ABCDEFGHIJKLMNOPQRSTUVWXYZAAAB
1
140 / 140 done
TermContext/Tag/CategoryDefinitionOriginal definitionSource2Term
Context/Tag/Category
DefinitionSourceOverlap#VALUE!
2
RMBAAISecurity ManagementAn abbreviation of "authentication and authorisation infrastructure", AAI refers to the technical mechanisms used to verify and manage users' access to computer systems.
See also: [Access Control]; [Authentication]; [Authorisation].
WG
3
RMBAccess ControlSecurity ManagementThe technical mechanism for controlling a known (authenticated) user’s access to a system and its underlying assets such as data. Access control is also referred to as authorisation (and shorthanded as “AuthZ” to distinguish it from authentication), as it determines what the user is authorised to do.
See also: [AAI]; [Authentication]; [Authorisation].
The technical mechanism for controlling a known (Authenticated) user’s access to the system. Sometimes referred to as Authorisation (and shorthanded as “Auth” often in concert with Authentication), as it determines what a user is authorised to do. Hutch and Bitfount use “Role Based Access Control” (RBAC) so a suitable administrator (e.g. of a project, or a TRE) can configure that certain Users have certain Roles, and those Roles have Permissions to perform authorised actions. In Hutch, Access Control checks for a user will take place after they are authenticated, by both the Submissions Layer outside a TRE and the Polling Layer inside a TRE, to ensure they are allowed to do what they are asking.  DAREAccess Control is the technical mechanism that determines what actions an authenticated user is authorized to perform within a system. Often referred to as Authorization (or "Auth"), it defines the permissions granted to a user. Systems commonly use Role-Based Access Control (RBAC), allowing administrators to assign specific roles to users, with each role granting certain permissions.BS edit
4
RMBAdministrative DataData in generalSee also: Administrative data in https://www.adruk.org/learning-hub/glossary/
5
RMBAlgorithmComputingA sequence of computational steps for processing data to achieve a particular outcome. Algorithms can range from the simple (add up a set of numbers) to the complex (use complicated mathematics to search for patterns in image data). Algorithms are usually described generally, as mathematics or in words, in contrast to computer programs which are written in specific computer languages.An algorithm is like a recipe or set of rules that tells a computer how to work with the data. It helps the computer process and understand the information by following a series of steps. Algorithms can do things like organising data, searching for specific pieces of information, or making calculations.DMAn algorithm is a set of rules or instructions that tells a computer how to process data. It guides the computer through a series of steps to organize, search, or perform calculations on the data.BS edit
6
RMBAnalysisComputingAlso Data Analysis. Techniques that produce knowledge from organised information. Processes of inspecting, cleaning, transforming, and modelling data with the goal of highlighting useful information, suggesting conclusions and supporting decision making. Data analysis has multiple facets and approaches, encompassing diverse techniques under a variety of names, in different business, science, and social science domains.
See also: Data Analysis in https://terms.codata.org/rdmt/data-analysis
7
RMBAnonymisationIdentifiabilityThe process of making personally identifiable data anonymous so that individuals can no longer be identified. In contrast to pseudonymisation, true anonymisation cannot be reversed.
See also: [Pseudonymisation].
Anonymisation makes data anonymous by removing anything that could identify people. Think about a database with blood test results, diagnoses, and ages, but no personal details. It's like making the data a secret puzzle—no one knows who it's about. This keeps the data private so no one can recognise individuals. Anonymisation happens by changing or taking out personal information, or by using special software to hide private details. Yet, researchers can still use this data for answers without knowing who's who. This helps researchers learn from data while keeping it private.DMAnonymisation is the process of making data anonymous by removing or altering any information that could identify individuals. For example, a database may contain blood test results, diagnoses, and ages without including personal details. This ensures that the data remains private and individuals cannot be identified. Anonymisation can be achieved by removing or modifying personal information, or by using software to hide private details. Researchers can still use anonymised data to gain insights without knowing the identities of the individuals involved, allowing for privacy while enabling valuable research.BS edit
8
RMBApplication DeploymentComputingThe process of installing, configuring, and making software applications available for use within a given enviornment (eg, a [TRE]).The process of installing, configuring, and making software applications available for use within the TRE.DARE
9
RMBApplication Programming Interface (API)ComputingA type of software interface that provides a way for two or more computer programs to communicate with each other. In contrast to a user interface, which connects a computer to a person, an application programming interface connects computers or pieces of software to each other.An abbreviation for Application Programming Interface, an API is a type of software interface that provides a way for two or more computer programs to communicate with each other. In contrast to a user interface, which connects a computer to a person, an application programming interface connects computers or pieces of software to each other. An important trend in API design is the RESTfull concept, which now dominates all APIs due to its simplifying principles.DAREAn API, short for Application Programming Interface, is a software interface that allows different computer programs to communicate with each other. Unlike a user interface, which connects a computer to a person, an API connects computers or software systems to each other. BS editBS comment: should reference to RESTful approach? If we do we need a definiton of RESTful API
10
RMBApplication StackComputingA number of applications, tools and other software that work in concert to form a complete software solution.An application stack is a number of applications or tools that work in concert to form a complete software solution. Hutch is an application stack consisting of several components, some of which are developed as part of Hutch itself, and others are pre-existing and used to complete the whole solution. DAREAn application stack is a collection of software components or technologies that work together to build and run an application. It typically includes an operating system, database, web server, and programming frameworks or languages. Each layer of the stack supports a specific part of the application's functionalityBS edit
11
RMBArtificial Intelligence (AI)ComputingA branch of computer science that aims to create technology and systems that perform tasks and make decisions in ways that resemble human intelligence. AI systems can be built in various ways, with the most common current method being Machine Learning.
Examples: A chess-playing computer program is an example of a specialised AI system (it can play chess, but nothing else). The programs inside a modern robot that can climb stairs and walk over uneven ground is an example of a more general AI system.
See also: [Machine Learning].
Artificial Intelligence (AI) is a branch of science that aims to create technology that may perform tasks and make decisions in a way that resembles human intelligence.
AI has advanced from rule-based systems to complex algorithms like deep learning. However, it lacks common sense, true understanding, and emotions, unlike human intelligence. Exaggerated expectations have led to misconceptions about AI's capabilities.
Potential pros of AI:
Efficiency: AI may automate tasks, boosting productivity.
Insights: AI may analyse data for better decision-making.
Personalisation: AI may tailor recommendations to individual preferences.
Healthcare: AI may aid in diagnosing medical conditions.
Language: AI could translate languages in real-time.
Automation: AI-driven robots may streamline industries.

Potential concerns about AI:
Bias: AI may perpetuate biases in its decisions.
Job Impact: Automation might lead to job displacement.
Privacy: AI's data use may raise privacy questions.
Ethics: AI decisions may raise ethical dilemmas.
Security: AI systems may be vulnerable to attacks.
Data Dependence: AI's accuracy might rely on quality data.

