Boussi Rahmouni Hanene, Solomonides Tony, Casassa Mont Marco, Shiu Simon
Bristol Institute of Technology, University of the West of England, Bristol BS16 1QY, UK.
Stud Health Technol Inform. 2009;150:695-9.
The harmonization of data protection legislation in Europe has been theoretically achieved by means of the EU directive on data protection. In practice the harmonization is not absolute and conflicts and inconsistencies continue to exist in the way Member States are implementing the directive. The integration of different European medical systems by means of grid technologies will continue to be challenging if technology does not intervene to enhance interoperability between national regulatory frameworks on data protection. In this paper we present an approach to automate privacy requirements for the sharing of patient data across Europe on a healthgrid domain and ensure its enforcement internally and within external domains where the data might travel. This approach is based on the semantic modelling of privacy obligations that are of legal, ethical or cultural nature. These requirements are for the sharing of personal data between different European Member States. Our model reflects both similarities and conflicts, if any, between the different Member States. This allows us to reason on the safeguards a data controller should ask from an organization belonging to another Member State before disclosing medical data to them. The system will also generate the relevant set of policies to be enforced at the process level of the grid to ensure privacy compliance before allowing access to the data.
欧洲数据保护立法的协调在理论上已通过欧盟数据保护指令得以实现。但在实践中,这种协调并非绝对,成员国在实施该指令的方式上仍存在冲突和不一致之处。如果技术不进行干预以增强国家数据保护监管框架之间的互操作性,那么通过网格技术整合不同的欧洲医疗系统仍将面临挑战。在本文中,我们提出了一种方法,用于自动确定在健康网格领域跨欧洲共享患者数据时的隐私要求,并确保在数据可能传输的内部和外部领域内执行这些要求。此方法基于对具有法律、伦理或文化性质的隐私义务进行语义建模。这些要求适用于不同欧洲成员国之间的个人数据共享。我们的模型反映了不同成员国之间的相似之处和冲突(如有)。这使我们能够推断出数据控制者在向属于另一个成员国的组织披露医疗数据之前应向其提出的保障措施。该系统还将生成在网格流程级别执行的相关政策集,以确保在允许访问数据之前符合隐私规定。