Insights Imaging. 2017 Jun;8(3):295-299. doi: 10.1007/s13244-017-0552-7. Epub 2017 Apr 24.
The European Society of Radiology (ESR) informs its membership and its associated Institutional Members about the new General Data Protection Regulation (GDPR) of the European Union (EU,) which will apply from 25 May 2018. Radiologists and radiology departments should be prepared to comply with several new rules for the protection of imaging data. Although the new GDPR applies to all domains of the public and private sectors, some specific derogations are defined for data concerning health, aiming at protecting the rights of data subjects and confidentiality of their personal health data, whilst preserving the benefits of processing data, including digital images for research and public health purposes. Specific new obligations which healthcare providers (including radiologists/radiology departments) should prepare for include data access for patients, rules for data processing including explicit consent of the data subject in the absence of derogations, or technical and organisational safeguards. National health authorities can define exceptions and derogations from certain obligations by means of national law. They will also define sanctions in the form of penalties or fines that may be applicable for organisations of the public and private sector that fail to comply with the rules of the GDPR.
• Explicit consent prior to data processing will be necessary. • Explicit consent prior to communication of imaging data will be necessary. • Providing patient access to their personal data, including portability, will be required. • Certain derogations and exceptions exist for healthcare and research. • Additional specific rules may be defined by national law.
欧洲放射学会(ESR)向其成员及其相关机构成员通报了欧盟(EU)新的《通用数据保护条例》(GDPR),该条例将于2018年5月25日起生效。放射科医生和放射科应准备好遵守若干保护影像数据的新规定。尽管新的GDPR适用于公共和私营部门的所有领域,但针对健康相关数据定义了一些特定的豁免规定,旨在保护数据主体的权利及其个人健康数据的保密性,同时保留处理数据(包括用于研究和公共卫生目的的数字图像)的益处。医疗服务提供者(包括放射科医生/放射科)应准备应对的特定新义务包括患者的数据访问权、数据处理规则(包括在无豁免情况下数据主体的明确同意)以及技术和组织保障措施。国家卫生当局可通过国内法界定某些义务的例外情况和豁免规定。他们还将确定对未遵守GDPR规则的公共和私营部门组织适用的处罚或罚款形式的制裁措施。
• 数据处理前需要明确同意。• 影像数据传输前需要明确同意。• 需要向患者提供其个人数据的访问权,包括可携带性。• 医疗保健和研究存在某些豁免和例外情况。• 国内法可能会定义其他特定规则。