Example: Large-Language Models:
Large-language models like GPT-3 exemplify AI. They understand and generate human-like text. These models fall under Natural Language Processing (NLP), part of machine learning, where computers learn from data patterns.

In essence, AI has made strides, but gaps remain in achieving human-like intelligence. Balancing benefits and concerns is crucial for responsible AI use.
DM
12
RMBAsset Management ProcessManagementA systematic approach to acquiring, operating, maintaining, and disposing of assets within an organisation, aimed at maximising their value and minimising risks.A systematic approach to acquiring, operating, maintaining, and disposing of assets within an organisation, aimed at maximising their value and minimising risks.DARE
13
RMBAuthenticationSecurity ManagementThe technical mechanism by which a computer user proves that they are who they say they are. Authentication is often shorthanded as “AuthN” to distinguish it from authorisation.
Example: The combination of a username and a password is a method of authentication.
See also: [AAI]; [Access Control]; [Authorisation].
Authentication is finding out who a user is and ensuring that they are who they say (i.e. they are authentic) via some acceptable proof. This goes hand in hand with Access Control (or “Authorisation”) and the two are both sometimes shorthanded (separately or together) as “Auth”. If there’s any doubt in the context of what “Auth” is referring to, it should be clarified!DARE
14
RMBAuthentication ApplicationSecurity ManagementA software system that verifies and validates the identities of users or entities accessing a system through authentication.
See also: [Authentication].
A software system that verifies and validates the identities of users or entities accessing a system through multifactor authentication.DARE
15
RMBAuthentication TokenSecurity ManagementA piece of data used to authenticate the identity of a user or application to a computer system. Authentication tokens are often generated by authentication applications, and possession of a given token is evidence that the owner has successfully authenticated themselves to the system in question.
See also: [Authentication]; [Authentication Application].
An authentication token is a piece of data that is used to authenticate the identity of a user or application. It is typically a string of characters or a digital certificate that is generated by an authentication server, and is then passed between the user or application and the server to verify their identity. Authentication tokens are commonly used in web applications, APIs, and other systems that require secure access control. When a user logs in to a system, the authentication server generates a token that is associated with the user's account and privileges. This token is then passed back to the user's browser or application, and is used to authenticate subsequent requests to the system. Authentication tokens can be generated using a variety of methods, such as cryptographic keys, digital certificates, or session IDs. They can also be time-limited or have other restrictions to enhance security and prevent unauthorised access. The use of authentication tokens helps to ensure that only authorised users or applications can access sensitive information or resources, and can provide an additional layer of security beyond traditional username/password authentication.DARE
16
RMBAutomated Disclosure ControlComputingDisclosure control (qv) without the intervention of a human being each time. Automated disclosure control aims to capture the necessary rules for ensuring a given dataset cannot be used to identify any individual in an automated software system.
See also: [Disclosure Control].
Disclosure control without the intervention of a human being each time. Configuring a software system to reliably detect that data it is provided with is “non-disclosive” (i.e. doesn’t disclose any information that is not allowed to be shared with the requesting person, or leave the environment where the data is held), such that a human doesn’t need to look at the data to determine its (non-)disclosive nature.DARE
17
RMBAuthorisationComputingAuthorisation is a process of verifying that a person or other agent can legitimately take some action, such as gaining access to a dataset, editing a document, entering a building or making a payment. An administrative authority must determine whether there are sufficient grounds for authorising the action. Authorisation is often shortened to "AuthZ" to disntinguish it from authentication.
See also: [AAI]; [Access Control]; [Authentication].
See also: Authorisation in https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-A_79.xml
18
RMBBest PracticeProcessesA set of guidelines that, if followed, is known to produce good outcomes. Best practice may be based on different levels of research evidence and/or collective experience.Best practice is a standard or set of guidelines that is known to produce good outcomes if followed. They may be based on different levels of research evidence and/ or collective experience.DM
19
RMBBig DataData in generalLarge amounts of information that, because of its scale, may need novel or non-standard methods to process. In the original coining, "big" referred to one or more of volume (the raw size of the data), velocity (the rate at which new data were generated) or variety (the complexity or richness of the data).Big Data means working with large amounts of information. The definition of "big" depends on the context. It can refer to data from a huge number of people, like health records from millions of individuals. It can also refer to data that requires a lot of storage space, such as DNA sequences, MRI scan images, or activity data from mobile phones. The term "big data" became popular in the early 2000s and has been associated with over 25,000 publications in the life sciences as of March 2023.DM
20
RMBCaldicott GuardianSpecial aspects in the NHS ContextA senior professional in the NHS who safeguards patient confidentiality and privacy. They are responsible for protecting patient information, including how it is used in, for example, research. Named after Dame Fiona Caldicott, the first UK National Data Guardian. In the NHS, the Caldicott Guardian is a senior professional who safeguards patient confidentiality and privacy. They are responsible for protecting patient information within NHS organisations, including how it is used, following the guidelines led by Dame Fiona Caldicott, the first National Data Guardian. Both the Caldicott Guardian and the National Data Guardian protect patient information. The National Data Guardian oversees data use across the entire UK health sector to ensure proper use of patient info. The Caldicott Guardian focuses on data protection within individual healthcare groups.DM
21
RMBCensusData in generalA survey of a national population which asks questions about age, gender, background and so on. In the UK, censuses are carried out every 10 years or so. Census information helps with things like local service planning and making important decisions. Census data can be used in academic research. If so, it is anonymised before being used.
See also: [Anonymisation].
A large survey that happens every 10 years in the UK. It asks people about things like their age, gender, and background. This information, collected from all over the country, helps with things like local service planning and making important decisions. The data is made anonymous before being used to understand the population better.DM
22
RMBCharacteristicData in generalA piece of information about an individual, place or thing that is potentially useful in data analysis. For example, characteristics of a person might be age, gender, ethnicity, socioeconomic status and education level. If data about individuals were recorded in a table, the columns of the table might be characteristics.
23
KO'SChief Investigator (CI)Running and overseeing researchThe researcher with overall responsibility for a research project, including ethical approval, research staff management and conduct and project outcomes. Also known as a Principal Investigator.
The investigator (researcher) with overall responsibility for a research study, and the person who seeks ethical approvals.DMChief Investigator [See also: Principal Investigator]
24
RMBClinical TrialHealth ResearchA research study conducted to test a new treatment, like a medicine or other therapy. When it comes to testing medicines, clinical trials are known as Clinical Trials of Investigational Medicinal Products (CTIMPs), and they have additional special rules and regulations that need to be followed. These rules ensure the safety and effectiveness of the new treatment being tested before it can be made available to the general public and the safety of the people participating in the trials.A trial refers to a research study conducted to test a new treatment, like a medicine or talking therapy. When it comes to testing medicines, clinical trials are known as Clinical Trials of Investigational Medicinal Products (CTIMPs), and they have additional special rules and regulations that need to be followed. These rules ensure the safety and effectiveness of the new treatment being tested before it can be made available to the general public and the safety of the people participating in the trials.DM
25
RMBClinical/ Medical/ Health Data or Healthcare dataHealth Services & Health DataA person's information about their health or day-to-day health care. This information is collected as people see healthcare professionals, or have tests and treatments as part of their care. It is stored in electronic health records (EHRs) used by the NHS. A person's information about their health or dat to day health care.

Healthcare data is the information collected about a person's health and medical care. This information is collected as people see healthcare professionals, have tests and treatments as part of their care. It is stored in electronic health records (EHRs) used by the NHS. There are different types of healthcare data:

1. Simple Data: This data is organised in a table format and includes basic information like the patient's name, date of birth, gender, NHS number, and contact details. It also includes details about the patient's health, such as the reason for their visit, any illnesses or conditions they have, and the treatments or care they received. This data is entered by healthcare professionals or automatically generated, like appointment dates, diagnosis codes, test results, and prescribed medications. Patients may also provide additional information through questionnaires or surveys.

2. Free-Text Data: This refers to unstructured text information, like notes or letters, that healthcare professionals write or patients provide. It doesn't follow a specific format and may contain detailed descriptions or additional information about the patient's health.

3. Images: Healthcare data can also include images, such as X-rays, CT scans, or MRI scans. These images help healthcare professionals see and analyse specific body parts to aid in diagnosis and treatment planning.

4. Complex Data: This includes more advanced types of data, like genetic information obtained from gene sequences in DNA. Currently, genetic sequencing is not widely used in the NHS, but it may become more common in the future. This type of data can provide insights into a person's genetic makeup and potential health risks as well as form the basis of personalised treatments


All of this healthcare data is important for healthcare professionals to understand a patient's health history, make accurate diagnoses, and provide appropriate care and treatment.

Researchers often use this data after it has been anonymised, to answer questions to improve people’s care.
DM
26
RMBCloud computingComputingA model of computer access or provision where users rent computer power remotely, rather than buying and installing their own hardware locally. Cloud computing may be described as "public cloud", meaning available to anyone from a wide number of cloud computing companies, or as "private cloud" or "on-premises" (or "on-prem") cloud, meaning installed and provided privately by, for example, a firm for its own uses.
Examples: Microsoft Azure, Amazon Web Services (AWS) and Google Cloud Platform (GCP) are large, public cloud providers.
Cloud computing means another company handles things like computers, storage, software, and more, over the internet. Big names like Amazon, Google, and Microsoft do this. They store your data and let you analyse it using their powerful machines (lots of computer processors and memory).

The provider typically looks after things like physical security (preventing break-ins), electronic security (only permitting access by authorised users and preventing hacking over the network), and ‘resilience ‘(e.g. keeping regular backups, having devices for when one breaks, having batteries or generators for power cuts, and maybe having other data centres in case of disasters). Many cloud providers allow the customer to choose the physical location of the data centre (e.g. Cardiff versus California), which may be important for compliance with relevant data protection laws. Cloud computing is distinguished from computing “on premises”, i.e. physical computers that an organisation (such as an NHS Trust) owns and looks after itself.
DM
27
RMBCloud storageComputingComputer data storage hosted by a cloud computing firm rather than provided locally. Access to cloud storage requires an Internet connection, in contrast to local storage which is either attached to a user's computer or needs only a local network connection.
Examples: Apple's iCloud storage, Google's Drive or Microsoft OneDrive are examples of cloud storage.
Cloud storage is like a virtual locker on the internet where you can keep your files, photos, and documents. Instead of storing everything on your device, you upload them to this online space. Think of streaming a movie online instead of downloading it, sharing photos on social media, storing files in Google Drive or iCloud, sending emails through services like Gmail, and collaborating on documents in real time. All these activities involve using cloud storage, where you access and manage content over the internet, without needing to keep everything on your device.DM
28
RMBCode ControlComputingThe management and oversight of software code or source files, including versioning, change tracking, access control , and collaboration.The management and oversight of software code or source files, including versioning, change tracking, access control , and collaboration.DARE
29
RMBCode ListsData in generalA collection of specific, standard codes that are used in healthcare to represent different things, such as medical diagnoses, treatments, or procedures.A collection of specific codes that are used in healthcare to represent different things, such as medical diagnoses, treatments, or procedures. These codes are standardised and help healthcare professionals classify and identify specific information in a consistent and uniform manner. Code lists make it easier to communicate and exchange information accurately within the healthcare field.DM
30
RMBCommand Line Interface (CLI)ComputingA text-based interface or environment that allows users to interact with a computer or software by typing commands or instructions, in contrast to a graphical user interface.
See also: [Graphical User Interface (GUI)].
A text-based interface or environment that allows users to interact with a computer or software by entering commands or instructions using a command line interpreter.DARE
31
RMBCommon Workflow Language (CWL)ComputingAn open standard for describing how to run software tools using command line interfaces, and how to chain them together to create workflows.
See also: [Command Line Interface (CLI)]; [Workflow].
Common Workflow Language is an open standard for describing how to run command line tools and connect them to create workflows. It is supported by WfExS. CWL workflow and tool descriptions are defined in YAML files.DARE
32
RMBCompliance CheckingSecurity ManagementRelated to Compliance in https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-C_42.xmlThe act of verifying and ensuring adherence to applicable laws, regulations, standards, or internal policies within the TRE organisation.DARE
33
ANOConsentProcessesConsent is defined as individual providing freely given, specific, informed and unambiguous indication of their wishes to provide their data for processing relating to him or her.
Consent within the context of data protection regulation is one of the grounds (lawful bases) for lawfully processing personal data in relation to an individual and is specific towards particlar activities.

Research consent is the process of documenting an individual's choice to be involved in a research project(s) and typically called informed consent - this conveys that there is a process to allow participants to make a meaningful choiceInformed consent" is used to emphasise that understanding is crucial before agreeing, and typically applies when sharing personal data or participating in research studies. Research consent is commonly required for participation in clinical trials/research.

Broad consent is a mechanism of gaining the consent of an individual who donates their biosamples and health data with a view to their future use in research, and may not be specific to a particular research project at the time of collection.

Assent is the process of providing approval for data processing/involvement in research by an individual who is not legally eligible to do so (e.g. a child under the age of 16), and will be supported by an adult providing legal consent.

Withdrawal of consent is both a legal, and ethical right of the individual whose data is being processed, and must be respected in reference to data protection and research compliance. It allows an infividual to discontinue/rescind access to his/her data and prevent further processing.

See also: [Unconsented Data]
Understanding how consent (or the lack of it) works for sharing healthcare data in the UK is essential. There are different rules depending on how easy it is to figure out who the data is about and where you are. In the UK, there's a rule that currently says you don't need to give informed consent if the data collected regularly is made fully anonymous. This means that your personal details are taken out, and no one can link the data back to you. However, it's a good question to ask whether all the data labeled as "anonymous" is truly untraceable. But, when it's about sharing personal healthcare data that can still identify you, it gets more complicated. The level of how easy it is to tell who you are and where you're located matters. Some places might want your agreement before they share your data, while others might not. It's important to note that the "National Data Opt-Out" is available in England. It lets you decide whether your data can be shared, even if you said yes before. This opt-out is like a way to say "no" to certain kinds of sharing. Remember, even though consent might not be explicitly requested in every situation, the choice not to ask for it is part of the current system.

