SlideShare a Scribd company logo
An itinerary for FAIR and
privacy respecting data-driven
innovation and research
National eScience Symposium 2017
October 12, Amsterdam
Marlon Domingus
“Nowadays people know the privacy risk of everything
and the value of nothing.”
variation on an Oscar Wilde theme
Itinerary
1. On the EU General Data Protection
Regulation
2. On Governance of Re-Use of Data
3. Privacy in the context of Research
and Big Data Research
4. Privacy and the Internet of Things
5. Next Steps
2
The GDPR Elephant Is In The Room
Image sources: Top, Bottom left side, Bottom right side.
Will you ignore it
and allow it to become
your weakness?
Or will you adapt to it
and make it your strength
to safeguard privacy?
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
September 2017
General Data Protection Regulation
Disclaimer
EU General Data Protection Regulation
What, Who, How, When
What & How
25 May 2018October 2017 15 December 2017
Who
University: provide necessary
general conditions to enable
researchers to comply; policy,
guidelines, infrastructure and
skilled and available research
support staff.
Dean: provide additional
necessary discipline specific
conditions to enable researchers
to comply; policy, guidelines,
infrastructure and skilled and
available research support staff.
Faculty: follow privacy principles
& use the privacy enabling
conditions (policy, guidelines,
infrastructure and skilled and
available research support staff).
Does Privacy Threaten Research
and / or
Does Research Threaten Privacy?
• The EU General Data Protection Regulation (GDPR) is principle based
• intended to facilitate the responsible free floating of data within the EU to
strengthen the internal market, especially by public - private driven innovation.
• The Right to Privacy is not an absolute right, but a fundamental right amongst
other rights.
• Conclusion: no business as usual, but also no disruption of research.
• GDPR is a game changer, and we have to shift to the new paradigm and
govern research in a new way.
5
Command & Control
• Fixed norm
• Actor
• Sanction
• Example: METC
Reflexive regulation
• Situated norm
• Multiple Actors
• Learn
• Example: intervision
Two Models of Governance
Source: Prof. Dr. Antoinette de Bont, Erasmus School of Health Policy & Management (ESHPM): The Governance of re-use of data. Summerschool 9-12 July 2017 @ Erasmus MC.
Reflexive Governance of Re-Use of Data
Source: Prof. Dr. Antoinette de Bont, Erasmus School of Health Policy & Management (ESHPM): The Governance of re-use of data. Summerschool 9-12 July 2017 @ Erasmus MC.
Set up research aimed to reduce margins of uncertainty;
Set up research to detect vulnerabilities in the environment;
Institute long‐term monitoring systems and facilities for early warnings
of possible harmful effects.
Invite stakeholders to contribute to strategic discussions about the
research you do
Privacy Before Research:
Research Design
Result: Data Management Plan
DPIA
Risks, Appropriate Organisational
and Technical Measures, Ethical
Self Assessment
2
Data Management Plan
See for DPIA: pg 14. Article 29 Data Protection Working Party: Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is “likely to result in a
high risk” for the purposes of Regulation 2016/679. Adopted on 4 April 2017. See: http://ec.europa.eu/newsroom/document.cfm?doc_id=44137
Privacy Principles
1
1. The EU General Data Protection Regulation:
Article 5 GDPR: Principles Relating to Processing of Personal Data
Source: http://gdprcoalition.ie/infographics/
2. The EU General Data Protection Regulation:
Privacy Before, During and After Research
Created in collaboration with the GDPR Coalition
Privacy Before Research:
Privacy by Design Strategy (‘traditional’)
Source: ENISA report (2015): Privacy By Design In Big Data. Online: https://www.enisa.europa.eu/publications/big-data-protection/at_download/fullReport
11
Privacy Before Research:
Privacy by Design Strategy (Big Data)
Source: ENISA report (2015): Privacy By Design In Big Data. Online: https://www.enisa.europa.eu/publications/big-data-protection/at_download/fullReport
12
Privacy Before Research:
Privacy Enhancing Technologies
in Big Data
Anonymization in big data (and beyond)
Utility and privacy
Attack models and disclosure risk
Anonymization privacy models
Anonymization privacy models and big data
Anonymization methods
Some current weaknesses of anonymization
Centralized vs decentralized anonymization for big data
Other specific challenges of anonymization in big data
Challenges and future research for anonymization in big data
Encryption techniques in big data
Database encryption
Encrypted search
Security and accountability controls
Granular access control
Privacy policy enforcement
Accountability and audit mechanisms
Data provenance
Transparency and access
Consent, ownership and control
Consent mechanisms
Privacy preferences and sticky policies
Personal data stores
Source: ENISA report (2015): Privacy By Design In Big Data. Online: https://www.enisa.europa.eu/publications/big-data-protection/at_download/fullReport
13
WP Art 29: Big Data Concerns:
14
- the sheer scale of data collection, tracking and profiling, also taking into
account the variety and detail of the data collected and the fact that
data are often combined from many different sources;
- the security of data, with levels of protection shown to be lagging
behind the expansion in volume;
- transparency: unless they are provided with sufficient information,
individuals will be subject to decisions that they do not understand and
have no control over;
- inaccuracy, discrimination, exclusion and economic imbalance;
- increased possibilities of government surveillance.
Source: Article 29 Data Protection Working Party. Opinion 03/2013 on purpose limitation. Adopted on 2 April 2013.
Online: http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2013/wp203_en.pdf
Balancing the legitimate interests
of the researcher
and the privacy rights of the individual
Source: Prof. Dr. Gloria González Fuster: Recent jurisprudence of the European Court of Human Rights and the Court of Justice of the European Union. Brussels Privacy
Hub, VUB Brussel, June 30 2017.
independent authority
individual’s rights
legitimate interests
15
GDPR
Member States’ Implementation Legislation
Codes of Conduct
Discipline Specific
Good Practices
of the researcher
of the data subject
Balancing: Four Steps
1. Legitimate interests of controller or 3rd party
• freedom of expression
• direct marketing and other forms of advertisement
• enforcement of legal claims
• prevention of fraud, misuse of services, or money laundering
• physical safety, security, IT and network security
• whistle-blowing schemes
2. Impact on data subject
Actual and potential repercussions
• Nature of the data
• How the data are processed
• Reasonable expectations data subject
• Nature of controller vis-à-vis data subject
3. Make provisional balance
“Necessary”
• Least intrusive means
• Reasonably effective
• Balance of interests
4. Safeguards
Measures to ensure that the data cannot be used to take decisions or other actions with regard to individuals.
• anonymisation techniques, aggregation of data
• privacy-enhancing technologies, privacy by design
• increased transparency
• general and unconditional right to opt-out
Source: Article 29 Data Protection Working Party. Opinion 06/2014 on the "Notion of legitimate interests of the data controller under Article 7 of Directive 95/46/EC". Adopted on 9
April 2014. Online: http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2014/wp217_en.pdf
16
Privacy in the Context of Research:
9 Generic Research Scenarios
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
principal investigator academia
Research Scenarios and the General Data Protection Regulation:
1. Individual Academic Research
Based on Existing Data
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
adequate organisational
and technical measures
accessing and collecting data
existing data
existing observed data
online / sensor data
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
Research Scenarios and the General Data Protection Regulation:
2. Academic Research by an International Research Group
Based on Existing Data
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
adequate organisational
and technical measures
accessing and collecting data
existing data
existing observed data
online / sensor data
accessing data
academic researcher
academic researcher
academic researcher
sharing data for analysing, archiving
and publishing purposes
analysing data
archiving data
publishing data
adequate organisational
and technical measures
principal investigator academia
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
principal investigator academia
Research Scenarios and the General Data Protection Regulation:
3. Individual Academic Research
Based on Generated Data from Data Subjects
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
- informed consent
- public interest
generating new data
data subjects
data subject's rights:
• to be informed
• of access
• to rectification
• to erasure
