Transcription of The EU General Data Protection Regulation: Implications ...
1 The EU General data Protection Regulation: Implications for ResearchLeslie Thornton, PhD, JDAssociate, Ropes & GrayNick Wallace, JDAssociate, Ropes & GrayJune 13, 2018 About AdvarraNorth America s premier provider of IRB, IBC and global research compliance servicesLeverage strengths in technology, regulatory expertise and customer service to serve increasingly complex research needsAbout AdvarraCombined 50+ years of experience Access to over 2,000 unique institutional research sitesGlobal consulting services The industry s most comprehensive and efficient Today s PresentersLeslie Thornton, PhD, JDAssociate, Ropes & GrayPractices in the health care clients on a broad range of compliance, regulatory and transactional issues, with a primary focus on research, including pre-clinical and clinical trials, federal grants and contracts, research misconduct, government enforcement, and privacy (HIPAA, GDPR).
2 Completed secondmentswithin the in-house research and development legal divisions of two manufacturers. Works with academic medical centers, universities, research institutes, hospitals, pharmaceutical and medical device manufacturers, managed care plans, health-focused startups, long-term care providers and other health care from Johns Hopkins Bloomberg School of Public HealthJD from University of California, Berkeley School of Law Served as supervising editor of California Law ReviewAbout Today s PresenterNick Wallace, JDAssociate, Ropes & GrayPractices in the health care clients on investigations.
3 Audits and regulatory matters, especially in the research and reimbursement on a variety of issues, including privacy regulations (HIPAA and GDPR), federal grant issues, informed consent, good clinical practice, research misconduct, and health care provider with clinical trial sponsors, universities, hospitals, research sites and other health care and life sciences from Yale Law School Served as editor of Yale Journal on RegulationThe EU General data Protection Regulation: Implications for Research Leslie Thornton, , Wallace.
4 Introduction to the GDPR Jurisdictional Scope of the GDPR Bases for Processing Personal data Consent under the GDPR Bases for Transferring Personal data Implications if GDPR Applies to Entities Hypotheticals/ExamplesAGENDA2 Introduction to the GDPR Jurisdictional Scope of the GDPR Bases for Processing Personal data Consent under the GDPR Bases for Transferring Personal data Implications if GDPR Applies to Entities Hypotheticals/ExamplesAGENDA3 Introduction Effective May 25, 2018, the european union s General data Protection Regulation (the GDPR ) has implemented a number of changes to privacy law in the european Economic Area ( EEA ).
5 This presentation provides an overview of certain situations in which GDPR may affect the research-related activities of entities, including companies, academic medical centers ( AMCs ), universities, and other research organizations. GDPR compliance will be especially relevant to Institutional Review Boards ( IRBs ) and Ethics Committees ( ECs ), charged with ensuring the ethical conduct of research, one dimension of which is respect for the privacy of subjects and the confidentiality of data . 4 GDPR and Superseded data Protection Directive GDPR superseded the prior EU data Protection Directive, which was adopted in 1995.
6 See EU data Privacy Directive (Directive 95/46/EC) (the Directive ) The Directive and GDPR apply in the 28 EU member states and 3 additional countries (Iceland, Liechtenstein and Norway) that together make up the EEA. The United Kingdom is preparing for GDPR implementation despite Brexit. As a regulation under EU law, the GDPR will apply directly across all of the EEA s member states, unlike the Directive, which supplied General principles that required implementation in the national legislation of each member of EEA Member States6 Personal data under the GDPR Personal data are defined broadly to include: [A]ny information relating to an identified or identifiable natural person( data subject ).
7 GDPR, Art. 4(1) An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data , online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identityof that person. GDPR, Art. 4(1)7 Personal data under the GDPR Set of data to which GDPR applies is broader than that covered under the Health Insurance Portability and Accountability Act of 1996 ( HIPAA ).
8 Applies to all personal data across all sectors of the economy, not only health care; no concept of covered entity. Personal data under GDPR include, for example, identifying information on EEA health care providers ( HCPs ), such as principal investigators, and other persons who are not patients. Research sponsors likely will also obtain this data from non-human subjects, such as those conducting the study. IRBs/ECs will need to consider Protection of a broader range of research subjects personal data under the Personal data under the GDPR Under GDPR, no anonymisation safe harbor akin to HIPAA removal of identifiers.
9 Whether data are anonymized such that they are no longer identifiable is judged on a facts and circumstances test, taking into account all the means reasonably likely to be used .. [e]ither by the controller or by another person to identify the natural person directly or indirectly. GDPR, Recital 26 Pseudonymised data ( , key-coded data ) remain personal data . 9 Special Categories of Personal data under the GDPR Prohibition on processing special categories of personal data absent an applicable exception. Special categories of personal data include: Racial or ethnic origin data concerning health data concerning a natural person s sex life or sexual orientation Genetic data Biometric data used for the purpose of uniquely identifying an individual Political opinions, religious or philosophical beliefs, or trade union membership GDPR, Art.
10 910 Controller vs. Processor Controller:Alone or jointly with others determines the purposes and meansof processing personal data . Processor:Processes personal data on behalf of the controller. Both controllers and processors regulated directly under GDPR. Controllers have more responsibilities, for example: Providing notices to data subjects, responding to exercise of subject rights, appointing representative in EEA, notifying supervisory authorities and data subjects of data breaches, maintaining records of Introduction to the GDPR Jurisdictional Scope of the GDPR Bases for Processing Personal data Consent under the GDPR Bases for Transferring Personal data Implications if GDPR Applies to Entities Hypotheticals/ExamplesAGENDA12 Directive s Application to Organizations GDPR applies apply extraterritorially in a broader range of circumstances than those in which the Directive had applied.