Skip to content

Legal changes - #47

Merged
luisajansen merged 5 commits into
mainfrom
legal-changes
Sep 4, 2026
Merged

Legal changes#47
luisajansen merged 5 commits into
mainfrom
legal-changes

Conversation

@luisajansen

Copy link
Copy Markdown
Collaborator

Changes and clarifications to legal parts of the tutorial

Added Christian Sillaber as a contributor

@luisajansen
luisajansen merged commit a0334f1 into main Sep 4, 2026
1 check passed

@MalikaIhle MalikaIhle left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow so very lucky to have an expert review the legal content!

Comment thread foundations/gdpr.qmd

The person or organization that determines the purposes and means of processing personal data.

**In research:** This is typically the principal investigator (PI) or the research institution. If you design a study and decide what data to collect and why, you are the controller, and you carry the legal responsibility for data protection.
**In research:** This is typically the research institution, not you personally. Researchers are employed to do research, and when this includes data collection, the institution is, by extension, the controller and carries the legal responsibility, while the principal investigator (PI) carries operational responsibility in day-to-day research. This may differ, depending on contracts and exact projects, though. When you collaborate across different institutions, it gets more complicated: usually, this means that the involved institutions act as joint controllers (Art. 26), requiring them (or better: their DPOs) to allocate responsibilities between them within a written contract.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

please speall out acronyn DPO


If you plan to anonymize and share the data, this should be stated in the consent form. A useful tutorial on writing GDPR-compliant consent forms for research is provided by @Hallinan2023_InformationProvisionInformed. It is also helpful to tell participants about the intended level of anonymization and what it means for them (e.g., plausible deniability).

Consent needs to be **freely given** (Art. 4(11)); this can be tricky in research, when mixed with a power imbalance between the researcher and participant, as it may be the case when collecting data of students or patients. In that case, consent may be invalid as a legal basis for processing of data and relying on another basis is the best way (e.g., processing in the public interest, Art. 6 (1)(e)); your institution's DPO can advise you on this.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

spell out acronym DPO

5. and did not deviate from the approved plan.

If someone is re-identified anyway, that is an institutional matter—reassessing the dataset, restricting access, notifying where required—not evidence of your personal fault. In our **personal opinion**, researchers who follow an approved, documented procedure have fulfilled their obligations and are not at fault. The circular logic that "someone was re-identified, therefore your anonymization was too lenient" gets the causality backward.
If someone is re-identified anyway, that is an institutional matter—reassessing the dataset, restricting access, notifying where required—not evidence of your personal fault. In this case, the participant has a right to be compensated for damages (Art. 82) and the institution may need to pay administrative fines issued by the supervisory authority (Art. 83). In our **personal opinion**, researchers who follow an approved, documented procedure have fulfilled their obligations and are not at fault. The circular logic that "someone was re-identified, therefore your anonymization was too lenient" gets the causality backward.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ping @nicebread FYI!

@luisajansen
luisajansen deleted the legal-changes branch September 4, 2026 08:11
@luisajansen

Copy link
Copy Markdown
Collaborator Author

Sorry, Malika! I was to quick with the merge. Will add the spelling out of DPO when making
the next changes!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants