Tag: gdpr

GDPR: Can I share research data with personal data with other researchers or institutions when my research project has ended?

The GDPR does not prevent research data containing personal data from being shared with other researchers for reproducibility and reuse after the research. What are the conditions for the reuse of personal data? Sufficient technical and organizational measures must be taken such as pseudonymization, limitation of access to the data, ...    Read more

GDPR: how am I transparent to data subjects in my research?

Informing the persons whose personal data are processed (the data subjects) is one of the basic principles and obligations of the General Data Protection Regulation (GDPR). As a researcher, it is your responsibility to communicate this information to the data subjects in a concise, transparent, comprehensible and easily ...    Read more

GDPR: how can I ensure that the processing of personal data is lawful?

The processing of personal data is only lawful if one of the conditions or legal grounds of the General Data Protection Regulation (GDPR) is met. It is very important to indicate the applicable legal basis for the processing at the start of your research in the GDPR register. The processing ...    Read more

GDPR: how can I protect my data correctly?

When you process personal data you have the ethical and legal obligation to ensure that personal data are sufficiently protected. The basic level of security must always be in accordance with the information security policy of Ghent University. However, additional measures may be necessary specifically for each processing. The ...    Read more

GDPR: how do I register personal data processing activities?

Why register processing activities? The General Data Protection Regulation (GDPR, known as AVG in Dutch) requires that all activities concerning the processing of personal data at UGent and UZ Gent are documented and registered in a 'register of processing activities', the GDPR Register. This internal registration replaces the ...    Read more

GDPR: how long can research data containing personal data be stored?

The General Data Protection Regulation (GDPR) requires that personal data cannot be kept longer than necessary to achieve the purposes for which they are processed (see the ‘storage limitation’ principle). The RDM Policy framework of Ghent University requires that research data be kept for a minimum of 5 ...    Read more

GDPR: what are personal data?

Personal data Personal data are any information about an identified or identifiable natural person. A natural person is considered to be identifiable if he or she can be identified directly or indirectly. some examples of 'normal' personal data include: name, address, e-mail address, photo, ID number, IP address, employee ...    Read more

GDPR: what are the basic principles?

The General Data Protection Regulation (GDPR) is based on six basic principles that you must take into account when processing personal data. Basic principles 1. Lawfulness, fairness and transparency You are obliged to process personal data in a transparent manner with respect for all applicable laws, regulations and rules. ...    Read more

GDPR: what are the different roles and responsibilities according to the GDPR?

Various roles are defined within the General Data Protection Regulation (GDPR) for the processing of personal data. The most important roles are:  Data controller Joint data controller  Data processor Since controllers and processors have different responsibilities and obligations, it is important that you clearly define these roles (together with ...    Read more

GDPR: What do I need to think about when transferring personal data to third countries or international organisations?

If you collaborate with researchers, partners or institutions located in another country, within or outside the EU, in your research, you must pay attention when making personal data accessible, forwarding or exchanging. This also applies when you use processors or subcontractors, such as Qualtrics (processor based in the USA). Moreover, ...    Read more

GDPR: what has changed with regard to the previous privacy legislation?

Although the main components of the previous privacy legislation are largely retained, the General Data Protection Regulation (GDPR) also introduces a number of important changes. 1. Accountability The former 'obligation to report' to the privacy commission was replaced with 'accountability' whereby you as the researcher must document the processing of ...    Read more

GDPR: what information should I include in an informed consent form when the processing of personal data is based on the consent of the data subjects?

To be lawful, the processing of personal data must be based on one of the legal grounds provided in the General Data Protection Regulation (GDPR). If the processing of personal data within your research project is based on the consent of the data subject as the legal basis, ...    Read more

GDPR: what is the General Data Protection Regulation?

When you process personal data for your research, you must follow the rules of the General Data Protection Regulation (GDPR). The GDPR: new European privacy legislation The GDPR, which has been in force since 25 May 2018, modernises the existing privacy legislation. It creates a uniform European legislative framework ...    Read more

GDPR: what rights do data subjects have, how do I respect them and what exceptions may apply to research?

The General Data Protection Regulation (GDPR) defines the persons whose personal data are processed as data subjects. As a researcher, you have to take into account that the data subjects can in accordance with the GDPR exercise different rights with regard to their personal data. 1. Right to information ...    Read more

GDPR: What should I do if there is a data breach?

A data breach is a security incident that affects the confidentiality, integrity or availability of personal data. Possible incidents that can lead to a data breach are: access to personal data by an unauthorised third party; intentional or unintentional action that affects the security of personal data; sending personal data ...    Read more

GDPR: what should I do in the event of further/secondary processing of personal data?

Primary vs. secondary processing In the case of further or secondary processing of personal data in a research project, the personal data will not be directly collected from the data subjects by you. If you do collect the personal data directly from the data subjects as part of your research ...    Read more

GDPR: what should I keep in mind when designing my research?

Privacy by design In the design phase of a research project, you normally think about the substance and methodological aspects of your research. In view of the General Data Protection Regulation (GDPR) it is important to also thoroughly consider and describe the collection and processing of personal data during the ...    Read more

GDPR: what should I keep in mind when processing special categories of personal data?

Special categories of personal data (sensitive personal data) Some personal data belong to the group of “special categories” of personal data: these are personal data revealing racial or ethnic origin, political views, religious or philosophical beliefs, membership of a trade union, genetic data, biometric data, data about health ...    Read more

GDPR: What should I think about when I collaborate with others or share my data?

Research data with personal data can be shared within Ghent University with researchers within your own research project or with fellow researchers under certain conditions for further processing or reuse of the research data. It is important to document and justify this transfer of data in the GDPR register. Also, ...    Read more

GDPR: What should I think about when processing personal data from minors?

Minors (children below the age of 18 year) have the right to specific protection, as they are often less aware of their rights, the possible risks and consequences associated with the processing of their personal data. Transparancy Children must be informed about which data are collected, what they will be ...    Read more

GDPR: When am I processing high-risk personal data and when do I need to conduct a DPIA?

What is a DPIA? When the personal data or the nature of the processing probably entails a high risk for the data subjects, the GDPR obliges you to carry out a risk analysis before the start of the processing, a so-called Data Protection Impact Assessment (DPIA). A DPIA is ...    Read more

GDPR: when does it apply to my research?

The General Data Protection Regulation (GDPR) applies when you (or your institution or organisation) process personal data in the framework of scientific research (e.g. collection, recording, classification, structuring, storage, adaptation or alteration, retrieval, consultation, use, etc.), regardless of the origin of the personal data when you (or your institution or ...    Read more

GDPR: who are considered as vulnerable persons?

Sometimes mention is made of vulnerable natural persons in the context of the General Data Protection Regulation (GDPR). Examples babies and young children pregnant women the elderly people with mental disorders asylum seekers people with disabilities ethnic minorities the sick and patients These are often persons who are legally ...    Read more

GDPR: why is it important to comply with this legislation?

Protecting the rights and freedoms of data subjects If you process personal data, your job is to protect the rights and freedoms of data subjects in accordance with the General Data Protection Regulation (GDPR). For this you must evaluate the possible risks associated with the processing of personal data ...    Read more