SlideShare a Scribd company logo
GDPR
- Thoughts on the
EU Data Protection
regulation, research and
libraries
Jonas Holm
Legal counsel
Stockholm University
Chair, LIBER Legal Working Group
jonas..holm@su.se
Disposition
Legal issues for research libraries
A legal backdrop to integrity law
Data protection and personal data -key principles
EU Data protection reform
GDPR Key Findings
Implications for libraries
Questions
Legal issues
for research
libraries
Contracts / Licensing
Exceptions and limitations to copyright
E-books
Open Access
Preservation of copyright protected works
Data protection
Open Science / Open research data
Making available copyright protected works
Publishing
Big data – Data mining
Legal deposit
Public access to information and secrecy
Availability for people with disabilities
Digitization
A legal backdrop to integrity law
European Convention on Human Rights
EU charter on fundamental rights
National legislation
The right to be forgotten
Data protection – what is personal data?
”Each data concerning an identified or identifiable person
that is alive”
An identifiable person is a person that directly or
indirectly can be identified through use of the data.
Data privacy does not include deseased indivduals.
What constitutes sensitive personal data?
Race or ethnical heritage
Political views
Religious or philosophical views
Labour union membership
Health
Sexual orientation
Biometric information concerning a person
Current (past) legal framework
on Data protection in the EU
Data Protection Directive 95/46/EC
National data protection legislation
Unharmonized application throughout the union
EU Data Protection Regulation (GDPR)
Direct application in all
members states from May
25th
2018.
National inquires into the
application underway.
National legislation will
follow
Key Changes through the GDPR
Overall goal is to protect all EU citizens from data privacy
breaches in an increasingly data driven world.
Increased territorial scope (extra-territorial
applicability)
Jurisdiction of the GDPR is extended to all entities
processing data of EU citizens, regardless of where the
entity is located
Consent and purpose based data processing
All data processing has to be based on informed,
intelligable and specific consent from subjects.
Processing of research data containing personal data has
to be purpose specific, not for general research databases!
Consent can be withdrawn!
Breach notification
Under the GDPR, breach notification will become
mandatory in all member states where a data breach is
likely to “result in a risk for the rights and freedoms of
individuals”.
This must be done within 72 hours of first having become
aware of the breach.
Right to Access and Right to be forgotten
Right for data subjects to obtain from the data controller
confirmation as to whether or not personal data
concerning them is being processed, where and for what
purpose. Further, the controller shall provide a copy of
the personal data, free of charge, in an electronic fromat
Entitles the data subject to have the data controller erase
his/her personal data, cease further dissemination of the
data, and potentially have third parties halt processing.
Privacy by Design
Inclusion of data protection from the onset of the
designing of systems, rather than an addition.
Article 23 GDPR
Data Protection Officers
Data controllers must appoint DPO's who:
- Must be appointed on the basis of professional qualities and, in
particular, expert knowledge on data protection law and practices
- May be a staff member or an external service provider
- Contact details must be provided to the relevant Data Protection
Agency
- Must be provided with appropriate resources to carry out their
tasks and maintain their expert knowledge
- Must report directly to the highest level of management
- Must not carry out any other tasks that could results in a conflict
of interest.​
Penalties
Under GDPR organizations in breach of GDPR can be
fined up to 4% of annual global turnover or €20
Million.
This is the maximum fine that can be imposed for the
most serious infringements e.g.not having sufficient
customer consent to process data or violating the core of
Privacy by Design concepts. There is a tiered approach to
fines e.g. a company can be fined 2% for not having their
records in order (Article 28)
Implications for libraries
To what extent will the GDPR apply to processing of
personal data in the activities at research libraries and to what
extent does research libraries hold responsibilites for the data
processing?
Due diligence inventory!
- Does high risk projects from a data protection view exist
today?
Implications for libraries, cont.
Personal data in infrastructure for library loans and use of
electronic resources
Personal data when digitizing and making available library
collections.
Does research publications publicized at research libraries or
in house university publishers contain personal data?
Personal data in infrastructure for library loans and use of
electronic resources
Personal data when digitizing and making available library
collections.
Does research publications publicized at research libraries or
in house university publishers contain personal data?
Implications for libraries, cont.
Does research data published open access or in databases
according to open science policies contain personal data?
Is TDM (Text and Data Mining) activities or other big data
processing (such as the use of algorithms) carried out at the
research library?
Does that material contain personal data?
Thanks!
jonas.holm@su.se

