scieee AI-readable full text Open interactive document viewer

PhysAgeNet Deliverable D2.1 Compendium of legal, ethical and resource aspects for open data repositories

Jansen, Carl-Philipp; Kekäläinen, Tiia; Sigurðardóttir, Aðalheiður Svana; MASINI, ALICE; Portegijs, Erja

Abstract

Network on evidence-based physical activity in old age (PhysAgeNet) The deliverable is a main outcome of the COST Action CA20104 - Network on evidence-based physical activity in old age (PhysAgeNet). The main aim and objective of the Action is to establish a sustainable network fostering evidence-based research and practice of physical activity in older adults and enhancing integration of innovative ICT solutions based on open data consolidated research information, in order to promote health and reduce the burden of inactivity in ageing populations. Working Group 2 (WG2) This WG will take an inclusive and holistic view in order to define relevant outcomes, markers and moderators in the context of technology-assisted physical activity for older persons. These variables will be structured making use of the WHO’s Healthy Aging Framework. Based on expert discussions and literature review, we will report these and define standards for utilizing these (D2.2). We will condense the list of variables to a minimal dataset of ‘must do’ and ‘should do’ and possibly ‘nice to have’ variables, ensuring a holistic approach (D2.3). This enables inclusion of established measures as well as promising, novel variables in our eventual repository ensuring its sustainability. As a prototype and demonstration of the use of the designed data structure, data of one or more actual project(s) will be delivered to an existing open data platform (D2.4). To ascertain ethical, legal and financial aspects for these procedures we will create a compendium (D2.1) The WG1 objectives can be structured in the following research coordination objectives: The objective of this WG is to define what one should assess before and/or after technology-assisted physical activity interventions in old age and how to assess it. We aim to define standards and create a data structure to be implemented as open data repository utilizing an existing open data platform. Practical, legal, ethical and resource aspects will be documentedand tested for actual data delivery. The eventual repository will enable pooling of data from multiple studies after completion of this Cost Action. This WG will take a holistic approach making use of the Healthy Aging Framework to define and categorize outcomes, markers and moderators from multiple sources relevant for the investigation and evaluation of technology-assisted physical activity interventions.

Full text

CA20104 – Network on evidence-based physical activity in old age (PhysAgeNet) Deliverable D2.1 D2.1 Compendium of legal, ethical and resource aspects for open data repositories Contributors Working Group 2 Carl-Philipp Jansen (WG2 co-leader), Tiia Kekäläinen (WG2 leader), Svava Sigurðardóttir (WG2 member), Alice Masini (WG2 member), Erja Portegijs (former WG2 leader, active member) Participants in the expert discussions and review groups have contributed to these results. Table of Contents 1. Introduction........................................................................................................................................................ 3 2. Ethical considerations in data sharing........................................................................................................5 2.1. Introduction and key ethical principles................................................................................................5 2.2. Informed consent, participant rights, and data anonymization...............................................6 2.3. Ethical review and oversight..............................................................................................................7 3. Best Practices and Recommendations.........................................................................................................8 4. Resource Considerations in Data Sharing..................................................................................................9 4.1. Infrastructure requirements, budgeting, and data management.............................................9 4.2. Data management costs......................................................................................................................10 5. Conclusion.........................................................................................................................................................11 6. References.........................................................................................................................................................12 1. INTRODUCTION In recent times, the provision of access to data for scientific purposes has gained increasing importance, but also complexity. Data sharing plays a crucial role in health research by enhancing collaboration, improving efficiency, and fostering innovation. However, effective data sharing requires careful navigation of legal, ethical, and resource-related challenges. The implementation of regulatory mandates, internal procedures, and technical processes to enable data provision is challenging. As a result, this task is often delayed and inefficient in most projects. Standardised procedures for this matter could foster data sharing procedures and create higher impact and efficiency. Data sharing is integral to modern health research as it enables: Greater collaboration and efficiency across projects. Enhanced research impact by allowing broader analysis of large