Cargando…

DAISY: A Data Information System for accountability under the General Data Protection Regulation

BACKGROUND: The new European legislation on data protection, namely, the General Data Protection Regulation (GDPR), has introduced comprehensive requirements for the documentation about the processing of personal data as well as informing the data subjects of its use. GDPR’s accountability principle...

Descripción completa

Detalles Bibliográficos
Autores principales: Becker, Regina, Alper, Pinar, Grouès, Valentin, Munoz, Sandrine, Jarosz, Yohan, Lebioda, Jacek, Rege, Kavita, Trefois, Christophe, Satagopam, Venkata, Schneider, Reinhard
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Oxford University Press 2019
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6892452/
https://www.ncbi.nlm.nih.gov/pubmed/31800037
http://dx.doi.org/10.1093/gigascience/giz140
_version_ 1783476031501369344
author Becker, Regina
Alper, Pinar
Grouès, Valentin
Munoz, Sandrine
Jarosz, Yohan
Lebioda, Jacek
Rege, Kavita
Trefois, Christophe
Satagopam, Venkata
Schneider, Reinhard
author_facet Becker, Regina
Alper, Pinar
Grouès, Valentin
Munoz, Sandrine
Jarosz, Yohan
Lebioda, Jacek
Rege, Kavita
Trefois, Christophe
Satagopam, Venkata
Schneider, Reinhard
author_sort Becker, Regina
collection PubMed
description BACKGROUND: The new European legislation on data protection, namely, the General Data Protection Regulation (GDPR), has introduced comprehensive requirements for the documentation about the processing of personal data as well as informing the data subjects of its use. GDPR’s accountability principle requires institutions, projects, and data hubs to document their data processings and demonstrate compliance with the GDPR. In response to this requirement, we see the emergence of commercial data-mapping tools, and institutions creating GDPR data register with such tools. One shortcoming of this approach is the genericity of tools, and their process-based model not capturing the project-based, collaborative nature of data processing in biomedical research. FINDINGS: We have developed a software tool to allow research institutions to comply with the GDPR accountability requirement and map the sometimes very complex data flows in biomedical research. By analysing the transparency and record-keeping obligations of each GDPR principle, we observe that our tool effectively meets the accountability requirement. CONCLUSIONS: The GDPR is bringing data protection to center stage in research data management, necessitating dedicated tools, personnel, and processes. Our tool, DAISY, is tailored specifically for biomedical research and can help institutions in tackling the documentation challenge brought about by the GDPR. DAISY is made available as a free and open source tool on Github. DAISY is actively being used at the Luxembourg Centre for Systems Biomedicine and the ELIXIR-Luxembourg data hub.
format Online
Article
Text
id pubmed-6892452
institution National Center for Biotechnology Information
language English
publishDate 2019
publisher Oxford University Press
record_format MEDLINE/PubMed
spelling pubmed-68924522019-12-10 DAISY: A Data Information System for accountability under the General Data Protection Regulation Becker, Regina Alper, Pinar Grouès, Valentin Munoz, Sandrine Jarosz, Yohan Lebioda, Jacek Rege, Kavita Trefois, Christophe Satagopam, Venkata Schneider, Reinhard Gigascience Technical Note BACKGROUND: The new European legislation on data protection, namely, the General Data Protection Regulation (GDPR), has introduced comprehensive requirements for the documentation about the processing of personal data as well as informing the data subjects of its use. GDPR’s accountability principle requires institutions, projects, and data hubs to document their data processings and demonstrate compliance with the GDPR. In response to this requirement, we see the emergence of commercial data-mapping tools, and institutions creating GDPR data register with such tools. One shortcoming of this approach is the genericity of tools, and their process-based model not capturing the project-based, collaborative nature of data processing in biomedical research. FINDINGS: We have developed a software tool to allow research institutions to comply with the GDPR accountability requirement and map the sometimes very complex data flows in biomedical research. By analysing the transparency and record-keeping obligations of each GDPR principle, we observe that our tool effectively meets the accountability requirement. CONCLUSIONS: The GDPR is bringing data protection to center stage in research data management, necessitating dedicated tools, personnel, and processes. Our tool, DAISY, is tailored specifically for biomedical research and can help institutions in tackling the documentation challenge brought about by the GDPR. DAISY is made available as a free and open source tool on Github. DAISY is actively being used at the Luxembourg Centre for Systems Biomedicine and the ELIXIR-Luxembourg data hub. Oxford University Press 2019-12-04 /pmc/articles/PMC6892452/ /pubmed/31800037 http://dx.doi.org/10.1093/gigascience/giz140 Text en © The Author(s) 2019. Published by Oxford University Press. http://creativecommons.org/licenses/by/4.0/ This is an Open Access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/), which permits unrestricted reuse, distribution, and reproduction in any medium, provided the original work is properly cited.
spellingShingle Technical Note
Becker, Regina
Alper, Pinar
Grouès, Valentin
Munoz, Sandrine
Jarosz, Yohan
Lebioda, Jacek
Rege, Kavita
Trefois, Christophe
Satagopam, Venkata
Schneider, Reinhard
DAISY: A Data Information System for accountability under the General Data Protection Regulation
title DAISY: A Data Information System for accountability under the General Data Protection Regulation
title_full DAISY: A Data Information System for accountability under the General Data Protection Regulation
title_fullStr DAISY: A Data Information System for accountability under the General Data Protection Regulation
title_full_unstemmed DAISY: A Data Information System for accountability under the General Data Protection Regulation
title_short DAISY: A Data Information System for accountability under the General Data Protection Regulation
title_sort daisy: a data information system for accountability under the general data protection regulation
topic Technical Note
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6892452/
https://www.ncbi.nlm.nih.gov/pubmed/31800037
http://dx.doi.org/10.1093/gigascience/giz140
work_keys_str_mv AT beckerregina daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT alperpinar daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT grouesvalentin daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT munozsandrine daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT jaroszyohan daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT lebiodajacek daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT regekavita daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT trefoischristophe daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT satagopamvenkata daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation
AT schneiderreinhard daisyadatainformationsystemforaccountabilityunderthegeneraldataprotectionregulation