SlideShare a Scribd company logo
General Data Protection
Regulation (GDPR)
#2019ResearchExpo
What is GDPR?
• GDPR is a European law which went into
effect on May 25, 2018
• Governs the type of notice that must be provided to people regarding
how their identifiable data is used
• Governs how companies are allowed to use and process identifiable
data
• Has stricter requirements for using sensitive data
#2019ResearchExpo
To Whom Does GDPR Apply?
• Those who offer goods or services to persons in the
EU/EEA
• European Economic Area (EEA) = European Union (EU) +
Iceland, Liechtenstein, Norway, & UK
• Those who control and process data about persons in the
EU/EEA
• Personal Data = any information that can identify a person
• Sensitive Data = race/ethnicity, political opinions,
religious/philosophical beliefs, union membership, genetic data,
biometric data, health data, data concerning a person’s sex life
or sexual orientation.
#2019ResearchExpo
Who Are Controllers and Processors?
• Controllers specify the means and purpose of the data processing
• Example: Industry Sponsor, PI of Investigator-Initiated research
• Processors conduct the processing under the direction of the
controller
• Clinical Research Coordinators, Database Administrators, PI of Industry-
Sponsored research
#2019ResearchExpo
What is Data Processing?
• Processing of data involves any and all of the following:
• Adapting
• Altering
• Collecting
• Combining
• Consulting
• Destroying
• Disclosing
• Erasing
• Organizing
• Recording
• Retrieving
• Storing
• Structuring
• Using
#2019ResearchExpo
What is Needed to Process Data?
• A “lawful basis” for doing so
• A “lawful basis” can be:
• When required for a contract
• When required for public interest
• When required to comply with a law
• When required to protect an individual’s life
• When required for the legitimate interests of a third party (no sensitive data)
• When freely given consent for a specific purpose has been provided
• If sensitive data is being processed, explicit consent for those data
elements is required.
#2019ResearchExpo
What Elements of Consent are Needed?
• Name and/or title of the data processor
• The purpose and basis for processing of the subject’s data
• The type of data to be processed
• Remember: When sensitive data are going to be processed, these data
elements must be explicitly listed in the consent.
• If data will be transferred to a less secure country (i.e. the U.S.)
#2019ResearchExpo
What is Needed for Legally Effective Consent?
• Must be in clear and plain language, intelligible, and easily accessible
• Must be specific about the purpose of the data processing
• Must be distinguishable from other matters
• Must be given by a clear act or statement
• Must be an unambiguous indication
• Must fully inform the data subject
• Must be freely given
#2019ResearchExpo
I Got Consent! Now What?
• Processors and Controllers must ensure privacy:
• Limit access to the data
• Code or encrypt the data where possible
• Limit processing to only the necessary data
• Retain the data for the least amount of time possible
• Incorporate data protection into the processing activities
#2019ResearchExpo
What About Secondary Research?
• Secondary research also requires a “lawful basis” for processing of
personal data
• Sensitive data must be explicitly detailed in the consent document
• The purpose of the secondary research must be compatible with the
initial purpose when consent is not obtained initially
#2019ResearchExpo
What Are the Subject’s Rights Under GDPR?
• Rectification of the personal data
• Notice when their personal data is used
• Includes modifications and erasures
• Can restrict how their data are processed
• Can reject automated individual decision-making
• Access to their personal data collected about them
• Must be able to receive their data and transfer it to a third party
#2019ResearchExpo
I’m a U.S. Researcher, Does This Rule Apply?
• Most research in the U.S. is not subject to this rule
• Exceptions (including but not limited to):
• Web-based surveys
• Studies with long-term follow-up
• Long-term biometric monitoring studies
• Studies sponsored by companies in the EU/EEA
#2019ResearchExpo
How Can I Remain Compliant?
• Exclude people in the EEA from taking web-based surveys
• Ask participants if they’ll be travelling to the EEA during the study
• No GDPR language in consent when people in the EEA aren’t subjects
• Include GDPR template language when appropriate
• The IRB provides template language on our template
“HRP-502 Template – General (2018 Common Rule
Compliant” on our forms page
#2019ResearchExpo
What Happens if I Don’t Follow GDPR?
• Fine of either €20,000,000 or 4% of annual revenue (whichever is
more) for:
• Not having a “lawful basis” to process data or getting insufficient consent
• Not being able to allow individuals to exercise their rights
• Fine of 2% of annual revenue for:
• Not having records in order
• Not providing proper notification of a breach
#2019ResearchExpo
QUESTIONS?

