This wiki has undergone a migration to Confluence found Here

Difference between revisions of "GDPR (General Data Protection Regulation)"

From HL7Wiki
Jump to navigation Jump to search
Line 39: Line 39:
 
*[https://ec.europa.eu/digital-single-market/en/news/code-conduct-privacy-mhealth-apps-has-been-finalised Final draft of the Code of Conduct on privacy for mHealth apps]
 
*[https://ec.europa.eu/digital-single-market/en/news/code-conduct-privacy-mhealth-apps-has-been-finalised Final draft of the Code of Conduct on privacy for mHealth apps]
 
*[http://ec.europa.eu/newsroom/dae/document.cfm?doc_id=5147 Green Paper on mobile health]
 
*[http://ec.europa.eu/newsroom/dae/document.cfm?doc_id=5147 Green Paper on mobile health]
 +
==GDPR Articles==
 +
*[https://www.theguardian.com/technology/2018/may/24/sites-block-eu-users-before-gdpr-takes-effect Sites block users, shut down activities and flood inboxes as GDPR rules loom] Unfortunately, even going to the extremes of blocking every user based in the EU might not be enough to inure companies from the consequences of GDPR: the law applies to data processed on EU citizens wherever they are based in the world.
  
 
==UMA Legal==
 
==UMA Legal==
 
*[https://gforge.hl7.org/gf/project/security/docman/Security%20White%20Papers/Is%20Privacy%20Obsolete%20Study%20Group%20Library/UMA/iaccmcontractingprinciples.pdf IACCM Contracting Principles International Association for Contract and Commercial Management]
 
*[https://gforge.hl7.org/gf/project/security/docman/Security%20White%20Papers/Is%20Privacy%20Obsolete%20Study%20Group%20Library/UMA/iaccmcontractingprinciples.pdf IACCM Contracting Principles International Association for Contract and Commercial Management]
 
*[https://gforge.hl7.org/gf/project/security/docman/Security%20White%20Papers/Is%20Privacy%20Obsolete%20Study%20Group%20Library/UMA/UMA%20Legal%20role%20definitions%20March%202018.pptx UMA Legal role definitions March 2018]
 
*[https://gforge.hl7.org/gf/project/security/docman/Security%20White%20Papers/Is%20Privacy%20Obsolete%20Study%20Group%20Library/UMA/UMA%20Legal%20role%20definitions%20March%202018.pptx UMA Legal role definitions March 2018]

Revision as of 13:59, 25 May 2018

Back to Security Main Page

GDPR Background

GDPR Presentations and Papers

GDPR Connectathon May 2018

GDPR mHealth Apps

  • mHealth Code to Aid App Developers in the EU Privacy Code of Conduct for mHealth apps was drafted by a working group set up in January this year and the final draft was published on 7th June and submitted to the Article 29 Working Party for their consideration and approval. If and when it receives the Working Party’s approval it could then be relied upon by app developers wishing to demonstrate a good standard of data protection compliance. The Code is an example of the type of initiative that is increasingly likely to develop under the forthcoming EU General Data Protection Regulation (GDPR). The second section of the Code sets out the practical guidelines. These are:
  1. Consent of users: the need to obtain valid explicit consent from the data subject to collect and use their data
  2. Data Protection Principles – Purpose Limitation, Data Minimisation, Transparency, Privacy by design and privacy by default and data subject rights: these reflect principles at the heart of EU Data Protection rules
  3. Information to provide to users before they use the app: guidance on adopting a layered notice approach and using a condensed notice and full privacy policy
  4. Data Retention: the Code acknowledges that it can be difficult to irreversibly anonymise health data when the retention period expires
  5. Security: the requirement to carry out a Privacy Impact Assessment and adopt security measures recommended by ENISA
  6. Advertising on the app: any advertising must be authorised by the user but there is a difference in approach depending on whether the advertising involves the processing of personal data
  7. Use of data for secondary purposes: in instances where data could be used for scientific research or other big data analysis
  8. Disclosing data to third parties: ensuring that there’s an agreement in place with the third party is essential
  9. Data Transfers: complying with the rules around international data transfers
  10. Data Breach: what to do and whom to notify when a data breach occurs
  11. Children’s data: when apps are deliberately aimed at children

Posted on June 17th, 2016 By Victoria Hordern. Posted in Health Privacy/HIPAA, International/EU Privacy

  • Trust in mHealth apps: As revealed by the European Commission's 2014 mHealth Green Paper consultation, people often do not trust mHealth apps, such as those monitoring your health or giving health advice. Respondents to the mentioned consultation considered that having users' consent as well as strong privacy and security tools in place is a crucial issue in relation to mobile health apps.

GDPR Articles

UMA Legal