SlideShare a Scribd company logo
1 of 14
Legally bound?
Data protection legislation and
research practice
Laurence Horton
(laurence.horton@gesis.org)
Katharina Kinder-Kurlanda
(katharina.kinder-kurlanda@gesis.org)
Presentation for 39th IASSIST Annual Conference
GESIS, Cologne, 30 May 2013
Legal context in the UK
• Data Protection Act (DPA)
• Information Commisioner Office (ICO)
guidance and commissioner precedents
Legal context in Germany
• Federal Data Protection Act =
Bundesdatenschutzgesetz (BDSG)
– “The purpose of this Act is to protect individuals
against infringement of their right to privacy as
the result of the handling of their personal data.“
– “Personal data” = any information concerning the
personal or material circumstances of an identified
or identifiable natural person
Anonymisation in the UK
"Anonymisation is the process of turning data
into a form which does not identify individuals
and where identification is not likely to take
place."
See: http://www.ico.org.uk/for_organisations/data_protection/topic_guides/anonymisation
Anonymisation in Germany
BDSG,§3,6 on ‚factual anonymisation‘:
“’Rendering anonymous’ shall mean the alteration
of personal data so that information concerning
personal or material circumstances cannot be
attributed to an identified or identifiable natural
person or that such attribution would require a
disproportionate amount of time, expense and
effort. “
Legal context of the EU
1995 Data Protection Directive
• personal data is any information relating to an
individual
• apply when a person can be identified,
directly or indirectly
• implemented (unevenly) through member
states
Current issues for researchers
Lack of harmonization in data access regimes due to
legal uncertainty
• What's fine for a Belgian is not fine for the Dutch
• Gaps, inconsistencies and contradictions
– Under what circumstances are small cell values
problematic...?
– What degree of security measures is 'enough'?
– Does the door of a safe room need to be closed...?
Current issues (2)
Technological developments are ahead of legal
ones
• Therefore 'best practice' has become very
important as everybody is cautious (Avoiding
unnecessarily conservative approaches)
– e.g.: the proposed EC current reforms
Current Issues (3)
Balancing researchers' needs against a public
mood of (understandable) suspicion
• Example: high profile cases of personal data leakage
(not research data, but still...)
• Example: Albrecht report: Legitimate concerns
regarding marketing interests pushing for cutting
down on privacy lead to researchers being 'punished'
• But: Data becomes more transparent through
research!
Archives to the rescue?
• Data archives are expanding their role within data
infrastructures. Not just end point data providers,
but support services for those creating data
– We have an interest in ensuring good quality data is
produced
• Archives build up a store of expertise through
experience
– We encounter a lot more data and a diversity of
projects that most researchers never encounter
Where archives help
Combating ignorance in the research community about
data protection laws, by...
• Active help with specific queries
• Proactive help: Creating training and support materials
Providing the technological capacity to share data that
could not ordinarily be shared
• Legally binding user licenses
• Secure data services for rich but sensitive data
Example: Advising researchers
Dear GESIS,
someone has accused me of profiling her and
asks that my research be approved by the
Bundesdatenschutzbeauftragter.
Please advise on whether doing so is required by
the law in Germany?
Yours,
a researcher.
Example: GESIS SDC -
Secure Data Center
• Contractual safeguards
• Technical safeguards
• Organisational safeguards
Thank you!

More Related Content

More from CESSDA Training

Alive and kicking! Keeping data re-usable in the European Values Study
Alive and kicking! Keeping data re-usable in the European Values StudyAlive and kicking! Keeping data re-usable in the European Values Study
Alive and kicking! Keeping data re-usable in the European Values Study
CESSDA Training
 
Access Policies and Licensing for Archives and Repositories
Access Policies and Licensing for Archives and RepositoriesAccess Policies and Licensing for Archives and Repositories
Access Policies and Licensing for Archives and Repositories
CESSDA Training
 

More from CESSDA Training (11)

Was sind Daten, Forschungsdaten, Metadaten?
Was sind Daten, Forschungsdaten, Metadaten?Was sind Daten, Forschungsdaten, Metadaten?
Was sind Daten, Forschungsdaten, Metadaten?
 
Supporting the creation, management, and long-term preservation of social sc...
Supporting the creation, management, and  long-term preservation of social sc...Supporting the creation, management, and  long-term preservation of social sc...
Supporting the creation, management, and long-term preservation of social sc...
 
Academic Writing and Research Data Management
Academic Writing and Research Data ManagementAcademic Writing and Research Data Management
Academic Writing and Research Data Management
 
Alive and kicking! Keeping data re-usable in the European Values Study
Alive and kicking! Keeping data re-usable in the European Values StudyAlive and kicking! Keeping data re-usable in the European Values Study
Alive and kicking! Keeping data re-usable in the European Values Study
 
De-mystifying OAIS compliance Benefits and challenges of mapping the OAIS re...
De-mystifying OAIS compliance  Benefits and challenges of mapping the OAIS re...De-mystifying OAIS compliance  Benefits and challenges of mapping the OAIS re...
De-mystifying OAIS compliance Benefits and challenges of mapping the OAIS re...
 
