scieee AI-readable full text Open interactive document viewer

Personal and Sensitive Data Kick-Off Meeting Slides

Futter, Christian; Krebs, Christine; Varrato, Francesco; van Rekum, Simon; Cotting, Alexandre; Churakova, Olga

Abstract

The Personal and Sensitive Data Kick-Off presentation was held on 28.10.2025 in order to inaugurate the newly constituted SRDSN Personal and Sensitive Data Node. The aim was to present the node organisation to its members and to allow the individual working groups constituting the node to present their aims and agendas to the entire node.

Full text

SRDSN Node Personal and Sensitive Data Official Kick-Off Meeting Christine Krebs, Christian Futter 28 October 2025 Agenda Time 14:15 Welcome and introduction 14:20 Founding and aims of the node 14:25 Presentations of potential working groups (10 min per topic): Simon van Rekum: WG data anonymization Francesco Varrato: Education on data protection in research Alexandre Cotting: Efficient training in data protection Olga Churakova: Data ethics and sensitive data governance 15:10 Voting for co-leads 15:20 Planning 2026 15:40 Wrap-up 15:45 End of kick-off meeting Founding of the node •Spring 2024: Initiation of SRDSN Working Group for Personal and Sensitive Data (Melanie, Olga, Christine) with prospect to transform Working Group into a Node. •Fall 2024: Development of Node Concept, Christian joined •Approval of the Node by SRDSN steering committee in July 2025 •Presentation of the node in the SRDSN Meeting in November 2025 Aims of the node •Bring data professionals together to exchange knowledge at the national level •Obtain input from experts on the topic •Provide a platform to share resources •Foster the exchange of needs and solutions covering all aspects of available support in personal and sensitive data •Be intra-, inter-, and -transdisciplinary Organization of the node •Bi-annual node meetings for all members, additional meetings of potential working groups •There are two co-leads, every fall one co-lead will be newly elected for two years •The node is planned to be open ended Internal Communication •PSDN Element room: Ask PSD related questions, share relevant news (e.g., events, new legislations) -> Please join! Link •SRDSN Zenodo Community: If possible, output from the node will be shared on Zenodo (e.g., the slides of this meeting). Link •Google Drive (SRDSN_Network): Find all node related documents (e.g., minutes, slides, reports). Link Working Groups •For registration to a WG please write your name in to the corresponding table in the Google spreadsheet. Link • The following working groups will be presented: ○WG data anonymization (Simon van Rekum) ○Education on data protection in research (Francesco Varrato) ○Efficient training in data protection (Alexandre Cotting) ○Data Ethics and Sensitive Data Governance (Olga Churakova) PSDN Kick-off meeting WG Data Anonymization 8 28/10/2025 Simon van Rekum [email protected] WG Data Anonymization 9 • Goal/proposition • develop workflows and best practices for the anonymization of quantitative and qualitative data • knowledge exchange • Context: ZHAW dedicated swissuniversities project DSembedded 2.0 at ZHAW (B5.2 extension) • Particular focus: possible use of GenAI for the anonymization of larger datasets EPFL GEP Guidelines and principles concepts 🡪 rules 🡪 practices Ethics is … difficult to teach Struggling distinction #1 concepts 🡪 rules 🡪 practices ▪Privacy: Rights of an individual to be protected from unwarranted interference with their personal life, family, home, communications, and personal data by public authorities or other persons. ▪Security: Protection against the unauthorized access to data DMP content of the mySNF form Struggling distinction #2 Information related to an identified or identifiable natural person: ▪Data that can directly* identify a person (e.g., name, photo, etc.) ▪Data that can make a person identifiable by combining information** ▪Information together with all the means reasonably likely to be used by anyone to identify an individual. Information related to: ▪religious, philosophical, political or trade union views or activities; ▪health, genetic data, private sphere or affiliation to a race or ethnicity; ▪biometric data that uniquely identifies a natural person; ▪administrative and criminal proceedings or sanctions, and social assistance measures. PERSONAL DATA PERSONAL SENSITIVE DATA Federal Act on Data Protection concepts 🡪 rules 🡪 practices Struggling distinction #3 1. Name; 2. Civil Identification Number; 3. Passport number; 4. Driver's license number; 5. Address details; 6. Email Address; 7. Phone number; 8. Fax Number; 9. Bank Account; 10. Vehicle identifiers and serial numbers, including license plate numbers; 11. Social Security Number; 12. Health Card Number; 13. Medical Record Number; 14. Device identifier and serial number; 15. Biometric identification codes, including fingerprints and voice prints, etc.; 16. Full face picture images and any other; comparable pairs of images; 17. Genetic information about a person; 18. Account number, certificate number; or license number; 19. Internet Protocol (IP) address number; 20. Web Universal Resource Locators (URLs) ; … 1. Gender; 2. Date of birth or age; 3. Date of event (e.g. admission, surgery, discharge, visit-related date); 4. Geographic range (e.g., zip code, building name, region); 5. Ethnic origin; 6. Nationality, place of origin; 7. Language; 8. Aboriginal Identity; 9. Visible minority status; 10. Job title, work unit, department and other occupational information; 11. Marital Status; 12. Education level; 13. Years of schooling; 14. Total revenue; 15. Religious beliefs; … * DIRECT IDENTIFIERS ** INDIRECT IDENTIFIERS concepts 🡪 rules 