datasets. Improved patient outcomes by leveraging shared data to develop innovative treatments and solutions. However, data sharing introduces legal, ethical technical, and resource aspects and complexities that must be addressed. According to Horizon Europe, data should be deposited as soon as possible after its creation and no later than the project's completion. However, additional requirements apply: Data supporting a scientific publication must be deposited no later than the time of publication, following standard community practices. In the event of a public emergency, and upon request from the granting authority, immediate open access must be provided. If open access exceptions apply, the data should still be made available to legal entities that require it to address the emergency. In exceptional circumstances, data may be deposited after the project's conclusion. This report is being written under thorough consideration of the following documents: „Data Sharing Playbook“, issued by the European Federation of Pharmaceutical Industries and Associations (EFPIA), 2022; OpenAIRE‘s guide for researchers on „How to find a trustworthy repository for your data“ (How to find a trustworthy repository for your data); OpenAIRE’s „A Research Data Management Handbook – A primer on managing your research data“ (https://www.openaire.eu/rdm-handbook); 2. LEGAL CONSIDERATIONS IN DATA SHARING The content of Chapter 2 was contributed by external legal experts who are not affiliated with PhysAgeNet.MM 2.1. MIntroduction and Purpose of the Framework Working Group 2 has launched an initiative, WG2, and identified the need to assess the legal framework for sharing research data about technology-assisted physical activity for older persons. The objective is to determine the conditions under which research data can be openly shared for use by other researchers within the EU. The aim is to establish a data repository on an existing platform where researchers can share gathered research data and access datasets shared by other researchers. The need to separately assess the sharing of pseudonymized and anonymized data has been identified. Additionally, it has been noted that the research data is likely to include health data. This framework describes the main considerations for openly sharing research data within the EU. It should be emphasized that the framework does not provide detailed instructions, and member states participating in the EU COST Action network must take into account the requirements arising from national laws in each case. 2.2. Scientific Research Purposes in the Context of the General Data Protection Regulation (GDPR) and the Treaty on the Functioning of the European Union (TFEU) The General Data Protection Regulation (GDPR) does not precisely define “scientific research purposes”, but Recital 159 states that “the processing of personal data for scientific research purposes should be interpreted in a broad manner including for example technological development and demonstration, fundamental research, applied research and privately funded research. In addition, it should take into account the Union's objective under Article 179(1) TFEU of achieving a European Research Area.”. Article 179(1) of the Treaty on the Functioning of the European Union (TFEU) states that “The Union shall have the objective of strengthening its scientific and technological bases by achieving a European research area in which researchers, scientific knowledge and technology circulate freely, and encouraging it to become more competitive, including in its industry, while promoting all the research activities deemed necessary by virtue of other Chapters of the Treaties”. Based on the provisions, it appears that the initiative falls within the scope of “scientific research purposes”. The described research can be interpreted as contributing to the advancement of technological development, or as either fundamental research or applied research, as outlined in Recital 159 of the GDPR. Additionally, it should be noted that the scope of scientific research is broad pursuant to the GDPR. From the perspective of the TFEU, the described research is specifically intended to promote EU-wide research, which aligns with the objectives stated in Article 179(1) of the TFEU. However, in this case, data is being shared on a research platform, rather than being used solely by the controller for their own scientific purposes. This requires that various obligations under the GDPR are taken into account, depending on the specific circumstances (such as roles of the parties).MM 2.3. General Data Protection Regulation Below is a high-level list of the requirements of the GDPR that must at least be considered when sharing the research data in the context of the initiative. i. GOVERNANCE, ACCOUNTABILITY AND DATA PROTECTION BY DESIGN Data controller: Responsibility for data collection and data sharing: Determine who is the data controller and thus responsible for the collection and sharing of research data. It is possible that there is one or several independent data controllers or joint controllership (e.g., between universities or research organizations). Collaboration Between Data Controllers: When data is shared between universities or research organizations, both collaborating parties are responsible for their respective data processing activities if they act as data controllers. This entails: Establishing agreements on data processing terms (e.g., a data transfer agreement or joint controller arrangement). Clearly documenting the data-sharing process and its purpose. Relevant provisions: Articles 4, 5, 24, 26 of the GDPR. The role of the platform