Purpose definition as a crucial step for determining the legal basis under the GDPR: implications for scientific research

Author:

Becker Regina1ORCID,Chokoshvili Davit1,Thorogood Adrian2,Dove Edward S3ORCID,Molnár-Gábor Fruzsina4,Ziaka Alexandra56,Tzortzatou-Nanopoulou Olga7,Comandè Giovanni8

Affiliation:

1. Luxembourg National Data Service , L-4362 Esch-sur-Alzette, Luxembourg

2. Terry Fox Research Institute , V5Z 1L3 Vancouver, Canada

3. University of Edinburgh School of Law, , EH8 9YL, Edinburgh, UK

4. Heidelberg University Faculty of Law, , 69117, Heidelberg, Germany

5. Tilburg Institute for Law, Technology & Society (TILT), Tilburg University , Tilburg 5037 DB, Netherlands

6. MPLegal , Athens 15231, Greece

7. Legal Department, Biomedical Research Foundation of the Academy of Athens , Athens 11527, Greece

8. Sant’Anna School of Advanced Studies , 56127, Pisa, Italy

Abstract

Abstract The General Data Protection Regulation (GDPR) of the European Union, which became applicable in 2018, contains a new accountability principle. Under this principle, controllers (ie parties determining the purposes and the means of the processing of personal data) are responsible for ensuring and demonstrating the overall compliance with the GDPR. However, interpretive uncertainties of the GDPR mean that controllers must exercise considerable judgement in designing and implementing an appropriate compliance strategy, making GDPR compliance both complex and resource-intensive. In this article, we provide conceptual clarity around GDPR compliance with respect to one core aspect of the law: the determination and relevance of the purpose of personal data processing. We derive from the GDPR’s text concrete requirements for purpose specification, which we subsequently apply to the area of secondary use of personal data for scientific research. We offer guidance for correctly specifying purposes of data processing under different research scenarios. To illustrate the practical necessity of purpose specification for GDPR compliance, we then show how our proposed approach can enable controllers to meet their compliance obligations, using the example of the overarching GDPR principle of lawfulness to highlight the relevance of purpose specification for the identification of a suitable legal basis.

Funder

German Federal Ministry of Education and Research, Project TrustDNA

Deutsche Forschungsgemeinschaft

Innovative Medicines Initiative 2 Joint Undertaking Research and Innovation Action European Platform for Neurodegenerative Diseases (EPND

European Union’s Horizon 2020 research and innovation programme Coordination and Support Action HealthyCloud

Genomic Data Infrastructure

Beyond 1 Million Genomes

Publisher

Oxford University Press (OUP)

Cited by 1 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3