Responsible Research and Innovation (‘RRI’) is a cross-cutting priority for scientific research in the European Union and beyond. This paper considers whether the way such research is organised and delivered lends itself to the aims of RRI. We focus particularly on international consortia, which have emerged as a common model to organise large-scale, multi-disciplinary research in contemporary biomedical science. Typically, these consortia operate through fixed-term contracts, and employ governance frameworks consisting of reasonably standard, modular components such as management committees, advisory boards, and data access committees, to co-ordinate the activities of partner institutions and align them with funding agency priorities. These have advantages for organisation and management of the research, but can actively inhibit researchers seeking to implement RRI activities. Conventional consortia governance structures pose specific problems for meaningful public and participant involvement, data sharing, transparency, and ‘legacy’ planning to deal with societal commitments that persist beyond the duration of the original project. In particular, the ‘upstream’ negotiation of contractual terms between funders and the institutions employing researchers can undermine the ability for those researchers to subsequently make decisions about data, or participant remuneration, or indeed what happens to consortia outputs after the project is finished, and can inhibit attempts to make project activities and goals responsive to input from ongoing dialogue with various stakeholders. Having explored these challenges, we make some recommendations for alternative consortia governance structures to better support RRI in future.
The EU General Data Protection Regulation (‘GDPR’) seeks to balance the public interest in research with privacy rights of individuals, in particular, through research exemptions and safeguards set out in Article 89. While this affords Member States limited opportunities to modify the application of the GDPR at a national level, including for data processing that is necessary for the performance of a task carried out in the public interest, it is necessary for national approaches to conform with Article 89 safeguards where appropriate. One development of interest to the research community in the UK is a statutory power for public authorities to disclose administrative data for research under the Digital Economy Act 2017 (DEA). This article uses the DEA as a case study for analysis of the GDPR provisions governing processing of data for research purposes—including de-identification—and draws on human rights norms and jurisprudence to interpret the broad requirement for ‘appropriate safeguards’ for the ‘rights and freedoms of the data subject’ under Article 89. This analysis is important for data controllers seeking to meet their obligations under the UK framework and for those in other EU Member States considering the development of similar national provisions for data processing for research purposes.
Researchers in genomics are exploring novel ways to interact directly with prospective participants without utilizing physicians, hospitals, or biobanks as intermediaries. Many researchers are interested in using the internet to directly recruit and enroll research participants in genomic studies by posting information online about active or proposed studies. This direct-to-participant (DTP) approach could take place under three main scenarios:
The UK government funded the Administrative Data Research Network (ADRN) with the explicit aim of making administrative data available for research; however, the legal framework for doing so is complex and the basis for disclosing these data to third party researchers is not straightforward. This paper critically analyses the legal framework for public authorities to disclose administrative data for the purposes of research, which will change significantly with the introduction of the General Data Protection Regulation (GDPR) and the UK Digital Economy Act 2017 (DEA). Our practical assessment of the new statutory power under the DEA for public authorities to disclose non-identifiable administrative data for research purposes highlights the challenges that may remain for researchers requiring access to linked administrative and health and adult social care data. Our review, in this paper, of the existing regimes for research using linked data is therefore necessary and useful for researchers, public authorities and data protection advisers.
Anonymisation of personal data has a long history stemming from the expansion of the types of data products routinely provided by National Statistical Institutes. Variants on anonymisation have received serious criticism reinforced by much-publicised apparent failures. We argue that both the operators of such schemes and their critics have become confused by being overly focused on the properties of the data itself. We claim that, far from being able to determine whether data is anonymous (and therefore non-personal) by looking at the data alone, any anonymisation technique worthy of the name must take account of not only the data but also its environment.This paper proposes an alternative formulation called functional anonymisation that focuses on the relationship between the data and the environment within which the data exists (the data environment). We provide a formulation for describing the relationship between the data and its environment that links the legal notion of personal data with the statistical notion of disclosure control. Anonymisation, properly conceived and effectively conducted, can be a critical part of the toolkit of the privacy-respecting data controller and the wider remit of providing accurate and usable data.
There has naturally been a good deal of discussion of the forthcoming General Data Protection Regulation. One issue of interest to all data controllers, and of particular concern for researchers, is whether the GDPR expands the scope of personal data through the introduction of the term ‘pseudonymisation’ in Article 4(5). If all data which have been ‘pseudonymised’ in the conventional sense of the word (e.g. key-coded) are to be treated as personal data, this would have serious implications for research. Administrative data research, which is carried out on data routinely collected and held by public authorities, would be particularly affected as the sharing of de-identified data could constitute the unconsented disclosure of identifiable information.Instead, however, we argue that the definition of pseudonymisation in Article 4(5) GDPR will not expand the category of personal data, and that there is no intention that it should do so. The definition of pseudonymisation under the GDPR is not intended to determine whether data are personal data; indeed it is clear that all data falling within this definition are personal data. Rather, it is Recital 26 and its requirement of a ‘means reasonably likely to be used’ which remains the relevant test as to whether data are personal. This leaves open the possibility that data which have been ‘pseudonymised’ in the conventional sense of key-coding can still be rendered anonymous. There may also be circumstances in which data which have undergone pseudonymisation within one organisation could be anonymous for a third party. We explain how, with reference to the data environment factors as set out in the UK Anonymisation Network's Anonymisation Decision-Making Framework.
The guide sets out the legal background to data protection laws in the UK, and offers a broad explanation of the current law relating to data sharing and linkage, as well as a consideration of the implications of the impending EU General Data Protection Regulation 2016 (GDPR). There is also consideration of some non-legal issues surrounding the topic.
This paper discusses the nature of genomic information, and the moral arguments in support of an individual's right to access it. It analyses the legal avenues an individual might take to access their sequence information. The authors describe the policy implications in this area and conclude that, for now, the law appears to strike an appropriate balance, but new policy will need to be developed to address this issue.
Consent forms are the principal method for obtaining informed consent from biomedical research participants. The significance of these forms is increasing as more secondary research is undertaken on existing research samples and information, and samples are deposited in biobanks accessible to many researchers. We reviewed a selection of consent forms used in European Genome-Wide Association Studies (GWAS) and identified four common elements that were found in every consent form. Our analysis showed that only two of the four most commonly found elements in our sample of informed consent forms were required in UK law. This raises questions about what should be put in informed consent forms for research participants. These findings could be beneficial for the formulation of participant information and consent documentation in the future studies.
Consent forms are the principal method for obtaining informed consent from biomedical research participants. The significance of these forms is increasing as more secondary research is undertaken on existing research samples and information, and samples are deposited in biobanks accessible to many researchers. We reviewed a selection of consent forms used in European Genome-Wide Association Studies (GWAS) and identified four common elements that were found in every consent form. Our analysis showed that only two of the four most commonly found elements in our sample of informed consent forms were required in UK law. This raises questions about what should be put in informed consent forms for research participants. These findings could be beneficial for the formulation of participant information and consent documentation in the future studies.
Analyses of individuals' genomes--their entire DNA sequence--have increased knowledge about the links between genetics and disease. Anticipated advances in 'next generation' DNA-sequencing techniques will see the routine research use of whole genomes, rather than distinct parts, within the next few years. The scientific benefits of genomic research are, however, accompanied by legal and ethical concerns. Despite the assumption that genetic research data can and will be rendered anonymous, participants' identities can sometimes be elucidated, which could cause data protection legislation to apply. We undertake a timely reappraisal of these laws--particularly new penalties--and identifiability in genomic research.