An article of the European Journal of Human Genetics highlights the challenges faced by secondary research on personal data and biospecimens shared in the international biobanking and databanking community following the implementation of the European General Data Protection Regulation (GDPR). By secondary research, experts refer to research on data or biospecimens collected for research studies and non-research studies, for example clinical care.
Amongst the challenges faced by secondary researchers on personal data in the context of EU’s GDPR is the treatment of anonymous versus pseudonymous data, and the current understanding of anonymised data and the way the research community is used to handling this type of data. Data in secondary research is key-coded (research subjects are assigned identifiers) and as this considered to be personal data, the research community has to comply with policy or formal agreement, and without a key, is impossible to deidentify or anonymise data and still allow for the follow-up of data subjects. Also, under the GDPR, pseudonymised data are considered as personal data. In biobanking research for example, key-coded data cannot be considered as not being personal data. In other regulatory regimes, for instance the United States (US), the US Health Insurance Portability and Accountability Act of 1996 (HIPAA), key-coded data can be deidentified or anonymised, and researchers can deidentify protected health data following advice of an expert who is able to ascertain that there is none or small risk to use the information, alone or in combination of other available information. The United Kingdom’s Health Research Authority does not consider pseudonymised data to be personal data.
Another challenge is the lack of a broad consent. Obtaining the consent of data subjects would solve the personal data issue, however in this area as well, while GDPR allows data subjects to consent to researchers using their data, there is a lack of a broad consent from EU and Member State regulatory agencies. Secondary research on health or genetic data are required to have a lawful basis according the Article 6 of the GDPR. Experts recommend that s special exceptions are introduced to allow ease use of personal data by the research community, including health data, in the case of scientific research. Such exceptions already exist, but are not yet applied to secondary use of personal data, like biobanking and databanking data. Other challenges are the collaboration between European Union research community and non-EU research community (GDPR requires a lawful basis for data transfer from the EU and outside the EU).
In conclusion, GDPR presents challenges for secondary research due to the absence of a clear basis on the way to proceed with personal data transfer, and the few existing regulations vary among EU Member States with significant costs. The European Data Protection Board (EDPB) guidance can help the research community in the anonymisation and the processing of personal data, and on cross-border transfer. The European Data Protection Supervisor, in a 2020 January opinion, called for a further guidance in 2020 with a focus on the relationship between data protection and scientific research.