1 of 49

Research Data Management & Open Science

This presentation is a part of Aalto University’s webinar series on

Autumn 2023

All slides in this presentation are licensed with CC-BY and can be reused with attribution unless explicitly mentioned otherwise.

2 of 49

Handling of Personal Data in Research

Enrico Glerean, Staff Scientist and Data Agent

Anniina Harju, Legal Counsel

Essi Viitanen, Senior Advisor and Data Agent

30.10.2023

3 of 49

Outline: Personal Data in Research

  1. What are personal data? Why do we need to handle them differently?
  2. Handling of personal data step-by-step
  3. Open questions and cases from the participants

Please note that what we cover here is “personal data in research”. Although similar considerations will apply for non-research purposes, it is always better to contact your School’s legal advisor if you need any clarification.

These slides have a CC-BY-4.0 license, feel free to reuse! Thanks to past collaborators on the materials of these slides: Päivi Lindström, Antti Rousi, Maria Rehbinder.

4 of 49

References

When in doubt, ask! researchdata@aalto.fi or your dept. legal advisor or data agent

5 of 49

1. What is personal data?

6 of 49

What is personal data?

  • Personal data is a broad concept under the EU’s General Data Protection Regulation (GDPR)
  • “Personal data” is any data about living people from which they can be identified
    • If you collect information from or of persons, consider it as personal data
    • Exception: anonymous data

7 of 49

Personal data: �direct and indirect identifiers

  1. Direct identifiers: information which is sufficient on its own to identify an individual-  e.g. a person’s name, email address (containing the person’s name), personal identification number, fingerprints, a facial image, a person's voice, video, brain scan images, dental records, DNA

  • Strong indirect identifiers: information which can be used to identify an individual fairly easily- e.g. a postal address, a phone number, a vehicle registration number, bibliographic citation of a publication, an email address not in the form of the personal name, an unusual job title, a very rare disease, a job position held by only one person at a time, a student ID number, a bank account number, IP address of a computer, cookie identifier, RFID tags, location data

  • Indirect identifiers: information that on its own is not enough to identify someone but, when linked with other available information, could be used to deduce the identity of a person- e.g. age, gender, education, status in employment, economic activity and occupational status, socio-economic status, household composition, income, marital status, mother tongue, ethnic background, place of work or study, postal code, municipality, major region.

��

8 of 49

Special categories of personal data (art 9)

  • personal data revealing racial or ethnic origin;
  • personal data revealing political opinions;
  • personal data revealing religious or philosophical beliefs;
  • personal data revealing trade union membership;
  • genetic data, biometric data (where used for identification purposes);
  • data concerning health;
  • data concerning a person’s sex life and data concerning a person’s sexual orientation.

9 of 49

The principles of the GDPR (art 5)

GDPR Principle

Practical Actions in Research Projects

1. Lawfulness, fairness, and transparency

Obtain and manage informed consent from research participants�Clearly explain data processing activities, purposes, and potential risks to participants�Maintain transparency in data sharing, storage, and access policies

2. Purpose limitation

Specify the research objectives and data processing purposes before collecting personal data

Use collected data only for the stated purposes�Obtain additional consent or establish a new legal basis if the purpose changes

3. Data minimization

Collect only the minimum amount of personal data necessary to achieve research objectives�Employ data anonymization or pseudonymization techniques to reduce the scope of identifiable information

4. Accuracy

Implement processes to ensure the accuracy and up-to-date nature of personal data�Allow research participants to rectify inaccurate or incomplete information�Regularly review and update collected data as needed

5. Storage limitation

Establish retention periods for personal data based on research objectives and legal requirements�Regularly delete or anonymize personal data when it is no longer necessary for the stated purpose or when the retention period ends

6. Integrity and confidentiality

Use appropriate security measures to protect personal data from unauthorized access, disclosure, or misuse�Train research team members on data protection and privacy practices�Implement access controls and encryption for data storage and transfer

7. Accountability

Document data processing activities, legal bases, and compliance measures�Conduct data protection impact assessments (DPIAs) for high-risk processing activities�Demonstrate adherence to GDPR principles and requirements in research practices

10 of 49

Rights of the data subject (art 12-23)

According to the General Data Protection Regulation (GDPR), data subjects have the right

  • to obtain information on the processing of their personal data
  • of access to their data
  • to rectification of their data
  • to the erasure of their data and to be forgotten
  • to restrict the processing of their data
  • to data portability
  • to object to the processing of their data
  • not to be subject to a decision based solely on automated processing.