Informed Consent and Choices:
Consent and informed consent are both about agreeing to something after understanding it fully. Regular "consent" involves knowing all the details and agreeing, just like when you give permission for the use of personal data in research after understanding the risks and benefits. "Informed consent" is a term we use when we want to emphasise that understanding is crucial before agreeing. In most cases, whether it's sharing personal data or participating in studies, consent should always be informed.

It's important to know that consent can change over time. People can decide to stop participating in research whenever they want, and this will not affect their healthcare treatment. This highlights how vital it is for researchers to keep talking with participants openly. This way, participants can freely decide what's best for them and feel like their choices matter.
DMConsent is defined as individual providing freely given, specific, informed and unambiguous indication of their wishes to provide their data for processing relating to him or her.
Consent within the context of data protection regulation is one of the grounds (lawful bases) for lawfully processing personal data in relation to an individual and is specific towards particlar activities.

Research consent is the process of documenting an individual's choice to be involved in a research project(s) and typically called informed consent - this conveys that there is a process to allow participants to make a meaningful choiceInformed consent" is used to emphasise that understanding is crucial before agreeing, and typically applies when sharing personal data or participating in research studies. Research consent is commonly required for participation in clinical trials/research.

Withdrawal of consent is both a legal, and ethical right of the individual whose data is being processed, and must be respected in reference to data protection and research compliance. It allows an infividual to discontinue/rescind access to his/her data and prevent further processing.
34
RMBControlsSecurity ManagementIn computer security management, measures, safeguards or mechanisms implemented to manage or mitigate risks and ensure the integrity, confidentiality, availability, and reliability of systems, processes, or data.Measures, safeguards, or mechanisms implemented to manage or mitigate risks and ensure the integrity, confidentiality, availability, and reliability of systems, processes, or data.DARE
35
RMBDataData in generalSee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_3.xml
See also: https://terms.codata.org/rdmt/data
See also: https://www.nice.org.uk/Glossary?letter=D
Data means information. It can be numbers, text, images, videos, sound recordings, or any other type of information that can be collected, stored and analysed by computers or humans. Data is a very broad term. In health research we usually mean information (data) about a person which is stored electronically (on-line).DM
36
KO'SData Archiving *Data ManagementThe practice of securely storing and preserving data in a read-only format for long-term retention, typically for compliance, historical reference, or reproducibility.
See also: https://vocabs.ardc.edu.au/repository/api/lda/codata/codata-research-data-management-terminology/v001/resource?uri=https%3A%2F%2Fterms.codata.org%2Frdmt%2Fresearch-data-management
The practice of securely storing and preserving data in a read-only format for long-term retention, typically for compliance, historical reference, or reproducibility.DARE
37
RMBData Classification *Data ManagementThe categorisation or labelling of data based on its sensitivity, risk, value, or other attributes, often used to determine appropriate handling, storage, and security controls.The categorisation or labelling of data based on its sensitivity, risk, value, or other attributes, often used to determine appropriate handling, storage, and security controls.DARE
38
MAData ControllerUK law and rulesA data controller is a person or organisation who decides how personal data, which is information about identifiable individuals, is used or handled. Examples of data controllers include NHS organisations like Trusts and GP surgeries. In the UK, most organisations handling personal data must register with the ICO (Information Commissioner's Office), and their details are public. Data controllers are legally responsible for how data is managed. They must prevent misuse, report breaches, and can be fined for failing to meet these duties.

See also: data processor, Information Commissioner's Office (ICO)
See also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_16.xml
See also: https://www.adruk.org/learning-hub/glossary/
See also: https://www.nice.org.uk/Glossary?letter=D
A data controller is a person or organisation who decides how personal data, which is information about identifiable individuals, is used or handled. Examples of data controllers include NHS organisations like Trusts and GP surgeries. On the other hand, a data processor is a person or organisation that processes personal data on behalf of the data controller. In the UK, all organisations that handle personal data, with very few exceptions, must be registered with the ICO (Information Commissioner's Office), and this registration information is publicly available. Data controllers have a legal responsibility and can be held accountable if there's a problem with how personal data is handled. This includes breaches or misuse of data. They must take measures to prevent issues, promptly report breaches to the relevant authorities, and can face fines if they don't meet their obligations.DM
39
RMBData CurationData in generalSee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_17.xml
See also: https://terms.codata.org/rdmt/data-curation
See also: https://www.nice.org.uk/Glossary?letter=D
This is like being a caretaker for data, similar to a museum curator. It is basically looking after data for other people to work with it.

This can involve putting data together, quality control (finding and removing errors or invalid data), describing it well so that other researchers can understand it (providing metadata or a catalogue), or mapping it to a standard “vocabulary” (e.g. if two databases record problems using different coding systems, can those be mapped to each other?).

The overall goal is to maintain and manage the data for easy use by others.
DM
40
MAData CustodianData ManagementThe person, organisation or other entity responsible for the data. They should control access to the data and protect the use of it and sharing of it (or subsets of it) to ensure regulations appropriate to the type of data are followed . This includes ensuring no private data is disclosed when it shouldn’t be.The person, organisation or other entity responsible for some data. They should control access to the data and protect the use of it and sharing of it (or subsets of it) to ensure regulations are followed appropriate to the type of data. This includes ensuring no private data is disclosed when (or to whom) it shouldn’t be.DARE
41
MAData DeletionData ManagementThe process of permanently removing or erasing data from storage systems or devices to ensure that it cannot be recovered or accessed.The process of permanently removing or erasing data from storage systems or devices, ensuring that it cannot be recovered or accessed.DARE
42
MAData DiscoveryProcessesThe process of identifying and accessing relevant data sources for research or analysis.The process of identifying and accessing relevant data sources for research or analysis.DM
43
MAData EgressData ManagementThe movement or transfer of data to infrastructure outside of a TRE either through manual or automated process. Often known as data outputs.The movement or transfer of data to infrastructure outside of TRE either through manual or automated process. Often known as data outputs.DARE
44
MA Data GovernanceProcessesPolicies, procedures, and regulations that govern the collection, storage, access, and use of data to ensure privacy, security, and ethical considerations are addressed.Policies, procedures, and regulations that govern the collection, storage, access, and use of data to ensure privacy, security, and ethical considerations are addressed.DM
45
MAData IngressData ManagementThe movement or transfer of data to infrastructure inside of a TRE either through manual or automated process. Often known as data inputs.The movement or transfer of data to infrastructure inside of TRE either through manual or automated process. Often known as data inputs.DARE
46
MAData Lifecycle Control *Data ManagementThe management and oversight of data throughout its lifecycle, including storage, usage, sharing, retention, and eventual disposal.The management and oversight of data throughout its lifecycle, including storage, usage, sharing, retention, and eventual disposal.DARE
47
MAData LiteracyData in generalThe ability to understand, analyse, interpret, and critically evaluate data and data related studies.DM
48
RMBData Minimisation *Data ManagementSee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_45.xmlThe practice of collecting, processing, and storing only the minimum amount of data necessary to fulfil a specific purpose or requirement to reduce privacy risks.DARE
49
RMBData MiningData in generalSee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_47.xml
See also: https://terms.codata.org/rdmt/data-mining
Data mining is like searching for patterns in data, especially when there's a lot of it. Instead of starting with a question (or ‘hypothesis testing’, you explore the data to find interesting things you didn't expect. Sometimes, this involves using machine learning techniques.