More Related Content

Similar to General-Data-Protection-Regulation-GDPR.pptx

Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
BartLieben
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
Priyab Satoshi
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
Harrison Clark Rickerbys
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
James Mulhern
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
TimBee1
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
TimBee1
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
GrittyCC
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
Elizabeth Dunne B.L. PC.dp
 
Constraintsand challenges
Constraintsand challengesConstraintsand challenges
Constraintsand challenges
jyotikhadake
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
Craig Clark ITIL, CIS LI,EU GDPR P
 
GDPR: What It Is and How (and Which) US Companies Are Affected
GDPR:  What It Is and How (and Which) US Companies Are AffectedGDPR:  What It Is and How (and Which) US Companies Are Affected
GDPR: What It Is and How (and Which) US Companies Are Affected
James C. Roberts III
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
WSO2
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
Symptai Consulting Limited
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
Kwanzoo Inc
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
Zoodikers
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
One North
 

Similar to General-Data-Protection-Regulation-GDPR.pptx (20)

Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
Constraintsand challenges
Constraintsand challengesConstraintsand challenges
Constraintsand challenges
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
GDPR: What It Is and How (and Which) US Companies Are Affected
GDPR:  What It Is and How (and Which) US Companies Are AffectedGDPR:  What It Is and How (and Which) US Companies Are Affected
GDPR: What It Is and How (and Which) US Companies Are Affected
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Preparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection BillPreparing your Business for the Data Protection Bill
Preparing your Business for the Data Protection Bill
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
 

Recently uploaded

How MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdfHow MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdf
MJ Global
 
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdfThe 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
thesiliconleaders
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
SabaaSudozai
 
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
AnnySerafinaLove
 
Income Tax exemption for Start up : Section 80 IAC
Income Tax  exemption for Start up : Section 80 IACIncome Tax  exemption for Start up : Section 80 IAC
Income Tax exemption for Start up : Section 80 IAC
CA Dr. Prithvi Ranjan Parhi
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
SOFTTECHHUB
 
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
Lacey Max
 
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
APCO
 
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel ChartSatta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
my Pandit
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
Christian Dahlen
 
-- June 2024 is National Volunteer Month --
-- June 2024 is National Volunteer Month ---- June 2024 is National Volunteer Month --
-- June 2024 is National Volunteer Month --
NZSG
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
techboxsqauremedia
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
taqyea
 
Building Your Employer Brand with Social Media
Building Your Employer Brand with Social MediaBuilding Your Employer Brand with Social Media
Building Your Employer Brand with Social Media
LuanWise
 
Best practices for project execution and delivery
Best practices for project execution and deliveryBest practices for project execution and delivery
Best practices for project execution and delivery
CLIVE MINCHIN
 
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
my Pandit
 
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
hartfordclub1
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
bosssp10
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
ssuser567e2d
 

Recently uploaded (20)

How MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdfHow MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdf
 
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdfThe 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
 
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
 
Income Tax exemption for Start up : Section 80 IAC
Income Tax  exemption for Start up : Section 80 IACIncome Tax  exemption for Start up : Section 80 IAC
Income Tax exemption for Start up : Section 80 IAC
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
 
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
 
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
 
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel ChartSatta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
 
-- June 2024 is National Volunteer Month --
-- June 2024 is National Volunteer Month ---- June 2024 is National Volunteer Month --
-- June 2024 is National Volunteer Month --
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
 
Building Your Employer Brand with Social Media
Building Your Employer Brand with Social MediaBuilding Your Employer Brand with Social Media
Building Your Employer Brand with Social Media
 
Best practices for project execution and delivery
Best practices for project execution and deliveryBest practices for project execution and delivery
Best practices for project execution and delivery
 
