Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

16 August 2016

Trust, Consent and Opt-outs in the Re-use of Health Data: Where Next?

By Graeme Laurie

In June 2016, the National Data Guardian, Dame Fiona Caldicott, published her Review of Data Security, Consent and Opt-Outs in relation to patient confidential data. She did so at the request of the Secretary of State for Health who had asked for recommendations on new data security standards, methods for compliance testing, and a new consent or opt-out model for sharing patient data for care and other purposes, such as services commissioning and research.

Dame Fiona is best known for her six Caldicott Principles for protecting confidentiality first issued in 1997. A further report in 2013 added a seventh Principle – that the duty to share information can be as important as the duty to protect patient confidentiality – but it seems that the message has been not getting through. Furthermore, the fallout from the ill-conceived and poorly executed care.data initiative is widespread in England. Although the 2016 Review did not address this directly, it undoubtedly cast a pall over proceedings (see further: Safe data, safe care).

10 March 2016

Genetic Non-Discrimination: A Long-Standing Concern Deserving a New Law?

By Shawn H.E. Harmon

The possibility of improving outcomes and cost-effectiveness by tailoring therapies to patients’ genetic profiles (stratified medicine) is a dream of researchers and healthcare programmes, although at present relatively few tests are viewed as reliable.[1] 

Counterbalancing these positives, genetic information can also be used to discriminate against individuals; information about otherwise healthy people’s predisposition can affect how decisions are made in relation to a wide range of fields, including insurance (coverage, premiums, deductibles), employment (hiring, promotion, dismissal), banking (loans), education (funding, acceptance), sports (participation), and more, and has already affected people in relation to employment and insurance.[2]

23 September 2015

The Motley Coat of Data

By Leslie Stevens

As a lawyer I am accustomed to, but sceptical of, hard and fast categories – we know all too well that bright line rules and seemingly fixed categories raise more questions than they provide answers. In data protection several such categories exist: anonymous data and personal data, sensitive personal data and ordinary personal data, data controller and data processor and so forth. Given the current reform of data protection law in Europe, and the anticipated introduction of the General Data Protection Regulation circa 2016/2017, questions should be (and have been) raised as to the effectiveness of these categories as regulatory tools. The lines between anonymous data and personal data have been blurred – the ease with which data may be re-identified and the power of data linkage has revealed the fallacy that is truly ‘anonymous’ data. Ordinary personal data, once considered innocuous, when combined with any countless array of other data, are likely to reveal intimate details about people’s lives – far more sensitive than data protection law would recognise.

9 September 2014

The Draft General Data Protection Regulation: current proposals [UPDATED 5 November 2013]

By Leslie Stevens

UPDATE, 5 November 2013: After much delay, the Civil Liberties, Justice and Home Affairs Committee of the European Commission considered and approved submitted amendments to the original draft of the proposed General Data Protection Regulation on 21 October 2013. The European Parliament aims to agree upon a finalised version of the Regulation by May 2014. Despite these intentions, recently published conclusions reached by the European Council have spurred intense debate over the possible postponement of the Regulation until 2015, and thus possible abandonment of the current draft proposal. However, given the political climate after revelations regarding surveillance of European citizens by the United States' National Security Agency, it remains a distinct possibility that the Regulation could meet the summer 2014 deadline. (The current draft as approved on 21 October 2013 can be downloaded here and here.)