However, one risk of data mining is of finding patterns that seem important but are actually just random or because your data is flawed. So, it's important to be careful and make sure the patterns you discover are truly meaningful.
DM
50
RMBData PoolingData ManagementSee also: https://www.nice.org.uk/Glossary?letter=DIn the context of Federation, but in contrast to Federated Data, Data Pooling refers to a data sharing case where different organisations or data custodians have their own data, with their own policies and autonomy of management, but subscribe to agreements which permit one or more of these individual datasets to be moved into a data handling environment different to that of their custodians, for the purpose of common linkage and onward analysis.DARE
51
BSData ProcessorUK law and rulesAn entity that processes personal data on behalf of a data controller, following the controller's instructions. They do not have control over how the data is used and are only allowed to perform tasks as directed by the controller. For example, a company hired to manage an email service for another organization acts as a data processor. The processor cannot use the data for any other purposes, such as marketing, without the controller's consent.Whereas a data controller decides what is done with data, data processors do what they’re told (and only what they’re told) by the controller, with the controller’s data. For example, it would be typical that an NHS Trust pays a computing company to run its e-mail service or to run an EHR system. In this situation, the NHS Trust is likely to be the data controller, and the computing company the data processor. The data processor isn’t allowed to use the controller’s data for other purposes, e.g. sending out advertising to individuals.DM
52
BSData Protection Act (DPA)UK law and rulesUK law that regulates how personal data—information that can identify living individuals—is collected, used, and stored. It provides rules for organizations on data handling, ensuring privacy and security, while giving individuals rights to access, correct, and control their own data. It implemented UK-specific aspects of the GDPR and superseded previous UK legislation.The Data Protection Act 2018 is the UK’s principal law governing the handling of data relating to identifiable living people (“personal data”). It implemented UK-specific aspects of the GDPR and superseded previous UK legislation. The Act primarily guides organisations in handling data, but it also grants individuals rights to protect their own data.DM
53
BSData Protection Impact AssessmentUK law and rulesA process used to identify and minimize risks to personal data before it is collected or processed. It evaluates how data use might impact individuals' privacy and outlines steps to protect their information. A DPIA helps ensure that data handling practices are safe and secure, functioning like a risk assessment for personal data.Before your personal information is used or processed, the possible risks to you as the ‘data subject’ need to be assessed. This assessment is your Data Protection Impact Assessment. It includes the measures planned to manage those risks and protect your personal information. It's like a safety check to make sure your information stays safe and secure.

It’s also called a privacy impact assessment.
DM
54
BSData Protection OfficerUK law and rulesA professional responsible for ensuring that organizations comply with data protection laws when handling personal data. They advise on data privacy practices, monitor compliance, and act as a point of contact for data protection authorities. Organizations processing large amounts of personal data or those in the public sector are required to appoint a DPO, and they are listed on the public register held by the [Information Commissioner's Office (ICO)]Where data controllers/processors are public bodies or organisations handling personal data on a large scale, they must (under the GDPR) appoint a data protection officer to advise them on data protection and monitor compliance. Data protection officers are listed on the public register held by the Information Commissioner's Office (ICO).DM
55
BSData ScienceData in generalData Science is a field focused on extracting knowledge and insights from data. It combines techniques from data management, computer science, and statistics to store, organize, and analyze data. Data science also involves applying this knowledge to specific problems, making it highly interdisciplinary, with experts from various backgrounds (such as clinicians and computer scientists) collaborating. Its goal is to uncover useful patterns and make data-driven decisions or predictions.Data science is a field of research that focuses on learning from data. It involves different areas of study, like storing, organising and processing data (data management, computer science), and analysing data to find useful patterns (computer science, statistics).It also requires thinking about the specific problem (e.g. a particular disease or condition of interest); after all, there is no science without data.

All these different parts mean data science is often an interdisciplinary field with lots of people from different scientific backgrounds working together (like clinicians and computer scientists).

Data science helps us gain knowledge and insights from the data we have.
DM
56
RMBData SubjectUK law and rulesSee also https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_79.xmlA person whose personal data is being held by a data controller.DM
57
RMBData Transfer AgreementUK law and rulesA Data Transfer Agreement is an agreement or contract between a data controller and another organisation (such as a data processor), governing the transfer of data.
See also: [Data Controller], [Data Processor].
Related to: Data Transfer, see https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_82.xml
When a person or organisation that has control over data wants to share that data with another organisation, they make an agreement or contract. This agreement outlines the terms and conditions for how the data can be transferred and used by the other organisation. The agreement ensures that both parties understand and agree on how the data should be handled.

So a Data Transfer Agreement is an agreement or contract between a data controller and another organisation (such as a data processor), governing the transfer of data.
DM
58
RMBData Transfer ServiceData ManagementA service or system that facilitates the secure and efficient transfer of data between different systems, networks, or locations.
Related to: Data Transfer, see https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_82.xml and https://w3id.org/shp#DataTransfer
A service or system that facilitates the secure and efficient transfer of data between different systems, networks, or locations.DARE
59
RMBData UsersData in generalSee also https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_85.xmlPeople or organisations who access and use collected data for research or other purposesDM
60
RMBDatabaseData in generalSee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_8.xml
See also: https://terms.codata.org/rdmt/database
Databases mainly consist of tables that hold organised information. These tables often connect with each other, forming "relationships" between records. These connections are typical in "relational" databases, where one record refers to another, even in different tables.