• to restriction of processing
• to objection of processing
• to data portability
• to withdraw consent
• to lodge a complaint to a supervisory authority
• right not to be subject to a decision
based solely on automated processing
adequate organisational
and technical measures
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
Research Scenarios and the General Data Protection Regulation:
4. Academic Research by an International Research Group
Based on Generated Data from Data Subjects
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
- informed consent
- public interest
generating new data
data subjects
adequate organisational
and technical measures
accessing data
academic researcher
academic researcher
academic researcher
sharing data for analysing, archiving
and publishing purposes
analysing data
archiving data
publishing data
adequate organisational
and technical measures
principal investigator academia
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
principal investigator academia
Research Scenarios and the General Data Protection Regulation:
5. Academic Research by an International Research Group
Based on Generated Data from Data Subjects Combined With Existing Data
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
- informed consent
- public interest
generating new data
data subjects
adequate organisational
and technical measures
accessing data
academic researcher
academic researcher
academic researcher
sharing data for analysing, archiving
and publishing purposes
analysing data
archiving data
publishing data
adequate organisational
and technical measures
accessing and collecting data
existing data
existing observed data
online / sensor data
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
Research Scenarios and the General Data Protection Regulation:
6. Academic Research by International Public - Private Research Group
Based on Generated Data from Data Subjects Combined With Existing Data
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
- informed consent
- public interest
generating new data
data subjects
adequate organisational
and technical measures
accessing data
academic researcher
academic researcher
academic researcher
sharing data for analysing, archiving
and publishing purposes
analysing data
archiving data
publishing data
adequate organisational
and technical measures
accessing and collecting data
existing data
existing observed data
online / sensor data
non academic
research partner
non academic
research partner
principal investigator academia
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
principal investigator academia
Research Scenarios and the General Data Protection Regulation:
7. Academic Research by International Public - Private Research Group
Based on Generated Data from Data Subjects Combined With Existing Data and Licensed Data
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
- informed consent
- public interest
generating new data
data subjects
adequate organisational
and technical measures
accessing data
academic researcher
academic researcher
academic researcher
sharing data for analysing, archiving
and publishing purposes
analysing data
archiving data
publishing data
adequate organisational
and technical measures
accessing and collecting data
existing data
existing observed data
online / sensor data
non academic
research partner
non academic
research partner
licensed data
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
Research Scenarios and the General Data Protection Regulation:
8. Academic Research by International Public - Private Research Group & Third Parties
Based on Generated Data from Data Subjects Combined With Existing Data and Commercial Data
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
- informed consent
- public interest
generating new data
data subjects
adequate organisational
and technical measures
accessing data
academic researcher
academic researcher
academic researcher
sharing data for analysing, archiving
and publishing purposes
analysing data
archiving data
publishing data
adequate organisational
and technical measures
accessing and collecting data
existing data
existing observed data
online / sensor data
non academic
research partner
non academic
research partner
licensed data
non academic
service provider
non academic
service provider
principal investigator academia
storing data
analysing data
deleting data archiving data for follow-on research
own research
publicly publishing data
principal investigator academia
Research Scenarios and the General Data Protection Regulation:
9. Academic Big Data Research by International Public - Private Research Group & Third Parties
Based on Generated Data from Data Subjects Combined With Existing Data and Commercial Data
Marlon Domingus
Erasmus University Rotterdam
marlon.domingus@eur.nl
August 24 2017
- informed consent
- public interest
generating new data
data subjects
adequate organisational
and technical measures
accessing data
academic researcher
academic researcher
academic researcher
sharing data for analysing, archiving
and publishing purposes
analysing data
archiving data
publishing data
adequate organisational
and technical measures
accessing and collecting data
existing data
existing observed data
online / sensor data
non academic
research partner
non academic
research partner
licensed data
non academic
service provider
non academic
service provider
HPC
juli 2017
Reflexive regulation
• Situated norm (in context)
• Multiple Actors
• Learn
Reprise: Two Models of Governance
Focus Points:
• Nature of the Data
• Nature of the Consortium
• Nature of the Dataflow
• Appropriate Measures
Private, Shared and Public - Boundary Transitions
29
Source: Personal website Andrew Treloar. Online: http://andrew.treloar.net/research/diagrams/index.shtml
Cross Border Data Transfers
Source: Prof. Christopher Kuner, International Transfers of Personal Data Post-GDPR. Brussels Privacy Hub, VUB Brussel, June 29 2017.
30
Privacy and the Internet of Things
31
Source: Internet of Things Architecture, pg 101, 102: http://iotforum.org/wp-content/uploads/2014/09/D1.5-20130715-VERYFINAL.pdf
Privacy and the Internet of Things
Source: Internet of Things Architecture, pg 101, 102: http://iotforum.org/wp-content/uploads/2014/09/D1.5-20130715-VERYFINAL.pdf
32
The subject must be able to choose sharing or not sharing information with someone else;
The subject must be able to fully control the mechanism used to ensure their privacy;
The subject shall be able to decide for which purpose the information will be used;
The subject shall be informed whenever information is used and by whom;
During interactions between a subject and an IoT system, only strictly needed information
shall be disclosed about the subject, and pseudonyms, secondary identity, or assertions
(certified properties of the end-user) shall be used whenever possible;
It shall not be possible to infer the subject‘s identity by aggregating/reasoning over information
available at various sources;
Information gained for a specific purpose shall not be used for another purpose. E.g., the
bank issuing a credit card should not use a given client‘s purchase information (logged so to
keep track of that client‘s account) to send him advertising on goods similar to his purchaces.
Privacy and the Internet of Things
Source: Internet of Things Architecture, pg 101, 102: http://iotforum.org/wp-content/uploads/2014/09/D1.5-20130715-VERYFINAL.pdf
33
The subject must be able to choose sharing or not sharing information with someone else;
The subject must be able to fully control the mechanism used to ensure their privacy;
The subject shall be able to decide for which purpose the information will be used;
The subject shall be informed whenever information is used and by whom;
During interactions between a subject and an IoT system, only strictly needed information
shall be disclosed about the subject, and pseudonyms, secondary identity, or assertions
(certified properties of the end-user) shall be used whenever possible;
It shall not be possible to infer the subject‘s identity by aggregating/reasoning over information
available at various sources;
Information gained for a specific purpose shall not be used for another purpose. E.g., the
bank issuing a credit card should not use a given client‘s purchase information (logged so to
keep track of that client‘s account) to send him advertising on goods similar to his purchaces.
What we don’t want; Data Breaches 2017:
Source: Information is Beautiful: Data Breaches (public), bit.ly/bigdatabreaches
34
Next Steps:
Privacy Maturity Model
Source:LCRDM.https://www1.edugroepen.nl/sites/RDM_platform/RDM_Blog/Lists/Posts/Post.aspx?ID=12
Privacy Awareness: Infographics
Source: EUR Research Matters website. Online: https://www.eur.nl/researchmatters/research_data_management/services/rdm_legal_services/
36
Questions?
drs. Marlon Domingus
Research Services
coordinator Community Research Data Management
T +31 10 4088006
E researchsupport@eur.nl
W https://www.eur.nl/researchmatters/research_data_management/ (services and templates)
Stay in touch via: https://www.linkedin.com/in/domingus/
37

