Vukovic Jakov, Ivankovic Damir, Habl Claudia, Dimnjakovic Jelena
Division for Health Informatics and Biostatistics, Croatian Institute of Public Health, Rockefellerova, Street 7, 10 000, Zagreb, Croatia.
Academisch Medisch Centrum Universiteit Van Amsterdam, Meibergdreef 9, 1105, Amsterdam, AZ, Netherlands.
Arch Public Health. 2022 Apr 9;80(1):115. doi: 10.1186/s13690-022-00866-7.
The General Data Protection Regulation is a regulation in EU law on data protection and privacy in the European Union. We aimed to provide an overview of the General Data Protection Regulation (GDPR) enablers and barriers to the secondary use of health data in Europe from the research we conducted in the Joint Action InfAct (Information for Action!) WP10 Assessing and piloting interoperability for public health policy, as well as to provide an example of a national-level case study on experiences with secondary use of health data and GDPR on an example of the Austrian COVID-19 data platform.
We have identified a number of European initiatives, projects and organizations that have dealt with cross-border health data sharing, linkage and management by desk research and we conducted 17 semi-structured in-depth interviews and analyzed the interview transcripts by framework analysis.
GDPR was seen as an enabler to the secondary use of health data in Europe when it comes to user rights over their data, pre-existing laws regarding data privacy and data sharing, sharing anonymized statistics, developing new data analysis approaches, patients` trust towards dealing with their health data and transparency. GDPR was seen as a barrier to the secondary use of health data in Europe when it comes to identifiable and individual-level data, data sharing, time needed to complete the process, workload increase, differences with local legal legislations, different (and stricter) interpretations and access to data.
The results of our analysis show that GDPR acts as both an enabler and a barrier for the secondary use of health data in Europe. More research is needed to better understand the effects of GDPR on the secondary use of health data which can serve as a basis for future changes in the regulation.
《通用数据保护条例》是欧盟法律中关于欧盟数据保护和隐私的一项条例。我们旨在通过我们在联合行动InfAct(行动信息!)项目10“评估和试点公共卫生政策的互操作性”中开展的研究,概述《通用数据保护条例》(GDPR)对欧洲健康数据二次使用的促进因素和障碍,并以奥地利新冠疫情数据平台为例,提供一个关于健康数据二次使用和GDPR国家层面案例研究的实例。
我们通过案头研究确定了一些处理跨境健康数据共享、链接和管理的欧洲倡议、项目和组织,并进行了17次半结构化深度访谈,通过框架分析对访谈记录进行了分析。
在用户对其数据的权利、关于数据隐私和数据共享的现有法律、共享匿名统计数据、开发新的数据分析方法、患者对处理其健康数据的信任以及透明度方面,GDPR被视为欧洲健康数据二次使用的促进因素。在可识别的个人层面数据、数据共享、完成流程所需时间、工作量增加、与地方法规的差异、不同(且更严格)的解释以及数据访问方面,GDPR被视为欧洲健康数据二次使用的障碍。
我们的分析结果表明,GDPR对欧洲健康数据的二次使用既是促进因素,也是障碍。需要更多研究来更好地理解GDPR对健康数据二次使用的影响,这可为该法规未来的变化提供依据。