Each table is like a grid with rows and columns, focusing on something of interest, such as clinic referrals. Columns represent simple details about the table, like "referral number" or "referral date." Each row, known as a "record," corresponds to a single instance, like a unique referral. In the grid, where rows and columns meet, you find a "value" (also called a "field" or "cell"), which holds a single piece of information, like "2023-01-01." Sometimes, values can be missing, appearing as blank or "null."
DM
61
RMBDe-identificationIdentifiabilitySee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_101.xml
See also: https://terms.codata.org/rdmt/de-identification
De-identified data is where personal details (those which can directly identify a person such as their name and address) have been removed. This is done by replacing or removing these direct identifiers. Where they are replaced by a research identifier (ID) or “pseudonym” this is called pseudonymisation. Both structured data and text can be de-identified. The aim is to ensure data used for analysis or research does not reveal who people are.DM
62
RMBDesktopComputingThe [Graphical User Interface] and environment presented to users on their computer screens, typically including icons, menus, and windows for interacting with applications and files.The graphical user interface (GUI) and environment presented to users on their computer screens, typically including icons, menus, and windows for interacting with applications and files.DARE
63
RMBDesktop ApplicationsComputingSoftware applications designed to be installed and run on individual computers or [Desktop] systems, often providing specific functionalities or tools.Software applications designed to be installed and run on individual computers or desktop systems, often providing specific functionalities or tools.DARE
64
RMBDisclosure ControlThe process of review by approved staff at a Trusted Research Environment (TRE) of any research or analysis results prior to their release from the TRE. The aim of disclosure control is to ensure there are no risks of identifying individuals in any released research results.
Related to: Disclosure Control Methods https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-D_142.xml
Related to: Disclosure Check https://w3id.org/shp#DisclosureCheck
Related to Data Egress - combine the two? Need a clear definition to Disclosure Control (this is the principle) - data egress is the specific process.
65
RMBEgress/Ingress ControlSecurity ManagementThe implementation of measures or controls to control and monitor the movement of data into and out of the TRE, to prevent sensitive data from leaving the TRE. Often known as output/input checking, or in the case of egress, disclosure control.
See also: [Disclosure Control]
The implementation of measures or controls to regulate and monitor the movement of data into and out of the TRE, to prevent sensitive data from leaving the TRE. Often known as output/input checking, or in the case of egress, disclosure control.DARE
66
RMBElectronic Health Record (EHR)Health Services & Health DataA person’s health records that are held digitally on a computer (as opposed to on paper). Also known as an electronic patient record (EPR).A person’s health records that are held digitally on a computer (as opposed to on paper). Also known as an electronic patient record (EPR).DM
67
LMEthical approvalsRunning and Overseeing ResearchEthical approvals are like getting the green light from a group of experts who make sure that research is done in a proper and respectful way. They ensure that participants' rights are protected and everything is conducted responsibly. It's like having a permission slip before starting the research to ensure everything is fair and safe.Ethical approvals are like getting the green light from a group of experts who make sure that research is done in a proper and respectful way. They ensure that participants' rights are protected and everything is conducted responsibly. It's like having a permission slip before starting the research to ensure everything is fair and safe.DM
68
LMEuropean Union (EU) General Data Protection Regulation (GDPR)UK law and rulesThe 2016 GDPR set out the EU framework for the handling of data relating to identifiable living people. Among many other things, it sets out a variety of legal bases for using personal data, such as “the data subject has given consent”, “a task... in the public interest”, or for “scientific... research”. The UK DPA was framed in its terms and set out UK-specific aspects. When the UK left the EU in 2020, the GDPR remained in UK law as the “frozen GDPR” or “UK GDPR”.The 2016 GDPR set out the EU framework for the handling of data relating to identifiable living people. Among many other things, it sets out a variety of legal bases for using personal data, such as “the data subject has given consent”, “a task... in the public interest”, or for “scientific... research”. The UK DPA was framed in its terms and set out UK-specific aspects. When the UK left the EU in 2020, the GDPR remained in UK law as the “frozen GDPR” or “UK GDPR”.DM
69
LMExternal AuditManagementAn independent assessment or review of the TRE organisation's controls, processes, or compliance conducted by external auditors or audit firms.An independent assessment or review of the TRE organisation's controls, processes, or compliance conducted by external auditors or audit firms.DARE
70
BSFAIR DataData in generalFAIR data is a set of principles ensuring data is:
Findable: Easy to locate through clear identification and metadata
Accessible: Retrievable through standard methods, even if authentication is needed
Interoperable: Can work across different systems and with other datasets
Reusable: Well-documented and properly licensed so others can use it

See also: https://terms.codata.org/rdmt/fair-data
See also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-F_3.xml
1. Findable: Making mental health datasets easy to find and locate.
2. Accessible: Ensuring that researchers and others can easily access and obtain mental health data.
3. Interoperable: Allowing different mental health datasets to work together and be combined for analysis.
4. Reusable: Allowing mental health data to be used multiple times for different research purposes.
DM
71
RMBFederationProcessesA grouping of organisations with their own policies and assets (e.g. datasets or computing resources) who agree to allow use of those assets by the broader group but without the assets leaving control or ownership of the organisation.
Ordinary real-world examples of this are the United States of America, Germany or Australia, where member states have individual laws and governance but also subscribe to central policies to enable and encourage working together. 
Federation typically refers to a fairly loose alignment of a number of entities who retain autonomy, but agree to align on certain things as a group. Ordinary real-world examples of this are the United States of America, Germany or Australia, where member states are still individuals with individual laws and management, but they also subscribe to a central body’s policies to enable and encourage working together.  In software terms federation typically then refers to separate organisations with their own policies and assets who agree to allow use of those assets but without the assets leaving control or ownership of the organisation.DARE
72
BSFederated​ AnalyticsComputingFederated analytics is when data analysis happens across multiple independent organisations, with each organisation keeping complete control of their own data. Instead of combining all data in one place, the analysis methods are sent to each organisation's data. For example, multiple hospitals could participate in medical research by running the same analysis on their local patient records, then sharing only the summarized statistical results - like average patient outcomes or treatment effectiveness. The raw patient data never leaves each hospital's secure system, but researchers can still draw insights from the combined statistical findings across all participating hospitalsThe running of “analytics” pipelines or workflows across federated datasets. This could be as simple as having access to one or more federated datasets to allow doing some simple maths or other statistical work, but it could also be simultaneously running interconnected analytics against multiple federated datasets and then aggregating the results.DARE
73
BSFederated DataComputingFederated data is when different organizations keep full control of their own data but agree on ways to safely share access to it for specific purposes. Each organization maintains its own data security and rules, but allows approved users to work with the data through agreed-upon tools and systems. For example, research institutions might share access to their datasets while keeping the data within their own secure environments, allowing collaborative research without moving sensitive data to a central locationAs per Federation above, Federated Data refers to a data sharing case where different organisations or data custodians have their own data, with their own policies and autonomy of management, but subscribe to agreements or organisations, or the use of tools which allow access to that data (e.g. for research purposes), without the raw data ever leaving the custodian’s environment.DARE
74
BSFederated Identity MappingComputingSee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-F_15.xml
The process of linking or mapping user identities across multiple systems or domains to enable seamless access and authentication.DARE
75
BSFederated LearningComputingSee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-F_16.xmlThe running of machine learning model training or predictions against federated datasets.DARE
76
BSFederation OperatorManagementAn organization or entity responsible for managing a federated identity system or network. In such systems, multiple independent organizations (known as "federated members") collaborate to enable secure, streamlined access to resources or services without requiring users to maintain separate credentials for each participating member.An entity or role responsible for managing and coordinating federated identities and access across multiple systems or organisations.DARE
77
BSFederated QueryComputingSee [Federated Analytics]Synonymous with Federated Analytics.DARE
78
BSFirewallSecurity ManagementA security device—either hardware, software, or a combination of both—that monitors and controls incoming and outgoing network traffic based on predetermined security rules. Its primary purpose is to establish a barrier between a trusted, secure internal network and untrusted external networks, like the internet, to protect against unauthorized access, cyberattacks, and other potential threats.
See also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-F_23.xml
A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on a set of predefined rules. It acts as a barrier between a private network (such as a company's internal network) and the public internet, filtering and blocking unwanted traffic while allowing legitimate traffic to pass through. Firewalls can be hardware devices, software applications, or a combination of both. They typically use a variety of techniques to filter network traffic, such as packet filtering, stateful inspection, and application-level filtering. Firewall rules can be configured to allow or block specific types of traffic based on factors such as the source or destination IP address, port number, protocol type, and content. Firewalls are commonly used in enterprise networks to protect against external threats such as malware, hacking attempts, and unauthorized access. They can also be used to control access to specific network resources and applications, and to enforce security policies and compliance requirements. While firewalls are an important component of network security, they are not foolproof and cannot provide complete protection against all types of threats. It is important for organizations to use a multi-layered approach to security, including regular software updates, employee training, and other security measures in addition to firewalls.DARE
79
BSFive SafesProcessesThe Five Safes framework is a set of principles developed to guide researchers and organizations in handling sensitive data.
See also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-F_26.xml
The Five Safes framework is a set of principles developed to guide researchers and organizations in the creation of [Trusted Research Environments] (TREs) for handling sensitive data. It is widely used in the research community. The Five Safes framework consists of five key principles that should be considered when handling sensitive data: safe projects, safe people, safe settings, safe data, safe output.