More Related Content

What's hot

CINECA webinar slides: Making cohort data FAIR
CINECA webinar slides: Making cohort data FAIRCINECA webinar slides: Making cohort data FAIR
CINECA webinar slides: Making cohort data FAIR
CINECAProject
 
Open Science - Global Perspectives/Simon Hodson
Open Science - Global Perspectives/Simon HodsonOpen Science - Global Perspectives/Simon Hodson
Open Science - Global Perspectives/Simon Hodson
Academy of Science of South Africa (ASSAf)
 
Winning Horizon 2020 with Open Science
Winning Horizon 2020 with Open ScienceWinning Horizon 2020 with Open Science
Winning Horizon 2020 with Open Science
Martin Donnelly
 
20160523 23 Research Data Things
20160523 23 Research Data Things20160523 23 Research Data Things
20160523 23 Research Data Things
Katina Toufexis
 
CINECA webinar slides: Open science through fair health data networks dream o...
CINECA webinar slides: Open science through fair health data networks dream o...CINECA webinar slides: Open science through fair health data networks dream o...
CINECA webinar slides: Open science through fair health data networks dream o...
CINECAProject
 
20160719 23 Research Data Things
20160719 23 Research Data Things20160719 23 Research Data Things
20160719 23 Research Data Things
Katina Toufexis
 
Open science as roadmap to better data science research
Open science as roadmap to better data science researchOpen science as roadmap to better data science research
Open science as roadmap to better data science research
Beth Plale
 
Open Science Globally: Some Developments/Dr Simon Hodson
Open Science Globally: Some Developments/Dr Simon HodsonOpen Science Globally: Some Developments/Dr Simon Hodson
Open Science Globally: Some Developments/Dr Simon Hodson
African Open Science Platform
 
Tijerina-RDA-NISO-Task Groups-sept11
Tijerina-RDA-NISO-Task Groups-sept11Tijerina-RDA-NISO-Task Groups-sept11
Tijerina-RDA-NISO-Task Groups-sept11
National Information Standards Organization (NISO)
 
Preparing Research Data for Sharing
Preparing Research Data for SharingPreparing Research Data for Sharing
Preparing Research Data for Sharing
London School of Hygiene and Tropical Medicine
 
Paolo Budroni at COAR Annual Meeting
Paolo Budroni at COAR Annual MeetingPaolo Budroni at COAR Annual Meeting
Paolo Budroni at COAR Annual Meeting
LEARN Project
 
Open Science: What, why, how?
Open Science: What, why, how? Open Science: What, why, how?
Open Science: What, why, how?
Biblioteca de la Universitat Jaume I
 
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
ARDC
 
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
The Petrie-Flom Center for Health Law Policy, Biotechnology, and Bioethics
 
Open Access Week 2017: Life Sciences and Open Sciences - worfkflows and tools
Open Access Week 2017: Life Sciences and Open Sciences - worfkflows and toolsOpen Access Week 2017: Life Sciences and Open Sciences - worfkflows and tools
Open Access Week 2017: Life Sciences and Open Sciences - worfkflows and tools
OpenAIRE
 
ANDS health and medical data webinar 23 May 2017. Ethics, Legal issues and Da...
ANDS health and medical data webinar 23 May 2017. Ethics, Legal issues and Da...ANDS health and medical data webinar 23 May 2017. Ethics, Legal issues and Da...
ANDS health and medical data webinar 23 May 2017. Ethics, Legal issues and Da...
ARDC
 
State of the Art Informatics for Research Reproducibility, Reliability, and...
 State of the Art  Informatics for Research Reproducibility, Reliability, and... State of the Art  Informatics for Research Reproducibility, Reliability, and...
State of the Art Informatics for Research Reproducibility, Reliability, and...
Micah Altman
 
Research data policy
Research data policyResearch data policy
Research data policy
Sarah Jones
 
Privacy protecting fitness trackers
Privacy protecting fitness trackersPrivacy protecting fitness trackers
Privacy protecting fitness trackers
iwhhu
 
Barbara Evans, "Big Data and the Meaning of Individual Autonomy in a Crowd"
Barbara Evans, "Big Data and the Meaning of Individual Autonomy in a Crowd"Barbara Evans, "Big Data and the Meaning of Individual Autonomy in a Crowd"
Barbara Evans, "Big Data and the Meaning of Individual Autonomy in a Crowd"
The Petrie-Flom Center for Health Law Policy, Biotechnology, and Bioethics
 

What's hot (20)

CINECA webinar slides: Making cohort data FAIR
CINECA webinar slides: Making cohort data FAIRCINECA webinar slides: Making cohort data FAIR
CINECA webinar slides: Making cohort data FAIR
 
Open Science - Global Perspectives/Simon Hodson
Open Science - Global Perspectives/Simon HodsonOpen Science - Global Perspectives/Simon Hodson
Open Science - Global Perspectives/Simon Hodson
 
Winning Horizon 2020 with Open Science
Winning Horizon 2020 with Open ScienceWinning Horizon 2020 with Open Science
Winning Horizon 2020 with Open Science
 
20160523 23 Research Data Things
20160523 23 Research Data Things20160523 23 Research Data Things
20160523 23 Research Data Things
 
CINECA webinar slides: Open science through fair health data networks dream o...
CINECA webinar slides: Open science through fair health data networks dream o...CINECA webinar slides: Open science through fair health data networks dream o...
CINECA webinar slides: Open science through fair health data networks dream o...
 
20160719 23 Research Data Things
20160719 23 Research Data Things20160719 23 Research Data Things
20160719 23 Research Data Things
 
Open science as roadmap to better data science research
Open science as roadmap to better data science researchOpen science as roadmap to better data science research
Open science as roadmap to better data science research
 
Open Science Globally: Some Developments/Dr Simon Hodson
Open Science Globally: Some Developments/Dr Simon HodsonOpen Science Globally: Some Developments/Dr Simon Hodson
Open Science Globally: Some Developments/Dr Simon Hodson
 
Tijerina-RDA-NISO-Task Groups-sept11
Tijerina-RDA-NISO-Task Groups-sept11Tijerina-RDA-NISO-Task Groups-sept11
Tijerina-RDA-NISO-Task Groups-sept11
 
Preparing Research Data for Sharing
Preparing Research Data for SharingPreparing Research Data for Sharing
Preparing Research Data for Sharing
 
Paolo Budroni at COAR Annual Meeting
Paolo Budroni at COAR Annual MeetingPaolo Budroni at COAR Annual Meeting
Paolo Budroni at COAR Annual Meeting
 
Open Science: What, why, how?
Open Science: What, why, how? Open Science: What, why, how?
Open Science: What, why, how?
 
