Data Sharing in EU
August 2025
Dr Cyril Pernet, PhD
cyril.pernet@nru.dk
@cyrilrpernet.bsky.social
Article 1(2) “The protection of natural persons in relation to the processing of personal data is a fundamental right.”
Recital 26 data-protection principles do not apply to anonymous information, but they do apply to pseudonymised data, because re-identification remains reasonably likely.
Meet Dr Commūnicāre
Problem number 1
One of her patients has a rare condition. She wants to send the DICOM file, with the patient’s name and details, to her colleague in France.
👉 Hands up: how many think this is allowed under GDPR?
👉 And how many think she must first get explicit patient consent?
What does the law say:
GDPR Article 6(1)(d) → processing is lawful if “necessary in order to protect the vital interests of the data subject or of another natural person.”
GDPR Article 6(1)(e) → processing is lawful if “necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.”
GDPR Article 9(2)(h) → explicitly allows processing of special categories of data (including health data) when “necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems …”
We don’t need to help her
Medical professionals don’t need consent to share personal health data with other professionals if it’s necessary for diagnosis or treatment. That’s exactly Dr. Commūnicāre’s case. She is doing her job.
Art 1(3): shall not restrict or prohibit the free movement of personal data within the Union
What is Privacy?
Data privacy: A set of principles and governance rules that define who may access which data and under what conditions. (technical)
Information privacy: “The claim of individuals … to determine for themselves when, how, and to what extent information about them is communicated to others.” (Westin, 1967 - philosophical)
Problem number 2
“Now, she wants to share a BIDS dataset of all her patients with other scientists.
👉 removing all ID = pseudonymization – can she share openly?
(data privacy issue)
|
|
|
Access to freely available datasets like post-codes, census, etc | Gaussian-copula modelling from (incomplete) metadata - not attempt to re-identify here, estimate likelihood of success given the data
| > 95% |
Re-identification and singling-out subjects
Metadata in neuroimaging !!
blurred
zero-ed
Re-identification from structural MRI
Loss of potential information!! defacing is likely not a solution anyway
Re-identification from PET
Re-identification from f-MRI
Re-identification from MEEG
good discriminability, stability over time, and tightly correlated with molecular expression/genes
|
|
|
|
Refacing Face matching | GANS, CNN, training is hard Access to freely available datasets photos like Facebook | - Reconstructing 3D MRI is mega easy - read the doc to use automated face-recognition software | 80-90% (Schwarz, et al. 2019) |
Re-identification from connectome | Access to multiple datasets and possibly original data | Imaging and connectomic knowledge, HPC - infer subject across sets, task performance, possibly ID if access to some original data | ~ 90% |
Re-identification from time series | Access to metadata outside the dataset to link genetic/molecular markers | Time-series and Spectral analysis knowledge | ?? |
Re-identification in neuroimaging
Neuroimaging data types under GDPR
Adapted from Poldrack & Gorgolewski (2014) https://www.nature.com/articles/nn.3818
Potential for reuse
Raw (+ clinical) + processed data
Personal
Raw data
Subject level summary data
Anonymous
/ Personal ?? lot of work to do
Anonymous
Group level summary data
Personal
Pseudonymization is a process – there is only two types of data
Problem number 2
“Now, she wants to share a BIDS dataset of all her patients with other scientists.
�👉 removing all ID = pseudonymization – can she share openly?
I’d say, no – imaging data remains personal (+ clinical data) and thus she needs to share under restricted access
👉 sharing with others – does she need consent for that?
(information privacy issue)
GDRP - again
Article 6(1)(e) – processing is lawful if “necessary for the performance of a task carried out in the public interest”. In most EU countries, scientific research by healthcare institutions and universities is considered such a task.
Article 9(2)(j) – allows processing of special categories (health data) if “necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes … subject to Article 89(1) safeguards.”
Article 89(1) – requires safeguards like pseudonymization, minimization, and governance.
(consent to be in a study obviously ≠ consent to share)
GDRP - again
Article 5(1)(b) – Purpose limitation: Data collected for one purpose can be further processed for scientific research purposes, provided Article 89 safeguards are applied.
Article 5(1)(e) – Storage limitation: Data may be stored longer “for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes” (again subject to safeguards in Art. 89).
🡪 Researchers have the flexibility on purpose limitation, storage and certain data-subject rights; in exchange, they must demonstrate state-of-the-art safeguards that keep data from becoming a vector of re-identification or discrimination.
Declaration of Taipei (2016)
Ethical use of health data beyond current studies.�Importance of transparency, patient autonomy, and trust.�→ Key idea: Patients’ right to control future use of their data.
Dynamic consent is a pretty tough ask, but at least we need to inform people on sharing, the consequences of sharing, and the ability to revoke access to people’s data.
Problem number 2
“Now, she wants to share a BIDS dataset of all her patients with other scientists.
�👉 removing all ID = pseudonymization – can she share openly?
I’d say, no – imaging data remains personal (+ clinical data) and thus she needs to share under restricted access
👉 sharing with others – does she need consent for that?
I’d say, at least information must be given about the sharing process, consequences, and ability to withdraw data + come up with a firm data sharing policy (~ license)
Explain how it will be shared
Explain re-usage, any limitations?
Consequences of sharing
For how long are data kept
How can people remove their data if they want to
If you want a consent to share …
A solution for sharing
PublicnEUro.eu
What does it looks like?
What does it looks like?
What about other datasets?
Each dataset comes with it’s own rules -- i.e. you tell us how you need your data to be legally shared and the platform accommodates your need.
What about other datasets?
Each dataset comes with it’s own rules -- i.e. you tell us how you need your data to be legally shared and the platform accommodates your need.
→ not only you can browse but it lists all sorts of metadata
What about other datasets?
Each dataset comes with it’s own rules -- i.e. you tell us how you need your data to be legally shared and the platform accommodates your need.
→ not only you can browse but it lists all sorts of metadata
What about other datasets?
Each dataset comes with it’s own rules -- i.e. you tell us how you need your data to be legally shared and the platform accommodates your need.
→ not only you can browse but it lists all sorts of metadata
→ PN000004 approve DUA online and download
What about other datasets?
→ PN000002 sign paperwork and re-upload, await approval, receive the link to download
(login as wam from Home, USA)
→ Note the SSC is something related to the institution, some layer/DPO/HoD has to approve this (and then works for all users)
You contract us
(yes there is a small fee for service and hosting)
Sharing on PublicnEUro for Dr Commūnicāre
Thank you for your attention: let’s free imaging data!