See also: [fivesafes.org]
WG
80
RMBGraphical User Interface (GUI)A way of interacting with a computer system based on visual presentations of documents, applications and so on as windows on a screen. Users interact with a GUI using pointing devices (e.g. a mouse or a finger) rather than having to type everything.
Contrast with [Command Line Interface].
Keep in as we reference it elsewhere (e.g. APIs)
81
BSIdentifiable DataIdentifiabilityData that can be used to identify, contact, or locate a specific individual, either by itself or when combined with other available information. This includes direct identifiers like full names, NHS numbers, and email addresses; indirect identifiers such as date of birth or workplace that could identify someone when combined; and context-dependent identifiers like IP addresses or device IDs. For example, while a person's age alone might not identify them, combining it with their job title and city of residence could make them identifiable – such as "a 45-year-old pediatric surgeon in Bolton, Greater Manchester" might be specific enough to identify a particular individual, even without naming them directly. This type of data requires special handling under various privacy regulations like GDPR to protect individuals' privacy and prevent unauthorized access or misuse.
See also: https://terms.codata.org/rdmt/direct-identifier and https://terms.codata.org/rdmt/indirect-identifier
See alos: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-I_5.xml
Identifiable data is information that directly tells you who someone is. It includes things like their name, date of birth, address, NHS number, and phone number. These are direct identifiers. For example, if you have a person's name, birthdate, and NHS number, you can easily identify them. This kind of data is private and needs to be handled carefully to protect people's personal information.