🡪 practices ANONYMIZATION PSEUDONYMIZATION (DE-IDENTIFICATION) Struggling distinction #4 ▪REPLACE Use identifiers as keys, stored separately & securely ▪ENCRYPT Encrypt the data and store the encryption key securely ▪… ▪REMOVE Suppress data (ex. the outliers) ▪GENERALIZE Diminish granularity by binning the variables ▪SHUFFLE Shuffle over a column without losing utility ▪FAKE Add fake data while preserving correlations ▪… ✔ REVERSIBLE ✔ FOR ACTIVE DATA ✔ IRREVERSIBLE ✔ FOR SHARING / PUBLISHING concepts 🡪 rules 🡪 practices Struggling distinction #5 K-anonymity Anonymization - Generalize (replace specific values with ranges) - Suppress (remove attributes) L-diversity Anonymization - Diversify sensitive attributes within each equivalence class T-closeness Anonymization - Maintain similar distribution of sensitive attributes across equivalence classes - Use in combination with k-anonymity and l-diversity Differential Privacy Anonymization - Add calibrated random noise to analysis results - Calibrate noise to ensure output insensitivity to individual records Tokenization Pseudonymization - Replace sensitive data with reversible, randomly generated tokens - Store mapping between tokens and original data securely Hash-based Pseudon. Pseudonymization - Replace identifiers with hashed values - Store mapping between hashed values and original identifiers securely Secure Multiparty Computation (SMC) Encryption - Use cryptographic protocols (e.g., secret sharing, homomorphic encryption) to enable joint computation on distributed private data Homomorphic Encryption Encryption - Use encryption schemes allowing computations on encrypted data - Perform computations on encrypted data to enable outsourcing to untrusted parties TECHNIQUE CONCEPT TYPE concepts 🡪 rules 🡪 practices Rules as laws are a TLDR www.epfl.ch/campus/services/data-protection/in-practice/privacy-in-research Other countries? ▪A federal list of international bodies guarantees an adequate level of data protection ▪For certified USA companies use a "master contract" with a simplified DPA Stay tuned 😟 concepts 🡪 rules 🡪 practices Someone likes it visual DMLawTool (USI, UNINE, etc.) Health Data Ethics Map (ETHZ) concepts 🡪 rules 🡪 practices Digital Ethics Canvas (EPFL) EU AI Act Compliance Checker (EU) Ethics Review, yes or not? NO & NO HUMANS YES MAYBE Can combining the data lead to a person**? Any direct* or indirect** identifiers? No need Health data? HREC Canton ethics commission Can the data lead* to a specific person? Contact HREC or RDM Team NO YES NO, BUT HUMANS INVOLVED concepts 🡪 rules 🡪 practices EVOLVING! oDMP for ethics review oAnonymize ASAP (ideally, collect already anonymized data) oSave Privacy Policy + Terms & Conditions of all services/platforms oData Processing Agreement (DPA) signed by services/platforms oInformed consent + Data transfer + Data access + … oOrdinance on Human Research (HRO): anonymized data preserved for 10 years after project oOrdinance on Clinical Trials (ClinO): “retain all documents required for the identification and follow-up of participants, and all other original data” for 20 years Wait! Other suggestions / rules / caveats / … concepts 🡪 rules 🡪 practices Welcome SRDSN members, who are supporting researchers working on and with sensitive data in: ● Governing sensitive data access and publication ● Developing data governance ● Developing AI guidelines and recommendations for AI ethics by design ● Developing sensitive data infrastructure ● Developing data ethics recommendations, guidelines in intra-, interand transdisciplinary research Scope Swiss Personalized Health Network ● Enabling the responsible use of sensitive data and fostering national collaborations that advance science and benefit society Working Group: Data Governance ● To promote harmonized governance frameworks for data access, enabling equitable and trustworthy further use of routine health data throughout its entire lifecycle Research Data Alliance: Sensitive Data Interest Group ● Sets community standards and best practices to optimize working on and with sensitive data for research https://sphn.ch/ https://www.rd-alliance.org/ Goal and Objectives Goal: Knowledge exchange and -transfer on data ethics recommendations and governing sensitive data access and publication in intra-, interand transdisciplinary research across Swiss landscape Objectives are to: ● Develop a harmonized terminology across the Swiss landscape ● Provide data sensitivity classification ● Develop a knowledge exchange platform on responsible data, AI guidelines, ethics recommendations, and governance on sensitive data across disciplines and the Swiss HEIs Communication & Dissemination Communication: ● Internal communication via Element ● External communication via SRDSN LinkedIn, institutional webpages Dissemination: ● International Data Policy Journals and scientific Journals ● Presentations at SRDSN meetings, national and international conferences Planning ● 4 exchange meetings: February, April, June, September 2026 ● Presentation of WG within PSDN: Q4 2025, 2026 ● Article draft with the lead of the UniBE: due Q3-4 2026, feedback Q4 2026, submission Q1 2027 Contact PD Dr. Olga Churakova E-mail: [email protected] Voting for co-leads •The node co-leads are elected for a duration of two years •Eligible to vote are the node members •Each year one co-lead will be newly elected while the other co-lead is confirmed for his/her second year Planning 2026 • Biannually Meeting of the entire PSDN node • Presentation and discussion of a specialist or of the progress of one or more working groups •Any suggestion are welcomed and can be placed in the planning document on Google Drive (Link) and in the Element room. Thank you for your attendance!