Individual Submission Summary
Share...

Direct link:

Post-GDPR Issues to Confidential Data Management: An Analysis of the Use of Privacy Enhancing Technologies in Health Data Research Centres

Fri, September 6, 4:30 to 6:00pm, Sheraton New Orleans Hotel, Floor: Eight, Zulu

Abstract

In health, there has been a proliferation of centralised research data centres in the last decade; so-called Trusted Research Environments (TRE). TREs are not trading or exchanging data, but are proving remote data access and means for data analytics within a closed environment. This approach promises valuable insights while at the same preserving people's privacy by limiting the exposure of personal health data. To ensure data owners, users, and the public that they are capable of providing safe and secure access to confidential data, TRE engage in complex operational procedures, information governance protocols, and accreditation processes.
Now, new data protection regulations, in particular the GDPR, are affecting the design of TREs. The GDPR aimed at giving data subjects and regulatory bodies more control over data, primarily to stop data brokers illegally selling data without people's knowledge. Requirements like "data protection by design and by default" (Art. 25) has led to a rethinking of existing practices in TREs and is creating new business models; so-called privacy enhancing technologies. In my talk, I will draw on ethnographic field work and provide an analysis of post-GDPR approaches to secure privacy and minimise risks in the case of a cloud-based TRE in the north of England. I can highlight how privacy enhancing technologies are turning access and analytics instead of data into assets. Further, they are distributing risk unevenly amongst the different stakeholders and are paradoxically reducing opportunities for regulatory bodies to oversee and for individuals to exercise data subject rights.

Author