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
 
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
 
Open Access Week 2017: Life Sciences and Open Sciences - worfkflows and tools
Open Access Week 2017: Life Sciences and Open Sciences - worfkflows and toolsOpen Access Week 2017: Life Sciences and Open Sciences - worfkflows and tools
Open Access Week 2017: Life Sciences and Open Sciences - worfkflows and tools
 
ANDS health and medical data webinar 23 May 2017. Ethics, Legal issues and Da...
ANDS health and medical data webinar 23 May 2017. Ethics, Legal issues and Da...ANDS health and medical data webinar 23 May 2017. Ethics, Legal issues and Da...
ANDS health and medical data webinar 23 May 2017. Ethics, Legal issues and Da...
 
State of the Art Informatics for Research Reproducibility, Reliability, and...
 State of the Art  Informatics for Research Reproducibility, Reliability, and... State of the Art  Informatics for Research Reproducibility, Reliability, and...
State of the Art Informatics for Research Reproducibility, Reliability, and...
 
Research data policy
Research data policyResearch data policy
Research data policy
 
Privacy protecting fitness trackers
Privacy protecting fitness trackersPrivacy protecting fitness trackers
Privacy protecting fitness trackers
 
Barbara Evans, "Big Data and the Meaning of Individual Autonomy in a Crowd"
Barbara Evans, "Big Data and the Meaning of Individual Autonomy in a Crowd"Barbara Evans, "Big Data and the Meaning of Individual Autonomy in a Crowd"
Barbara Evans, "Big Data and the Meaning of Individual Autonomy in a Crowd"
 

Similar to An itinerary for FAIR and privacy respecting data-driven innovation and research

Privacy and Data Protection in Research
Privacy and Data Protection in ResearchPrivacy and Data Protection in Research
Privacy and Data Protection in Research
Marlon Domingus
 
Open Science in Research Libraries: Research, Research Integrity and Legal As...
Open Science in Research Libraries: Research, Research Integrity and Legal As...Open Science in Research Libraries: Research, Research Integrity and Legal As...
Open Science in Research Libraries: Research, Research Integrity and Legal As...
Marlon Domingus
 
Legal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research dataLegal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research data
OpenAIRE
 
Christopher Millard Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard   Legally Compliant Use Of Personal Data In E Social ScienceChristopher Millard   Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard
 
Ethics, Research & Society
Ethics, Research & SocietyEthics, Research & Society
Ethics, Research & Society
Guillaume Dumas
 
LEARN Webinar
LEARN WebinarLEARN Webinar
LEARN Webinar
LEARN Project
 
Privacy experience in Plone and other open source CMS
Privacy experience in Plone and other open source CMSPrivacy experience in Plone and other open source CMS
Privacy experience in Plone and other open source CMS
Interaktiv
 
Gobinda Chowdhury
Gobinda ChowdhuryGobinda Chowdhury
Gobinda Chowdhury
maredata
 
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral ResearchersAdjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Travis Greene
 
Using Open Science to advance science - advancing open data
Using Open Science to advance science - advancing open data Using Open Science to advance science - advancing open data
Using Open Science to advance science - advancing open data
Robert Oostenveld
 
Data science and privacy regulation
Data science and privacy regulationData science and privacy regulation
Data science and privacy regulation
blogzilla
 
Legal issues in dealing with Research Data - new OpenAIRE guides for research...
Legal issues in dealing with Research Data - new OpenAIRE guides for research...Legal issues in dealing with Research Data - new OpenAIRE guides for research...
Legal issues in dealing with Research Data - new OpenAIRE guides for research...
OpenAIRE
 
Open Data - strategies for research data management & impact of best practices
Open Data - strategies for research data management & impact of best practicesOpen Data - strategies for research data management & impact of best practices
Open Data - strategies for research data management & impact of best practices
Martin Donnelly
 
Responsible research: professionalism and integrity. The practical, legal and...
Responsible research: professionalism and integrity. The practical, legal and...Responsible research: professionalism and integrity. The practical, legal and...
Responsible research: professionalism and integrity. The practical, legal and...
Marlon Domingus
 
Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights Management
Sabrina Kirrane
 
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM PolicyLEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
LEARN Project
 
Brussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACKBrussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACK
Trilateral Research
 
Cyber Summit 2016: Privacy Issues in Big Data Sharing and Reuse
Cyber Summit 2016: Privacy Issues in Big Data Sharing and ReuseCyber Summit 2016: Privacy Issues in Big Data Sharing and Reuse
Cyber Summit 2016: Privacy Issues in Big Data Sharing and Reuse
Cybera Inc.
 
PLA Legal aspects of Big Data analytics final
PLA Legal aspects of Big Data analytics finalPLA Legal aspects of Big Data analytics final
PLA Legal aspects of Big Data analytics final
Sofie van der Meulen
 
Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics'
Axon Lawyers
 

Similar to An itinerary for FAIR and privacy respecting data-driven innovation and research (20)

Privacy and Data Protection in Research
Privacy and Data Protection in ResearchPrivacy and Data Protection in Research
Privacy and Data Protection in Research
 
Open Science in Research Libraries: Research, Research Integrity and Legal As...
Open Science in Research Libraries: Research, Research Integrity and Legal As...Open Science in Research Libraries: Research, Research Integrity and Legal As...
Open Science in Research Libraries: Research, Research Integrity and Legal As...
 
Legal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research dataLegal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research data
 
Christopher Millard Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard   Legally Compliant Use Of Personal Data In E Social ScienceChristopher Millard   Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard Legally Compliant Use Of Personal Data In E Social Science
 
Ethics, Research & Society
Ethics, Research & SocietyEthics, Research & Society
Ethics, Research & Society
 
LEARN Webinar
LEARN WebinarLEARN Webinar
LEARN Webinar
 
Privacy experience in Plone and other open source CMS
Privacy experience in Plone and other open source CMSPrivacy experience in Plone and other open source CMS
Privacy experience in Plone and other open source CMS
 
Gobinda Chowdhury
Gobinda ChowdhuryGobinda Chowdhury
Gobinda Chowdhury
 
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral ResearchersAdjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
 
Using Open Science to advance science - advancing open data
Using Open Science to advance science - advancing open data Using Open Science to advance science - advancing open data
Using Open Science to advance science - advancing open data
 
Data science and privacy regulation
Data science and privacy regulationData science and privacy regulation
Data science and privacy regulation
 
Legal issues in dealing with Research Data - new OpenAIRE guides for research...
Legal issues in dealing with Research Data - new OpenAIRE guides for research...Legal issues in dealing with Research Data - new OpenAIRE guides for research...
Legal issues in dealing with Research Data - new OpenAIRE guides for research...
 
Open Data - strategies for research data management & impact of best practices
Open Data - strategies for research data management & impact of best practicesOpen Data - strategies for research data management & impact of best practices
Open Data - strategies for research data management & impact of best practices
 
Responsible research: professionalism and integrity. The practical, legal and...
Responsible research: professionalism and integrity. The practical, legal and...Responsible research: professionalism and integrity. The practical, legal and...
Responsible research: professionalism and integrity. The practical, legal and...
 
Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights Management
 
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM PolicyLEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
 
Brussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACKBrussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACK
 
Cyber Summit 2016: Privacy Issues in Big Data Sharing and Reuse
Cyber Summit 2016: Privacy Issues in Big Data Sharing and ReuseCyber Summit 2016: Privacy Issues in Big Data Sharing and Reuse
Cyber Summit 2016: Privacy Issues in Big Data Sharing and Reuse
 
PLA Legal aspects of Big Data analytics final
PLA Legal aspects of Big Data analytics finalPLA Legal aspects of Big Data analytics final
PLA Legal aspects of Big Data analytics final
 
Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics'
 

More from Marlon Domingus

Safeguarding privacy in research design
Safeguarding privacy in research designSafeguarding privacy in research design
Safeguarding privacy in research design
Marlon Domingus
 
The GDPR perspectives: Philosophy
The GDPR perspectives: PhilosophyThe GDPR perspectives: Philosophy
The GDPR perspectives: Philosophy
Marlon Domingus
 
VSNU gedragscode voor gebruik van persoonsgegevens in wetenschappelijk onderzoek
VSNU gedragscode voor gebruik van persoonsgegevens in wetenschappelijk onderzoekVSNU gedragscode voor gebruik van persoonsgegevens in wetenschappelijk onderzoek
VSNU gedragscode voor gebruik van persoonsgegevens in wetenschappelijk onderzoek
Marlon Domingus
 
Research Support @ Erasmus University Rotterdam
Research Support @ Erasmus University RotterdamResearch Support @ Erasmus University Rotterdam
Research Support @ Erasmus University Rotterdam
Marlon Domingus
 
Towards Privacy by Design. Key issues to unlock science.
Towards Privacy by Design. Key issues to unlock science.Towards Privacy by Design. Key issues to unlock science.
Towards Privacy by Design. Key issues to unlock science.
Marlon Domingus
 
Masterclass Research Support
Masterclass Research SupportMasterclass Research Support
Masterclass Research Support
Marlon Domingus
 
Finding the Law for Sharing Data in Academia
Finding the Law for Sharing Data in AcademiaFinding the Law for Sharing Data in Academia
Finding the Law for Sharing Data in Academia
Marlon Domingus
 

More from Marlon Domingus (7)

Safeguarding privacy in research design
Safeguarding privacy in research designSafeguarding privacy in research design
Safeguarding privacy in research design
 
The GDPR perspectives: Philosophy
The GDPR perspectives: PhilosophyThe GDPR perspectives: Philosophy
The GDPR perspectives: Philosophy
 
VSNU gedragscode voor gebruik van persoonsgegevens in wetenschappelijk onderzoek
VSNU gedragscode voor gebruik van persoonsgegevens in wetenschappelijk onderzoekVSNU gedragscode voor gebruik van persoonsgegevens in wetenschappelijk onderzoek
VSNU gedragscode voor gebruik van persoonsgegevens in wetenschappelijk onderzoek
 
Research Support @ Erasmus University Rotterdam
Research Support @ Erasmus University RotterdamResearch Support @ Erasmus University Rotterdam
Research Support @ Erasmus University Rotterdam
 
Towards Privacy by Design. Key issues to unlock science.
Towards Privacy by Design. Key issues to unlock science.Towards Privacy by Design. Key issues to unlock science.
Towards Privacy by Design. Key issues to unlock science.
 
Masterclass Research Support
Masterclass Research SupportMasterclass Research Support
Masterclass Research Support
 
Finding the Law for Sharing Data in Academia
Finding the Law for Sharing Data in AcademiaFinding the Law for Sharing Data in Academia
Finding the Law for Sharing Data in Academia
 

Recently uploaded

Sustainable Land Management - Climate Smart Agriculture
Sustainable Land Management - Climate Smart AgricultureSustainable Land Management - Climate Smart Agriculture
Sustainable Land Management - Climate Smart Agriculture
International Food Policy Research Institute- South Asia Office
 
Microbiology of Central Nervous System INFECTIONS.pdf
Microbiology of Central Nervous System INFECTIONS.pdfMicrobiology of Central Nervous System INFECTIONS.pdf
Microbiology of Central Nervous System INFECTIONS.pdf
sammy700571
 
11.1 Role of physical biological in deterioration of grains.pdf
11.1 Role of physical biological in deterioration of grains.pdf11.1 Role of physical biological in deterioration of grains.pdf
11.1 Role of physical biological in deterioration of grains.pdf
PirithiRaju
 
Clinical periodontology and implant dentistry 2003.pdf
Clinical periodontology and implant dentistry 2003.pdfClinical periodontology and implant dentistry 2003.pdf
Clinical periodontology and implant dentistry 2003.pdf
RAYMUNDONAVARROCORON
 
ESA/ACT Science Coffee: Diego Blas - Gravitational wave detection with orbita...
ESA/ACT Science Coffee: Diego Blas - Gravitational wave detection with orbita...ESA/ACT Science Coffee: Diego Blas - Gravitational wave detection with orbita...
ESA/ACT Science Coffee: Diego Blas - Gravitational wave detection with orbita...
Advanced-Concepts-Team
 
Authoring a personal GPT for your research and practice: How we created the Q...
Authoring a personal GPT for your research and practice: How we created the Q...Authoring a personal GPT for your research and practice: How we created the Q...
Authoring a personal GPT for your research and practice: How we created the Q...
Leonel Morgado
 
Physiology of Nervous System presentation.pptx
Physiology of Nervous System presentation.pptxPhysiology of Nervous System presentation.pptx
Physiology of Nervous System presentation.pptx
fatima132662
 
Summary Of transcription and Translation.pdf
Summary Of transcription and Translation.pdfSummary Of transcription and Translation.pdf
Summary Of transcription and Translation.pdf
vadgavevedant86
 
Direct Seeded Rice - Climate Smart Agriculture
Direct Seeded Rice - Climate Smart AgricultureDirect Seeded Rice - Climate Smart Agriculture
Direct Seeded Rice - Climate Smart Agriculture
International Food Policy Research Institute- South Asia Office
 
Describing and Interpreting an Immersive Learning Case with the Immersion Cub...
Describing and Interpreting an Immersive Learning Case with the Immersion Cub...Describing and Interpreting an Immersive Learning Case with the Immersion Cub...
Describing and Interpreting an Immersive Learning Case with the Immersion Cub...
Leonel Morgado
 
Signatures of wave erosion in Titan’s coasts
Signatures of wave erosion in Titan’s coastsSignatures of wave erosion in Titan’s coasts
Signatures of wave erosion in Titan’s coasts
Sérgio Sacani
 
Mechanisms and Applications of Antiviral Neutralizing Antibodies - Creative B...
Mechanisms and Applications of Antiviral Neutralizing Antibodies - Creative B...Mechanisms and Applications of Antiviral Neutralizing Antibodies - Creative B...
Mechanisms and Applications of Antiviral Neutralizing Antibodies - Creative B...
Creative-Biolabs
 
Sexuality - Issues, Attitude and Behaviour - Applied Social Psychology - Psyc...
Sexuality - Issues, Attitude and Behaviour - Applied Social Psychology - Psyc...Sexuality - Issues, Attitude and Behaviour - Applied Social Psychology - Psyc...
Sexuality - Issues, Attitude and Behaviour - Applied Social Psychology - Psyc...
PsychoTech Services
 