A fictional example: “John Smith, male, DOB 3 Jan 1948, NHS# 1234567890, diagnoses of depression and heart failure” where “John Smith, male, DOB 3 Jan 1948, NHS# 1234567890” is the identifiable data.
DM
82
BSIdentity and Access Management ServicesSecurity ManagementSee also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-I_18.xmlServices, systems, or processes that govern and control user identities, access privileges, authentication, and authorization within an organisation.DARE
83
BSIdentity VerificationSecurity ManagementThe process of confirming or authenticating the identity of individuals or entities, often through the verification of personal information, credentials, or biometric data.The process of confirming or authenticating the identity of individuals or entities, often through the verification of personal information, credentials, or biometric data.DARE
84
LMInformation Asset Owner *Data ManagementAn individual or role accountable for managing and overseeing an information asset, including their acquisition, use, maintenance, and protection.An individual or role accountable for managing and overseeing an information asset, including their acquisition, use, maintenance, and protection.DARE
85
LMInformation Commissioner's Office (ICO)UK law and rulesThe UK’s independent authority for upholding information rights in the interest of the public.
The ICO oversees the application of the Data Protection Act and the UK GDPR, and has the power to issue monetary pentalties for infringement of dat protection legislation.
The UK’s independent authority for data protection. The ICO oversees the application of the Data Protection Act. If you have questions about data protection or want to report a data breach, you can reach out to the ICO through:DMKeep in as it's a national regulatory institution.
86
LMInformation Governance (IG)UK law and rulesHow an organisation takes care of its information or data. It involves strategies and processes for defining, collecting, storing, securing, using, protecting and disposing of data safely, while also respecting privacy. IG ensures that data is managed well throughout its life cycle, following guidelines and laws. It helps organisations handle data responsibly, protect it from risks, and use it in a way that follows rules and keeps people's information safe.
Information governance also identifies the processes to be followed in the event of a failure to protect personal data, and any reporting, or escalation to regulatory bodies if necessary,.
Information Governance (IG) is how an organisation takes care of its information or data. It involves strategies and processes for collecting, storing, securing, using, protecting and disposing of data safely, while also respecting privacy. IG ensures that data is managed well throughout its life cycle, following guidelines and laws. It helps organisations handle data responsibly, protect it from risks, and use it in a way that follows rules and keeps people's information safe.DM
87
LMInternal AuditManagementAn independent evaluation process performed within the TRE organisation that assesses and improves its internal controls, risk management, and governance.An independent evaluation process within the TRE organisation that assesses and improves its internal controls, risk management, and governance.DARE
88
BSInteroperabilityComputingThe ability of two or more systems, devices, or applications to exchange and use information seamlessly. Interoperability enables these systems to work together, often through the adoption of open standards, that facilitate consistent communication and data sharing without requiring custom intergration. Good interoperability promotes collaboration, scalability, and the extension of services by allowing different systems to work together in a standarised, vendor-neutral way, thereby reducing techinal and operational barriers.
See also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-I_65.xml
Allowing mutual operation between (inter) two or more systems. Mainly letting systems work together, or communicate with each other. If you control the development of two systems it is easy to get them to interoperate using a proprietary defined interface between those two specific systems, but good interoperability is usually achieved through the use of open standards, whereby any system can understand the standard being used and be developed to work with it, encouraging collaboration, extension etc.DARE
89
LMIssue Management ProcessComputingA systematic approach to identifying, tracking, resolving, and managing issues or problems that arise within a TRE organisation, aiming to minimise their impact and ensure timely resolution.
Common mechanisms to manage the effective resolution of such issues can include Corrective and Preventive Actions (CAPAs), which enable such instances to be documented and provide an audit trail of activities undertaken to prevent recurrence.
A systematic approach to identifying, tracking, resolving, and managing issues or problems that arise within a TRE organisation, aiming to minimise their impact and ensure timely resolution.DARE
90
SLIT Service ProviderComputingA company, department, or entity that delivers information technology services or support to internal or external clients, such as network management, software development, or helpdesk support.A company, department, or entity that delivers information technology services or support to internal or external clients, such as network management, software development, or helpdesk support.DARE
91
LMLawful BasisUK law and rulesOn 25 May 2018 the General Data Protection Regulation (“GDPR”) came into force. From this date, you must have a defined lawful basis to hold and use ‘personal data’. The Health Research Authority (HRA) and Information Commissioner’s Office (ICO) advise that for almost all research conducted in the UK organisations should rely on either: (1) ‘Task in public interest’ – for all public bodies (NHS / HSC, Universities, UKRI etc), or (2) ‘Legitimate interest’ – for non-public bodies (charities etc.)
See also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-L_3.xml
WG
92
RMBLinkage of data (data linkage)ProcessesJoining two or more sets of data together using one (or more) pieces of information common to all (often called "common keys"). Linkage may be based on straightforward rules (“two records with the same NHS number are from the same person”) or based on probability (“if two records share the same forename, surname, and date of birth, they are more likely to be from the same person”). Links may be made using identifiable data (e.g. NHS number) or de-identified data (e.g. a research pseudonym).
For example: joining a health dataset with an employment dataset using a common key based on individual names and addresses.
Joining (linking) data from more than one source. For example, to study the relationships between mental and physical health conditions, it might be necessary to link data from NHS mental health services to primary care (GPs) or acute hospital data. To study the relationships between health conditions and education, it might be necessary to link data from health services and a government education department.
Linkage may be legally complex because it involves data from more than one data controller. Linkage may be based on straightforward rules (“two records with the same NHS number are from the same person”) or based on probability (“if two records share the same forename, surname, and date of birth, they are more likely to be from the same person”). Links may be made using identifiable data (e.g. NHS number) or de-identified data (e.g. a research pseudonym).
WG
93
RMBLongitudinal DatasetData in GeneralA collection of data related to the same group of people over a long time to see how things change. This may involve asking the same questions at different ages.A collection of data related to the same group of people over a long time to see how things change. This may involve asking the same questions at different ages.DM
94
RMBMachine Learning (ML)AnalysisA computer programming technique particularly suited to identifying patterns or rules in large amounts of data. Rather than beginning with a fixed set of rules, an ML program builds up ("learns") a set of likely rules by processing many example datasets (this stage of ML is known as "training"). When the set of likely rules is complete, the ML program can apply them to new datasets and offer a likely prediction (this stage is known as "inference").
For example: an ML program trained to recognise car numberplates would be trained on many pictures of car numberplates, building up a set of likely rules that will enable to program to "recognise" car numberplates in the future.
See also: https://www.elgaronline.com/display/book/9781035300921/b-9781035300921-M_2.xml
Machine learning is like teaching a computer to learn on its own. It can find patterns in data and make predictions about what might happen in the future based on the data. ML algorithms (which are computer programs) can work by themselves (“unsupervised”) to discover patterns, or can be trained to classify data automatically based on examples classified by a human (“supervised”).
Machine learning can do impressive things like spotting breast cancer in X-ray pictures.
But there are two problems. First, what is learnt in one system doesn't always work in another. Second, is that a system taught by machine learning may be like a “black box”: it might be difficult for a researcher, clinician, patient or member of the public to understand how it reached its decision, and therefore to trust its results.
DM
95
RMBMalware Scanning ApplicationSecurity ManagementA software application or tool that scans and detects malicious software or malware on computer systems or networks, aiming to prevent security breaches or infections.A software application or tool that scans and detects malicious software or malware on computer systems or networks, aiming to prevent security breaches or infections.DARE
96
RMBMetadataData in generalMetadata is data that describes or provides information about other data. It is used to provide context, meaning, and structure to data, and helps to make it easier to understand and use. Metadata can describe various aspects of data, such as its content, format, structure, origin, quality, and usage.Metadata is data that describes or provides information about other data. It is used to provide context, meaning, and structure to data, and helps to make it easier to understand and use. Metadata can describe various aspects of data, such as its content, format, structure, origin, quality, and usage.DARE
97
RMBMinimum Viable Product (MVP)ComputingA minimal viable product (MVP) is a version of a product or service that has the minimum set of features and functionality required to meet the needs of early adopters or customers. The goal of an MVP is to quickly validate the product idea and test the market demand, while minimizing development costs and time-to-market.A minimal viable product (MVP) is a version of a product or service that has the minimum set of features and functionality required to meet the needs of early adopters or customers. The goal of an MVP is to quickly validate the product idea and test the market demand, while minimizing development costs and time-to-market.DARE
98
RMBMonitoringManagementThe continuous or periodic observation, measurement, or tracking of systems, processes, activities, or events to ensure compliance, performance, or security.The continuous or periodic observation, measurement, or tracking of systems, processes, activities, or events to ensure compliance, performance, or security.DARE
99
LMNational Data GuardianSpecial aspects in the NHS ContextThe National Data Guardian (NDG) for Health and Social Care is an independent champion for patients and the public when it comes to matters of their confidential health and social care data, and appointed by the Secretary of State for Health and Social Care by statute . To support the development and maintenance of trustworthy systems and practices, the NDG provide advice, encouragement, and challenge to the health and social care system on the safe, appropriate, and ethical use of people’s confidential health and care information.

The NDG advise the UK government and NHS on the processing of health and adult social care data in England. Both the Caldicott Guardian and the National Data Guardian protect patient information. The Caldicott Guardian focuses on data protection within individual healthcare organisations.
The National Data Guardian for Health and Social Care advises the UK government and NHS on the processing of health and adult social care data in England. They are independent and appointed by the Secretary of State for Health and Social Care by statute. Their job is to make sure people’s confidential information is safeguarded securely and used properly. Both the Caldicott Guardian and the National Data Guardian protect patient information. The National Data Guardian oversees data use across the entire UK health sector to ensure proper use of patient info. The Caldicott Guardian focuses on data protection within individual healthcare organisations.DM
100
LMNational Data Opt-Out (NDO)Special aspects in the NHS ContextBy default, patients are included in the system. But if you don't want your private information to be shared, you can choose to opt-out using the National Data Opt-out in England and Wales.
The NHS National Data Opt-Out allows you say 'no' to sharing your personal information for things like research without asking you first. This comes from the NHS Act Section 251 and the requirements outlined in the UK GDPR and Data Protection Act.
When you decide to opt-out, your personal information remains exclusively for your medical care.
By default, patients are included in the system. But if you don't want your private information to be shared, you can choose to opt-out using the National Data Opt-out in England.
The NHS National Data Opt-Out allows you say 'no' to sharing your personal information for things like research without asking you first. This comes from the NHS Act Section 251.
However, if your information can't be linked to you or the NHS only uses it for their own purposes, this rule doesn't count. Sometimes, if they get special permission (Section 251 approval), they can still use information that identifies you.
The trouble is, not many people know about this choice to opt-out. Usually, patients are added automatically unless they decide not to be.
When you decide to opt-out, your personal information remains exclusively for your medical care.
DM