administrator(s): Responsibilities and duties: Clearly define responsibilities and duties of platform administrator(s) for ensuring secure processing and sharing of data.MM Access to the data: Monitor who has access to the data and how it is being used.MM Role(s) of the platform administrator(s): Define the role of the platform administrator from a data protection perspective (data controller or data processor). If you transfer data to data processor, a data processing agreement is required (Article 28 of the GDPR). If you act as a joint controller with other controller(s), you shall in a transparent manner determine your respective responsibilities (Article 26 of the GDPR). Relevant provisions: Articles 4, 5, 24, 26, 28 and 32 of the GDPR. Accountability and documentation: Documentation: Document all data processing activities, including the sharing of data among researchers. ROPA: Conduct a Record of Processing Activities (ROPA) where applicable.MM Relevant provisions: Articles 5, 24, 28, 30 and 32 of the GDPR. Data protection by design: Supporting GDPR requirements: The platforms and processes used for sharing data must support GDPR requirements (such as data protection principles outlined in Article 5).MM Development phase: Practical measures and technical solutions should be implemented during the development phase. Secure access to the data: Use platforms that enable secure access to the data.MM Relevant provisions: Articles 5, 25 and 32 of the GDPR. ii. LEGAL BASIS AND PURPOSE OF PROCESSING Grounds for processing personal data: Original Legal Basis: Ensure that the initial data collection is based on a lawful ground for processing (e.g., consent or public interest in scientific research, Art. 6(1)(e) or Art. 9(2)(j)).MM Legal Basis for Further Use: If the data is shared for use in new research purposes, this may require a new legal basis for processing, unless othe original legal basis also covers further use or oit can be interpreted that the further processing for scientific research purpose is compatible with the purpose for which the data was initially collected (see e.g., Recital 50 of the GDPR). Relevant provisions: Articles 6 and 9 and Recital 50 of the GDPR. Purposes of data processing and purpose limitation: Original legal basis: The original purpose for processing personal data must be compatible with the purpose of further processing. Legal basis for further use: The GDPR’s Recital 50 acknowledges that further processing of personal data for scientific research purposes is generally considered compatible with the original purpose, if: oThe further use remains within the limits of scientific research purposes.MM oThe further processing complies with the GDPR's requirements and includes necessary safeguards (Art. 89(1)). Contractual arrangements: Agree in writing with other researchers that the research data may only be further used for scientific research purposes. Relevant provisions: Article 5(1)(b) and Article 89(1) and Recital 50 of the GDPR.MM iii. DATA SECURITY AND PROCESSING SAFEGUARDS Anonymization and pseudonymization: Anonymization: If the research data is fully anonymized, the GDPR does not apply (see Recital 26 of the GDPR). However, it must be noted that the concept of anonymization must be interpreted strictly, which means that the data cannot be restored to an identifiable form, even with the use of additional tools, to be considered anonymized.MM Pseudonymization: If the data is pseudonymized but individuals remain identifiable, the GDPR applies. In this case, adequate technical and organizational safeguards, particularly those ensuring data minimization, must be ensured (Article 89(1) of the GDPR)).MM Relevant provisions: Article 89(1) and Recitals 26 and 156 of the GDPR.MM Access control, terms of use and security measures: Access control: Platforms used for data sharing must include access control (e.g., role-based permissions).MM Terms of use: If data is shared on open research platforms, clearly define its terms of use and ensure that the data remains limited to scientific purposes.MM Encryption: Encryption of data during transfer and storage must be implemented.MM Relevant provisions: Articles 5 and 32 and Recital 83 of the GDPR. iv. CONSENT AND RIGHTS OF DATA SUBJECTS Consent: M Clear and documented consent: Ensure that clear and documented consent has been obtained from participants for sharing their data for research purposes, especially for possible further use by other researchers. The scope and main requirements of consent: The consent must cover data sharing within the EU and the specific purposes of processing. Even though the scientific research purpose is interpreted as compatible with the original purpose under the GDPR (see e.g., Recital 50), consent must be broad enough to include data sharing and possible data reuse. Consent must be voluntary, specific, informed, and unambiguous. Consent may be given in writing, electronically, or in another form that clearly documents it.MM The withdrawal of consent: The data subject shall have the right to withdraw his or her consent at any time. This right must be communicated clearly to participants during the consent process. For pseudonymized or identifiable data, procedures must be in place to address withdrawal requests effectively. If the data has been anonymized, withdrawal is no longer applicable. Specific challenges in research contexts: Identifiable data: When sharing identifiable data, the right to withdraw consent at any time poses practical challenges, especially if the data has already been shared or reused.MM Anonymized data: If the data is anonymized, consent may not be required, as anonymized data falls