More Related Content

What's hot

Is Poland Ready for GDPR?
Is Poland Ready for GDPR? Is Poland Ready for GDPR?
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
Kroll.cross border ediscovery-2016
Kroll.cross border ediscovery-2016Kroll.cross border ediscovery-2016
Kroll.cross border ediscovery-2016
Kate Chan
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
m-hance
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
- Mark - Fullbright
 
Ico sme-webinar-slides-090217
Ico sme-webinar-slides-090217Ico sme-webinar-slides-090217
Ico sme-webinar-slides-090217
Tony Dowling
 
Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...
BCC - Solutions for IBM Collaboration Software
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
Ulf Mattsson
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
Exove
 
20200429_Data, Data Ownership and Open Science
20200429_Data, Data Ownership and Open Science20200429_Data, Data Ownership and Open Science
20200429_Data, Data Ownership and Open Science
OpenAIRE
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
Browne Jacobson LLP
 
20200429_OpenAIRE Legal Policy Webinar: GDPR and Sharing Data
20200429_OpenAIRE Legal Policy Webinar: GDPR and Sharing Data20200429_OpenAIRE Legal Policy Webinar: GDPR and Sharing Data
20200429_OpenAIRE Legal Policy Webinar: GDPR and Sharing Data
OpenAIRE
 
The Policy Framework: GDPR and all that
The Policy Framework: GDPR and all thatThe Policy Framework: GDPR and all that
The Policy Framework: GDPR and all that
EUDAT
 
Legal update - Leeds
Legal update - LeedsLegal update - Leeds
Legal update - Leeds
Rachel Aldighieri
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
Karel Holst
 
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
Fife Centre for Equalities
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
Karel Holst
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and Processing
PromptCloud
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Financial Poise
 

What's hot (19)

Is Poland Ready for GDPR?
Is Poland Ready for GDPR? Is Poland Ready for GDPR?
Is Poland Ready for GDPR?
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
Kroll.cross border ediscovery-2016
Kroll.cross border ediscovery-2016Kroll.cross border ediscovery-2016
Kroll.cross border ediscovery-2016
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
Ico sme-webinar-slides-090217
Ico sme-webinar-slides-090217Ico sme-webinar-slides-090217
Ico sme-webinar-slides-090217
 
Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
20200429_Data, Data Ownership and Open Science
20200429_Data, Data Ownership and Open Science20200429_Data, Data Ownership and Open Science
20200429_Data, Data Ownership and Open Science
 
Administrative and public law seminar
Administrative and public law seminarAdministrative and public law seminar
Administrative and public law seminar
 
20200429_OpenAIRE Legal Policy Webinar: GDPR and Sharing Data
20200429_OpenAIRE Legal Policy Webinar: GDPR and Sharing Data20200429_OpenAIRE Legal Policy Webinar: GDPR and Sharing Data
20200429_OpenAIRE Legal Policy Webinar: GDPR and Sharing Data
 
The Policy Framework: GDPR and all that
The Policy Framework: GDPR and all thatThe Policy Framework: GDPR and all that
The Policy Framework: GDPR and all that
 
Legal update - Leeds
Legal update - LeedsLegal update - Leeds
Legal update - Leeds
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and Processing
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 

Similar to GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries

Ethics and data protection .docx
Ethics and data protection          .docxEthics and data protection          .docx
Ethics and data protection .docx
elbanglis
 
Privacy, Social Network Sites and the law
Privacy, Social Network Sites and the lawPrivacy, Social Network Sites and the law
Privacy, Social Network Sites and the law
dariphagen
 
Legal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research dataLegal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research data
OpenAIRE
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
Acquia
 
GDPR
GDPRGDPR
GDPR
Gopi PD
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
zayadeen2003
 
GDPR master class accountable research organisations (january 2018)
GDPR master class   accountable research organisations (january 2018)GDPR master class   accountable research organisations (january 2018)
GDPR master class accountable research organisations (january 2018)
MRS
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1rtjbond
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
Joseph V. Moreno
 
