Changes for page Onboarding to the Human Intracerebral EEG Platform HIP
Last modified by melissargos on 2024/10/11 18:12
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -83,7 +83,7 @@ 83 83 84 84 [[image:image-20241010130312-2.png||height="398" width="401"]] 85 85 86 -(% class="small" %)//Illustration from:** **//[[(% class="small small small small small small" %)//GDPR - Back to Basics | URM Consulting//>>url:https://www.urmconsulting.com/blog/gdpr-back-to-basics#Section-3]]86 +(% class="small" %)//Illustration from:** **//[[(% class="small small small small" %)//GDPR - Back to Basics | URM Consulting//>>url:https://www.urmconsulting.com/blog/gdpr-back-to-basics#Section-3]] 87 87 88 88 89 89 Several aspects are crucial for demonstrating GDPR compliance. Hereunder is a compliance assessment for the HIP, based on the GDPR core principles: ... ... @@ -95,7 +95,7 @@ 95 95 96 96 DPIAs*, Data Transfer Agreements (DTAs) and approved research protocols provide a legal framework and are mandated before any data transfer or data sharing, ensuring compliance with Article 28(3) regarding processor agreements (GDPR Articles 5(1)(a), 6, and 7). 97 97 98 - (% style="color:#c0392b" %)//~*~*The HIP Data Protection Impact Assessment (DPIA) is currently under full revision and will become functional upon final approval by the CHUV DPO. Per Article 35(3)(b) of GDPR a Data Protection Impact Assessment is required whenever processing is likely to result in a high risk to the rights and freedoms of individuals and at least in the case of large-scale processing of sensitive data.//98 +//~*~*The HIP Data Protection Impact Assessment (DPIA) is currently under full revision and will become functional upon final approval by the CHUV DPO. Per Article 35(3)(b) of GDPR a Data Protection Impact Assessment is required whenever processing is likely to result in a high risk to the rights and freedoms of individuals and at least in the case of large-scale processing of sensitive data.// 99 99 100 100 **Fairness:** Ethical compliance is ensured by obtaining informed consent before data entry into the HIP, getting ethical approvals of projects and signing data transfer agreements (DTA or DSA) prior to data sharing. Data pseudonymisation is required before integration in the HIP, which minimises the risk of reidentification, protecting data subjects from potential harm (GDPR Article 6(1)(a)). FAIRification efforts to display metadata of datasets on the HIP in the EBRAINS Knowledge Graph are underway. 101 101 ... ... @@ -133,7 +133,7 @@ 133 133 134 134 Patients' rights to access, rectify, and erase their data are respected. The responsibility lies with the Data controllers, who can remove their data from private and collaborative spaces, ensuring compliance with GDPR rights (GDPR Articles 15, 16, 17, and 18). 135 135 136 -* (% style="color:#27ae60" %)**Data Transfers (Articles 44-50)**136 +* **Data Transfers (Articles 44-50)** 137 137 138 138 The HIP ensures that any data transfers comply with GDPR’s requirements for international data transfers. This is achieved using DTAs and DSAs, ensuring that data transferred across borders is protected under equivalent data protection standards. 139 139 )))