(June 12, 2024) Webinar: Development of PET theranostics targeting the molecu...
(June 12, 2024) Webinar: Development of PET theranostics targeting the molecu...(June 12, 2024) Webinar: Development of PET theranostics targeting the molecu...
(June 12, 2024) Webinar: Development of PET theranostics targeting the molecu...
Scintica Instrumentation
 
gastroretentive drug delivery system-PPT.pptx
gastroretentive drug delivery system-PPT.pptxgastroretentive drug delivery system-PPT.pptx
gastroretentive drug delivery system-PPT.pptx
Shekar Boddu
 
Alternate Wetting and Drying - Climate Smart Agriculture
Alternate Wetting and Drying - Climate Smart AgricultureAlternate Wetting and Drying - Climate Smart Agriculture
Alternate Wetting and Drying - Climate Smart Agriculture
International Food Policy Research Institute- South Asia Office
 
fermented food science of sauerkraut.pptx
fermented food science of sauerkraut.pptxfermented food science of sauerkraut.pptx
fermented food science of sauerkraut.pptx
ananya23nair
 
AJAY KUMAR NIET GreNo Guava Project File.pdf
AJAY KUMAR NIET GreNo Guava Project File.pdfAJAY KUMAR NIET GreNo Guava Project File.pdf
AJAY KUMAR NIET GreNo Guava Project File.pdf
AJAY KUMAR
 
Juaristi, Jon. - El canon espanol. El legado de la cultura española a la civi...
Juaristi, Jon. - El canon espanol. El legado de la cultura española a la civi...Juaristi, Jon. - El canon espanol. El legado de la cultura española a la civi...
Juaristi, Jon. - El canon espanol. El legado de la cultura española a la civi...
frank0071
 
Farming systems analysis: what have we learnt?.pptx
Farming systems analysis: what have we learnt?.pptxFarming systems analysis: what have we learnt?.pptx
Farming systems analysis: what have we learnt?.pptx
Frédéric Baudron
 

Recently uploaded (20)

Sustainable Land Management - Climate Smart Agriculture
Sustainable Land Management - Climate Smart AgricultureSustainable Land Management - Climate Smart Agriculture
Sustainable Land Management - Climate Smart Agriculture
 
Microbiology of Central Nervous System INFECTIONS.pdf
Microbiology of Central Nervous System INFECTIONS.pdfMicrobiology of Central Nervous System INFECTIONS.pdf
Microbiology of Central Nervous System INFECTIONS.pdf
 
11.1 Role of physical biological in deterioration of grains.pdf
11.1 Role of physical biological in deterioration of grains.pdf11.1 Role of physical biological in deterioration of grains.pdf
11.1 Role of physical biological in deterioration of grains.pdf
 
Clinical periodontology and implant dentistry 2003.pdf
Clinical periodontology and implant dentistry 2003.pdfClinical periodontology and implant dentistry 2003.pdf
Clinical periodontology and implant dentistry 2003.pdf
 
ESA/ACT Science Coffee: Diego Blas - Gravitational wave detection with orbita...
ESA/ACT Science Coffee: Diego Blas - Gravitational wave detection with orbita...ESA/ACT Science Coffee: Diego Blas - Gravitational wave detection with orbita...
ESA/ACT Science Coffee: Diego Blas - Gravitational wave detection with orbita...
 
Authoring a personal GPT for your research and practice: How we created the Q...
Authoring a personal GPT for your research and practice: How we created the Q...Authoring a personal GPT for your research and practice: How we created the Q...
Authoring a personal GPT for your research and practice: How we created the Q...
 
Physiology of Nervous System presentation.pptx
Physiology of Nervous System presentation.pptxPhysiology of Nervous System presentation.pptx
Physiology of Nervous System presentation.pptx
 
Summary Of transcription and Translation.pdf
Summary Of transcription and Translation.pdfSummary Of transcription and Translation.pdf
Summary Of transcription and Translation.pdf
 
Direct Seeded Rice - Climate Smart Agriculture
Direct Seeded Rice - Climate Smart AgricultureDirect Seeded Rice - Climate Smart Agriculture
Direct Seeded Rice - Climate Smart Agriculture
 
Describing and Interpreting an Immersive Learning Case with the Immersion Cub...
Describing and Interpreting an Immersive Learning Case with the Immersion Cub...Describing and Interpreting an Immersive Learning Case with the Immersion Cub...
Describing and Interpreting an Immersive Learning Case with the Immersion Cub...
 
Signatures of wave erosion in Titan’s coasts
Signatures of wave erosion in Titan’s coastsSignatures of wave erosion in Titan’s coasts
Signatures of wave erosion in Titan’s coasts
 
Mechanisms and Applications of Antiviral Neutralizing Antibodies - Creative B...
Mechanisms and Applications of Antiviral Neutralizing Antibodies - Creative B...Mechanisms and Applications of Antiviral Neutralizing Antibodies - Creative B...
Mechanisms and Applications of Antiviral Neutralizing Antibodies - Creative B...
 
Sexuality - Issues, Attitude and Behaviour - Applied Social Psychology - Psyc...
Sexuality - Issues, Attitude and Behaviour - Applied Social Psychology - Psyc...Sexuality - Issues, Attitude and Behaviour - Applied Social Psychology - Psyc...
Sexuality - Issues, Attitude and Behaviour - Applied Social Psychology - Psyc...
 
(June 12, 2024) Webinar: Development of PET theranostics targeting the molecu...
(June 12, 2024) Webinar: Development of PET theranostics targeting the molecu...(June 12, 2024) Webinar: Development of PET theranostics targeting the molecu...
(June 12, 2024) Webinar: Development of PET theranostics targeting the molecu...
 
gastroretentive drug delivery system-PPT.pptx
gastroretentive drug delivery system-PPT.pptxgastroretentive drug delivery system-PPT.pptx
gastroretentive drug delivery system-PPT.pptx
 
Alternate Wetting and Drying - Climate Smart Agriculture
Alternate Wetting and Drying - Climate Smart AgricultureAlternate Wetting and Drying - Climate Smart Agriculture
Alternate Wetting and Drying - Climate Smart Agriculture
 
fermented food science of sauerkraut.pptx
fermented food science of sauerkraut.pptxfermented food science of sauerkraut.pptx
fermented food science of sauerkraut.pptx
 
AJAY KUMAR NIET GreNo Guava Project File.pdf
AJAY KUMAR NIET GreNo Guava Project File.pdfAJAY KUMAR NIET GreNo Guava Project File.pdf
AJAY KUMAR NIET GreNo Guava Project File.pdf
 
Juaristi, Jon. - El canon espanol. El legado de la cultura española a la civi...
Juaristi, Jon. - El canon espanol. El legado de la cultura española a la civi...Juaristi, Jon. - El canon espanol. El legado de la cultura española a la civi...
Juaristi, Jon. - El canon espanol. El legado de la cultura española a la civi...
 
