scieee AI-readable full text Open interactive document viewer

Practical Data Protection in Research

Vishen, Neelam

Abstract

This presentation was created for an online workshop on the practical data protection in research, which took place on 6 November 2025 as part of the RDMTraining4NFDI hybrid event's interactive workshop series. The description provided to participants is given below. Data protection can sometimes feel like a maze, full of rules, exceptions, and grey areas. This session is designed to make it clearer and more manageable for people working in research data management (RDM) and research support. Drawing on real examples and practical experience, we’ll explore how GDPR principles can fit naturally into everyday research workflows. Together, we’ll look at practical tools, common scenarios, and simple strategies that help teams stay compliant without losing focus on good research. Whether you’re new to RDM or already supporting researchers, the session aims to give you the confidence and clarity to handle data protection in a realistic, hands-on way. Basically, to make you less nervous and more confident about finding the right resources and support, and to help make compliance a natural, regular part of your RDM journey.

Full text

Practical Data Protection in Research: Tools, Guidance, and Everyday Solutions Neelam Vishen, LL.M. Base4NFDI University of Mannheim 06/11/2025 1 What’s your first reaction when someone mentions GDPR in a research context? 06/11/2025 2 Which RDM domain best describes your work? 06/11/2025 3 True or False: A list of postal/zip codes is personal data. 06/11/2025 4 Metadata like (browser type, IP address) is not personal data. 06/11/2025 5 Why Data Protection is important for RDM? Data protection is essential in Research Data Management (RDM) to ensure ethical integrity, legal compliance, and the trust of participants whose data powers discovery. 06/11/2025 6 Protecting research data through legal clarity enables open, responsible science. Open Science Advocates 06/11/2025 7 How privacy-by-design enabled open data in a citizen science project. An illustration drawn from common best practices and real-world approaches used across several citizen science and open data initiatives. 06/11/2025 8 Project Planning Consent & Transparency Pseudonymisation & Safeguards Aggregation & Anonymisation Open Data Publication Basics of GDPR 06/11/2025 9 GDPR protects personal data and privacy Applies to any data that can identify a person Sets rules for data processing 06/11/2025 Relationship between Controller, Processor, Researcher, DPO, Data Subject, and RDM Support. 16 ControllerController ProcessorProcessor DPODPO RDM SupportRDM Support ResearcherResearcher Data Subject GDPR Exceptions for Research purposes 06/11/2025 17 GDPR allows certain derogations for research under Article 89. These exceptions apply only if appropriate safeguards are in place (e.g., pseudonymisation). Rights such as access, rectification, or objection may be limited for research if: It is impossible or requires disproportionate effort. It seriously impairs research objectives. Always document the justification for relying on an exception. Article 3: GDPR applies based on where data processing happens and who the data subjects are. Example in ResearchDoes GDPR Apply?Scenario Processing within the EU/EEA YesProcessing within the EU/EEA A US research institute runs an online study inviting EU residents to take part. YesController or Processor outside the EU but targets EU participants A non-EU researcher analyses EU users’ social media activity for a study. YesMonitoring behaviour of individuals in the EU A Canadian team studies only local participants with no EU connection. NoProcessing by non-EU partners with no link to EU participants 06/11/2025 18 GDPR applies when personal data is processed by an organisation established in the EU, no matter where the individuals are. It also applies to non-EU organisations that target or monitor individuals in the EU. If neither condition is met, or only anonymised data is processed, GDPR does not apply. Here’s a tricky but important case. A Belgian university is part of an international research network but only contributes expertise, say, on study design or statistics. The actual participant data is collected, stored, and analysed entirely in Canada. The EU team never receives or accesses any personal data; they just give methodological advice. Even though the EU university is ‘involved’ in the project, GDPR doesn’t apply to that activity because no processing of personal data occurs within the EU, and the EU partner isn’t acting as a controller or processor for the data.” 06/11/2025 19 GDPR follows the data; if EU participants’ information is involved, it applies even outside the EU. Case Study Formalities for Publicly available personal data Public ≠ Free to use Social media posts, blogs, or open websites may be publicly accessible, but still count as personal data under GDPR. Even for public data, GDPR requires a legal basis, like consent, public interest (for universities), or legitimate interest (for others – private funded research, NGOs, etc). GDPR principles still apply: If you collect/process this data for research, legal grounds and safeguards still apply (e.g., lawful basis, transparency, purpose limitation, and if possible, data minimisation and retention). Inform individuals when feasible If collecting data indirectly (e.g., from a website), you must inform the person unless: →It requires disproportionate effort, →Or it would render the research impossible. Tip: Use layered privacy notices on project websites or info sheets shared via platform messages. 