Last modified by melissargos on 2024/10/11 18:12

From version 18.1
edited by bschaffha
on 2024/10/10 13:57
Change comment: There is no comment for this version
To version 17.1
edited by bschaffha
on 2024/10/10 13:22
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -83,7 +83,7 @@
83 83  
84 84  [[image:image-20241010130312-2.png||height="398" width="401"]]
85 85  
86 -(% class="small" %)//Illustration from:** **//[[(% class="small small small small small small" %)//GDPR - Back to Basics | URM Consulting//>>url:https://www.urmconsulting.com/blog/gdpr-back-to-basics#Section-3]]
86 +(% class="small" %)//Illustration from:** **//[[(% class="small small small small small" %)//GDPR - Back to Basics | URM Consulting//>>url:https://www.urmconsulting.com/blog/gdpr-back-to-basics#Section-3]]
87 87  
88 88  
89 89  Several aspects are crucial for demonstrating GDPR compliance. Hereunder is a compliance assessment for the HIP, based on the GDPR core principles:
... ... @@ -95,7 +95,7 @@
95 95  
96 96  DPIAs*, Data Transfer Agreements (DTAs) and approved research protocols provide a legal framework and are mandated before any data transfer or data sharing, ensuring compliance with Article 28(3) regarding processor agreements (GDPR Articles 5(1)(a), 6, and 7).
97 97  
98 -(% style="color:#c0392b" %)//~*~*The HIP Data Protection Impact Assessment (DPIA) is currently under full revision and will become functional upon final approval by the CHUV DPO. Per Article 35(3)(b) of GDPR a Data Protection Impact Assessment is required whenever processing is likely to result in a high risk to the rights and freedoms of individuals and at least in the case of large-scale processing of sensitive data.//
98 +//~*~*The HIP Data Protection Impact Assessment (DPIA) is currently under full revision and will become functional upon final approval by the CHUV DPO. Per Article 35(3)(b) of GDPR a Data Protection Impact Assessment is required whenever processing is likely to result in a high risk to the rights and freedoms of individuals and at least in the case of large-scale processing of sensitive data.//
99 99  
100 100  **Fairness:** Ethical compliance is ensured by obtaining informed consent before data entry into the HIP, getting ethical approvals of projects and signing data transfer agreements (DTA or DSA) prior to data sharing. Data pseudonymisation is required before integration in the HIP, which minimises the risk of reidentification, protecting data subjects from potential harm (GDPR Article 6(1)(a)). FAIRification efforts to display metadata of datasets on the HIP in the EBRAINS Knowledge Graph are underway.
101 101