Farming systems analysis: what have we learnt?.pptx
Farming systems analysis: what have we learnt?.pptxFarming systems analysis: what have we learnt?.pptx
Farming systems analysis: what have we learnt?.pptx
 

An itinerary for FAIR and privacy respecting data-driven innovation and research

  • 1. An itinerary for FAIR and privacy respecting data-driven innovation and research National eScience Symposium 2017 October 12, Amsterdam Marlon Domingus “Nowadays people know the privacy risk of everything and the value of nothing.” variation on an Oscar Wilde theme
  • 2. Itinerary 1. On the EU General Data Protection Regulation 2. On Governance of Re-Use of Data 3. Privacy in the context of Research and Big Data Research 4. Privacy and the Internet of Things 5. Next Steps 2
  • 3. The GDPR Elephant Is In The Room Image sources: Top, Bottom left side, Bottom right side. Will you ignore it and allow it to become your weakness? Or will you adapt to it and make it your strength to safeguard privacy? Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl September 2017 General Data Protection Regulation Disclaimer
  • 4. EU General Data Protection Regulation What, Who, How, When What & How 25 May 2018October 2017 15 December 2017 Who University: provide necessary general conditions to enable researchers to comply; policy, guidelines, infrastructure and skilled and available research support staff. Dean: provide additional necessary discipline specific conditions to enable researchers to comply; policy, guidelines, infrastructure and skilled and available research support staff. Faculty: follow privacy principles & use the privacy enabling conditions (policy, guidelines, infrastructure and skilled and available research support staff).
  • 5. Does Privacy Threaten Research and / or Does Research Threaten Privacy? • The EU General Data Protection Regulation (GDPR) is principle based • intended to facilitate the responsible free floating of data within the EU to strengthen the internal market, especially by public - private driven innovation. • The Right to Privacy is not an absolute right, but a fundamental right amongst other rights. • Conclusion: no business as usual, but also no disruption of research. • GDPR is a game changer, and we have to shift to the new paradigm and govern research in a new way. 5
  • 6. Command & Control • Fixed norm • Actor • Sanction • Example: METC Reflexive regulation • Situated norm • Multiple Actors • Learn • Example: intervision Two Models of Governance Source: Prof. Dr. Antoinette de Bont, Erasmus School of Health Policy & Management (ESHPM): The Governance of re-use of data. Summerschool 9-12 July 2017 @ Erasmus MC.
  • 7. Reflexive Governance of Re-Use of Data Source: Prof. Dr. Antoinette de Bont, Erasmus School of Health Policy & Management (ESHPM): The Governance of re-use of data. Summerschool 9-12 July 2017 @ Erasmus MC. Set up research aimed to reduce margins of uncertainty; Set up research to detect vulnerabilities in the environment; Institute long‐term monitoring systems and facilities for early warnings of possible harmful effects. Invite stakeholders to contribute to strategic discussions about the research you do
  • 8. Privacy Before Research: Research Design Result: Data Management Plan DPIA Risks, Appropriate Organisational and Technical Measures, Ethical Self Assessment 2 Data Management Plan See for DPIA: pg 14. Article 29 Data Protection Working Party: Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is “likely to result in a high risk” for the purposes of Regulation 2016/679. Adopted on 4 April 2017. See: http://ec.europa.eu/newsroom/document.cfm?doc_id=44137 Privacy Principles 1
  • 9. 1. The EU General Data Protection Regulation: Article 5 GDPR: Principles Relating to Processing of Personal Data Source: http://gdprcoalition.ie/infographics/
  • 10. 2. The EU General Data Protection Regulation: Privacy Before, During and After Research Created in collaboration with the GDPR Coalition
  • 11. Privacy Before Research: Privacy by Design Strategy (‘traditional’) Source: ENISA report (2015): Privacy By Design In Big Data. Online: https://www.enisa.europa.eu/publications/big-data-protection/at_download/fullReport 11
  • 12. Privacy Before Research: Privacy by Design Strategy (Big Data) Source: ENISA report (2015): Privacy By Design In Big Data. Online: https://www.enisa.europa.eu/publications/big-data-protection/at_download/fullReport 12
  • 13. Privacy Before Research: Privacy Enhancing Technologies in Big Data Anonymization in big data (and beyond) Utility and privacy Attack models and disclosure risk Anonymization privacy models Anonymization privacy models and big data Anonymization methods Some current weaknesses of anonymization Centralized vs decentralized anonymization for big data Other specific challenges of anonymization in big data Challenges and future research for anonymization in big data Encryption techniques in big data Database encryption Encrypted search Security and accountability controls Granular access control Privacy policy enforcement Accountability and audit mechanisms Data provenance Transparency and access Consent, ownership and control Consent mechanisms Privacy preferences and sticky policies Personal data stores Source: ENISA report (2015): Privacy By Design In Big Data. Online: https://www.enisa.europa.eu/publications/big-data-protection/at_download/fullReport 13
  • 14. WP Art 29: Big Data Concerns: 14 - the sheer scale of data collection, tracking and profiling, also taking into account the variety and detail of the data collected and the fact that data are often combined from many different sources; - the security of data, with levels of protection shown to be lagging behind the expansion in volume; - transparency: unless they are provided with sufficient information, individuals will be subject to decisions that they do not understand and have no control over; - inaccuracy, discrimination, exclusion and economic imbalance; - increased possibilities of government surveillance. Source: Article 29 Data Protection Working Party. Opinion 03/2013 on purpose limitation. Adopted on 2 April 2013. Online: http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2013/wp203_en.pdf
  • 15. Balancing the legitimate interests of the researcher and the privacy rights of the individual Source: Prof. Dr. Gloria González Fuster: Recent jurisprudence of the European Court of Human Rights and the Court of Justice of the European Union. Brussels Privacy Hub, VUB Brussel, June 30 2017. independent authority individual’s rights legitimate interests 15 GDPR Member States’ Implementation Legislation Codes of Conduct Discipline Specific Good Practices of the researcher of the data subject
  • 16. Balancing: Four Steps 1. Legitimate interests of controller or 3rd party • freedom of expression • direct marketing and other forms of advertisement • enforcement of legal claims • prevention of fraud, misuse of services, or money laundering • physical safety, security, IT and network security • whistle-blowing schemes 2. Impact on data subject Actual and potential repercussions • Nature of the data • How the data are processed • Reasonable expectations data subject • Nature of controller vis-à-vis data subject 3. Make provisional balance “Necessary” • Least intrusive means • Reasonably effective • Balance of interests 4. Safeguards Measures to ensure that the data cannot be used to take decisions or other actions with regard to individuals. • anonymisation techniques, aggregation of data • privacy-enhancing technologies, privacy by design • increased transparency • general and unconditional right to opt-out Source: Article 29 Data Protection Working Party. Opinion 06/2014 on the "Notion of legitimate interests of the data controller under Article 7 of Directive 95/46/EC". Adopted on 9 April 2014. Online: http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2014/wp217_en.pdf 16
  • 17. Privacy in the Context of Research: 9 Generic Research Scenarios
  • 18. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data principal investigator academia Research Scenarios and the General Data Protection Regulation: 1. Individual Academic Research Based on Existing Data Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 adequate organisational and technical measures accessing and collecting data existing data existing observed data online / sensor data
  • 19. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data Research Scenarios and the General Data Protection Regulation: 2. Academic Research by an International Research Group Based on Existing Data Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 adequate organisational and technical measures accessing and collecting data existing data existing observed data online / sensor data accessing data academic researcher academic researcher academic researcher sharing data for analysing, archiving and publishing purposes analysing data archiving data publishing data adequate organisational and technical measures principal investigator academia
