Abstract
Biobanks are essential infrastructures in current health and biomedical research. Advanced scientific research increasingly relies on processing and correlating large amounts of genetic, clinical and behavioural data. These data are particularly sensitive in nature and the risk of privacy invasion and misuse is high. The EU General Data Protection Regulation (GDPR) developed and increased harmonisation, resulting in a framework in which the specific duties and obligations of entities processing personal data—controllers and processors—were defined. Biobanks, in the exercise of their functions, assume the role of controllers and/or processors and as such need to comply with a number of complex rules. This chapter analyses these rules in the light of Article 89 GDPR, which creates safeguards and derogations relating to ‘processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes’. It identifies key compliance challenges faced by biobanks as data controllers and processors, such as determining whether the GDPR is applicable and its intersection with other regulations; when a biobank should be considered controller and processor; and what are the main duties of biobanks as data controllers and processors and options for compliance.
Author supplied keywords
Cite
CITATION STYLE
Nordberg, A. (2021). Biobank and Biomedical Research: Responsibilities of Controllers and Processors Under the EU General Data Protection Regulation. In Law, Governance and Technology Series (Vol. 43, pp. 61–89). Springer Science and Business Media B.V. https://doi.org/10.1007/978-3-030-49388-2_5
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.