Protection of patient data in EU vs. US
Protection of patient data in EU vs. USProtection of patient data in EU vs. US
Protection of patient data in EU vs. US
Erik R. Ranschaert, MD, PhD
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
BenjaminShalevSalovi
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .
ClinosolIndia
 
Data privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptxData privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptx
kandalamsailaja17
 
0303 Julius Zaleskis - GDPR and data protection for cancer advocates
0303 Julius Zaleskis - GDPR and data protection for cancer advocates0303 Julius Zaleskis - GDPR and data protection for cancer advocates
0303 Julius Zaleskis - GDPR and data protection for cancer advocates
Workgroup of European Cancer Patient Advocacy Networks
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
Lilian Edwards
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
IISPEastMids
 
Christopher Millard Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard   Legally Compliant Use Of Personal Data In E Social ScienceChristopher Millard   Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard Legally Compliant Use Of Personal Data In E Social ScienceChristopher Millard
 
Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?
Edouard Nguyen
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
ImogenRutherford
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guide
Angad Dayal
 

Similar to GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries (20)

Ethics and data protection .docx
Ethics and data protection          .docxEthics and data protection          .docx
Ethics and data protection .docx
 
Privacy, Social Network Sites and the law
Privacy, Social Network Sites and the lawPrivacy, Social Network Sites and the law
Privacy, Social Network Sites and the law
 
Legal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research dataLegal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research data
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
GDPR
GDPRGDPR
GDPR
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
GDPR master class accountable research organisations (january 2018)
GDPR master class   accountable research organisations (january 2018)GDPR master class   accountable research organisations (january 2018)
GDPR master class accountable research organisations (january 2018)
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 
Protection of patient data in EU vs. US
Protection of patient data in EU vs. USProtection of patient data in EU vs. US
Protection of patient data in EU vs. US
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Data Privacy and consent management .. .
Data Privacy and consent management  ..  .Data Privacy and consent management  ..  .
Data Privacy and consent management .. .
 
Data privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptxData privacy and consent management (K.sailaja).pptx
Data privacy and consent management (K.sailaja).pptx
 
0303 Julius Zaleskis - GDPR and data protection for cancer advocates
0303 Julius Zaleskis - GDPR and data protection for cancer advocates0303 Julius Zaleskis - GDPR and data protection for cancer advocates
0303 Julius Zaleskis - GDPR and data protection for cancer advocates
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
Christopher Millard Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard   Legally Compliant Use Of Personal Data In E Social ScienceChristopher Millard   Legally Compliant Use Of Personal Data In E Social Science
Christopher Millard Legally Compliant Use Of Personal Data In E Social Science
 
Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guide
 

More from LIBER Europe

LIBER Europe Covid-19 Research Libraries Survey - December 2020
LIBER Europe Covid-19 Research Libraries Survey - December 2020LIBER Europe Covid-19 Research Libraries Survey - December 2020
LIBER Europe Covid-19 Research Libraries Survey - December 2020
LIBER Europe
 
LIBER Webinar: Turning FAIR Data Into Reality
LIBER Webinar: Turning FAIR Data Into RealityLIBER Webinar: Turning FAIR Data Into Reality
LIBER Webinar: Turning FAIR Data Into Reality
LIBER Europe
 
Copyright Reform: EU Legislative Process & LIBER Advocacy
Copyright Reform: EU Legislative Process & LIBER AdvocacyCopyright Reform: EU Legislative Process & LIBER Advocacy
Copyright Reform: EU Legislative Process & LIBER Advocacy
LIBER Europe
 
LIBER Webinar: Supporting Data Literacy
LIBER Webinar: Supporting Data LiteracyLIBER Webinar: Supporting Data Literacy
LIBER Webinar: Supporting Data Literacy
LIBER Europe
 
Applying Bourdieu's Field Theory to MLS Curricula Development. Charlotte Nord...
Applying Bourdieu's Field Theory to MLS Curricula Development. Charlotte Nord...Applying Bourdieu's Field Theory to MLS Curricula Development. Charlotte Nord...
Applying Bourdieu's Field Theory to MLS Curricula Development. Charlotte Nord...
LIBER Europe
 
