Data Protection Principals Flashcards
Lawfulness, fairness and transparency
The EU General DataProtection Regulation Training Deck
Clinical Operations Training - Slide 5
- Personal data must be processed based on valid grounds under the GDPR.
- Personal data must be processed in a “transparent manner in relation to the data subject.” Reflected in an increased amount of information to be provided to individuals when collecting and processing their personal data, i.e. Informed Consent Forms.
- Ethics Committees sometimes delete the GDPR wording as unnecessarily confusing potentially putting the Sponsor and the Site in breach of their GDPR “fairness and transparency” obligations.
Purpose Limitation
The EU General DataProtection Regulation Training Deck
Clinical Operations Training - Slide 5
- Data must only be collected for specified, explicit and legitimate purposes and not used in manner incompatible with those purposes.
- Limited exceptions for scientific research in the public interest using pseudonymous data.
- Legislative factors to take into account when assessing if a new use for data is “compatible” with its original purposes.
- Secondary use of data which is anonymised does not fall within the scope of the GDPR.
Regarding Purpose Limitation: (complete the sentence)
Data must only be collected for specified, explicit and legitimate purposes and not used in any manner…
The EU General DataProtection Regulation Training Deck
Clinical Operations Training - Slide 5
…incompatible with those purposes.
Regarding Purpose Limitation: (complete the sentence)
Limited exceptions for scientific research in the public interest using…
The EU General DataProtection Regulation Training Deck
Clinical Operations Training - Slide 5
…pseudonymous data.
Regarding Purpose Limitation: (complete the sentence)
Legislative factors to take into account when assessing if a new use for data is…
The EU General DataProtection Regulation Training Deck
Clinical Operations Training - Slide 5
…“compatible” with its original purposes.
True or False
Secondary use of data which is anonymised does fall within the scope of the GDPR.
The EU General DataProtection Regulation Training Deck
Clinical Operations Training - Slide 5
False