11 of 49

2. Handling personal data in research step by step

12 of 49

Step by step process for handling personal data in research

Data Management Plan

  • Detailed plan of what personal data you will collect and how you will process it

Privacy Notice and consent forms

  • Comply to GDPR with privacy notices & to ethics with consent to participate

Ethical pre-review

  • Ethical review at Aalto (or HUS) if needed

Data collection

  • Follow what you wrote in your plan, adopt the best practices in your field, ensure Aalto policies are respected
  • Use secure storage

Data processing

  • Minimise and analyse your data following what you wrote in your DMP
  • Use secure workflows

Data publishing

  • Make the information about your data open
  • If possible, share data on requests according to consent given

Note: This is the process in its chronological form for the researcher!

A PDF version and more resources available at �“How to Handle Personal Data in Research” (aalto.fi)

13 of 49

Data protection roadmap for scientific researchby the Finnish Office of the Data Protection Ombudsman

14 of 49

2. Handling personal data in research step by step

2.1 Data management and research plan

15 of 49

Data Management Plan (DMP)

  • Know your data and their lifecycle
    1. Data description
    2. Ethical and legal issues
    3. Documentation and metadata
    4. Data storage
    5. Opening and sharing
    6. Responsibilities
  • Good as a reflection, but necessary to others (grant agencies, research services, ethical committee) to know about the details and requirements of your research project
  • ...however: it is not just an exercise to make grant agencies happy! It is an opportunity to learn the best practices in your field and to take a moment to plan ahead

16 of 49

Research plan

  • This outlines your research topic and objectives as well as the theoretical background and methods used. 
  • The format of a research plan may vary depending on whether you are preparing it for an external funder or as a part of your doctoral studies
  • A preregistration of the research plan in a public repository can be used to make the research hypothesis, study design, and planned analysis available before data is collected. �Training session on preregistrations and registered reports 24th of November 

17 of 49

2. Handling personal data in research step by step

2.2 Prepare legal documents

18 of 49

Inform the data subjects of the processing of personal data: privacy notice

  • Data subjects must always be informed for which purpose and how you will process their personal data, the legal basis for the processing, and their rights under the GDPR
  • The information to be provided slightly varies depending on whether the data is collected directly from the data subjects or from other sources (GDPR Article 13 / Article 14)
  • Full list of information to be provided at tietosuoja.fi

19 of 49

Planning is the key�Plan the entire life cycle of the data

  • how you collect personal data (from which sources),
  • what type of personal data you collect,
  • what you will do with the data (describe your research),
  • who is the controller / processor of data,
  • what is the legal basis for processing the data (in scientific research public interest or consent; in Master’s thesis phase generally consent), 
  • will you share the data with anyone outside of Aalto,
  • will you transfer data outside of the EU,
  • how long will you store the data,
  • will you pseudononymise or anonymize the data at any point (and when)?
  • will you archive any data and where?
  • when will the data be destroyed?

20 of 49

Aalto’s privacy notice templates

  • Use Aalto’s templates, available under section 6 at https://www.aalto.fi/en/services/how-to-handle-personal-data-in-research  
  • If Aalto is controller, always use Aalto's templates!
  • Choose the right legal basis for processing personal data 
    • For scientific research: public interest (scientific research)
    • For students preparing a Master’s thesis without employment to Aalto ,and not working as part of professional research group: consent.
      • Privacy notice and consent templates available for master's student's as well

  • Privacy notices can be published at https://www.aalto.fi/en/services/privacy-notices
      • privacy notice must be published when you cannot contact the data subjects

Dedicated session this Thursday!

21 of 49

Consider who is the processor/ controller of personal data

  • Legal obligations arise under the GDPR on the controller and processor of personal data
  • Is Aalto University the controller or processor of personal data?
    • Or is it the researcher / student who handles personal data in his/her research? (criteria: is the person employed by Aalto?)
  • Are Aalto’s research partners’ also handling personal data?

Remember that if Aalto University is the controller or processor of personal data (instead of the researcher), you cannot take the data with you without separate arrangements

22 of 49

Sharing personal data outside of Aalto University?

Remember to

  • inform the data subjects about any disclosures and transfers of data (inside and outside of the EU)
  • agree with anyone you share personal data with about the roles and responsibilities (e.g. DPA)
  • if you plan to transfer personal data outside of the EU, ensure that it is legal https://ec.europa.eu/info/law/law-topic/data-protection_en
  • This is relevant also when data is shared with external parties (e.g. a company doing transcription services)

23 of 49

Consent to participate in research vs. informing data subjects of the processing of their personal data

If you collect personal data directly from data subjects in scientific research, you need to BOTH

  • Obtain the data subjects’ consent to participate in the research (research ethics require this), AND
  • Inform the data subjects what you will do with their personal data (GDPR Article 13)
    • Generally no need to obtain consent to the processing of personal data, and legal basis for processing may be public interest