Growing a Culture for Change at The University of Manchester Library. Penny H...
Growing a Culture for Change at The University of Manchester Library. Penny H...Growing a Culture for Change at The University of Manchester Library. Penny H...
Growing a Culture for Change at The University of Manchester Library. Penny H...
LIBER Europe
 
Knowledge Exchange Consensus: Monitoring of Open Access Publications and Cost...
Knowledge Exchange Consensus: Monitoring of Open Access Publications and Cost...Knowledge Exchange Consensus: Monitoring of Open Access Publications and Cost...
Knowledge Exchange Consensus: Monitoring of Open Access Publications and Cost...
LIBER Europe
 
The GND initiative 2017-2021: Developing a Backbone for the Web of Cultural a...
The GND initiative 2017-2021: Developing a Backbone for the Web of Cultural a...The GND initiative 2017-2021: Developing a Backbone for the Web of Cultural a...
The GND initiative 2017-2021: Developing a Backbone for the Web of Cultural a...
LIBER Europe
 
The Role of Libraries in the Adoption of Research Data Management. Ingeborg V...
The Role of Libraries in the Adoption of Research Data Management. Ingeborg V...The Role of Libraries in the Adoption of Research Data Management. Ingeborg V...
The Role of Libraries in the Adoption of Research Data Management. Ingeborg V...
LIBER Europe
 
LibChain – Open, Verifiable and Anonymous Access Management. Juan Cabello, P...
 LibChain – Open, Verifiable and Anonymous Access Management. Juan Cabello, P... LibChain – Open, Verifiable and Anonymous Access Management. Juan Cabello, P...
LibChain – Open, Verifiable and Anonymous Access Management. Juan Cabello, P...
LIBER Europe
 
From Open Access to Open Data: Collaborative Work in the University Libraries...
From Open Access to Open Data: Collaborative Work in the University Libraries...From Open Access to Open Data: Collaborative Work in the University Libraries...
From Open Access to Open Data: Collaborative Work in the University Libraries...
LIBER Europe
 
The Perks and Challenges of Drawing Maps and Walking at the Same Time
The Perks and Challenges of Drawing Maps and Walking at the Same TimeThe Perks and Challenges of Drawing Maps and Walking at the Same Time
The Perks and Challenges of Drawing Maps and Walking at the Same Time
LIBER Europe
 
TIB AV-Portal: Semantic Content Mining with Semi-Automatic Metadata Editing. ...
TIB AV-Portal: Semantic Content Mining with Semi-Automatic Metadata Editing. ...TIB AV-Portal: Semantic Content Mining with Semi-Automatic Metadata Editing. ...
TIB AV-Portal: Semantic Content Mining with Semi-Automatic Metadata Editing. ...
LIBER Europe
 
Text and Data Mining : Making the Most of a Copyright Exception. Julien Roche...
Text and Data Mining : Making the Most of a Copyright Exception. Julien Roche...Text and Data Mining : Making the Most of a Copyright Exception. Julien Roche...
Text and Data Mining : Making the Most of a Copyright Exception. Julien Roche...
LIBER Europe
 
Adoption and Integration of Persistent Identifiers in European Research Infor...
Adoption and Integration of Persistent Identifiers in European Research Infor...Adoption and Integration of Persistent Identifiers in European Research Infor...
Adoption and Integration of Persistent Identifiers in European Research Infor...
LIBER Europe
 
Digital Humanities Clinics – Leading Dutch Librarians into DH. Lotte Wilms, N...
Digital Humanities Clinics – Leading Dutch Librarians into DH. Lotte Wilms, N...Digital Humanities Clinics – Leading Dutch Librarians into DH. Lotte Wilms, N...
Digital Humanities Clinics – Leading Dutch Librarians into DH. Lotte Wilms, N...
LIBER Europe
 
COUNTER Standards for Open Access: The Value of Measuring/The Measuring of Va...
COUNTER Standards for Open Access: The Value of Measuring/The Measuring of Va...COUNTER Standards for Open Access: The Value of Measuring/The Measuring of Va...
COUNTER Standards for Open Access: The Value of Measuring/The Measuring of Va...
LIBER Europe
 
