GDPR for Research Data Management – workshop report

This blog post provides a brief overview of a workshop organised for the London Area Research Data (LARD) group on the implications of the General Data Protection Regulation (GDPR) for research data management. The event was held at the London School of Hygiene & Tropical Medicine on November 17, 2017. It was organised by Gareth Knight (LSHTM), in conjunction with Helen Porter (SOAS) and Laurence Horton (LSE). A second write-up of the session has been produced by Laurence Horton.
Gareth Knight, LSHTM’s Research Data Manager, opened the session by emphasising the importance of ensuring GDPR awareness across all levels of the university. The new GDPR legislation comes into force in May 2018, but he noted relatively little guidance existed tailored to the needs of research support staff. The meeting was intended to partially address this need by providing attendees with a better understanding of GDPR and an opportunity to discuss its implications for research data management. The topic clearly struck a chord with many people, attracting almost 70 attendees. Gareth emphasised that this was just the first step, with a need for follow-on events to improve understanding and compare implementations as we get closer to the May deadline.
Tim Rodgers of Imperial College London provided a gentle introduction to GDPR. GDPR was described as a set of rules that governed how organisations process personal data on data subjects (some of whom could be research participants). As part of the changes introduced by GDPR, the definition of personal data will be broadened to include machine-generated data generated through device use, such as location, cookies, and IP addresses, among others. Data subjects are also given additional rights over how information about them is used.
To address GDPR, organisations must adopt a “Privacy by design” strategy, implementing technical and organisational measures that enables them to protect data subject information and address associated risks. They must also demonstrate ethical compliant, maintaining evidence on how and when consent to collect and use information was obtained, and provide opportunities for individuals to view and correct information stored about them, or withdraw consent for its use (with some qualifications). Further information on these may be found in the 12 Steps to preparing for GDPR guide.
Although GDPR compliance requires significant work to implement, Tim argued it will benefit academic research over time. GDPR harmonises the rules surrounding the performance of scientific, historical and health research across the European Union, which will make it easier to collaborate across countries. The need to produce a ‘Privacy Impact Assessment’ to ensure the rights of the data subject are taken into account when performing research will also help researchers to recognise and fulfill their ethical obligations.
Paul Stokes, Senior co-design manager at JISC,led a dynamic discussion on the support needs of research support staff attending the event, making extensive use of Sli.do to gauge the implication of GDPR for attendees. Paul had been given only 1 day notice by his manager that he would have to attend, so we were extremely pleased that he could make such an extensive contribution to the session.
After determining that 95% of those who voted believed they would be directly affected by GDPR (with only 5% believing it was someone else’s problem within the institution), Paul moved on to describe the GDPR resources in-development at JISC and asked for suggestions on topics that would be helpful to cover in a forthcoming GDPR for RDM toolkit.


