Riou Christine, El Azzouzi Mohamed, Hespel Anne, Guillou Emeric, Coatrieux Gouenou, Cuggia Marc
University Hospital of Rennes, 2 rue Henri Le Guilloux, Rennes, 35000, France, 33 0299284215.
DOMASIA, LTSI, UMR INSERM, University of Rennes, Rennes, France.
JMIR Med Inform. 2025 Apr 17;13:e63754. doi: 10.2196/63754.
BACKGROUND: The European Union's General Data Protection Regulation (GDPR) has profoundly influenced health data management, with significant implications for clinical data warehouses (CDWs). In 2021, France pioneered a national framework for GDPR-compliant CDW implementation, established by its data protection authority (Commission Nationale de l'Informatique et des Libertés). This framework provides detailed guidelines for health care institutions, offering a unique opportunity to assess practical GDPR implementation in health data management. OBJECTIVE: This study evaluates the real-world applicability of France's CDW framework through its implementation at a major university hospital. It identifies practical challenges for its implementation by health institutions and proposes adaptations relevant to regulatory authorities in order to facilitate research in secondary use data domains. METHODS: A systematic assessment was conducted in May 2023 at the University Hospital of Rennes, which manages data for over 2 million patients through the eHOP CDW system. The evaluation examined 116 criteria across 13 categories using a dual-assessment approach validated by information security and data protection officers. Compliance was rated as met, unmet, or not applicable, with criteria classified as software-related (n=25) or institution-related (n=91). RESULTS: Software-related criteria showed 60% (n=15) compliance, with 28% (n=7) noncompliant or partially compliant and 12% (n=3) not applicable. Institution-related criteria achieved 72% (n=28) compliance for security requirements. Key challenges included managing genetic data, implementing automated archiving, and controlling data exports. The findings revealed effective privacy protection measures but also highlighted areas requiring regulatory adjustments to better support research. CONCLUSIONS: This first empirical assessment of a national CDW compliance framework offers valuable insights for health care institutions implementing GDPR requirements. While the framework establishes robust privacy protections, certain provisions may overly constrain research activities. The study identifies opportunities for framework evolution, balancing data protection with research imperatives.
JMIR Mhealth Uhealth. 2024-6-21
Stud Health Technol Inform. 2018
Ned Tijdschr Geneeskd. 2019-11-14
BMC Med Inform Decis Mak. 2009-6-15
JMIR Med Inform. 2019-3-25
Sci Data. 2023-7-13
Int J Environ Res Public Health. 2023-1-16
Med Health Care Philos. 2023-6
Int J Environ Res Public Health. 2022-6-16
Med J Aust. 2022-6-20