Last modified by melissargos on 2024/10/11 18:22

From version 27.1
edited by melissargos
on 2024/10/11 18:20
Change comment: There is no comment for this version
To version 30.1
edited by melissargos
on 2024/10/11 18:22
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -36,14 +36,12 @@
36 36  
37 37  //**Figure 1:** User Interface of the Medical Informatics Platform MIP//
38 38  
39 -​
39 +== Creation of a MIP User Account ==
40 40  
41 -== Creation of a MIP User Account ==
42 -
43 43  **Prerequisite – Step 1**: Access to the MIP requires an EBRAINS user account, which needs to be permitted and authenticated. EBRAINS user accounts are available to users with a legitimate interest (mainly research and development) from Europe and beyond.
44 44  
45 45  Request an EBRAINS user account: [[https:~~/~~/www.ebrains.eu/page/sign-up>>url:https://www.ebrains.eu/page/sign-up]]
46 -The EBRAINS user account allows users to directly access the** Public MIP ([[https:~~/~~/mip.ebrains.eu/>>url:https://mip.ebrains.eu/]]**) with no further accreditation being required.
44 +The EBRAINS user account allows users to directly access the** Public MIP ([[https:~~/~~/mip.ebrains.eu/>>url:https://mip.ebrains.eu/]]**) with no further accreditation being required.
47 47  
48 48  **Access to a specific MIP Federation – Step 2:** EBRAINS authorised Users with an active EBRAINS account can request access to a specific MIP Federation by contacting [[support@ebrains.eu>>path:mailto:support@ebrains.eu]], who will forward the specific request to the MIP Management team. Users can also get in direct contact with the MIP team via the online form on the EBRAINS website: [[https:~~/~~/www.ebrains.eu/tools/medical-informatics-platform>>url:https://www.ebrains.eu/tools/medical-informatics-platform]]
49 49  
... ... @@ -53,7 +53,6 @@
53 53  
54 54  Upon login to the MIP, users are mandated to accept the Terms of Use of the MIP. Accredited users access the MIP through a web-based interface, which will provide them with direct access to the respective federation on the MIP.
55 55  
56 -
57 57  == MIP Data Governance ==
58 58  
59 59  [[image:1728560441625-436.png]]
... ... @@ -66,7 +66,6 @@
66 66  
67 67  === //MIP and data anonymisation// ===
68 68  
69 -
70 70  **Note**: (% style="color:#27ae60" %)**The MIP is handling anonymised data.**(%%) The definition for anonymisation (//ISO standard (ISO 29100:2011)//) of personal data is the process of encrypting or removing personally identifiable data from data so that a person can no longer be directly or indirectly identified (see also **Recital 26 of the GDPR)**. As soon a person cannot be re-identified the data is no longer considered personal data and the GDPR does not apply for further use.
71 71  
72 72  However, processing personal data **for the purpose of anonymisation** is still processing that must have a **legal basis under Article 6 of GDPR**. The anonymisation process is defined as “**further processing**” and this processing must be compliant with the principle of purpose limitation. The process of data anonymisation can be used to improve data protection compliance, e.g., as part of the “**privacy by design**” strategy, with the goal to improve the protection of the processed data; or as part of the “**data minimisation**” strategy, where data can be anonymised and used without the risk of harming the data subjects.
... ... @@ -114,7 +114,6 @@
114 114  
115 115  Several aspects are crucial for demonstrating GDPR compliance. Hereunder is a compliance assessment based on the GDPR core principles:
116 116  
117 -
118 118  (% style="color:#27ae60" %)**Lawfulness, Fairness, and Transparency (Article 5 GDPR)**
119 119  
120 120  **Lawfulness and Fairness:** In alignment with GDPR requirements for lawful processing (Article 6(1)(a)), the MIP legal contracts with Data Providers require that data processing is based on informed consent obtained from data subjects. It requires users to accept the EBRAINS General Terms of Use, adhering to all applicable laws and regulations, including GDPR. Data Transfer Agreements (DTAs) and Data Sharing Agreements (DSAs) provide a legal framework and are mandated before any data transfer or data sharing, ensuring compliance with Article 28(3) regarding processor agreements (GDPR Articles 5(1)(a), 6, and 7). Strict authentication and authorisation procedures are in place, to only provide access to accredited users. Data anonymisation is required before integration in the MIP, which minimises the risk of reidentification, protecting data subjects from potential harm (GDPR Article 6(1)(a)). An additional built in privacy threshold restricts data analysis to receiving aggregate results of at least 10 participant records.
XWiki.XWikiRights[3]
Allow/Deny
... ... @@ -1,0 +1,1 @@
1 +Allow
Levels
... ... @@ -1,0 +1,1 @@
1 +view
Users
... ... @@ -1,0 +1,1 @@
1 +XWiki.XWikiGuest
XWiki.XWikiRights[4]
Allow/Deny
... ... @@ -1,0 +1,1 @@
1 +Allow
Groups
... ... @@ -1,0 +1,1 @@
1 +XWiki.XWikiAllGroup
Levels
... ... @@ -1,0 +1,1 @@
1 +view