposed Health-RI poster Privacy Framework for (regional) FAIR data, the three aspects are addressed in the following way:

The 5 highlights of the proposed Privacy Framework

  1. Anonymity is protected by  including 4 access control protection layers in the design (addressing the A in FAIR);
  2. The personal health train (PHT video ) must have all lights green within  a  truth table pattern to access personal data. As a result of this (e.g.) the A.I. pattern oblige data scientists (bringing the algorithm to the data) secure data access can only be addressed via a technology anonymization layer;
  3. Absolute boundary condition is that secondary used data with personal data is always minimal protected, therefore data is always pseudomised at the source;
  4. First step (getting started) in design is to define the institutional view on the positive sum of a social perspective, gaining the proper balance between common interest (e.g. the patient) against the individual privacy aspects;  
  5. First step in implementation is think big, act small, learn and improve. Recommendation is therefore to start  the implementation  process involving at least 3 institutes (e.g. working together at a regional level) choosing low fruit project proposals.  

 

Files

A0Poster healthri final.pdf

Files (888.0 kB)

Name Size Download all
md5:2f45305e6c524444b597e06673c4aee9
888.0 kB Preview Download