Becker Regina, Chokoshvili Davit, Thorogood Adrian, Dove Edward S, Molnár-Gábor Fruzsina, Ziaka Alexandra, Tzortzatou-Nanopoulou Olga, Comandè Giovanni
Luxembourg National Data Service, L-4362 Esch-sur-Alzette, Luxembourg.
Terry Fox Research Institute, V5Z 1L3 Vancouver, Canada.
J Law Biosci. 2024 Feb 1;11(1):lsae001. doi: 10.1093/jlb/lsae001. eCollection 2024 Jan-Jun.
The General Data Protection Regulation (GDPR) of the European Union, which became applicable in 2018, contains a new accountability principle. Under this principle, controllers (ie parties determining the purposes and the means of the processing of personal data) are responsible for ensuring and demonstrating the overall compliance with the GDPR. However, interpretive uncertainties of the GDPR mean that controllers must exercise considerable judgement in designing and implementing an appropriate compliance strategy, making GDPR compliance both complex and resource-intensive. In this article, we provide conceptual clarity around GDPR compliance with respect to one core aspect of the law: the determination and relevance of the purpose of personal data processing. We derive from the GDPR's text concrete requirements for purpose specification, which we subsequently apply to the area of secondary use of personal data for scientific research. We offer guidance for correctly specifying purposes of data processing under different research scenarios. To illustrate the practical necessity of purpose specification for GDPR compliance, we then show how our proposed approach can enable controllers to meet their compliance obligations, using the example of the overarching GDPR principle of lawfulness to highlight the relevance of purpose specification for the identification of a suitable legal basis.
欧盟的《通用数据保护条例》(GDPR)于2018年开始适用,其中包含一项新的问责原则。根据这一原则,控制者(即决定个人数据处理目的和方式的各方)有责任确保并证明全面遵守GDPR。然而,GDPR的解释不确定性意味着控制者在设计和实施适当的合规策略时必须行使相当大的判断力,这使得GDPR合规既复杂又耗费资源。在本文中,我们围绕GDPR合规在该法律的一个核心方面提供概念上的清晰性:个人数据处理目的的确定及其相关性。我们从GDPR的文本中得出目的规范的具体要求,随后将其应用于个人数据用于科学研究的二次使用领域。我们为在不同研究场景下正确确定数据处理目的提供指导。为了说明目的规范对于GDPR合规的实际必要性,我们接着以GDPR的首要合法性原则为例,展示我们提出的方法如何使控制者履行其合规义务,以突出目的规范对于确定合适法律依据的相关性。