« UK-NCSC COVID-19関連の電子メール詐欺を報告するよう市民に要請 | Main | Cloud Security Alliance がクラウド上でのインシデント対応のフレームワーク(クイックガイド)を公表していますね。。。 »

2020.04.23

欧州データ保護委員会 COVID-19に関する研究目的の健康データ処理についてのガイドライン

こんにちは、丸山満彦です。

欧州データ保護委員会がCOVID-19に関する研究目的の健康データ処理についてのガイドラインを公表していますね。。。

Europian Data Protection Board (EDPB)

・2020.04.21 Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak

・[PDF]

 

 

Table of contents
1.Introduction
2.Application of the GDPR
3.Definitions
 3.1 “Data concerning health”
 3.2 “Processing for the purpose of scientific research”
 3.3 “Furthåer processing”
4. Legal basis for the processing
4.1 Consent
4.2 National legislations
5. Data protection principles
 5.1 Transparency and information to data subjects
  5.1.1 When must the data subject be informed?
  5.1.2 Exemptions
 5.2 Purpose limitation and presumption of compatibility
 5.3 Data minimisation and storage limitation
 5.4 Integrity and confidentiality
6. Exercise of the rights of data subjects
7. International data transfers for scientific research purposes
8. Summary 

-----

8. Summary 

The key findings of these guidelines are:
1. The GDPR provides special rules for the processing of health data for the purpose of scientific research that are also applicable in the context of the COVID-19 pandemic.
2. The national legislator of each Member State may enact specific laws pursuant to Article (9) (2) (i) and (j) GDPR to enable the processing of health data for scientific research purposes. The processing of health data for the purpose of scientific research must also be covered by one of the legal bases in Article 6 (1) GDPR. Therefore, the conditions and the extent for such processing varies depending on the enacted laws of the particular member state.

3. All enacted laws based on Article (9) (2) (i) and (j) GDPR must be interpreted in the light of the principles pursuant to Article 5 GDPR and in consideration of the jurisprudence of the ECJ. In particular, derogations and limitations in relation to the protection of data provided in Article 9 (2) (j) and Article 89 (2) GDPR must apply only in so far as is strictly necessary.

4. Considering the processing risks in the context of the COVID-19 outbreak, high emphasise must be put on compliance with Article 5 (1) (f), Article 32 (1) and Article 89 (1) GDPR. There must be an assessment if a DPIA pursuant to Article 35 GDPR has to be carried out.

5. Storage periods (timelines) shall be set and must be proportionate. In order to define such storage periods, criteria such as the length and the purpose of the research should be taken into account. National provisions may stipulate rules concerning the storage period as well and must therefore be considered.

6. In principle, situations as the current COVID-19 outbreak do not suspend or restrict the possibility of data subjects to exercise their rights pursuant to Article 12 to 22 GDPR. However, Article 89 (2) GDPR allows the national legislator to restrict (some) of the data subject’s rights as set in Chapter 3 of the GDPR. Because of this, the restrictions of the rights of data subjects may vary depending on the enacted laws of the particular Member State.

7. With respect to international transfers, in the absence of an adequacy decision pursuant to Article 45 (3) GDPR or appropriate safeguards pursuant to Article 46 GDPR, public authorities and private entities may rely upon the applicable derogations pursuant to Article 49 GDPR. However, the derogations of Article 49 GDPR do have exceptional character only.

|

« UK-NCSC COVID-19関連の電子メール詐欺を報告するよう市民に要請 | Main | Cloud Security Alliance がクラウド上でのインシデント対応のフレームワーク(クイックガイド)を公表していますね。。。 »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« UK-NCSC COVID-19関連の電子メール詐欺を報告するよう市民に要請 | Main | Cloud Security Alliance がクラウド上でのインシデント対応のフレームワーク(クイックガイド)を公表していますね。。。 »