Purpose definition as a crucial step for determining the legal basis under the GDPR: implications for scientific research

被引:5
作者
Becker, Regina [1 ]
Chokoshvili, Davit [1 ]
Thorogood, Adrian [2 ]
Dove, Edward S. [3 ]
Molnar-Gabor, Fruzsina [4 ]
Ziaka, Alexandra [5 ,6 ]
Tzortzatou-Nanopoulou, Olga [7 ]
Comande, Giovanni [8 ]
机构
[1] Luxembourg Natl Data Serv, L-4362 Esch Sur Alzette, Luxembourg
[2] Terry Fox Res Inst, Vancouver, BC V5Z 1L3, Canada
[3] Univ Edinburgh, Sch Law, Edinburgh EH8 9YL, Scotland
[4] Heidelberg Univ, Fac Law, D-69117 Heidelberg, Germany
[5] Tilburg Univ, Tilburg Inst Law Technol & Soc TILT, NL-5037 DB Tilburg, Netherlands
[6] MPLegal, Athens 15231, Greece
[7] Acad Athens, Legal Dept, Biomed Res Fdn, Athens 11527, Greece
[8] St Anna Sch Adv Studies, I-56127 Pisa, Italy
基金
欧盟地平线“2020”;
关键词
data protection; GDPR; lawfulness; legal basis; purpose specification; scientific research;
D O I
10.1093/jlb/lsae001
中图分类号
B82 [伦理学(道德学)];
学科分类号
摘要
The General Data Protection Regulation (GDPR) of the European Union, which became applicable in 2018, contains a new accountability principle. Under this principle, controllers (ie parties determining the purposes and the means of the processing of personal data) are responsible for ensuring and demonstrating the overall compliance with the GDPR. However, interpretive uncertainties of the GDPR mean that controllers must exercise considerable judgement in designing and implementing an appropriate compliance strategy, making GDPR compliance both complex and resource-intensive. In this article, we provide conceptual clarity around GDPR compliance with respect to one core aspect of the law: the determination and relevance of the purpose of personal data processing. We derive from the GDPR's text concrete requirements for purpose specification, which we subsequently apply to the area of secondary use of personal data for scientific research. We offer guidance for correctly specifying purposes of data processing under different research scenarios. To illustrate the practical necessity of purpose specification for GDPR compliance, we then show how our proposed approach can enable controllers to meet their compliance obligations, using the example of the overarching GDPR principle of lawfulness to highlight the relevance of purpose specification for the identification of a suitable legal basis.
引用
收藏
页数:30
相关论文
共 37 条
[11]   Impossible, unknowable, accountable: Dramas and dilemmas of data law [J].
Cool, Alison .
SOCIAL STUDIES OF SCIENCE, 2019, 49 (04) :503-530
[12]   Biobanking in health care: evolution and future directions [J].
Coppola, Luigi ;
Cianflone, Alessandra ;
Grimaldi, Anna Maria ;
Incoronato, Mariarosaria ;
Bevilacqua, Paolo ;
Messina, Francesco ;
Baselice, Simona ;
Soricelli, Andrea ;
Mirabelli, Peppino ;
Salvatore, Marco .
JOURNAL OF TRANSLATIONAL MEDICINE, 2019, 17 (1)
[13]  
Court of Justice of the European Union (Third Chamber), 2019, TK v Asociatia de Proprietari bloc M5A-ScaraA
[14]  
digital-strategy, The European 1+ Million Genomes Initiative
[15]  
European Data Protection Board, 2019, Opinion 3/2019 concerning the questions and answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection Regulation (GDPR) (art. 70.1.b)
[16]  
European Parliament and the Council of the European Union, 2022, REG EU 2022 868 EUR
[17]  
Finck M., 2021, Technol. Regul, V2021, P44, DOI [10.26116/techreg.2021.004, DOI 10.26116/TECHREG.2021.004, 10.71265/z7r0t122, DOI 10.71265/Z7R0T122]
[18]   On Compliance of Cookie Purposes with the Purpose Specification Principle [J].
Fouad, Imane ;
Santos, Cristiana ;
Al Kassar, Feras ;
Bielova, Nataliia ;
Calzavara, Stefano .
2020 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2020), 2020, :326-333
[19]  
Garante per la Protezione dei dati Personali, 2022, Parere Ai Sensi Del Ai Sensi Dell'art. 110 Del Codice e Dell'art. 36 Del Regolamento
[20]  
Hansen J., 2021, Assessment of the EU Member States rules on health data in the light of GDPR