24 of 49

Students preparing a Master’s or Bachelor’s Thesis

NOTE that Master’s (and Bachelor’s) students CANNOT generally be considered to be performing scientific research yet

  • Under Finnish legal practice, the definition of scientific research includes a requirement that the researcher has sufficient seniority (PhD level and beyond)
  • Unless a Master’s student is a member of a research project where more senior researchers are involved, the student cannot rely on public interest as a legal basis for handling personal data, but must obtain the consent of the data subjects for the processing of their personal data

25 of 49

Students preparing a Master’s or Bachelor’s Thesis (II)

NOTE that when the legal basis for processing personal data is consent:

  • The data subjects have the right to withdraw their consent to the processing of personal data at any time
    • If this happens, the data concerning that person has to be destroyed
  • Registry-based research should not be undertaken
    • because it is not possible to obtain consent from the people whose personal data are included in the registry

26 of 49

When the risks are higher, complete a DPIA (Data Protection Impact Assessment)

Template and more info at section 4.2 of https://www.aalto.fi/en/services/how-to-handle-personal-data-in-research

Likelihoods of harm can be higher if researchers have sloppy cybersecurity practices!

27 of 49

Other legal requirements

Other legal documents that you might need to provide to your data subjects:

  • Copyright permissions (Check decision flowchart here)

If you are planning to use data controlled by Aalto (e.g. data from Aalto systems about students or staff), please check the “Research Permission Process for Aalto University

28 of 49

2. Handling personal data in research step by step

2.3 Ethical pre-review at Aalto

29 of 49

Ethics is not Law

Ethics

Law

30 of 49

Ethical review for studies with human participants

31 of 49

When should we apply for ethical review?

TENK Guidelines Section 4.2 

The researcher must request an ethical review statement from a human sciences ethics committee, if their research contains any of the following: 

a) Participation in the research deviates from the principle of informed consent

b) the research involves intervening in the physical integrity of research participants, 

c) the focus of the research is on minors under the age of 15, without separate consent from a parent or carer or without informing a parent or carer in a way that would enable them to prevent the child’s participation in the research, 

d) research that exposes participants to exceptionally strong stimuli, 

e) research that involves a risk of causing mental harm that exceeds the limits of normal daily life to the research participants or their family members or others closest to them or 

f) conducting the research could involve a threat to the safety of participants or researchers or their family members or others closest to them. 

Aalto has a Research Ethics Review (full committee ethics review for research involving the above TENK criteria), as well as a Research Ethics Request (decision by commiteee chair, for funder/publisher requests or when planning on using Aalto student data)

32 of 49

How to apply for ethical review at Aalto?

Research Ethics Review

  1. Check the deadline for the next research ethics committee meeting: Next deadline: November 2nd 2023
  2. Make sure you can access the form for filling in your ethical application
  3. Select Review Type "Full review"
  4. Attach Privacy Notice and Consent To Participate forms to the ethical application�You might want to get them checked by your dept. legal advisor. Consider if you might need a DPIA.
  5. Fill in the form and submit

Research Ethics Request

  1. Submissions are accepted on a rolling basis
  2. Make sure you can access the form for filling in your ethical application
  3. Select Review Type "Concise review"
  4. Questions concerning research ethical risks can be answered "not applicable", if there are no research ethical issues involved. 
  5. Fill in the form and submit

33 of 49

2. Handling personal data in research step by step

2.4 GDPR compliant processing: data collection and storage

34 of 49

Collecting personal data

  • Follow best practices of your field�If you use certain technologies (e.g. Magnetic Resonance Imaging) you know what are the best practices in your field. If you are not sure, contact researchdata@aalto.fi 
  • Personal data collection over the web�Ideally, do not collect personal data (principle of minimisation)… If you must, use GDPR compliant tools such as webropol http://survey.aalto.fi/
  • Balance between anonymous data collection versus the ethicality of handling incidental findings�

What is important is that the data is saved in a location that cannot be accessed publicly or by people who are not authorised

35 of 49

Classification of information at Aalto

Public

Internal

Confidential

Secret

Examples:

  • publications
  • media releases and bulletins
  • decisions that apply to the entire university

Examples:

  • work files
  • drafts
  • memoranda
  • files not to be published

Examples:

  • personal data
  • trade secrets
  • information about negotiations
  • research proposals
  • details about information systems

Examples:

  • private information (e.g. patient and health records)
  • sensitive research data
  • safety information

36 of 49

Personal data storage

  • Dedicated lectures on storing research data https://www.aalto.fi/en/services/rdm-training
  • Simple rules to remember
    1. Be paranoid about your data
    2. Encryption alone is never enough
    3. Do not store personal data in a physical location that is accessible by everyone even if it is encrypted (memory sticks, USB drives, laptops, phones)
    4. Store personal/sensitive data “on the cloud” but be aware that not all clouds are equal… (e.g. if data are not stored in EU, other legislations apply e.g. FISA)
    5. Do not store passwords on your laptop/phone.
    6. Use common sense (higher risks -> higher security)
    7. Rule of thumb: If it’s not using multi-factor authentication, then it is not good for confidential or secret data
    8. Take the Aalto Cybersecurity mandatory course, if you didn’t already

