Research Data Management & Open Science
This presentation is a part of Aalto University’s webinar series on
Autumn 2023
All slides in this presentation are licensed with CC-BY and can be reused with attribution unless explicitly mentioned otherwise.
Handling of Personal Data in Research
Enrico Glerean, Staff Scientist and Data Agent
Anniina Harju, Legal Counsel
Essi Viitanen, Senior Advisor and Data Agent
30.10.2023
Outline: Personal Data in Research
Please note that what we cover here is “personal data in research”. Although similar considerations will apply for non-research purposes, it is always better to contact your School’s legal advisor if you need any clarification.
These slides have a CC-BY-4.0 license, feel free to reuse! Thanks to past collaborators on the materials of these slides: Päivi Lindström, Antti Rousi, Maria Rehbinder.
References
When in doubt, ask! researchdata@aalto.fi or your dept. legal advisor or data agent
1. What is personal data?
What is personal data?
Personal data: �direct and indirect identifiers
��
Special categories of personal data (art 9)
The principles of the GDPR (art 5)
GDPR Principle | Practical Actions in Research Projects |
1. Lawfulness, fairness, and transparency | Obtain and manage informed consent from research participants�Clearly explain data processing activities, purposes, and potential risks to participants�Maintain transparency in data sharing, storage, and access policies |
2. Purpose limitation | Specify the research objectives and data processing purposes before collecting personal data Use collected data only for the stated purposes�Obtain additional consent or establish a new legal basis if the purpose changes |
3. Data minimization | Collect only the minimum amount of personal data necessary to achieve research objectives�Employ data anonymization or pseudonymization techniques to reduce the scope of identifiable information |
4. Accuracy | Implement processes to ensure the accuracy and up-to-date nature of personal data�Allow research participants to rectify inaccurate or incomplete information�Regularly review and update collected data as needed |
5. Storage limitation | Establish retention periods for personal data based on research objectives and legal requirements�Regularly delete or anonymize personal data when it is no longer necessary for the stated purpose or when the retention period ends |
6. Integrity and confidentiality | Use appropriate security measures to protect personal data from unauthorized access, disclosure, or misuse�Train research team members on data protection and privacy practices�Implement access controls and encryption for data storage and transfer |
7. Accountability | Document data processing activities, legal bases, and compliance measures�Conduct data protection impact assessments (DPIAs) for high-risk processing activities�Demonstrate adherence to GDPR principles and requirements in research practices |
Rights of the data subject (art 12-23)
According to the General Data Protection Regulation (GDPR), data subjects have the right
2. Handling personal data in research step by step
Step by step process for handling personal data in research
Data Management Plan
Privacy Notice and consent forms
Ethical pre-review
Data collection
Data processing
Data publishing
Note: This is the process in its chronological form for the researcher!
A PDF version and more resources available at �“How to Handle Personal Data in Research” (aalto.fi)
Data protection roadmap for scientific research �by the Finnish Office of the Data Protection Ombudsman
2. Handling personal data in research step by step
2.1 Data management and research plan
Data Management Plan (DMP)
Research plan
2. Handling personal data in research step by step
2.2 Prepare legal documents
Inform the data subjects of the processing of personal data: privacy notice
Planning is the key�Plan the entire life cycle of the data
Aalto’s privacy notice templates
Dedicated session this Thursday!
Consider who is the processor/ controller of personal data
Remember that if Aalto University is the controller or processor of personal data (instead of the researcher), you cannot take the data with you without separate arrangements
Sharing personal data outside of Aalto University?
Remember to
Consent to participate in research vs. informing data subjects of the processing of their personal data
If you collect personal data directly from data subjects in scientific research, you need to BOTH
Students preparing a Master’s or Bachelor’s Thesis
NOTE that Master’s (and Bachelor’s) students CANNOT generally be considered to be performing scientific research yet
Students preparing a Master’s or Bachelor’s Thesis (II)
NOTE that when the legal basis for processing personal data is consent:
When the risks are higher, complete a DPIA (Data Protection Impact Assessment)
Template and more info at section 4.2 of https://www.aalto.fi/en/services/how-to-handle-personal-data-in-research
Likelihoods of harm can be higher if researchers have sloppy cybersecurity practices!
Other legal requirements
Other legal documents that you might need to provide to your data subjects:
If you are planning to use data controlled by Aalto (e.g. data from Aalto systems about students or staff), please check the “Research Permission Process for Aalto University”
2. Handling personal data in research step by step
2.3 Ethical pre-review at Aalto
Ethics is not Law
Ethics
Law
Ethical review for studies with human participants
When should we apply for ethical review?
The researcher must request an ethical review statement from a human sciences ethics committee, if their research contains any of the following:
a) Participation in the research deviates from the principle of informed consent,
b) the research involves intervening in the physical integrity of research participants,
c) the focus of the research is on minors under the age of 15, without separate consent from a parent or carer or without informing a parent or carer in a way that would enable them to prevent the child’s participation in the research,
d) research that exposes participants to exceptionally strong stimuli,
e) research that involves a risk of causing mental harm that exceeds the limits of normal daily life to the research participants or their family members or others closest to them or
f) conducting the research could involve a threat to the safety of participants or researchers or their family members or others closest to them.
Aalto has a Research Ethics Review (full committee ethics review for research involving the above TENK criteria), as well as a Research Ethics Request (decision by commiteee chair, for funder/publisher requests or when planning on using Aalto student data)
How to apply for ethical review at Aalto?
Research Ethics Review
Research Ethics Request
2. Handling personal data in research step by step
2.4 GDPR compliant processing: data collection and storage
Collecting personal data
What is important is that the data is saved in a location that cannot be accessed publicly or by people who are not authorised
Classification of information at Aalto
Public | Internal | Confidential | Secret |
Examples:
| Examples:
| Examples:
| Examples:
|
Personal data storage
2. Handling personal data in research step by step
2.5 GDPR compliant processing: data minimisation and data analysis
Data minimisation
E.g. for MRIs of the head, you can remove the facial features if you do not need them. For geo-spatial data, you can remap locations to a synthetic map.
Pseudonymous data ARE personal data �Dedicated session next month https://www.aalto.fi/en/services/rdm-training
Identifier types
Data minimisation spectrum
Personal data with direct identifiers and no minimisation
Easy to re-identify
Pseudonymisation Replacing strong identifiers: tokenization, hashing, encryption
Can be re-identified with the key
Masking Suppression of strong identifiers
The key is lost, but other data (will) exist, and it can be reasonably likely to re-identify
Anonymisation
K-anonymity, l-diversity, t-closeness, perturbation (data swapping, differential privacy)
Impossible to re-identify, but still related to an individual
Anonymisation
Aggregation, data synthesis
Impossible to re-identify and not related to an individual anymore
Glerean, Handbook of Data Minimisation (in preparation)�GDPR art 4 and recital 26.
GDPR compliant data analysis
Other data processing duties
2. Handling personal data in research step by step
2.6 Personal data sharing and publishing
Can personal data be opened/shared?
Secure reuse of personal data
Federated analysis approaches
Data access control
Procedure adopted by the (federated) EGA (European Genome Phenome Archive)
In the federated approach, “Download” is replaced with remote secure computing
2. Handling personal data in research step by step
Let’s recap
Step by step process for handling personal data in research
Data Management Plan
Privacy Notice and consent forms
Ethical pre-review
Data collection
Data processing
Data publishing
Please note that long term archiving is not yet established! (From biobanks to databanks?)
A PDF version and more resources available at �“How to Handle Personal Data in Research” (aalto.fi)
Thank you!