Enabling the Exchange and use of Data in Agriculture
Enabling the Exchange and use of Data in AgricultureEnabling the Exchange and use of Data in Agriculture
Enabling the Exchange and use of Data in Agriculture
LIBER Europe
 
Research Data Services and Data Collections: Library Synergies for Economic R...
Research Data Services and Data Collections: Library Synergies for Economic R...Research Data Services and Data Collections: Library Synergies for Economic R...
Research Data Services and Data Collections: Library Synergies for Economic R...
LIBER Europe
 
The Tribal Approach Academia Takes to Research Data Management
The Tribal Approach Academia Takes to Research Data ManagementThe Tribal Approach Academia Takes to Research Data Management
The Tribal Approach Academia Takes to Research Data Management
LIBER Europe
 

More from LIBER Europe (20)

LIBER Europe Covid-19 Research Libraries Survey - December 2020
LIBER Europe Covid-19 Research Libraries Survey - December 2020LIBER Europe Covid-19 Research Libraries Survey - December 2020
LIBER Europe Covid-19 Research Libraries Survey - December 2020
 
LIBER Webinar: Turning FAIR Data Into Reality
LIBER Webinar: Turning FAIR Data Into RealityLIBER Webinar: Turning FAIR Data Into Reality
LIBER Webinar: Turning FAIR Data Into Reality
 
Copyright Reform: EU Legislative Process & LIBER Advocacy
Copyright Reform: EU Legislative Process & LIBER AdvocacyCopyright Reform: EU Legislative Process & LIBER Advocacy
Copyright Reform: EU Legislative Process & LIBER Advocacy
 
LIBER Webinar: Supporting Data Literacy
LIBER Webinar: Supporting Data LiteracyLIBER Webinar: Supporting Data Literacy
LIBER Webinar: Supporting Data Literacy
 
Applying Bourdieu's Field Theory to MLS Curricula Development. Charlotte Nord...
Applying Bourdieu's Field Theory to MLS Curricula Development. Charlotte Nord...Applying Bourdieu's Field Theory to MLS Curricula Development. Charlotte Nord...
Applying Bourdieu's Field Theory to MLS Curricula Development. Charlotte Nord...
 
Growing a Culture for Change at The University of Manchester Library. Penny H...
Growing a Culture for Change at The University of Manchester Library. Penny H...Growing a Culture for Change at The University of Manchester Library. Penny H...
Growing a Culture for Change at The University of Manchester Library. Penny H...
 
Knowledge Exchange Consensus: Monitoring of Open Access Publications and Cost...
Knowledge Exchange Consensus: Monitoring of Open Access Publications and Cost...Knowledge Exchange Consensus: Monitoring of Open Access Publications and Cost...
Knowledge Exchange Consensus: Monitoring of Open Access Publications and Cost...
 
The GND initiative 2017-2021: Developing a Backbone for the Web of Cultural a...
The GND initiative 2017-2021: Developing a Backbone for the Web of Cultural a...The GND initiative 2017-2021: Developing a Backbone for the Web of Cultural a...
The GND initiative 2017-2021: Developing a Backbone for the Web of Cultural a...
 
The Role of Libraries in the Adoption of Research Data Management. Ingeborg V...
The Role of Libraries in the Adoption of Research Data Management. Ingeborg V...The Role of Libraries in the Adoption of Research Data Management. Ingeborg V...
The Role of Libraries in the Adoption of Research Data Management. Ingeborg V...
 
LibChain – Open, Verifiable and Anonymous Access Management. Juan Cabello, P...
 LibChain – Open, Verifiable and Anonymous Access Management. Juan Cabello, P... LibChain – Open, Verifiable and Anonymous Access Management. Juan Cabello, P...
LibChain – Open, Verifiable and Anonymous Access Management. Juan Cabello, P...
 
From Open Access to Open Data: Collaborative Work in the University Libraries...
From Open Access to Open Data: Collaborative Work in the University Libraries...From Open Access to Open Data: Collaborative Work in the University Libraries...
From Open Access to Open Data: Collaborative Work in the University Libraries...
 