outside the scope of the GDPR. However, strict anonymization standards must be met to ensure that re-identification is not possible. Relevant provisions: Articles 4(11) and 7 and Recitals 32, 42, 50 of the GDPR.MM Special categories of personal data: Explicit consent: If special categories of personal data are processed, the consent must be explicit (GDPR, Article 9 (2)(a)) in addition to the other requirements for consent (GDPR, Article 4 (11); Article 6(1)(a) and Article 7). Relevant provisions: Articles 4, 6, 7 and 9 of the GDPR. Rights of the data subject: Rights of the data subject: Ensure that the rights of the data subject can be exercised (e.g., the right to access, rectify, or object to the processing of their data) pursuant to Articles 12-22 of the GDPR. Exceptions for the rights of the data subject: EU or member state law may provide for derogations from the rights referred to in Articles 15, 16, 18 and 12 of the GDPR.MM Relevant provisions: Articles 12-22 and 89(2) of the GDPR. Informing data subjects: Informing data subjects: Data subjects must be informed in clear and understandable manner that their data is being collected and further shared for research purposes.MM Content of communication: Communication should emphasize how data is processed (description of processing activities) and what rights data subjects have. Additionally, data subjects should be informed how their data is protected. Relevant provisions: Articles 12-14, 15-22 and 32 of the GDPR. v. OPERATIONAL REQUIREMENTS Organizational requirements (policies, guidelines, etc.): Guidelines: Establish clear organizational guidelines or policies on how data is shared responsibly and lawfully. Documentation: Document practices related to data sharing, particularly among EU researchers.MM Relevant provisions: Articles 24, 25 and 89(1) of the GDPR. Data lifecycle: Data retention and deletion: Define how long the data (including backups) will be retained and when it will be deleted. Data deletion: Deletion practices must be clear and documented. Exception for longer retention periods: Personal data may be stored for longer periods insofar as the personal data will be processed solely for, for example, scientific research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures. Relevant provisions: Article 5 of the GDPR. vi. DATA TRANSFERS Data transfers: Contractual arrangements: Use data protection agreements or other formal arrangements among researchers if needed. Ensure that data protection and data security are implemented in data transfers. Safeguards for data transfers: If data is processed within the EU/EEA, safeguards for international data transfers are not required. If data is transferred outside the EU/EEA (e.g., the platform operator processes data in a third country), there must be an appropriate safeguard for the transfer (e.g., Standard Contractual Clauses (SCCs)).MM Openly available data: If the data is openly available without restrictions based on location, it can be presumed data is transferred outside EU/EEA. If the data contains personal data, the Data Controller is obliged to assess that it has a right to transfer the data as well as to assess risks based on the recipient´s country/area. In cases where data is openly available it might be hard to control and assess all the areas and their legislation where the data could be transferred. If the access to data is restricted to EU/EEA and/or it is anonymized efficiently so that it no longer is considered personal data, these obligations on data transfers don´t apply. Relevant provisions: Articles 5, 26 and 28 of the GDPR. Third-party processors: Contractual arrangements: If third parties (e.g., platform administrators or service providers) are involved in data sharing, ensure in writing that they comply with GDPR requirements.MM ensuring data accessibility for the public good. Ethical frameworks should promote nondiscriminatory access to research data. Lesson learned from ethics review boards provided important guidance for ongoing review of research using personal data. In studies that need approval from ethics committees, there should be information in the research plan about data collection and use. Researchers provide all necessary information about the data use, and that should include data sharing in the future. Ethics committes assess risks to data subjects in the context of benefits for science and society, and potential risks associated with data sharing and open data repository is primarily privacy risks that can cause informational harm. Confidentiality and data protection are key principles in responding to such potential harm and for respecting the privacy of data subjects. 4. BEST PRACTICES AND RECOMMENDATIONS Early stakeholder involvement Engage legal, ethical, and resource experts early in the project to prevent delays. Identify key decision-makers and involve them in negotiations from the outset. Provide training on responsible data handling and sharing. Clear and standardized documentation Use pre-approved templates for agreements to reduce administrative burden. Maintain detailed data flow diagrams to clarify processing roles. Proactive risk mitigation Address potential GDPR conflicts and IP concerns before formalizing data-sharing agreements. Transparency about planned data sharing and open data repositories at the beginning of research if possible, and explictly explain the use of data in the consent process. Adopting the SAFE Data Standard: security measures, anonymization, funcionality, and ethical compliance – to maximize research potential while safegarding privacy. Develop contingency plans to handle unforeseen challenges. Promoting a data-sharing culture Organizations should cultivate an internal culture that values data sharing and recognizes its benefits. Transparency and mutual agreements among stakeholders will ensure efficient collaboration. Trustworthy Digital Repository (TDR) for data protection to foster trust and respecting privacy. Use cloud-based or decentralized storage for scalability and accessibility. Implement APIs for automated and efficient data exchange. Monitor network bandwidth to prevent slowdowns or bottlenecks. Ensure system interoperability to facilitate seamless integration. 