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
 
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
 

General-Data-Protection-Regulation-GDPR.pptx

  • 2. #2019ResearchExpo What is GDPR? • GDPR is a European law which went into effect on May 25, 2018 • Governs the type of notice that must be provided to people regarding how their identifiable data is used • Governs how companies are allowed to use and process identifiable data • Has stricter requirements for using sensitive data
  • 3. #2019ResearchExpo To Whom Does GDPR Apply? • Those who offer goods or services to persons in the EU/EEA • European Economic Area (EEA) = European Union (EU) + Iceland, Liechtenstein, Norway, & UK • Those who control and process data about persons in the EU/EEA • Personal Data = any information that can identify a person • Sensitive Data = race/ethnicity, political opinions, religious/philosophical beliefs, union membership, genetic data, biometric data, health data, data concerning a person’s sex life or sexual orientation.
  • 4. #2019ResearchExpo Who Are Controllers and Processors? • Controllers specify the means and purpose of the data processing • Example: Industry Sponsor, PI of Investigator-Initiated research • Processors conduct the processing under the direction of the controller • Clinical Research Coordinators, Database Administrators, PI of Industry- Sponsored research
  • 5. #2019ResearchExpo What is Data Processing? • Processing of data involves any and all of the following: • Adapting • Altering • Collecting • Combining • Consulting • Destroying • Disclosing • Erasing • Organizing • Recording • Retrieving • Storing • Structuring • Using
  • 6. #2019ResearchExpo What is Needed to Process Data? • A “lawful basis” for doing so • A “lawful basis” can be: • When required for a contract • When required for public interest • When required to comply with a law • When required to protect an individual’s life • When required for the legitimate interests of a third party (no sensitive data) • When freely given consent for a specific purpose has been provided • If sensitive data is being processed, explicit consent for those data elements is required.
  • 7. #2019ResearchExpo What Elements of Consent are Needed? • Name and/or title of the data processor • The purpose and basis for processing of the subject’s data • The type of data to be processed • Remember: When sensitive data are going to be processed, these data elements must be explicitly listed in the consent. • If data will be transferred to a less secure country (i.e. the U.S.)
  • 8. #2019ResearchExpo What is Needed for Legally Effective Consent? • Must be in clear and plain language, intelligible, and easily accessible • Must be specific about the purpose of the data processing • Must be distinguishable from other matters • Must be given by a clear act or statement • Must be an unambiguous indication • Must fully inform the data subject • Must be freely given
  • 9. #2019ResearchExpo I Got Consent! Now What? • Processors and Controllers must ensure privacy: • Limit access to the data • Code or encrypt the data where possible • Limit processing to only the necessary data • Retain the data for the least amount of time possible • Incorporate data protection into the processing activities
  • 10. #2019ResearchExpo What About Secondary Research? • Secondary research also requires a “lawful basis” for processing of personal data • Sensitive data must be explicitly detailed in the consent document • The purpose of the secondary research must be compatible with the initial purpose when consent is not obtained initially
  • 11. #2019ResearchExpo What Are the Subject’s Rights Under GDPR? • Rectification of the personal data • Notice when their personal data is used • Includes modifications and erasures • Can restrict how their data are processed • Can reject automated individual decision-making • Access to their personal data collected about them • Must be able to receive their data and transfer it to a third party
  • 12. #2019ResearchExpo I’m a U.S. Researcher, Does This Rule Apply? • Most research in the U.S. is not subject to this rule • Exceptions (including but not limited to): • Web-based surveys • Studies with long-term follow-up • Long-term biometric monitoring studies • Studies sponsored by companies in the EU/EEA
  • 13. #2019ResearchExpo How Can I Remain Compliant? • Exclude people in the EEA from taking web-based surveys • Ask participants if they’ll be travelling to the EEA during the study • No GDPR language in consent when people in the EEA aren’t subjects • Include GDPR template language when appropriate • The IRB provides template language on our template “HRP-502 Template – General (2018 Common Rule Compliant” on our forms page
  • 14. #2019ResearchExpo What Happens if I Don’t Follow GDPR? • Fine of either €20,000,000 or 4% of annual revenue (whichever is more) for: • Not having a “lawful basis” to process data or getting insufficient consent • Not being able to allow individuals to exercise their rights • Fine of 2% of annual revenue for: • Not having records in order • Not providing proper notification of a breach