The Perks and Challenges of Drawing Maps and Walking at the Same Time
The Perks and Challenges of Drawing Maps and Walking at the Same TimeThe Perks and Challenges of Drawing Maps and Walking at the Same Time
The Perks and Challenges of Drawing Maps and Walking at the Same Time
 
TIB AV-Portal: Semantic Content Mining with Semi-Automatic Metadata Editing. ...
TIB AV-Portal: Semantic Content Mining with Semi-Automatic Metadata Editing. ...TIB AV-Portal: Semantic Content Mining with Semi-Automatic Metadata Editing. ...
TIB AV-Portal: Semantic Content Mining with Semi-Automatic Metadata Editing. ...
 
Text and Data Mining : Making the Most of a Copyright Exception. Julien Roche...
Text and Data Mining : Making the Most of a Copyright Exception. Julien Roche...Text and Data Mining : Making the Most of a Copyright Exception. Julien Roche...
Text and Data Mining : Making the Most of a Copyright Exception. Julien Roche...
 
Adoption and Integration of Persistent Identifiers in European Research Infor...
Adoption and Integration of Persistent Identifiers in European Research Infor...Adoption and Integration of Persistent Identifiers in European Research Infor...
Adoption and Integration of Persistent Identifiers in European Research Infor...
 
Digital Humanities Clinics – Leading Dutch Librarians into DH. Lotte Wilms, N...
Digital Humanities Clinics – Leading Dutch Librarians into DH. Lotte Wilms, N...Digital Humanities Clinics – Leading Dutch Librarians into DH. Lotte Wilms, N...
Digital Humanities Clinics – Leading Dutch Librarians into DH. Lotte Wilms, N...
 
COUNTER Standards for Open Access: The Value of Measuring/The Measuring of Va...
COUNTER Standards for Open Access: The Value of Measuring/The Measuring of Va...COUNTER Standards for Open Access: The Value of Measuring/The Measuring of Va...
COUNTER Standards for Open Access: The Value of Measuring/The Measuring of Va...
 
Enabling the Exchange and use of Data in Agriculture
Enabling the Exchange and use of Data in AgricultureEnabling the Exchange and use of Data in Agriculture
Enabling the Exchange and use of Data in Agriculture
 
Research Data Services and Data Collections: Library Synergies for Economic R...
Research Data Services and Data Collections: Library Synergies for Economic R...Research Data Services and Data Collections: Library Synergies for Economic R...
Research Data Services and Data Collections: Library Synergies for Economic R...
 
The Tribal Approach Academia Takes to Research Data Management
The Tribal Approach Academia Takes to Research Data ManagementThe Tribal Approach Academia Takes to Research Data Management
The Tribal Approach Academia Takes to Research Data Management
 

Recently uploaded

2017 Omnibus Rules on Appointments and Other Human Resource Actions, As Amended
2017 Omnibus Rules on Appointments and Other Human Resource Actions, As Amended2017 Omnibus Rules on Appointments and Other Human Resource Actions, As Amended
2017 Omnibus Rules on Appointments and Other Human Resource Actions, As Amended
johnmarimigallon
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
SERUDS INDIA
 
Uniform Guidance 3.0 - The New 2 CFR 200
Uniform Guidance 3.0 - The New 2 CFR 200Uniform Guidance 3.0 - The New 2 CFR 200
Uniform Guidance 3.0 - The New 2 CFR 200
GrantManagementInsti
 
kupon sample qurban masjid indonesia terbaru.pptx
kupon sample qurban masjid indonesia terbaru.pptxkupon sample qurban masjid indonesia terbaru.pptx
kupon sample qurban masjid indonesia terbaru.pptx
viderakai
 
A proposed request for information on LIHTC
A proposed request for information on LIHTCA proposed request for information on LIHTC
A proposed request for information on LIHTC
Roger Valdez
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Christina Parmionova
 
Invitation Letter for an alumni association
Invitation Letter for an alumni associationInvitation Letter for an alumni association
Invitation Letter for an alumni association
elmerdalida001
 
Get Government Grants and Assistance Program
Get Government Grants and Assistance ProgramGet Government Grants and Assistance Program
Get Government Grants and Assistance Program
Get Government Grants
 
