Arrow Left Home

Webinar joint controllers in large research consortia

What are the limits of being a joint controller?

This webinar is organized in collaboration with

For whom

Legal counsel and DPOs of partners in biomedical research consortia and all others who are involved in European research collaborations with at least some basic background knowledge of the GDPR, from researchers to funders.

Time and place

The webinar will take place on 13th April 2021, between 14:00 and 17:00 (CET). It is an online event. Complete schedule and a WebEx link will be sent after the registration.

Register

  • Chevron Down

    Program

    13.30-14.00

    Virtual walk-in

    14.00-14.05

    General introduction
    by moderator Petra Wilson (Health Connect Partners)

    14.05-14.20

    Introduction of the theme
    by Evert-Ben van Veen (MLCF)

    14.20-14.50

    First use case: Platform as a Service*
    (introduction by Jan Willem Boiten, Lygature)
    (comment by Martin Boeckhout, MLCF)

    14.50-15.20

    Second use case: A federated model*
    (comment by Vasco Dias, INESCTEC)

    15.20-15.30

    Break

    15.30-16.00

    Third use case: Central assembly of the data*
    (comment by Irene Schlünder, TmF)

    16.00-16.05

    Mentimeter questions

    16.05-16.35

    General discussion

    16.35-16.45

    Wrap up
    by Petra Wilson

    16.45-16.55

    Next steps, poll with mentimeter

    16.55-17.00

    Closure

    *All use cases will be introduced by Jan-Willem Boiten, Lygature

  • Chevron Down

    Presentations

  • Chevron Down

    Background

    Research consortia play a pivotal role in European health research. As we all know that research needs to be compliant with the General Data Protection Regulation (and applicable national legislation). A key concept of the GDPR is that of controller, i.e., the entity which alone or jointly with others decides about purpose and means of the data processing. All responsibilities for compliance rest primarily on the controller(s). With European research projects all partners usually have at least an advisory role in the data processing involved in the research. They all have common interest that the research succeeds. Yet, some of those partners may never have access to the data. That is not their role. And where several specific research questions are being analyzed by the same consortium, some partners may have access to some data but not to other data which belong to another aspect of the broader research endeavor. This makes it difficult to define the demarcation between controllers in the sense of the GDPR for the data or subsets of the data and other partners in the consortium with a more advisory or supporting role in the data exchange for the research to which all partners are committed.

    The interactive webinar will address these difficulties based on three use cases. The discussion during the webinar should give input for a white paper with guidelines how the demarcation might become clearer.

  • Chevron Down

    More about the legal background and demarcation problems

    Recently the European Data Protection Board (EDPB) issued draft Guidelines on the concept of controller and processor under the GDPR.  Amongst other things the (at the moment of writing) draft Guidelines discuss the issue of joint controllers, based on the decisions of the European Court of Justice. Joint controllership happens when there is a close entanglement in interests, purposes and – to a somewhat lesser extent - means. It does not mean that each party is also joint controller for all the preceding or subsequent procession of the other parties.  Joint processing as controllers relates to where that entanglement is the case.

    The cases thus far discussed by the EDPB were rather straightforward, involving only 2 parties. In large research consortia there are many parties who together committed to the purpose and means as described in the original research proposal in broad terms. They have a common interest that the project succeeds. Yet, it would take things to the extreme to label all those parties (sometimes more than 50) as joint controllers for all data processing which happens in the execution of the research. Some will only be involved in project management, dissemination or ELSI support. Some parties will only be involved in the data processing of specific question of the research and only collect or have access to data relating to that specific question. Yet, that a party in the consortium never has access to the personal data is as such not a criterion ac.  A company which commissions a specific survey to a marketing research bureau will often be the controller even though that company will only receive the aggregated statistical outcomes.

    So, what are the limits? Entanglement, as we have phrased it, should be nuanced, perhaps in the light of the purposes of the research and the interests of the partners involved in the consortium. For some it is getting patents or publications out based on the data. But they might only use subsets of the data for that. Others will not have access to any personal data at all. They only have an advisory role about the research to be executed such as ethics or data protection advisors. But being part of the consortium, also those have an interest that the research succeeds and that the objectives are met. There is at least some form of entanglement. Any demarcation is feeble and prone to interpretation problems.

  • Chevron Down

    Use cases to be discussed at the webinar

    1. A consortium creating a Platform as a Service (PaaS) which offers analytic tools to other researchers to analyze their data. A researcher can organize its own research pipeline on the Platform, either with only the data which that researcher has submitted or combined with the data of other data contributors.  Clearly that PaaS provider is a processor and each researcher doing research with his/her ‘own’ data a controller. Yet the situation becomes more complex when the consortium is not neutral to the research questions and the legal basis to analyze the data and hence influences what data may be analyzed for what purposes on the platform.
       
    2. A consortium with a federated system, where data are being exchanged based on a common model, a federated data exchange infrastructure sustained by the consortium and a common governance of the consortium to decide which data may be exchanged under what conditions. Those data may either be personal data or aggregated anonymized results of analyses made on premise at the sire of each data contributor as can be the case with a ‘data shield’ like model. Yet, though the consortium has agreed upon the governance and has set up the infrastructure, not all partners of the consortium will be involved in the datasharing for a specific research project via the infrastructure. That will depend on each specific project.  
       
    3. A consortium where data from the project results will be centrally registered. These data will consist of newly generated raw data from the research, such as via a clinical trial, but also already existing datasets may be added. Several specific research questions can be run on that central data platform and not all partners may be at the same time using the data and certainly not all data. That will depend on the specific research question and access rules tailored for the specific research questions. But all partners have been involved in the data management plan for the platform and have a stake that the research succeeds through all the specific research questions combined.

Registration

The webinar is organized by

The webinar is induced by questions raised in the following projects IDEA-FAST, RECAP-preterm, HEAP, Big Picture, EOSC-life 

Share this page…