SECURITY AND PRIVACY SUPPORT MEASURE FOR SURPASS IMPLEMENTATION

The consortium developed ‘Security and Privacy support measures for SurPass v2.0 implementation in clinical research/public health and patient-centred healthcare processes’ (as reported in D3.4). During the PanCareSurPass project, clinics in Austria, Belgium, Germany, Italy, Lithuania and Spain collected and sent data for survivors enrolled in the implementation study to the SurPass v2.0 platform in Italy. The SurPass platform was used to process relevant data for the health-related conditions and treatments received by cancer survivors. Strong data protection measures were needed to make sure that the processed data was safe. Partners considered both European and local data protection regulations in their evaluation of the SurPass platform’s Security and Privacy support measures. Measures conform with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General data protection regulation (GDPR)), in particular Article 25 (principle of privacy by design). Partners ensured that they implemented controls related to security and privacy options, including right exercising and data processing accountability. Activities were identified as necessary for clinics implementing the SurPass, including establishing privacy by design, conducting data protection impact assessments (DPIAs), establishing local training calendars, carrying out program software/system audits and using security tools. 20 recommendations were developed to assure all the requisite of “Privacy by Design and by default”, which ultimately involves complying with the GDPR, were applied on the IT system’s security and personal data protection of the SurPass Platform (CINECA-Italy) and also at each PanCareSurPass clinic site (CCRI/AIT-Austria, KU Leuven-Belgium, UMC-Mainz/UzL-Germany, IGG-Italy, VULSK-Lithuania, HULAFE-Spain).

The summary above about the Security and Privacy support measures for SurPass v2.0 implementation in clinical research/public health and patient-centred healthcare processes will be made available on the PanCare website in the Toolkit. Clinics implementing the SurPass in future will be provided with further details by the SurPass provider.

Experiences and Best Practices from the clinics

The clinics participating in the SurPass Implementation Study reported the implementation of basic privacy measures to ensure protection of the survivors’ medical data. Measures included institutional cybersecurity, pseudonymizing data before transmission to the platform, and restricting access to the tool to a limited number of employees. Most participating clinics found internal and external support regarding privacy matters helpful. Support was provided by institutional data protection officers, ethical committees, IT departments or GDPR experts.

Disclaimer

PanCare strives to provide accurate and complete information that is up-to-date as of the date of publication.

No warranty or representation, expressed or implied, is made concerning the accuracy, reliability, completeness, relevance, or timeliness of this information.

The PanCare materials are free to use for anyone aiming to inform about late effects and long-term survivorship care. However, no financial advantage may be achieved. All communication should reference PanCare and link to the PanCare website.

PanCareSurPass has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 899999. The material presented and views expressed here are the responsibilities of the author(s) only. The EU Commission takes no responsibility for any use made of the information set out.