  • 20. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data principal investigator academia Research Scenarios and the General Data Protection Regulation: 3. Individual Academic Research Based on Generated Data from Data Subjects Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 - informed consent - public interest generating new data data subjects data subject's rights: • to be informed • of access • to rectification • to erasure • to restriction of processing • to objection of processing • to data portability • to withdraw consent • to lodge a complaint to a supervisory authority • right not to be subject to a decision based solely on automated processing adequate organisational and technical measures
  • 21. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data Research Scenarios and the General Data Protection Regulation: 4. Academic Research by an International Research Group Based on Generated Data from Data Subjects Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 - informed consent - public interest generating new data data subjects adequate organisational and technical measures accessing data academic researcher academic researcher academic researcher sharing data for analysing, archiving and publishing purposes analysing data archiving data publishing data adequate organisational and technical measures principal investigator academia
  • 22. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data principal investigator academia Research Scenarios and the General Data Protection Regulation: 5. Academic Research by an International Research Group Based on Generated Data from Data Subjects Combined With Existing Data Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 - informed consent - public interest generating new data data subjects adequate organisational and technical measures accessing data academic researcher academic researcher academic researcher sharing data for analysing, archiving and publishing purposes analysing data archiving data publishing data adequate organisational and technical measures accessing and collecting data existing data existing observed data online / sensor data
  • 23. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data Research Scenarios and the General Data Protection Regulation: 6. Academic Research by International Public - Private Research Group Based on Generated Data from Data Subjects Combined With Existing Data Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 - informed consent - public interest generating new data data subjects adequate organisational and technical measures accessing data academic researcher academic researcher academic researcher sharing data for analysing, archiving and publishing purposes analysing data archiving data publishing data adequate organisational and technical measures accessing and collecting data existing data existing observed data online / sensor data non academic research partner non academic research partner principal investigator academia
  • 24. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data principal investigator academia Research Scenarios and the General Data Protection Regulation: 7. Academic Research by International Public - Private Research Group Based on Generated Data from Data Subjects Combined With Existing Data and Licensed Data Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 - informed consent - public interest generating new data data subjects adequate organisational and technical measures accessing data academic researcher academic researcher academic researcher sharing data for analysing, archiving and publishing purposes analysing data archiving data publishing data adequate organisational and technical measures accessing and collecting data existing data existing observed data online / sensor data non academic research partner non academic research partner licensed data
  • 25. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data Research Scenarios and the General Data Protection Regulation: 8. Academic Research by International Public - Private Research Group & Third Parties Based on Generated Data from Data Subjects Combined With Existing Data and Commercial Data Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 - informed consent - public interest generating new data data subjects adequate organisational and technical measures accessing data academic researcher academic researcher academic researcher sharing data for analysing, archiving and publishing purposes analysing data archiving data publishing data adequate organisational and technical measures accessing and collecting data existing data existing observed data online / sensor data non academic research partner non academic research partner licensed data non academic service provider non academic service provider principal investigator academia
  • 26. storing data analysing data deleting data archiving data for follow-on research own research publicly publishing data principal investigator academia Research Scenarios and the General Data Protection Regulation: 9. Academic Big Data Research by International Public - Private Research Group & Third Parties Based on Generated Data from Data Subjects Combined With Existing Data and Commercial Data Marlon Domingus Erasmus University Rotterdam marlon.domingus@eur.nl August 24 2017 - informed consent - public interest generating new data data subjects adequate organisational and technical measures accessing data academic researcher academic researcher academic researcher sharing data for analysing, archiving and publishing purposes analysing data archiving data publishing data adequate organisational and technical measures accessing and collecting data existing data existing observed data online / sensor data non academic research partner non academic research partner licensed data non academic service provider non academic service provider HPC
  • 28. Reflexive regulation • Situated norm (in context) • Multiple Actors • Learn Reprise: Two Models of Governance Focus Points: • Nature of the Data • Nature of the Consortium • Nature of the Dataflow • Appropriate Measures
  • 29. Private, Shared and Public - Boundary Transitions 29 Source: Personal website Andrew Treloar. Online: http://andrew.treloar.net/research/diagrams/index.shtml
  • 30. Cross Border Data Transfers Source: Prof. Christopher Kuner, International Transfers of Personal Data Post-GDPR. Brussels Privacy Hub, VUB Brussel, June 29 2017. 30
  • 31. Privacy and the Internet of Things 31 Source: Internet of Things Architecture, pg 101, 102: http://iotforum.org/wp-content/uploads/2014/09/D1.5-20130715-VERYFINAL.pdf
  • 32. Privacy and the Internet of Things Source: Internet of Things Architecture, pg 101, 102: http://iotforum.org/wp-content/uploads/2014/09/D1.5-20130715-VERYFINAL.pdf 32 The subject must be able to choose sharing or not sharing information with someone else; The subject must be able to fully control the mechanism used to ensure their privacy; The subject shall be able to decide for which purpose the information will be used; The subject shall be informed whenever information is used and by whom; During interactions between a subject and an IoT system, only strictly needed information shall be disclosed about the subject, and pseudonyms, secondary identity, or assertions (certified properties of the end-user) shall be used whenever possible; It shall not be possible to infer the subject‘s identity by aggregating/reasoning over information available at various sources; Information gained for a specific purpose shall not be used for another purpose. E.g., the bank issuing a credit card should not use a given client‘s purchase information (logged so to keep track of that client‘s account) to send him advertising on goods similar to his purchaces.
  • 33. Privacy and the Internet of Things Source: Internet of Things Architecture, pg 101, 102: http://iotforum.org/wp-content/uploads/2014/09/D1.5-20130715-VERYFINAL.pdf 33 The subject must be able to choose sharing or not sharing information with someone else; The subject must be able to fully control the mechanism used to ensure their privacy; The subject shall be able to decide for which purpose the information will be used; The subject shall be informed whenever information is used and by whom; During interactions between a subject and an IoT system, only strictly needed information shall be disclosed about the subject, and pseudonyms, secondary identity, or assertions (certified properties of the end-user) shall be used whenever possible; It shall not be possible to infer the subject‘s identity by aggregating/reasoning over information available at various sources; Information gained for a specific purpose shall not be used for another purpose. E.g., the bank issuing a credit card should not use a given client‘s purchase information (logged so to keep track of that client‘s account) to send him advertising on goods similar to his purchaces.
  • 34. What we don’t want; Data Breaches 2017: Source: Information is Beautiful: Data Breaches (public), bit.ly/bigdatabreaches 34
  • 35. Next Steps: Privacy Maturity Model Source:LCRDM.https://www1.edugroepen.nl/sites/RDM_platform/RDM_Blog/Lists/Posts/Post.aspx?ID=12
  • 36. Privacy Awareness: Infographics Source: EUR Research Matters website. Online: https://www.eur.nl/researchmatters/research_data_management/services/rdm_legal_services/ 36
  • 37. Questions? drs. Marlon Domingus Research Services coordinator Community Research Data Management T +31 10 4088006 E researchsupport@eur.nl W https://www.eur.nl/researchmatters/research_data_management/ (services and templates) Stay in touch via: https://www.linkedin.com/in/domingus/ 37