5. RESOURCE CONSIDERATIONS IN DATA SHARING Efficient resource allocation ensures that data-sharing initiatives are sustainable and cost-effective. 5.1. Infrastructure requirements, budgeting, and data management With regards to infrastructure and technology requirements, organizations must select an appropriate data-sharing model: Centralized Model: A single repository for data storage. Federated Model: Distributed data access without centralizing storage. Hybrid Model: A mix of both approaches. Standardized common data models and existing platforms should be leveraged to avoid unnecessary duplication. With regards to budgeting and cost management, infrastructure costs for secure data storage, legal and compliance costs (e.g., GDPR assessments, legal counsel), and personnel costs for data governance and security management must be considered. Developing a Data Management Plan (DMP) ensures clarity on data-sharing workflows. Within this task, roles should be assigned for data governance oversight (e.g., Data Protection Officers), legal compliance (e.g., contract managers), and IT and security (e.g., cybersecurity experts). According to the Research Data Management Handbook, a DMP briefly defines: how the data will be created; how it will be documented; who will be able to access it; where it will be stored; who will back it up; whether (and how) it will be shared and preserved. Data-sharing initiatives must adhere to recognized security standards to mitigate risks. Therefore, organizations should implement access control mechanisms (e.g., role-based access), encryption techniques for data transmission, and audit trails to monitor data access and compliance. Long-term data sustainability strategies should be embedded in project planning, whereas publicprivate collaboration can enhance resource availability and long-term data access. 5.2. Data management costs Proper planning for data management and sharing is essential, as these activities require both time and resources. Early planning can help minimize costs. Expenses related to open access for research data can be considered eligible costs, for example under a Horizon 2020 grant, provided they meet the conditions outlined in the respective Grant Agreement. Generally, this means they must be budgeted in advance and approved in the grant proposal, and they can only be claimed during the project's duration. As an example, under https://www.openaire.eu/how-to-comply-to-h2020-mandates-rdm-costs a tool is provided to estimate costs for reseacrh data management. A four-step approach is advised (see link above): “Step 1:MCheck the data management activities in the table and tick those that may apply to your proposed research. Step 2:MFor each selected activity, estimate the additional time and/or other resources needed and cost this, e.g. people’s time or physical resources needed such as hardware or software. Find out which resources, e.g. for data storage and backup, are available to you from your institution. Consider whether you need a dedicated data manager. Step 3:MAdd these data management costs to your research application. Coordinate resourcing and costing with your institution, research office and institutional IT services. Step 4:MPlan the data management activities in advance to avoid them competing with the need to focus on research excellence.“ 6. CONCLUSION Legal, ethical, and resource-related considerations are fundamental to successful data sharing. By establishing clear legal frameworks, ensuring ethical compliance, and optimizing resources, organizations can create robust, sustainable, and impactful data-sharing initiatives. Proactive planning and adherence to best practices will facilitate seamless collaboration, enhance research impact, and foster trust among stakeholders. 7. REFERENCES „Data Sharing Playbook“, issued by the European Federation of Pharmaceutical Industries and Associations (EFPIA), 2022. OpenAIRE‘s guide for researchers on „How to find a trustworthy repository for your data“ (How to find a trustworthy repository for your data). OpenAIRE‘s guide for researchers on „How to identify and assess Research Data Management (RDM) costs“ (https://www.openaire.eu/how-to-comply-to-h2020-mandates-rdm-costs). OpenAIRE’s „A Research Data Management Handbook – A primer on managing your research data“ (https://www.openaire.eu/rdm-handbook). Ethics and data protection, p. 11: https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/guidance/ethicsand-data-protection_he_en.pdf Open science: https://rea.ec.europa.eu/open-science_en Ethics and data protection, p. 11: https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/guidance/ethicsand-data-protection_he_en.pdf Ethics and data protection, p. 12: https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/guidance/ethicsand-data-protection_he_en.pdf Ethics and data protection, p. 11: https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/guidance/ethicsand-data-protection_he_en.pdf Ethics and data protection, p. 12: https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/guidance/ethicsand-data-protection_he_en.pdf