如何办理(uoit毕业证书)加拿大安大略理工大学毕业证文凭证书录取通知原版一模一样
如何办理(uoit毕业证书)加拿大安大略理工大学毕业证文凭证书录取通知原版一模一样如何办理(uoit毕业证书)加拿大安大略理工大学毕业证文凭证书录取通知原版一模一样
如何办理(uoit毕业证书)加拿大安大略理工大学毕业证文凭证书录取通知原版一模一样
850fcj96
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
ARCResearch
 
Transit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group MeetingTransit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group Meeting
Cuyahoga County Planning Commission
 
2024: The FAR - Federal Acquisition Regulations, Part 39
2024: The FAR - Federal Acquisition Regulations, Part 392024: The FAR - Federal Acquisition Regulations, Part 39
2024: The FAR - Federal Acquisition Regulations, Part 39
JSchaus & Associates
 
State crafting: Changes and challenges for managing the public finances
State crafting: Changes and challenges for managing the public financesState crafting: Changes and challenges for managing the public finances
State crafting: Changes and challenges for managing the public finances
ResolutionFoundation
 
2024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 382024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 38
JSchaus & Associates
 
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdfPNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
ClaudioTebaldi2
 
ZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdfZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdf
Saeed Al Dhaheri
 
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Congressional Budget Office
 
NHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdfNHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdf
AjayVejendla3
 
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
OECDregions
 
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
850fcj96
 

Recently uploaded (20)

2017 Omnibus Rules on Appointments and Other Human Resource Actions, As Amended
2017 Omnibus Rules on Appointments and Other Human Resource Actions, As Amended2017 Omnibus Rules on Appointments and Other Human Resource Actions, As Amended
2017 Omnibus Rules on Appointments and Other Human Resource Actions, As Amended
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
 
Uniform Guidance 3.0 - The New 2 CFR 200
Uniform Guidance 3.0 - The New 2 CFR 200Uniform Guidance 3.0 - The New 2 CFR 200
Uniform Guidance 3.0 - The New 2 CFR 200
 
kupon sample qurban masjid indonesia terbaru.pptx
kupon sample qurban masjid indonesia terbaru.pptxkupon sample qurban masjid indonesia terbaru.pptx
kupon sample qurban masjid indonesia terbaru.pptx
 
A proposed request for information on LIHTC
A proposed request for information on LIHTCA proposed request for information on LIHTC
A proposed request for information on LIHTC
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
 
Invitation Letter for an alumni association
Invitation Letter for an alumni associationInvitation Letter for an alumni association
Invitation Letter for an alumni association
 
Get Government Grants and Assistance Program
Get Government Grants and Assistance ProgramGet Government Grants and Assistance Program
Get Government Grants and Assistance Program
 
如何办理(uoit毕业证书)加拿大安大略理工大学毕业证文凭证书录取通知原版一模一样
如何办理(uoit毕业证书)加拿大安大略理工大学毕业证文凭证书录取通知原版一模一样如何办理(uoit毕业证书)加拿大安大略理工大学毕业证文凭证书录取通知原版一模一样
如何办理(uoit毕业证书)加拿大安大略理工大学毕业证文凭证书录取通知原版一模一样
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
 
Transit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group MeetingTransit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group Meeting
 
2024: The FAR - Federal Acquisition Regulations, Part 39
2024: The FAR - Federal Acquisition Regulations, Part 392024: The FAR - Federal Acquisition Regulations, Part 39
2024: The FAR - Federal Acquisition Regulations, Part 39
 
State crafting: Changes and challenges for managing the public finances
State crafting: Changes and challenges for managing the public financesState crafting: Changes and challenges for managing the public finances
State crafting: Changes and challenges for managing the public finances
 
2024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 382024: The FAR - Federal Acquisition Regulations, Part 38
2024: The FAR - Federal Acquisition Regulations, Part 38
 
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdfPNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
 
ZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdfZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdf
 
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
 
NHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdfNHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdf
 
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
Preliminary findings _OECD field visits to ten regions in the TSI EU mining r...
 