06/11/2025 20 Continued….. Check the Original Purpose of the Data If data was published for another reason (e.g., journalism, activism), reusing it in research might conflict with the original intent. Checklist Tip: Was the person aware that the data might be reused? Is the new research purpose compatible? Is there public interest or a legal basis? Have a Reuse Justification File Template Consider Platforms' Terms of Use. Even if data is public, platform policies may prohibit automated scraping or reuse without consent. 06/11/2025 21 Public Interest (in the context of GDPR and research) •How to tell if your project serves the public interest: Does the research address a societal challenge or public good? Is it funded by a public body (e.g., university, government, research council)? Is the outcome expected to benefit the wider public, not just commercial gain? •Examples: Studying social media posts to detect early signs of depression in teenagers. Analyzing trends in public transport complaints to inform better services. Note: Claiming "public interest" is not automatic. It should be justified and ideally backed by an institution’s legal or ethical review. 06/11/2025 22 Privacy by Design & Default Build data protection into your project from the start Collect only necessary data Use pseudonymisation or anonymization Keep records of your data processing and your decisions 06/11/2025 23 Practical Checklist for RDM Define what personal data you collect Identify legal basis Comply with GDPR Principles when processing personal data Obtain informed consent if needed Secure data properly Plan sharing and retention Follow institutional policies 06/11/2025 24 Interactive Activity – Try iVA Tool •Follow the Link •iVA1 – GDPR Application - https://wiki.bib.unimannheim.de/xerte/play.php?template_id=225#page1 •iVA2 – Consent Management https://wiki.bib.unimannheim.de/xerte/play.php?template_id=229#page1 •iVA3 – Legal Basis https://wiki.bib.unimannheim.de/xerte/play.php?template_id=217#page1 06/11/2025 25 https://www.berd-nfdi.de/legal-questions/ GDPR into Practice: Everyday Strategies Key Takeaways Plan early: Build privacy into your research design Map your data: Know what you're collecting and why Use trusted tools: Institutional storage, survey tools with privacy settings Strict Access Controls: Only people working with the personal data/metadata can access it. Transparency: Even if the data is public or indirectly collected, when reasonably possible Keep it documented: Data protection impact, Record of Processing Activity, legal basis, consent, or justification for using public interest. 06/11/2025 32 True or False: Anonymised data is always safe and can’t be re-identified. 06/11/2025 33 / / True or False: If someone posts personal data on a public forum, I can use it for research without restriction. 06/11/2025 34 / / Which of these are helpful, GDPRfriendly research practices? Options: A. Informing participants B. Using institutional storage C. Documenting your legal basis D. Using a personal USB stick for backups 06/11/2025 35 / / True or False: Consent is always required to process personal data in research. 06/11/2025 36 / / True or False: GDPR compliance is the DPO’s responsibility alone. 06/11/2025 37 / / You discover a dataset from a past project on a shared drive with names and emails, what’s your first step? 06/11/2025 38 / / What’s one thing you’ll do differently after today to make data protection part of your RDM routine?” 06/11/2025 39 / / Let’s Fill a ROPA together Article 30 of the GDPR mandates that data controllers and processors maintain a Record of Processing Activity(RoPA). Link to the doc: ROPA Template Think of a scenario from your work where you need to process personal data. Start by giving a suitable name that you will remember in case you need the document. 06/11/2025 40 Tools & Templates GDPR Compliance Checklist: https://gdprchecklist.io/ Anonimsation: https://www.edps.europa.eu/system/files/202104/21-04-27_aepd-edps_anonymisation_en_5.pdf Free online tool from Spain’s Data Protection Authority for GDPR compliance. Allows up to 500 processing activities to be recorded (ROPA), supports risk analysis, DPIA guidance, breach measures, and more: https://www.aepd.es/en/guides-andtools/tools/gestiona2 https://gestiona2.aepd.es/ There’s a plethora of free tools in GitHub “dsgvo - https://github.com/topics/dsgvo ” or "awesome-gdpr - https://github.com/LGPD-GDPR-Grupo-deEstudo/gdpr-awesome?tab=readme-ov-file " collections, including: Klaro (consent manager), Opendsr (data subject rights), Data Processing Agreement collection, and so on… 06/11/2025 41