Access Policies and Licensing for Archives and Repositories
Access Policies and Licensing for Archives and RepositoriesAccess Policies and Licensing for Archives and Repositories
Access Policies and Licensing for Archives and Repositories
 
A Look at CESSDA and Data Re-use Licenses
A Look at CESSDA and Data Re-use LicensesA Look at CESSDA and Data Re-use Licenses
A Look at CESSDA and Data Re-use Licenses
 
Archive and Data Management Training Center
Archive and Data Management Training CenterArchive and Data Management Training Center
Archive and Data Management Training Center
 
Archiving and Data Management Training and Information Center
Archiving and Data Management Training and Information CenterArchiving and Data Management Training and Information Center
Archiving and Data Management Training and Information Center
 
Archives as a market regulator, or how can archives connect supply and demand?
Archives as a market regulator, or how can archives connect supply and demand?Archives as a market regulator, or how can archives connect supply and demand?
Archives as a market regulator, or how can archives connect supply and demand?
 
Election studies: a research data management challenge
Election studies: a research data management challengeElection studies: a research data management challenge
Election studies: a research data management challenge
 

Recently uploaded

Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
kauryashika82
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
ciinovamais
 
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
fonyou31
 

Recently uploaded (20)

Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
9548086042 for call girls in Indira Nagar with room service
9548086042  for call girls in Indira Nagar  with room service9548086042  for call girls in Indira Nagar  with room service
9548086042 for call girls in Indira Nagar with room service
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..
 
fourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writingfourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writing
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Disha NEET Physics Guide for classes 11 and 12.pdf
Disha NEET Physics Guide for classes 11 and 12.pdfDisha NEET Physics Guide for classes 11 and 12.pdf
Disha NEET Physics Guide for classes 11 and 12.pdf
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
Interactive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationInteractive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communication
 
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptxINDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
 
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
 
Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17Advanced Views - Calendar View in Odoo 17
Advanced Views - Calendar View in Odoo 17
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
 
APM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across SectorsAPM Welcome, APM North West Network Conference, Synergies Across Sectors
APM Welcome, APM North West Network Conference, Synergies Across Sectors
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 

Legally Bound? Data Protection Legislation and Research Practice

  • 1. Legally bound? Data protection legislation and research practice Laurence Horton (laurence.horton@gesis.org) Katharina Kinder-Kurlanda (katharina.kinder-kurlanda@gesis.org) Presentation for 39th IASSIST Annual Conference GESIS, Cologne, 30 May 2013
  • 2. Legal context in the UK • Data Protection Act (DPA) • Information Commisioner Office (ICO) guidance and commissioner precedents
  • 3. Legal context in Germany • Federal Data Protection Act = Bundesdatenschutzgesetz (BDSG) – “The purpose of this Act is to protect individuals against infringement of their right to privacy as the result of the handling of their personal data.“ – “Personal data” = any information concerning the personal or material circumstances of an identified or identifiable natural person
  • 4. Anonymisation in the UK "Anonymisation is the process of turning data into a form which does not identify individuals and where identification is not likely to take place." See: http://www.ico.org.uk/for_organisations/data_protection/topic_guides/anonymisation
  • 5. Anonymisation in Germany BDSG,§3,6 on ‚factual anonymisation‘: “’Rendering anonymous’ shall mean the alteration of personal data so that information concerning personal or material circumstances cannot be attributed to an identified or identifiable natural person or that such attribution would require a disproportionate amount of time, expense and effort. “
  • 6. Legal context of the EU 1995 Data Protection Directive • personal data is any information relating to an individual • apply when a person can be identified, directly or indirectly • implemented (unevenly) through member states
  • 7. Current issues for researchers Lack of harmonization in data access regimes due to legal uncertainty • What's fine for a Belgian is not fine for the Dutch • Gaps, inconsistencies and contradictions – Under what circumstances are small cell values problematic...? – What degree of security measures is 'enough'? – Does the door of a safe room need to be closed...?
  • 8. Current issues (2) Technological developments are ahead of legal ones • Therefore 'best practice' has become very important as everybody is cautious (Avoiding unnecessarily conservative approaches) – e.g.: the proposed EC current reforms
  • 9. Current Issues (3) Balancing researchers' needs against a public mood of (understandable) suspicion • Example: high profile cases of personal data leakage (not research data, but still...) • Example: Albrecht report: Legitimate concerns regarding marketing interests pushing for cutting down on privacy lead to researchers being 'punished' • But: Data becomes more transparent through research!
  • 10. Archives to the rescue? • Data archives are expanding their role within data infrastructures. Not just end point data providers, but support services for those creating data – We have an interest in ensuring good quality data is produced • Archives build up a store of expertise through experience – We encounter a lot more data and a diversity of projects that most researchers never encounter
  • 11. Where archives help Combating ignorance in the research community about data protection laws, by... • Active help with specific queries • Proactive help: Creating training and support materials Providing the technological capacity to share data that could not ordinarily be shared • Legally binding user licenses • Secure data services for rich but sensitive data
  • 12. Example: Advising researchers Dear GESIS, someone has accused me of profiling her and asks that my research be approved by the Bundesdatenschutzbeauftragter. Please advise on whether doing so is required by the law in Germany? Yours, a researcher.
  • 13. Example: GESIS SDC - Secure Data Center • Contractual safeguards • Technical safeguards • Organisational safeguards