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
 

GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries

  • 1. GDPR - Thoughts on the EU Data Protection regulation, research and libraries Jonas Holm Legal counsel Stockholm University Chair, LIBER Legal Working Group jonas..holm@su.se
  • 2. Disposition Legal issues for research libraries A legal backdrop to integrity law Data protection and personal data -key principles EU Data protection reform GDPR Key Findings Implications for libraries Questions
  • 3. Legal issues for research libraries Contracts / Licensing Exceptions and limitations to copyright E-books Open Access Preservation of copyright protected works Data protection Open Science / Open research data Making available copyright protected works Publishing Big data – Data mining Legal deposit Public access to information and secrecy Availability for people with disabilities Digitization
  • 4. A legal backdrop to integrity law European Convention on Human Rights EU charter on fundamental rights National legislation The right to be forgotten
  • 5. Data protection – what is personal data? ”Each data concerning an identified or identifiable person that is alive” An identifiable person is a person that directly or indirectly can be identified through use of the data. Data privacy does not include deseased indivduals.
  • 6. What constitutes sensitive personal data? Race or ethnical heritage Political views Religious or philosophical views Labour union membership Health Sexual orientation Biometric information concerning a person
  • 7. Current (past) legal framework on Data protection in the EU Data Protection Directive 95/46/EC National data protection legislation Unharmonized application throughout the union
  • 8. EU Data Protection Regulation (GDPR) Direct application in all members states from May 25th 2018. National inquires into the application underway. National legislation will follow
  • 9. Key Changes through the GDPR Overall goal is to protect all EU citizens from data privacy breaches in an increasingly data driven world. Increased territorial scope (extra-territorial applicability) Jurisdiction of the GDPR is extended to all entities processing data of EU citizens, regardless of where the entity is located
  • 10. Consent and purpose based data processing All data processing has to be based on informed, intelligable and specific consent from subjects. Processing of research data containing personal data has to be purpose specific, not for general research databases! Consent can be withdrawn!
  • 11. Breach notification Under the GDPR, breach notification will become mandatory in all member states where a data breach is likely to “result in a risk for the rights and freedoms of individuals”. This must be done within 72 hours of first having become aware of the breach.
  • 12. Right to Access and Right to be forgotten Right for data subjects to obtain from the data controller confirmation as to whether or not personal data concerning them is being processed, where and for what purpose. Further, the controller shall provide a copy of the personal data, free of charge, in an electronic fromat Entitles the data subject to have the data controller erase his/her personal data, cease further dissemination of the data, and potentially have third parties halt processing.
  • 13. Privacy by Design Inclusion of data protection from the onset of the designing of systems, rather than an addition. Article 23 GDPR
  • 14. Data Protection Officers Data controllers must appoint DPO's who: - Must be appointed on the basis of professional qualities and, in particular, expert knowledge on data protection law and practices - May be a staff member or an external service provider - Contact details must be provided to the relevant Data Protection Agency - Must be provided with appropriate resources to carry out their tasks and maintain their expert knowledge - Must report directly to the highest level of management - Must not carry out any other tasks that could results in a conflict of interest.​
  • 15. Penalties Under GDPR organizations in breach of GDPR can be fined up to 4% of annual global turnover or €20 Million. This is the maximum fine that can be imposed for the most serious infringements e.g.not having sufficient customer consent to process data or violating the core of Privacy by Design concepts. There is a tiered approach to fines e.g. a company can be fined 2% for not having their records in order (Article 28)
  • 16. Implications for libraries To what extent will the GDPR apply to processing of personal data in the activities at research libraries and to what extent does research libraries hold responsibilites for the data processing? Due diligence inventory! - Does high risk projects from a data protection view exist today?
  • 17. Implications for libraries, cont. Personal data in infrastructure for library loans and use of electronic resources Personal data when digitizing and making available library collections. Does research publications publicized at research libraries or in house university publishers contain personal data? Personal data in infrastructure for library loans and use of electronic resources Personal data when digitizing and making available library collections. Does research publications publicized at research libraries or in house university publishers contain personal data?
  • 18. Implications for libraries, cont. Does research data published open access or in databases according to open science policies contain personal data? Is TDM (Text and Data Mining) activities or other big data processing (such as the use of algorithms) carried out at the research library? Does that material contain personal data?