37 of 49

2. Handling personal data in research step by step

2.5 GDPR compliant processing: data minimisation and data analysis

38 of 49

Data minimisation

  • If you do not need a certain personal data type, then remove it from your data�E.g. delete email address and past emails of a participant that came to your study if you are not planning to collect more data from them
  • Data minimization techniques depend on the data type

E.g. for MRIs of the head, you can remove the facial features if you do not need them. For geo-spatial data, you can remap locations to a synthetic map.

  • Do not collect and keep everything forever just because “you never know” �This also relates to (unconscious) questionable research practices such as HARKing. Be able to justify why you need certain data types.

Pseudonymous data ARE personal dataDedicated session next month https://www.aalto.fi/en/services/rdm-training

39 of 49

Identifier types

40 of 49

Data minimisation spectrum

Personal data with direct identifiers and no minimisation

Easy to re-identify

Pseudonymisation Replacing strong identifiers: tokenization, hashing, encryption

Can be re-identified with the key

Masking Suppression of strong identifiers

The key is lost, but other data (will) exist, and it can be reasonably likely to re-identify

Anonymisation

K-anonymity, l-diversity, t-closeness, perturbation (data swapping, differential privacy)

Impossible to re-identify, but still related to an individual

Anonymisation

Aggregation, data synthesis

Impossible to re-identify and not related to an individual anymore

Glerean, Handbook of Data Minimisation (in preparation)�GDPR art 4 and recital 26.

41 of 49

GDPR compliant data analysis

  • After minimisation you want to analyse your data in a secure way -> personal data should not be stored in a location accessible to others
  • Aalto workflows for data analysis:
    1. Use remote computing
    2. VDI https://vdi.aalto.fi (confidential)
    3. Triton high performance computing cluster (confidential)
    4. Aalto SECDATA and CSC SD Desktop (secret)
  • Higher risks -> higher security
  • In doubt? Discuss your data processing with Aalto Scientific Computing, every day at 1pm on zoom.

42 of 49

Other data processing duties

  • Dealing with participants’ requests if you still can identify the participant or in longitudinal studies
    1. Data deletion
    2. Data correction
    3. Right to withdraw from the study
  • It is possible to deviate from some of the subjects’ rights (only if you are not processing special categories of personal data; for special categories you can deviate with a DPIA)
  • Incidental findings

43 of 49

2. Handling personal data in research step by step

2.6 Personal data sharing and publishing

44 of 49

Can personal data be opened/shared?

  • FAIR: Information about your data should be open (metadata)
  • Pay attention to what is informed in the privacy notice to the participant (possibility to update is limited). The given information is binding, there is no time machine. Contact legal counsels for help if you are unsure if transfer is ok or not
  • Sharing with non-EU partner institutions requires special arrangements, please consider this before starting to collect the data
  • Data opening (work ongoing, case-by-case scenarios): 
  • It is not possible to open personal research data, we can make data available on request. However we can make data FAIR
    1. We need to ask for permissions for “secondary use of data”
    2. Share data under a “Data Use Agreement”. See for example: https://data.donders.ru.nl/doc/dua/?0 
    3. There are  still ethical implications (data leaks, data abuse)

45 of 49

Secure reuse of personal data

Federated analysis approaches

  • Data stays with owners who can run the same code
  • Aggregator can join models from multiple data owners

46 of 49

Data access control

Procedure adopted by the (federated) EGA (European Genome Phenome Archive)

In the federated approach, “Download” is replaced with remote secure computing

47 of 49

2. Handling personal data in research step by step

Let’s recap

48 of 49

Step by step process for handling personal data in research

Data Management Plan

  • Detailed plan of what personal data you will collect and how you will process it

Privacy Notice and consent forms

  • Comply to GDPR with privacy notices & to ethics with consent to participate

Ethical pre-review

  • Ethical review at Aalto (or HUS) if needed

Data collection

  • Follow what you wrote in your plan, adopt the best practices in your field, ensure Aalto policies are respected
  • Use secure storage

Data processing

  • Minimise and analyse your data following what you wrote in your DMP
  • Use secure workflows

Data publishing

  • Make the information about your data open
  • If possible, share data on requests according to consent given

Please note that long term archiving is not yet established! (From biobanks to databanks?)

A PDF version and more resources available at �“How to Handle Personal Data in Research” (aalto.fi)

49 of 49

Thank you!